Jump to content

Roberto

Members
  • Posts

    2,735
  • Joined

  • Last visited

Everything posted by Roberto

  1. What the responsible person probably should do is "risk assess" the threat (e.g. likelyhood of breach, nature of information likely to be lost in a breach) and make a reasoned decision as to what is appropriate and write that up as policy/guidelines for staff to follow. GDPR is not supposed to stop organisations from doing what needs to be done, rather it's supposed to make the organisation think about whether or not something is a risk, and if so is the risk neccessary or appropriate. I'd suggest that for taking work home you could say it should be kept securely in transit and stored securely when not in use. This might suggest that marking should be locked in the car boot during transit rather than left on the seat of an unattended car and once home couldn't be left out on the dining room table unattended, not that it couldn't be done at home at all.
  2. One might suggest there should be test/training systems with dummy data in them for this kind of thing, which would nicely get around the issue. Besides, general staff training is arguably not a reasonable use of students' personal data.
  3. We don't really. we've got some legacy groups/workflows where we might still do something custom for the users, and OneDrive Mapper can set a cookie for mapping the main sharepoint site while its setting up a drive letter for the user's onedrive and having this cookie pre-set by ODM gets around having to visit the site and log in to make drive mappings work. But fundamentally the amount of work required to do this is vastly disproportionate to the benefit when the likes of MS Office and Acrobat can work natively with sharepoint online. We're trying hard to shift the "drive letter" mentality. It actually helps to point out to people that if they can get away from accessing documents on their ODfB or sharepoint online site via a drive letter and learn to do it natively from Office then they can keep the same workflow for finding the document whether working from home or on premises. I'm not trying to pretend this is easy by the way, people who have spent a very long time working in one particular way will genuinely struggle to change, especially if there's no obvious benefit to them.
  4. It absolutely is a classroom discipline issue rather than a technological one, I agree 100%. I also think the main focus of dealing with it should be discipline-led rather than technology-led. That doesn't mean that some reasonable amount of applying technology to support the discipline process can't be useful. So we block, as well as log, to make it difficult to just trip into playing online games and to clear to students that it's not welcome.
  5. There's no set amount of time you need to set to be magically GDPR compliant just as there's no set-GDPRcompliant -yes powershell command for windows server 2016 because the exact time isn't important. What matters is that you have a policy that states you're keeping the CCTV data for a set amount of time consistent with reasonable use for your needs, processing it carefully, etc. and then complying with that policy.
  6. Is there no history of Office being purchased in the finance records? What are the school doing for Windows licence keys for devices/servers? I'd suggest the thing to do is to talk to a supplier about getting something like Microsoft Campus set up, or alternatively going a bit left-field and looking at chromebooks... but if you can't provide proof of the licence key being purchased and don't know what terms its being used under then you really can't use it at all. This is not going to be a quick fix.
  7. You can visit the site using https and it works but this really is very shoddy of them; they should as an absolute bare minimum force a redirect for login and the fact that they don't do this calls their competence into question. I would have trouble trusting them with my data too at this point.
  8. I'd strongly suggest this is a risk you should be thinking about, yes. If the exam board won't co-operate with you to find a solution then how far is it reasonable for your school to stick its neck out on their behalf? Not very, I'm thinking.
  9. In these cases you can do things like use Bitlocker to encrypt laptops (if your laptops support this), use things like MDM to regulate both organisation and personal user devices' access to data (including email). Tools are readily available in Exchange/Office 365 policies to lock this down and can potentially allow you to reset and erase a phone remotely whenever you're concerned, and other platforms have similar tools available. As for "ask them to keep the school data safe on the phones." I'm a little worried by this statement. GDPR is a process that should be in place across your whole organisation which should include things like risk assessments of use of personal phones for work and policies created and pushed by your SLT at the highest level to regulate this, not something that can be dealt with as "ask the IT whiz to push a few buttons". To paraphrase myself in an earlier post, there simply isn't "One Weird Trick To Be GDPR Compliant" - every part of the org should be thinking about how it gathers, stores, uses and disposes of data and technical changes to laptops and phones need to be part of this overall set of policies. SLT needs to be telling people to keep data safe, rather than IT 'asking' them.
  10. We dump our local cache for papercut into c:\programdata\papercutclient and haven't had problems. If you're worried about students keeping bad things in that folder then a quick delete and re-create of that folder in a computer startup script won't be a problem, or maybe delete *.* from that folder with a logout script if you need to keep things really tight. .
  11. There's two things. First of all the "policy" you're talking about refers to hiding the drive in explorer. This doesn't secure the drive, it just hides it. It's frankly a bit mickey mouse and not any kind of serious security barrier. We don't bother hiding the drive here for example and its never been an issue. You need to lock down permissions to the c:\ drive, which has always been something that should be done as well as hiding the drive if you wish to keep students away from interfering with it. You say "the system requires this write access to function" , but what specificallyneeds access? Do student accounts need write access? Windows itself doesn't have any requirements for user accounts to write to the root of the c:\ drive, so what does? If you have some kind of staff software that needs users to write to c:\ then you can just give that access to staff. If students really need write access to the root of the c:\ drive then this is a horrific security issue imho regardless of whether or not the drive is hidden, and if that is the case then it's a simple choice, blender or this other thing.
  12. I was trying to resist this but using this for an actual backup (I assumed you were talking about taking an image for imaging) is "one of the dumbest design choices ever". If you must use this kind of imaging tool, Acronis can do it while booted. So... Windows PE, which I already suggested?
  13. What exactly is "one of the dumbest design choices ever" about this? The pagefile contains a snapshot of RAM pages and is a very clear potential source of confidential leaks in a secure environment. If you're in that kind of environment the pagefile should absolutely be wiped instead of just deleted. There's more detail here. Not sure if I can call this untrue or just absolute short-termism at its worse. It might be true in the same way that strapping a jet engine to your car makes it go faster: maybe technically true but still a terrible idea. You could delete pagefile.sys out of band in WinPE or suchlike before taking your image if this is important to you. A new one should be created when the image is booted from.
  14. I recommend Aruba. We've had very little trouble with that here ;-)
  15. AFAIK there isn't a "one weird trick to being GDPR compliant, data commissioners hate it when you do this but they can't stop you" answer like "yes it needs to be encrypted" or "no, it doesn't". There needs to be an assessment of what data you have, how its used, what the risks are, etc. and there needs to be a policy that reflects appropriate storage and use of that data that needs to be properly implemented and controlled. You might decide that data needs to be encrypted "at rest" on the server or you might not, this depends on what you think the risks are. For example, do lots of people have admin access to the server? Is sensitive data held on shares or other services that are more open than they need to be, etc.
  16. It wouldn't. Mail for a domain can only really be delivered to one place at a time. Now that one place can possibly forward mail for certain mailboxes onwards, so the best answer to your wanting to trial gmail for just one user is to either give up on doing this with a live account and use a test user on a test domain or set up a forwarding rule on the exchange server to forward all mail for the trial user onwards. This would let you trial the gmail front-end user experience but wouldn't really be representative of the entire experience of being a gmail user.
  17. Needs to have admin control separate from teacher login; not all admins are teachers, not all teachers are admins. Admins need to be able to find and delete personal information related to users (something something GDPR). Also we need data be removed in a timely manner when accounts expire, ideally in an automated maner if we're using SSO to integrate logins with AD, for example. Login needs to be possible via SAML SSO or similar to work with most of the single sign solutions you might find in schools (e.g. it must work with ADFS for Microsoft shops, other SSO standards for people predominantly using Google apps for Education) No, I'm not uploading user information with a CSV file. Should be platform independent (that at least should be reasonably easy in a web app). I should be able to run it from an iPad, a Chromebook or a Windows box, among others, without any drama.
  18. Just to second this, we migrated a 3000 user domain away from RM/CC way back. The domain was set up on Windows 2000 with CC3 and the same domain is now RM-free and at the W2016 domain functional level with no issues. It does take a bit of effort to untangle the RM stuff but less so than setting up a new domain (having done both in my time) and provided the domain is essentially well-run now and will be so in the future, keeping and tidying up is just fine. I've had no regrets. Technical reasons why a domain must be rebuilt are extremely rare. Certainly "it's a bit of a mess" or "there are one or two schema extensions we don't need now" are not reasons to evacuate an AD domain.
  19. If you could do this, I would. I personally would not be comfortable using certificates from a provider that had ever held on to private keys. They should never have had them in the first place, and despite putting "don't use in production" on the webpage for generating them, to my mind it's essentially maintaining a public nuisance to have a page like that at all. No, that is a terrible thing. Your certificate's private keys should remain privately held on the server that uses them. There's even a clue in the name. They should never have generated private keys for customers in the first place. They should never have held on to private keys in the first place.
  20. We used to do this but found that with the large number of different devices we had to support within the college (e.g. Windows, MacOS, iOS, Android, Linux) plus BYOD devices where proxy auth would be an issue, we simply don't use a traditional proxy server at all. We simply route traffic through a UTM firewall as the only route out to the internet and watch what goes by on the wire. Much more robust and reliable.
  21. we run Jira Service Desk on site. I'm a huge fan of it and I believe it meets the requirements.
  22. I think this is key. I won't claim to have fully made the transition in my own mind yet but for those of us who are used to servers on-site just being there and having resources to spare, running a server in the cloud on the same basis will prove to be massively expensive. This is a similar change of mind-set from where we stand with on-site virtual server farms, or maybe even a larger one, than what was required in order to "get" server virtualisation on site in the first place. Being able to break things down so you're running more discrete 'services' on an as-needed basis is the way to go, but it does require a totally different mind-set, not least thinking hard about whether capacity in the cloud is best served by scaling up the way we typically do on-site by buying a bigger server or by scaling out by running a set of small containerised instances and automatically increasing/decreasing the amount of containers based on load; the cost of 10 small VMs can be far smaller than one large VM in both Azure and AWS.
  23. I've always thought the value of BETT was being able to meet up with suppliers across the whole range of various curriculum, front-of-house and infrastructure ranges more than "ooh that's new and shiny" to be honest. I'm looking into new network switching, for example, and while I'll keep an eye out, I'm not counting on finding anything ready to demo at the level I want at the show.
  24. What do you normally buy that you'd consider something based around an i5 to be basic? We've actually had good results in classrooms with "recent Pentium"-based PCs with SSDs in them from Stone. They seem to build faster, perform just fine in our tests and overall seem to be very well balanced machines for most classroom tasks... though I probably wouldn't put any in our specialist music,design or autocad labs, though they do load and run both the autocad s/w and the adobe suite and cope with at least some workload much better than you'd expect.
×
×
  • Create New...