Jump to content

What information do you allow when accessing MIS from home?


Recommended Posts

Posted

Hi guys and gals,

 

In terms of teachers accessing MIS from home, what data do you make available to them? What are the relevant parts of DPA that relate to this? So, we can allow access solely for report writing with no real identifiable/personal data. But, is there a good reason to allow access to things like DOB, contact details (including phone numbers and address) of parents/guardians etc..

 

Thanks in advance

 

Ben

Posted

Which MIS do you use? The answer to that may control / restrict what you can let them see anyway.

Broadly speaking if you can, limit it to only what they need. If they're just putting marks in, then just give them assessment areas. If they need contact numbers and SLT approve the action then fine, but if you can limit it, then it's just a safer system.

Posted

The relevant parts of the DPA are nothing more than the same parts that relate to onsite usage. There is nothing prescriptive in the DPA about remote access.

 

The only part of our MIS we expose for remote access is basic contact details for pupils and those people listed as emergency contacts for each pupil. We give staff this because we would rather they access the data remotely using a (strong) password than print out the details on paper and leave them lying around somewhere on a trip.

 

At one point there was strong guidance from the DCSF that remote access had to use two-factor authentication, but that guidance was swept away when the Tories got in, because we can just apparently do whatever we want now and market forces will determine who's right.

Posted
They get the same access externally as they do in school here.

 

...and what information do they have access to inside school? Addresses and contact details of parents (and therefore child, more often than not) and guardians etc..?

Posted
The relevant parts of the DPA are nothing more than the same parts that relate to onsite usage. There is nothing prescriptive in the DPA about remote access.

 

The only part of our MIS we expose for remote access is basic contact details for pupils and those people listed as emergency contacts for each pupil. We give staff this because we would rather they access the data remotely using a (strong) password than print out the details on paper and leave them lying around somewhere on a trip.

 

At one point there was strong guidance from the DCSF that remote access had to use two-factor authentication, but that guidance was swept away when the Tories got in, because we can just apparently do whatever we want now and market forces will determine who's right.

 

Thank you. Seems sensible. At the end of the day, if they wanted address details for malicious reasons, then they could be taken from school anyway.

Posted
Which MIS do you use? The answer to that may control / restrict what you can let them see anyway.

Broadly speaking if you can, limit it to only what they need. If they're just putting marks in, then just give them assessment areas. If they need contact numbers and SLT approve the action then fine, but if you can limit it, then it's just a safer system.

 

We use PASS/3SYS. It is very customisable and I can restrict most things.

Posted
...and what information do they have access to inside school? Addresses and contact details of parents (and therefore child, more often than not) and guardians etc..?

 

They have that (I Think) our data manager looks afters sims perms

Posted

You give access to whatever is deemed relevant and then combine it with policies to ensure that it is accesses, processed and shared appropriately.

 

Access to DOB, etc might be given to allow pastoral staff (eg form tutors) to plan for birthdays or other notable events.

Address might allow for planning of home visits.

Other details might be part of letters home ...

 

The list could go on but it has to be agreed by the schools and it has to also be appropriate for work / life balance.

 

It is not so much what data can be shared, but where. You might allow remote access but how to do you specify that it should be done on a machine which is not viewable by others (ie those who have no rights to see or process the data)? You can do some of this with tech (ie lock it down so it is not accessible outside of school) or you can use policies / procedures.

 

This is related to Data Protection Principle 7.

  • Thanks 1
Posted
You give access to whatever is deemed relevant and then combine it with policies to ensure that it is accesses, processed and shared appropriately.

 

Access to DOB, etc might be given to allow pastoral staff (eg form tutors) to plan for birthdays or other notable events.

Address might allow for planning of home visits.

Other details might be part of letters home ...

 

The list could go on but it has to be agreed by the schools and it has to also be appropriate for work / life balance.

 

It is not so much what data can be shared, but where. You might allow remote access but how to do you specify that it should be done on a machine which is not viewable by others (ie those who have no rights to see or process the data)? You can do some of this with tech (ie lock it down so it is not accessible outside of school) or you can use policies / procedures.

 

This is related to Data Protection Principle 7.

 

Thank you very much GrumbleDook :)

Posted

Same access externally as they get internal here as well.

 

Have had a bit of extra piece of mind since we mixed in security certs into the authentication process of our remote PCs as well – this way even if someone were to figure out a staff members password they would need a valid AD security cert to actually connect.

Posted (edited)

Allow remote access to the same as they would have in school but dual factor encrypted authentication using app with encrypted key built in so dual factor is seamless for user, locks machine, after a few minutes or whatever the school wants if not used and other security features inluding logging so who has accessed the system etc for auditing, tracebility.

 

The reason we use Dual Factor is so that if a student knew a staff username and password would not be able to access MIS systems externally.

 

Use polices with staff as well as security to enforce use.

 

Feel this is better than allowing data to go offsite and this is explained at various meetings via SLT and through school policies adn consequences.

Edited by Steven_Cleaver
Posted
The thing about remote access is, what if they leave the machine logged on, but are in an internet cafe in the costa del sol, or stuck at the airport. Even at home, if they print something out, then leave it lying around. The same issues exist at school, and the data could be taken home, but when you're not even aware of what is happening or where, it's an extra factor of potential trouble. I'd still be asking what they need and why. Doing reports from home is great, filling in behaviour reports after the fact, looking up phone numbers for parents or other things which are not essential and just a convenience i'd probably say isn't a necessity.
Posted

Your right Vikpaw but we tell staff they need to use their own devices and it is set to autolock remote computer if not used after a few minutes can't print anything out as that is locked down but could screen print and because they use Encrypted Key usually on Memory stick or own device and a username and password so dual Factor couldn't access any MIS systems without Encrypted App (App can't be copied or replicated and is disabled if incorrectly used and Username and Password. Just feel we have secured best we can with this and feel this is a bit more secured than Staff taking data off site on Laptops USB or paper etc and less complicated than trying to make sure all data is Encrypted or no documents are taken offsite to be honest we use various methods and techniques to secure, restrict and log what is going on but would be a lot to discuss on here and all is done technical side of things so it makes it seamless for the user.

 

So MIS user double clicks App (this authenticates using Encrypted key) and user Logs in with Username and Password no App can't access MIS systems so even if students knew a member of Staffs password they wouldn't be able to access the MIS systems.

  • Thanks 1
Posted
@Steven_Cleaver - Probably not right to go into extra detail on this thread, but be very interested to hear about your two-factor setup and other steps for securing data... If you have time, we can start another thread.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...