Jump to content

Recommended Posts

Posted
Just spotted this on the news and after reading was wondering how many times we all tell users not to use the same password for everything?

 

Thing is, Don't you think the issue is with the fact the website got hacked by a pupil, more than someone used same pass though? :p If a pupil didn't get the password through the hack on website, they wouldn't gain access to MIS. Although I'm not saying it's right to use the same password for both either. :D

 

Steve

Posted
Thing is, Don't you think the issue is with the fact the website got hacked by a pupil, more than someone used same pass though? :p If a pupil didn't get the password through the hack on website, they wouldn't gain access to MIS. Although I'm not saying it's right to use the same password for both either. :D

 

Steve

 

It's a chicken and egg situation I think... if the member of staff hadn't used the same password for both the student would have had a more difficult time off 'hacking' the site.

Posted

It's great them saying the school will undertake annual penetration tests, who pays for that?

As an independant school how do we fund such a thing to stay safe?

 

Plus, I wish the media would stop using the term hackers and hacked for things such as a kid knowing a teachers password. From what the reports say, it wasn't a stolen password via malware/keylogger or any other attempts, so they could have seen said teacher type it in.

Posted

It is your legal responsibility to ensure compliance with DPA and all the costs associated with it, the same way you have to with H&S, fire regulations, etc ... there is also a healthy discussion going on via a LinkedIn group of eSafety law which is pointing to legal requirements around negligence in a number of areas in schools ...

 

You would not skimp on fire prevention / protection so you should not skimp on Data Protection.

Posted
Plus, I wish the media would stop using the term hackers and hacked for things such as a kid knowing a teachers password. From what the reports say, it wasn't a stolen password via malware/keylogger or any other attempts, so they could have seen said teacher type it in.

 

That's not how I read it. There was two parts to this:

 

a) The website hacked, and a password found.

b) Password used for MIS access as it could access both.

 

"This password was subsequently discovered during the original hacking incident and then used by a pupil to access other parts of the system."

 

Unless I read that wrong?

 

Steve

Posted
It is your legal responsibility to ensure compliance with DPA and all the costs associated with it

 

is annual network penetration a legal requirement (not being sarcastic here, genuinely asking)?

Posted
is annual network penetration a legal requirement (not being sarcastic here, genuinely asking)?

 

not specifically stated as a legal requirement (but then neither is encrypting laptops)

Posted

The legal requirement is that you have taken all appropriate action to ensure the security of your data. If you have staff laptops which hold data and they are taken off-site then not encrypting them is likely to be seen as a lax approach (as seen in a recent ICO case where data has been lost on a school laptop).

 

If you have a website which contains such data, or a VLE / MIS which holds it then you should either be looking to ensure that it is as secure as it needs to be, or the responsibility for managing that aspect is with a company who are contract to ensure the security of it. The choice of company and the verification that they are taking the appropriate action remains with the school (the risk is shared, not passed on), so the school still holds liability on this.

Posted
I feel for you on this one, best of luck regardless what happens!

 

No probs, gets me out of my cage. So....where are all the new babe-techs? ;)

  • 2 weeks later...
Posted (edited)

Ensure security? Cue the now very old favourite, the Ranum 'ULTIMATELY Secure Firewall'.

 

I'm not kidding, much. If pen test kind of territory is now a de-facto ICO hurdle, then you either swiftly drop most of the visionary-external-access-involvement-engagement ICT panacea tat from the last decade like a shot (ditto probably, for any cloud-fluff), focus very seriously on the security arms race yourself which is a bit of a full-time job, or sack some internal staff so you can afford to pay someone else to fret[1]. And given the latter doesn't excuse you entirely, how do you determine that Org X, Vendor Y, Pentesters R Us at al, will actually deliver at some arcane level that's way beyond your ken? Do you know what any gobbledygook certs do or don't prove? What may or may not be genuinely good value in this area? Etc...

 

The main difficulty I have is that should someone clever exploit some subtle hole despite having lots of "appropriate" boxes ticked, whatever they may be on the day the ICO reviews the breach, will they say: a) OK you took reasonable precautions vis-a-vis the genuine risks, were obviously unlucky, so we'll let you off, b) A hole existed and was exploited ergo you hadn't done enough?

 

[1] You might also discard one or two products from some 'well-known' vendors in this sector, because I'm 100% certain that some won't withstand serious scrutiny (not that you'd likely afford tests like that, but the vendors probably could on behalf of their customers interests).

Edited by PiqueABoo
Posted

 

If pen test kind of territory is now a de-facto ICO hurdle, then you either swiftly drop most of the visionary-external-access-involvement-engagement ICT panacea tat from the last decade like a shot (ditto probably, for any cloud-fluff),

 

 

Stop there, that gets my vote........and very well-worded, too, may I add.

 

'visionary-external-access-involvement-engagement ICT panacea tat .....', sums it all up in a nutshell to me.......eloquent turn of phrase, mate.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...