sister_annex Posted August 9, 2011 Posted August 9, 2011 http://www.guardian.co.uk/government-computing-network/2011/aug/08/house-bay-school-hampshire-data-protection-hack Just spotted this on the news and after reading was wondering how many times we all tell users not to use the same password for everything? 4
Steve21 Posted August 9, 2011 Posted August 9, 2011 Just spotted this on the news and after reading was wondering how many times we all tell users not to use the same password for everything? Thing is, Don't you think the issue is with the fact the website got hacked by a pupil, more than someone used same pass though? If a pupil didn't get the password through the hack on website, they wouldn't gain access to MIS. Although I'm not saying it's right to use the same password for both either. Steve
sister_annex Posted August 9, 2011 Author Posted August 9, 2011 Thing is, Don't you think the issue is with the fact the website got hacked by a pupil, more than someone used same pass though? If a pupil didn't get the password through the hack on website, they wouldn't gain access to MIS. Although I'm not saying it's right to use the same password for both either. Steve It's a chicken and egg situation I think... if the member of staff hadn't used the same password for both the student would have had a more difficult time off 'hacking' the site.
GrumbleDook Posted August 9, 2011 Posted August 9, 2011 More information is on the ICO site, including the undertaking the school has entered into ... well worth reading and an Undertaking can be seen as typical actions a school should be doing anyway, if they want to prove / test how secure they are. Hampshire school breached data protection rules - ICO news release
MK-2 Posted August 9, 2011 Posted August 9, 2011 It's great them saying the school will undertake annual penetration tests, who pays for that? As an independant school how do we fund such a thing to stay safe? Plus, I wish the media would stop using the term hackers and hacked for things such as a kid knowing a teachers password. From what the reports say, it wasn't a stolen password via malware/keylogger or any other attempts, so they could have seen said teacher type it in.
GrumbleDook Posted August 9, 2011 Posted August 9, 2011 It is your legal responsibility to ensure compliance with DPA and all the costs associated with it, the same way you have to with H&S, fire regulations, etc ... there is also a healthy discussion going on via a LinkedIn group of eSafety law which is pointing to legal requirements around negligence in a number of areas in schools ... You would not skimp on fire prevention / protection so you should not skimp on Data Protection.
Steve21 Posted August 9, 2011 Posted August 9, 2011 Plus, I wish the media would stop using the term hackers and hacked for things such as a kid knowing a teachers password. From what the reports say, it wasn't a stolen password via malware/keylogger or any other attempts, so they could have seen said teacher type it in. That's not how I read it. There was two parts to this: a) The website hacked, and a password found. b) Password used for MIS access as it could access both. "This password was subsequently discovered during the original hacking incident and then used by a pupil to access other parts of the system." Unless I read that wrong? Steve
Jake Posted August 9, 2011 Posted August 9, 2011 Bay House is my school. Thats pretty much all I am at liberty to say publicly.
MK-2 Posted August 9, 2011 Posted August 9, 2011 It is your legal responsibility to ensure compliance with DPA and all the costs associated with it is annual network penetration a legal requirement (not being sarcastic here, genuinely asking)?
jdoyle Posted August 9, 2011 Posted August 9, 2011 is annual network penetration a legal requirement (not being sarcastic here, genuinely asking)? not specifically stated as a legal requirement (but then neither is encrypting laptops)
GrumbleDook Posted August 10, 2011 Posted August 10, 2011 The legal requirement is that you have taken all appropriate action to ensure the security of your data. If you have staff laptops which hold data and they are taken off-site then not encrypting them is likely to be seen as a lax approach (as seen in a recent ICO case where data has been lost on a school laptop). If you have a website which contains such data, or a VLE / MIS which holds it then you should either be looking to ensure that it is as secure as it needs to be, or the responsibility for managing that aspect is with a company who are contract to ensure the security of it. The choice of company and the verification that they are taking the appropriate action remains with the school (the risk is shared, not passed on), so the school still holds liability on this.
featured_spectre Posted August 10, 2011 Posted August 10, 2011 Bay House is my school. Thats pretty much all I am at liberty to say publicly. I feel for you on this one, best of luck regardless what happens!
Jake Posted August 10, 2011 Posted August 10, 2011 I feel for you on this one, best of luck regardless what happens! No probs, gets me out of my cage. So....where are all the new babe-techs?
PiqueABoo Posted August 22, 2011 Posted August 22, 2011 (edited) Ensure security? Cue the now very old favourite, the Ranum 'ULTIMATELY Secure Firewall'. I'm not kidding, much. If pen test kind of territory is now a de-facto ICO hurdle, then you either swiftly drop most of the visionary-external-access-involvement-engagement ICT panacea tat from the last decade like a shot (ditto probably, for any cloud-fluff), focus very seriously on the security arms race yourself which is a bit of a full-time job, or sack some internal staff so you can afford to pay someone else to fret[1]. And given the latter doesn't excuse you entirely, how do you determine that Org X, Vendor Y, Pentesters R Us at al, will actually deliver at some arcane level that's way beyond your ken? Do you know what any gobbledygook certs do or don't prove? What may or may not be genuinely good value in this area? Etc... The main difficulty I have is that should someone clever exploit some subtle hole despite having lots of "appropriate" boxes ticked, whatever they may be on the day the ICO reviews the breach, will they say: a) OK you took reasonable precautions vis-a-vis the genuine risks, were obviously unlucky, so we'll let you off, b) A hole existed and was exploited ergo you hadn't done enough? [1] You might also discard one or two products from some 'well-known' vendors in this sector, because I'm 100% certain that some won't withstand serious scrutiny (not that you'd likely afford tests like that, but the vendors probably could on behalf of their customers interests). Edited August 22, 2011 by PiqueABoo
Earthling Posted August 23, 2011 Posted August 23, 2011 If pen test kind of territory is now a de-facto ICO hurdle, then you either swiftly drop most of the visionary-external-access-involvement-engagement ICT panacea tat from the last decade like a shot (ditto probably, for any cloud-fluff), Stop there, that gets my vote........and very well-worded, too, may I add. 'visionary-external-access-involvement-engagement ICT panacea tat .....', sums it all up in a nutshell to me.......eloquent turn of phrase, mate.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now