jamin100 Posted June 9, 2009 Posted June 9, 2009 I've just held a meeting with staff and i've upset quite a lot of them to be honest. One of the assistant heads an I went on a data protection course in Birmingham a few months ago and we were told about the requirement for encryption and the fact that sensitive school work should only be done on a school owned computer (teachers laptop, desktop etc) I've put whole disk encryption on staff laptops (truecrypt) Brought AES encrypted USB drives Told staff that sensitive school work (reports mainly) need to be done on a school computer We've also said that any USB drives that are used by staff must be ones brought by school but were not supplying them to TA's and therefore they cannot use USB drives. Now, the bit about TA's not using memory sticks was the heads idea. Do any other schools operate like this?
si84 Posted June 9, 2009 Posted June 9, 2009 We're about to! Just in the process of gathering information to write a data security policy. I am also about to start looking at Truecrypt so it's interesting to see how other's are using it.
PEO Posted June 9, 2009 Posted June 9, 2009 this thread talks about this topic http://www.edugeek.net/forums/how-do-you-do/26570-truecrypt-container-mode.html
FN-GM Posted June 9, 2009 Posted June 9, 2009 We use truecrypt to Encrypt whole laptop drives and to encrypt USB drives. We dont use the encrypt container method.
jamin100 Posted June 9, 2009 Author Posted June 9, 2009 We use truecrypt to Encrypt whole laptop drives and to encrypt USB drives. We dont use the encrypt container method. How did staff take it? There really not happy bunnys tonight
featured_spectre Posted June 9, 2009 Posted June 9, 2009 The staff have had to live with this for the past 3 months and i still get it in the neck. I have explained that if they werent such idiots then it wouldnt be a problem.
PiqueABoo Posted June 9, 2009 Posted June 9, 2009 There really not happy bunnys tonight Yeah but imagine how unhappy they'd be (and the school would be with them) if it was their name in the local press because they'd left some device containing confidential data in the pub. FWIW I think you've done the tech right.
FN-GM Posted June 9, 2009 Posted June 9, 2009 How did staff take it? There really not happy bunnys tonight No idea it was in place before i started. Everyone now does it automatically now.
powdarrmonkey Posted June 9, 2009 Posted June 9, 2009 We're just starting off down this road. I think you'll find that like a lot of things, there'll be lots of smoke without fire for a while until people start getting used to being more sensitive to what they're working on, and it'll die down gradually. It's partly for their own protection, after all.
john Posted June 9, 2009 Posted June 9, 2009 We seem to be skating around it but our Data Manager is with me and we should be doing it now, she is not impressed with schools sloppy data proection, shes from a high security background where she is used to having double protection so encrypted PC, with passworded files as a minimum, and is shocked that we just email confidental student info around and stick it on sticky notes and pin it on boards, leave it lying around etc. Must admit I am appalled, and am working on the above, but I know it will cause a revolt among staff, but I have said lets go for September for it
PiqueABoo Posted June 9, 2009 Posted June 9, 2009 I know it will cause a revolt among staff Ask them to explain why this kind of thing isn't a big issue for staff in large tracts of the real-world, or for that matter large tracts of the public sector?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now