Jump to content

Data Retention - Guidelines for Schools From MyCloudBackup


DataRentenion-small.jpg.b553e0f096dbb79ed4213ed9c993d4da.jpg

 

 

The Department for Education has urged schools to ramp up protection for their systems and data following a new round of targeted ransomware attacks.

 

Targets for the recent cyber-attacks included all 17 schools in Cambridge Meridian Academies Trust, 15 schools at Nova Education Trust in Nottingham and 24 Schools across South Gloucestershire, including all seven at Castle School Education Trust.

 

Jon Gilbert, Chief Information Security Officer for the DfE, is now asking UK education establishments to confirm they are taking action to protect their systems and ensure that they have both a backup regime and incident management plan in place.

 

He wrote: “We have been working closely with the National Cyber Security Centre (NCSC) and have been made aware of an increasing number of cyber-attacks involving ransomware infections affecting the education sector recently, notably multi-academy trusts.

 

“These incidents appear to be financially driven but opportunistic, taking advantage of system weaknesses such as unpatched software, poor authentication systems or the susceptibility of users to misdirection.

 

“It is important that as heads of multi-academy trusts you understand the nature of the threat and the potential for ransomware to cause considerable damage to your institutions in terms of lost data and access to critical services, as highlighted in the NCSC Alert.”

 

The increase in attacks comes at a time when schools are being asked to rely heavily on technology, carry out additional reporting and change the nature of examinations.

 

In the most recent DfE notification, schools are urged to confirm with their IT team or provider that: 

 

  • They are backing up the right data – including Covid-19 testing information, associated data, and data relating to exams alongside other key elements.
  • Backups are held fully offline and not connected to systems or in cold storage
  • Tests are carried out to ensure backups and restore services are working and data can be recovered

 

To combat this spike in malicious malware, the NCSC recommends a ‘defence-in-depth’ approach and above all urges organisations to have ‘up-to-date and tested offline backups’.

Data Retention Policies – Considerations / Reasoning

 

 

Consider four periods of data retention:

 

Daily: This captures the data from the very beginning and reduces the risk of loss to a few hours (maximum of one day). Early stage data retention is critical in save guarding from loss of day to day project work.

 

  1. Monthly: This provides an archive of the most recent work and further ensures that any loss of data is minimised.
  2. Yearly: Good practice, as well as mitigating widescale data loss ie: where a ransomware attack renders substantial amounts of data unusable..
  3. Long term (3+ years): Provides for instances where historical / analytical information may be useful or required.

 

When setting a data retention policy, consider the following questions:

 

  • Why am I holding this data?
  • Am I under legal duty to retain the information for a set period of time?' Consider legal duties that impose specific time periods for data retention
  • Do I need to pass it on? Once I have passed it on, am I required to keep it? Do I still need to use it?
  • What is the school’s actual responsibility – is appropriate long-term retention actually someone else’s job such as a ‘receiving institution’ or local authority?
  • What might Ofsted expect from me in terms of the length of time I can perform detailed reporting?
  • As time goes on, can I delete some of the information – for example would aggregated data (‘counts’ of pupils that you might share with governors) or de-personalised data (individual rows, but with names and other identifiers removed) do the job just as well?
  • “Because I always have done” is not a justification, but it may be a clue as to a justification. “ Why might we have that policy?” Is a good question to ask.

 

A number of schools have collaborated with sharing thinking on data retention with us in creating this document, and their shared work is provided in Annex 5.1. This is provided to stimulate thinking and discussion at a local level. As data controllers, schools should determine their own policies that work for them and their particular context.

 

If you have any questions or require further information, please forward them to: [email protected]

 

MyCloudBackup is a data backup service. All data is held in our own UK based Data Centres.


User Feedback

Recommended Comments

There are no comments to display.



Guest
Add a comment...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.




×
×
  • Create New...