Jump to content

Recommended Posts

Posted
or is there still an issue with data leaving the EU

I'm sure GD will find one :)

 

[Comment of whole thread]

(Its non-issues like this that make me despair of modern society! :) )

 

Do a risk assesment - count the possible data breaches - count the possible damage - do the maths :)

Simon

[/]

Posted

Apologies for not putting an update on for this after Daniel's post ... I have been trying to follow it up to try and cover the other queries about The Patriot Act too. I'll stick up a longer article shortly but the summary is as follows.

 

Dropbox have now agreed and certified to the US-EU Safe Harbor Agreement, and have put in their entry what they comprehensively cover, process, store, etc ... and this does indeed meet the requirements under the DPA for transfer of data outside of the European Economic Area. The issue that surrounds them being a US company and under The Patriot Act has to be a judgement by the school (as they would for any other service such as Google, Microsoft, Apple, Box, etc) as to whether they believe this is a risk (that a law enforcement agency may seize the data), but understand that we have a similar section in our DPA to cover our companies operating overseas. I have requested an update from the ICO as to whether this needs to be considered a risk and so far, again there is no quotable response, but the points raised previously stand.

 

If the issue was the lack of Safe Harbor Agreement then that has now been met, if the issue is with it being outside of the EU then we know that DropBox use Amazon servers in San Francisco and if the issue is one of the The Patriot Act then it is a judgement call as to whether you believe that it is or isn't correct that a law enforcement agency from another country can seize data, in the same manner we have equivalent laws to seize data in the UK and this already applies to many services already used within schools (and there has been no issue so far or significant legal challenge).

 

For me ... it is no longer a risk assessment about whether they are a risk as to whether there could be a problem (i.e. break the law but no harm, no foul) but now simply a case of they *can* follow the law ... but, as with all such firms, you are making an assessment about whether they will and there is nothing to indicate that they won't.

  • Thanks 2
Posted

If the issue was the lack of Safe Harbor Agreement then that has now been met, if the issue is with it being outside of the EU then we know that DropBox use Amazon servers in San Francisco and if the issue is one of the The Patriot Act then it is a judgement call as to whether you believe that it is or isn't correct that a law enforcement agency from another country can seize data, in the same manner we have equivalent laws to seize data in the UK and this already applies to many services already used within schools (and there has been no issue so far or significant legal challenge).

 

TBH the patriot act is the last of our worries; the US government can already close you down and have you extradited to the states without presenting any evidence to a British court. The fact they might be able to cease my data sort of pails into insignificance given that I could face an indeterminate sentence in a US prison if one of my users so much as looked at some copyrighted material.

Posted
TBH the patriot act is the last of our worries; the US government can already close you down and have you extradited to the states without presenting any evidence to a British court. The fact they might be able to cease my data sort of pails into insignificance given that I could face an indeterminate sentence in a US prison if one of my users so much as looked at some copyrighted material.

 

For some organisations it is an issue and the proposed changes to the EU data laws which are likely to deal with these concerns might make some consider it as an issue too, until it is resolved.

 

Whilst some may make light of it, the law is there for a reason.

  • 1 month later...
Posted

So what are peoples thoughts on this now?

 

We are just rolling out skydrive desktop app to all staff. I need to be able to give them some guidelines on its usage.

 

I've heard all the arguments and to be honest I am pretty happy them saving files to their skydrive accounts. They have already been using live@edu email in the same way for a year now with no problems so far.

Posted

I've just installed Skydrive app on my laptopm to see what it's all about.

 

I'm still not really sure about it, or any 'cloud' based storage, that will potentially have student confidential data saved to it. It's a MS app after all, and it's Windows Live based, which to my mind, makes it a target for hacking, password-publishing and all the rest of it. One of the reasons I gave for retaining our Exchange server and not migrating to Live@Edu.

 

I'm firmly of the opinion that, if we used Live@Edu or Skydrive or Dropbox here, someone, somewhere here would store something confidential, their account would get hacked amongst thousands of others and it would all end in tears........and I'm too short-time for that.

Posted (edited)
One of the reasons I gave for retaining our Exchange server and not migrating to Live@Edu.

 

We've been on Live@edu for a while now for email and had all those conversations before moving. Now we are on it, I really do wonder what the fuss was all about.

 

Touch wood, We have not had a single incidence of hacking or any kind of data loss since we started using it.

 

Storing files in the cloud is just another step along that path I think. But I do have the same reservations as everyone else about the security. So far though I have not seen any evidence of this happening on live@edu.

Edited by zag
Posted
We've been on Live@edu for a while now for email and had all those conversations before moving. Now we are on it, I really do wonder what the fuss was all about.

 

Touch wood, We have not had a single incidence of hacking or any kind of data loss since we started using it.

 

Storing files in the cloud is just another step along that path I think. But I do have the same reservations as everyone else about the security. So far though I have not seen any evidence of this happening on live@edu.

 

Touch wood..........

 

I think I'm being realistic when I think that it WILL happen sooner or later. Hotmail was always being hacked every couple of years and I'm sure Windows Live will be just as much a target, if (maybe) a bit harder to crack. But hey, if it works for you, good luck. I have other reasons for not wanting to go Live@Edu, too. That's just one of them.

Posted

If it is now just an issue of password security how is a pupil giving out their password for Dropbox or Live@EDU any worse than giving out their password for the school domain (if you have some form of remote access to your internal servers set up). In fact in this senario if users are compromised on your network then the piossiblilites for some heath-robinson remote access solution being hacked are worse as your INTERNAL network and servers could be compromised.

 

My point is surely from a IT security point of view having less "vectors" into your internal network is preferable. Cloud storage is one way of allowing sharing between home and school without opening up your network.

 

Google and Microsoft should be tailoring their products to allow lock downs on sharing files with users outside your organisation and the online editing/viewing features should be used to facilitate the disabling of download permissions entirely (of course copy and paste and screenshot is a loophole) so files could not be downloaded from a secure folder and then distributed.

 

Another idea is that the web application detects that when you are sending e-mail to an external domain and pop's up a reminder of your responsibilities under the DPA and gives you an "are you sure" message.

 

Just basic e-mail has allowed the worst kind of DPA infringements in history but we don't all block hotmail and gmail in schools.

Posted
If it is now just an issue of password security how is a pupil giving out their password for Dropbox or Live@EDU any worse than giving out their password for the school domain (if you have some form of remote access to your internal servers set up). In fact in this senario if users are compromised on your network then the piossiblilites for some heath-robinson remote access solution being hacked are worse as your INTERNAL network and servers could be compromised.

 

My point is surely from a IT security point of view having less "vectors" into your internal network is preferable. Cloud storage is one way of allowing sharing between home and school without opening up your network.

 

The main reason you don't want people getting into your servers is so they can't get a hold of all the sweet gooey data inside them - sure them being trashed is annoying but the data is key - if all that data is now external you still have the issues but little control of the system. In short, your protecting your internal network by removing many/all targets of value from it, moving the problem, not solving it.

Posted
In short, your protecting your internal network by removing many/all targets of value from it, moving the problem, not solving it.

 

The key from a managerial point of view, is that you move it to being some one else's problem.

Provided you jump through the correct hoops, you get the bonus of deny-ability to boot.

If MS servers get cracked and data leaked, we've done all we need to from ICO point of view - we checked their safeharbour status and it isreasonable to assume that they have more technical security knowledge to secure their servers than I do. If my servers get cracked and data leaked, I'm in a whole heap load more trouble and could be criminally liable.

Posted
The key from a managerial point of view, is that you move it to being some one else's problem.

Provided you jump through the correct hoops, you get the bonus of deny-ability to boot.

If MS servers get cracked and data leaked, we've done all we need to from ICO point of view - we checked their safeharbour status and it isreasonable to assume that they have more technical security knowledge to secure their servers than I do. If my servers get cracked and data leaked, I'm in a whole heap load more trouble and could be criminally liable.

 

Sorry, but that is wrong. What you are doing is sharing the responsibility and giving yourself the option of taking someone else to court *after* you have been hung, drawn and quartered first (though the knives will probably be well and truly blunt before they get to a school after having gone through the hosting provider but the risk is still there). You cannot completely devolve legal responsibilities on data protection and safeguarding, and it is the school's legal responsibility to appropriately choose the right partners to work with. This is one of several reasons why the large scale frameworks sorted out by LAs, RBCs and central Govt go through so many legal hoops ... to save schools having to the same amount of investigation because it has already been done and deemed as appropriate as possible.

Posted
Sorry, but that is wrong. What you are doing is sharing the responsibility and giving yourself the option of taking someone else to court *after* you have been hung, drawn and quartered first (though the knives will probably be well and truly blunt before they get to a school after having gone through the hosting provider but the risk is still there). You cannot completely devolve legal responsibilities on data protection and safeguarding, and it is the school's legal responsibility to appropriately choose the right partners to work with. This is one of several reasons why the large scale frameworks sorted out by LAs, RBCs and central Govt go through so many legal hoops ... to save schools having to the same amount of investigation because it has already been done and deemed as appropriate as possible.

 

 

That is correct from a certain point of view. Moving data to Google wasn't my decision, but we went through the correct processes and senior staff/governors accepted the risk. parents are informed via ICO. I have day-to-day responsibility for server and infrastructure maintenance - I am NOT in charge of data protection. It might be a problem for the school if someone hacked their data, but it if they even attempted to pin it on me they'd be in court for an unfair dismissal with victimisation charge quicker than I could say live@edu . If I opened our firewalls for everyone I'd be the one in deep trouble.

Posted
That is correct from a certain point of view. Moving data to Google wasn't my decision, but we went through the correct processes and senior staff/governors accepted the risk. parents are informed via ICO. I have day-to-day responsibility for server and infrastructure maintenance - I am NOT in charge of data protection. It might be a problem for the school if someone hacked their data, but it if they even attempted to pin it on me they'd be in court for an unfair dismissal with victimisation charge quicker than I could say live@edu . If I opened our firewalls for everyone I'd be the one in deep trouble.

 

Very true ... and I tend to say 'you' and 'yourself' as meaning the school, your employer and the people you are trying to do a good job for ... my apologies that I didn't make that part clear.

 

So ... the school still has legal responsibilities and will delegate actions to individuals, which should be part of established processes which are agreed by the SIRO / DPO and are part of job descriptions which, should you opt to follow these processes mean that you are complicit in them unless you can show you made serious attempts to refuse to do certain actions (ad nauseum to the point of dismissal / constructive dismissal, etc).

 

There are some members who have been in this position already and have had to leave jobs because they were being left in it by those further up who believed that you cannot completely delegate responsibility and take shortcuts. That is the main point I was trying to make.

Posted

So ... the school still has legal responsibilities and will delegate actions to individuals, which should be part of established processes which are agreed by the SIRO / DPO and are part of job descriptions which, should you opt to follow these processes mean that you are complicit in them unless you can show you made serious attempts to refuse to do certain actions (ad nauseum to the point of dismissal / constructive dismissal, etc).

 

Trust me. I have ample evidence of supplying information to those delegated with responsibility for data protection. I also have a complete lack of evidence of me getting any relevant training in securing on-site systems, despite requests. Sure I am complicit in introducing cloud systems to our school, if I wasn't I wouldn't have a job. I am after all a minor part-time cog in the machine that is our school, if the teachers and senior team see a really good way to save money with marked improvements to pedagogy then I'm rather obliged to follow their lead.

Posted
Trust me. I have ample evidence of supplying information to those delegated with responsibility for data protection. I also have a complete lack of evidence of me getting any relevant training in securing on-site systems, despite requests. Sure I am complicit in introducing cloud systems to our school, if I wasn't I wouldn't have a job. I am after all a minor part-time cog in the machine that is our school, if the teachers and senior team see a really good way to save money with marked improvements to pedagogy then I'm rather obliged to follow their lead.

 

Yep ... and if any members have it suggested to them that they become SIRO then unless you have to (because you are at a very senior level / sit on SLT / etc) then politely show the person the door ... and to think I even volunteered! I was mad, I tell you ... mad!!!

  • 2 months later...
Posted
On a personal note (I know this isn't scalable at an organisational level) I use truecrypt and encrypt my data before it hits dropbox. Its an extra step, but I know my data is safe and secure that way.

 

Nice idea, we're sharing folders with Linux, Windows and Mac users... encryption is a pain in the nuts

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...