mjk
Members-
Posts
938 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by mjk
-
I wouldn't mind betting there are some GDPR 'consultants' out there trying to ban Royal Mail as we speak.
-
Ever get the feeling we might be over thinking this?: we don't encrypt paper copies and seem happy enough using the same postal system that we do for the USB/CD's. As the AQA said - it's not a requirement and there is no more risk of anything getting into the wrong hands being on USB/CD.
-
For those that don't want to faff around with educational licensing with winzip, or cannot use Bitlocker (macs, older windows): I can confirm that 7zip is a good opensource alternative that will create files that can be opened in winzip. Just choose zip and AES-256 as the encryption method.
-
0 */1 * * * will run every one hour. If you put the script in: /etc/cron.hourly/ it will do the same thing and you won't need the cron config. Remember to make the script executable chmod u+x /etc/cron.hourly/script.sh
-
Run it in a container and nobody cares what the OS is, with the added advantage of being able to fail over to cloud systems. - - - Updated - - - here you go: https://hub.docker.com/r/farfui/3cx/
-
please could anybody help with these questions: 1) If a school has a contract with a company who shares data with a third party, does the school need to report that they share data to the third party ? An example would be that the school contracts it's MIS data to Capita, and that Capita store their data on Microsoft and Amazon's servers and then subcontract the support to another company. When we report to students and parents, do we say that we share data with all of the companies - or just Capita. (this is a hypothetical scenario - I've no idea where Capita host their data). 2) If a school subcontracts to a third party who does not hold data, do we need to report to students and parents that we share data with them. An example might be an engineer who would remote in and have access to data but would not store or copy the data.
-
That's very interesting because the DfE document seems to be quite clear that only a small amount of information should be retained for 25 years. I'm genuinely interested because it would save us a lot of time if we are able to keep all information this long. Do you have any legal advice from you MAT's lawyers that you could share with the forum - it will certainly help others out!
-
I'm sure a lot of Chromebook schools have been waiting for passthrough wifi authentication. https://chromereleases.googleblog.com/
-
We've had no problems with reliability.
-
Sort of, it replaces the network drive with a "G" drive using file stream.
-
Exporting Cisco ASA Web Filter Rules
mjk replied to RabbieBurns's topic in Internet Related/Filtering/Firewall
ssh into it and 'show running-config' sorry I don't think I read your question properly before replying -
I don't think it is a reasonable request because it would become impractical: If I have 3000 parents and some don't like Google, some don't like paper, some don't like open source and some won't use propriety I cannot be expected to create an ad hoc system for each parent: thus (as @Edutech98 pointed out) the data would best be processed under a legitimate interest.
-
None of these points are talking about the system in which the data is held so they are irrelevant, rather they are talking abut consent around how the data is used (who it is shared with). You are misinterpreting the law if you think that you can dictate to institutions the systems that they use, that's not what the GDPR is designed for, nor how it can be used. I absolutely can guarantee you that (as a parent) I cannot make any institution hold data about me only on paper or system Y and it's ridiculous to suggest otherwise. You might be getting muddled up with offering alternatives about storing biometric data - where you would offer an alternative because the student refuses to give the data - but it's not about the system.
-
For Desktop virtualisation we now use RHEV. It's been pretty good so far. There are free versions but we went with fully supported: https://www.redhat.com/en/technologies/virtualization/enterprise-virtualization
-
we had to ditch Citrix as their new pricing model would have cost us £20,000 per year. Shame as we've been a loyal customer for over ten years.
-
What actually needs encrypting?
mjk replied to enjay's topic in Data Protection & Information Handling
I think that would be a problem with the security settings on the legacy system. If any user can get any sensitive information out of the legacy system they's just email it out. Need to tighten up how the users get the sensitive info into the system in the first place. I've heard teachers claim this, but when management actually did an investigation they found it to be a non issue from some whiners. Our department ( ITSupport ) had to convert a handful of files and the problem went away. That's not a surprise for microsoft to remove a nice migration path -
What actually needs encrypting?
mjk replied to enjay's topic in Data Protection & Information Handling
Agreed. I'd be inclined to install powerpoint viewer on the school machines to help get across the point that these documents are legacy and staff shouldn't be creating new ones. -
What actually needs encrypting?
mjk replied to enjay's topic in Data Protection & Information Handling
I've not found it to be quite that bad but I think you should check my earlier comment: 1) chose an online suite such as google/office etc 2) prevent documents being downloaded What you've done is: 1) chose an online suite such as google/office etc 1a) continue to use the old system 1b) have a mismatched system 2) get complaints because you have mismatched systems 2b) not get the benefits of either system I'm not saying it's your fault as it sounds suspiciously like management had their hand in this one; but at the end of the day if you're using Gsuite then you really need to start enforcing staff to create documents in it and treat Powerpoint as legacy.
