Jump to content

Recommended Posts

Posted

You may already have done this, and just not posted it in public for obvious reasons, however I would start by questioning the Governor's motives - how much do they know about IT? What has made them ask about encryption? When you have answers to those, then start to address what alternatives there are which a) don't have the performance hit, and b) allow midnight restarts. Then present the Governors with the options and your advice. There will be some performance hit as a result, but that isn't a reason not to do it, it may be felt that the hit is worth it.

 

Don't - as others have suggested - get protective over "your" server, it is well within the role of the Governors to question such things. Yes, it is your job to have an answer/solution and to implement said solution, however it is their job to ask questions. Ultimately, if the server were to get nicked and lots of data go public (or worse), it is the Governors who catch the fall-out, not you; therefore, they have every right to ask.

Posted
One good reason to not use encryption is anything that cause’s a reboot or power loss will stop the server from powering backup till the encryption password is typed in.

 

But encryption is no problem if your servers are virtual machines - if the original poster's server isn't already a physical machine running a bunch of virtual servers then maybe the ability to encrypt storage volumes is a good enough reason for the govenors to approve an upgrade?

Posted (edited)
Sorry ... encryption of servers where appropriate is not bad practice ... it is just that it is unlikely to be the best practice in this case. As soon as you start saying something is bad practice you are on dodgy grounds when it is not. If that governor happens to have previously been a Data Centre designer for MOD then he is likely to know far more than you, but if they are just someone with a strong personal interest but no specialism then it is simply that they don't understand the impact in this specific case.

 

As I've mentioned already ... knocking Governors when you don't know the full background or making generalisations is out of order. I'd love to see you do it to @witch ... that *would* be a sight to see.

 

Clearly you can take the situation out of context for the purpose of diminishing my point if you like. That's your choice to make. But we're talking about a primary school server, are we not?

Edited by hathor
Posted
You may already have done this, and just not posted it in public for obvious reasons, however I would start by questioning the Governor's motives - how much do they know about IT? What has made them ask about encryption? When you have answers to those, then start to address what alternatives there are which a) don't have the performance hit, and b) allow midnight restarts. Then present the Governors with the options and your advice. There will be some performance hit as a result, but that isn't a reason not to do it, it may be felt that the hit is worth it.

 

Don't - as others have suggested - get protective over "your" server, it is well within the role of the Governors to question such things. Yes, it is your job to have an answer/solution and to implement said solution, however it is their job to ask questions. Ultimately, if the server were to get nicked and lots of data go public (or worse), it is the Governors who catch the fall-out, not you; therefore, they have every right to ask.

Thank you - yes, it IS within the remit of governors to question such things. Some of us are IT governors and that is why we do know what we are talking about. Perhaps, as @elsigee40 said, it shouldnt be *one* governor but in my experience governors who know about such things tend to ask the questions or they don't get asked.

The governors are responsible for security - and asking about encrypting the server is actually a reasonable question given that we are all being hassled to encrypt encrypt encrypt all the time.

There's no mystery or problem - the question has been asked - answer it with your reasoning and all will be well:)

Governors are actually your friends - THEY are the ones who will approve big spends - not SLT, so it is in your interest to keep them informed.

Personally I would be happy to see a goveror in either of my schools to discuss IT, anytime, but sadly it hasn't happened yet

  • Thanks 1
Posted
But we're talking about a primary school server, are we not?

Yes, we're talking Primary School servers and Grumbledook mentioned military servers, but what you're overlooking is that Governors are expected to bring their experience and knowledge from their industries into education (this is why governing bodies aren't 100% teachers, and let's not forget are volunteers so need to be working somewhere else), so it is right and proper for a Governor with a working knowledge of one IT system to ask about its practicality and suitability in the school context.

  • Thanks 1
Posted
Sounds like he has been listening to some marketeering scaremongering and has little technical knowledge of the IT industry, not a good mix.

Can you cite your evidence for that claim...

  • Thanks 1
Posted (edited)
Can you cite your evidence for that claim...

 

Sorry, Just an observation based on the way I read the original post and there was no personal judgement intended to any viewers of the post or in the community.

Edited by Davit2005
  • Thanks 1
Posted

One other thing to throw into the mix would be notebook PC encryption - they are a lot more portable than any server and as such present a much greater risk to data loss.

 

Agreed there is a whole lot to consider. Any physical or logical movement of data is an issue. From DataPens, Emails, VPN etc and the human elememt of a discruntaled employee.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...