Jump to content

Recommended Posts

Posted (edited)

Might be my ipad but the page can not be found......is it me

 

 

No its a known issue with ios devices

Edited by round2it
Posted
Hi Armadillo,

 

Below is a link to the document. Hopefully this will work!

 

Can i stress that this is not my work in the document but a fellow EduGeek member who publicly shared this us a couple of years ago. I did want to use this a guide to write my own Staff ICT Handbook but just have not got around to it yet.

 

https://www.dropbox.com/s/j0u67eln27u0ehf/new%20staff%20guide.docx

 

I will leave this up for a while so people can access it as required. If the originator happens to come across this post and would like me to remove this, please feel free to message me and i will remove immediately.

 

Regards,

David

 

Thank you very much for activating the link again; it's now worked.

Regards

  • 3 years later...
Posted

Incorporate it into your login information that you hand out!

 

Two or three pages:

This is your pasword for the network, log on to any computer with zzz and yyy. You can change your password here...

These are the shared areas...

This is your password for the e-mail system. Get to it here...

This is your password for the photocopiers. You can print to any machine. Use your access fob to...

We have this program... here is your password for it...

We also have this website... Use the same password you use to get on the computer.

You must comply with oiur AUP data protection, copy attached...

  • Thanks 1
Posted
Incorporate it into your login information that you hand out!

Two or three pages:

[ ... ]

We also have this website... Use the same password you use to get on the computer.

 

Err, not this one. Here is an example where the ICO only rapped a school's knuckles (hard) for permitting duplicate passwords internally and externally, but I definitely recall a £60,000 fine for something similar.

 

Of course, the real issue was (I hope) procedures. We definitely want single-sign-on, so let's hope that the ICO is happy with it when it's backed up by something like 2FA.

Posted (edited)
Err, not this one. Here is an example where the ICO only rapped a school's knuckles (hard) for permitting duplicate passwords internally and externally, but I definitely recall a £60,000 fine for something similar.

 

Of course, the real issue was (I hope) procedures. We definitely want single-sign-on, so let's hope that the ICO is happy with it when it's backed up by something like 2FA.

Depends - possibly not the best phrasing, but for practical purposes it might be what the user has to do. That's the instruction I give our users. What actually happens is that behind the scenes an encrypted key is passed to an IDaaS system which sends another encrypted call to our DC to make sure it matches the users' current AD credentials. It then passes further encrypted keys to other platforms to verify identity on them. I don't think most of our users need to know that though... Edited by jmak
Posted
Depends - possibly not the best phrasing, but for practical purposes it might be what the user has to do. That's the instruction I give our users. What actually happens is that behind the scenes an encrypted key is passed to an IDaaS system which sends another encrypted call to our DC to make sure it matches the users' current AD credentials. It then passes further encrypted keys to other platforms to verify identity on them. I don't think most of our users need to know that though...

 

I'm not much interested in the technicalities of the particular SSO - it's the sharing of passwords between internal systems and externally-facing websites (potentially containing the kind of information that the ICO cares about) which the ICO has, in the past, said should not happen. I'm just saying ...

Posted
I'm not much interested in the technicalities of the particular SSO - it's the sharing of passwords between internal systems and externally-facing websites (potentially containing the kind of information that the ICO cares about) which the ICO has, in the past, said should not happen. I'm just saying ...

 

I guess it depends if the external facing website is there to access data, which is the same data on the internal systems. For example, Sims data being put on various systems so that parents and staff can access it anywhere, it is externally accessible but all the data that would have only been accessible internally, is now accessible externally. As long as you have a good password policy then having the same login details for multiple systems isn’t terrible and quite common in this time (such as using sso or ad authentication).

Posted
The problem is not that you are sharing a password ... it is the lack of risk analysis that is a problem.

 

There may be times when it is acceptable.

 

Agreed.

 

If a password is shared, can you identify who used that login to perform an action? Does it matter?

 

Who sent an email that’s at the centre of a kerfuffle matters.

 

Who changed something on SIMS matters.

 

Who used the login that only allows you to operate the franking machine may not matter as much... or it may matter from the auditors point of view... the risk has to be balanced.

Posted

The discussion started as one user using a single password to access multiple systems, not sharing a password between users.

 

Incorporate it into your login information that you hand out!

 

Two or three pages:

This is your pasword for the network, log on to any computer with zzz and yyy. You can change your password here...

 

We also have this website... Use the same password you use to get on the computer.

You must comply with oiur AUP data protection, copy attached...

 

 

 

Agreed.

 

If a password is shared, can you identify who used that login to perform an action? Does it matter?

 

Who sent an email that’s at the centre of a kerfuffle matters.

 

Who changed something on SIMS matters.

 

Who used the login that only allows you to operate the franking machine may not matter as much... or it may matter from the auditors point of view... the risk has to be balanced.

 

I'll give two examples where I tell users to use the same password for different things:

 

County hosted services (which they log on to a Windows domain via RDP and email. Many users see these as separate because they use mostly webmail, but it's actually the same domain.

 

RM Unify (a website which provides SSO) and computers on our network.

 

If I was writing a user manual, I would say something like "passwords for these systems are always synchronised", but a regular conversation I have is "I can't do the register because I've forgotten my password for hosted services"and I reply "I can see you're logged into your email; use the same password".

 

However, none of this is really helping the OP who wanted suggestions for a staff handbook [emoji3]

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...