-
Posts
3,240 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by mthomas08
-
More than welcome to drop me a PM. We had a scheme for 5 years and 4/5 was a Windows based device. It was a mix of cheap as chips netbooks to more pricier ones. Cheap devices are fine if covering the basics - word/internet. The second you want to treat it like a PC, that's where you look at higher spec machines. Up to £250 each depending on what you go for. One year we attempted android tablets which generally were more reliable but the sheer damages on charging ports/smashed screens and the limited Apps available.. we didn't go there again. We considered iPads but the cost increase even on educating pricing at the time was far too high. We included extended warranty and insurance on ours.. so we did our best to cut the costs.. Our schemes are all but stopped, we decided to cut down costs to IT, remove any Parent problems etc and go back to basics : PCs.
-
GDPR & USB Pen drives
mthomas08 replied to Mark182's topic in Data Protection & Information Handling
Phase out and head towards something like Google Drive. So far the majority of our exam boards will accept this but some still need double checking. -
Getting staff to take it seriously...
mthomas08 replied to Gongalong's topic in Data Protection & Information Handling
Scare them. -Take the laptop so they have to effectively report it as stolen -Any insecure area with sensitive data is a risk and should be assessed reported - do your duty and pass it on the HT/Governors. Inform staff that this is the process and that it could also go to the ICO which may end up including those responsible for the risks. We informed staff that the individual and company can be named/fined. If they have received the training and still refuse to listen. As the DPO you should know the procedure especially under GDPR, follow it. Our HT did a presentation to scare them. And it worked. We are not expecting perfection because it's a mentality change but we do want progress. If the same member of staff constantly leaves sensitive data laying around, unlocked area..... scare tactics work. I think at the end of the day you need leadership all on the same page. -
Is this a world that gets reset every now and then or permanently left? Assuming survival? I picked this up again recently.... so weird..
-
We've got multiple choices here.. I don't like edge but sometimes gives us issues on older software/sites.. 2018 and we still have software which only works on a single browser...
-
Where do you see IT going in education in the next 5 years?
mthomas08 replied to Qas's topic in General Chat
We have pulled back on BYOD/Mobile devices in education and a few SBMs I've spoken to seem to be taking this approach. I think it really depends, if you have the funds to install new technology like having large screens instead of projectors etc. I've gone down the route of going for simple, cost effective and PCs in classrooms without mobile devices galore. I also see more schools returning to this route (already know of 3 others). Mobile devices are fine if the school is prepared to do it properly with the support, time and money. Simply sticking in devices that are easily damaged, expensive to repair and require more support depending on your school. We are not a grammar and with that we do have quite a portion of students requiring extra time/care. We have Office 365, G Suite and Moodle. It allows staff to choose what's best for their departments and it depends. Our future is always considering moving completely to 'cloud' but that does require extra broadband and reliance on our external links. The good news is, our broadband reliability really seems to be 99.99% but considering how much work students/staff are saving internally.. there is a hesitancy to switch completely. IF we do switch, it will be perhaps one year at a time to see how it progresses. When you look at the money schools have spent going 1/10GB internal networking.. just simply switching to a broadband of 100MB (or worse less) could be problematic. I think email would be the first thing we switched and most likely students. With budget cuts etc, I'd stick to A) reliability, B) cost effective, C) doesn't require any more support reliance. So in summary, I don't see education being any different in 5 years. I'd like to think schools would be in a better condition but with cuts/layoffs I see the same circle. That circle being: cut backs/layoffs > failing > more money/staff > working > return to start. Similar to the NHS mess regarding the cyber attack. -
Do we need to encrypt server for GDPR?
mthomas08 replied to Anothername's topic in Data Protection & Information Handling
Nope. It sounds like you are perfectly okay in regards to security and encrypted portable devices. -
Sigh...... "46 per cent saying they were not offered a choice about the use of web monitoring technologies". So does that mean I have to go through parents instead the usual 3 quotations to Governors? They have any idea how many staff we've had to fight over the years to get a good filtering system in place? (you know.. those staff who think kids should have unfiltered access because they are all little darling angels) Do they realise that they've no idea how these systems work and if I attempted to explain.. they'd be asleep in 5 minutes? Are we going to have systems based on IT illiterate people instead of what we believe? It's like ignoring a mechanic to what breaks to have for your car.. sure cardboard ones will do because it's my choice.. "When asked what information they should have, 84 per cent of parents said they should be informed of which keywords are flagged. Some 69 per cent also said they thought the kids should know what the keywords were." Here you go.. here is a list of all the keywords we have filtered.. oh *sends it to the students too*..I look forward to the kids not using those words more often... because again.. they are angels.. "Most parents (86 per cent) said they wanted to be told what the consequences were if the keywords are searched, and the same proportion felt the children should know too." They do.. it's in the AUP which is part of the parent package and the first IT lessons students get covered this.. I would also assume every school had something similar.. "She also voiced concern about the effect web monitoring might have on childrens' willingness or ability to use "vital" advice sites like Childline." Not got a clue have they? I've yet to see a single school block educational or helpline websites. In fact most if not all will have them setup 'allowed'.. So in simple terms they've not looked at filtering systems, not sat down and discussed with some one in IT who manages the system.. "CCTV in toilets is ludicrous," said Oladuti. "If your toilet is in such a state you need surveillance, I think you need to redesign your toilet." We did that.. and they still got trashed.. try working in schools with some difficult children... how do you make a toilet that's bomb (child) proof..
-
Data Map - Do we need to publish?
mthomas08 replied to crc-ict's topic in Data Protection & Information Handling
No you don't need to. -
We are on 17.2.2 and no issues. Our plan is to upgrade during next half term.
-
Dedicated staff for GDPR
mthomas08 replied to genesis's topic in Data Protection & Information Handling
We have a DPO and I assist him on half the work. I don't have to but he scratches our backs so we scratch his. I am able to spare the time for GDPR because we have leadership backing to make things work. I've also got two technicians who can run most things without me. Without that team.. I couldn't do it. -
I'm sure this isn't correct way of doing it at all. We are told that it's recommended to use school email for all related emails to the school. Not to use personal ones to store work etc. We are even setting up the Governors to use school email. If there is a breach or sensitive information sent around and that data is on a 'personal' email account.......... Sorry but I consider this a 'risk' and although not punishable... unless there is a breach because it's on personal email and not a work one.
-
YES. There was recently an incident that a member of staff in the Education sector took a screenshot/photo of FSM data and shared it with some one they shouldn't. That individual who took the photo was fined. This wasn't the link I had but this is it: https://parissmith.co.uk/blog/education-worker-fined-850-following-conviction-data-protection-breach-magistrates-court/
-
School CCTV cameras "hacked" and streamed online.
mthomas08 replied to spacebar's topic in General Chat
Sadly yes... I have dealt with around 2 different companies and a few contractors. Security of the actual equipment or networking wasn't exactly their speciality. Hopefully though, most of us are -
School CCTV cameras "hacked" and streamed online.
mthomas08 replied to spacebar's topic in General Chat
If they are being moved around.. it takes time to really get to know 'that' school. How things are setup... how things work... when a single school is being half ignored in favour of the Trust as a whole. Someone I know went through it. Thank you for nit picking though... I could have carried on listing things but I'd be here all day. -
School CCTV cameras "hacked" and streamed online.
mthomas08 replied to spacebar's topic in General Chat
Lets be honest here... CCTV tends to be covered by us IT people.. this is on top of everything which is fast becoming IT and all under O U R remit. Some years ago I wouldn't have even considered to be looking after CCTV. It was run by the premises staff installed by contractors and used only for theft/serious incidents not for bullying. Now we have budget cuts/squeezed, staff redundancies, being moved around in MATs. Schools would rather spend hours upon hours and thousands of pounds on pretty devices or projects that get cancelled. Instead of spending the time/money on improving what they currently have. We could also mention the amount of IT staff being TAs, PAs and every other word that means assistant in education. Some of us move jobs constantly for one reason or another. To top it all off.. we are very lucky IF leadership support us.. to do things properly.. GDPR is a prime example.. We can all sit there and say "common sense" but in the situation some of us are in.. I am very surprised it hasn't happened more often. I am very lucky, GDPR has full support from leadership and so does my team. One thing we have recently been doing is tightening security on CCTV and even the recordings. With GDPR/ICO we are seeing what breaches occur in education. I've seen quite a few pop up recently and I think it's needed. -
I was just about to post this. CCTV is covered in regards to consent, why you have it, who has access to it and should they have access. We have limited who can ask for it, who has access to the footage all for GDPR and in simple terms 'covering our backs'. Although I wouldn't call it a safeguarding issue, I'd play it safe by not having it on display just for GDPR. And some one else mentioned the privacy risk.. this is a good example... it could be classified as a risk. If there is no valid reason you have CCTV on display in the office I would just stop it to protect your selves.
-
This, it makes life simple. Our audit is not far from being complete - bar all the generic stuff we know most staff hold in their areas. Staff will hold a load of copies of student names in their areas or the shared drive - we know why 99.99% of this is being held. We are going to double check with everyone anyway just to be safe. A dozen staff are down for data controllers, they hold sensitive data outside of SIMs and it's paper/electronic copies. This is the main priority which is almost finished.
-
Secondary/Sixth Form 2000+ devices 2 technicians full time, 1 NM
-
Our GDPR Timeplan for comment!
mthomas08 replied to kennysarmy's topic in Data Protection & Information Handling
Every week the school assistants send out a newsletter to staff. I include an IT one which has had parts of GDPR for the last 6 weeks or so. Course not everyone is reading them. Sort of: CCTV reminders (what's there for) Locking PCs, classrooms Taking extra care what sensitive data is (more than just names, looked after children, medical, addresses etc) Reminders really and in small doses. Similar to child protection, they will need training and refreshers every year at least. It will be a pain but it helps them realise that names on student folders on staff desks don't matter so much (but still lock classrooms) because it's education. Sensitive data areas though will be told to lock their doors, not leave their machines logged on and risk assessments will be undertaken by a site walk at random times. -
Sharing DPO Role with GDPR
mthomas08 replied to Wubbalubbadub's topic in Data Protection & Information Handling
Was used as an example, you may not want to or be able to etc. The SBM/NM example was given to me the KCC rep, I simply altered it to match what we do. I could potentially give those conflict of interest moments to one of my guys but it's question if they would accept them (they would by no means ever be pressured to say yes because that's not my style). -
Our GDPR Timeplan for comment!
mthomas08 replied to kennysarmy's topic in Data Protection & Information Handling
We are currently split responsibility here, I'm dealing with the audit and discussing with the controllers on the big questions (what we have, security, who has access etc). My spreadsheet is currently 20 columns and 50 sub categories (half of these are simple tick boxes like staff, student, parent - personal, sensitive etc). 60+ items on this audit so far. -
Sharing DPO Role with GDPR
mthomas08 replied to Wubbalubbadub's topic in Data Protection & Information Handling
It's pretty simply, if there's a conflict of interest it's a no. You need to either not be the DPO or remove the conflict of interest. We can help, but you are under no obligation to. I am currently helping our DPO move forward and I have right now got our Audit open... it's currently a large list and what action we need to take.. all to make sure we are compliant. As explained to me this week by the KCC rep, I could be the DPO if those 'conflict of interest' responsibilities were passed on (potentially to the technicians just an e.g.) and it would be okay. You've got to ask your self though are you passing on too much, are you still able to perform your own job etc. Likewise for my line manager, if he passed on his conflict of interests on to me.. being the DPO doesn't become a problem for him. At least that's the example he used when explaining to us. Problem is for us, we are administrators that have full access to ALL the data, we permission it ALL, we secure it ALL, we control ALL the backups, we make ALL the system alterations surrounding that data - it's all a minefield of conflicted interests. We do ALL the servers which contain 95% of all the personal data. You also have to realise it's not primarily about personal data (names) but the sensitive data is crucial (health, looked after children, addresses, DOBs etc). And where is 95% of that? on your -
Yes. As long as you are not needing to investigate your self, not the controller of the data you would be the DPO responsible for - no conflict of interest. Assuming the schools have separate data systems. Potentially even if they merge - you could be the DPO if every data controller responsibility/decision you had normally was 'duck shoved' else where. Luckily enough we know some one who is the GDPR person for our LEA and he really made simple sense of a few things we was unsure of. It was a good listen, he explained that if I was the DPO or even my LM (SBM leadership) - we could 'duck shove' those data controller responsibilities on to each other allowing one of us to be the DPO. As long as you don't have a conflict of interest where you would be investigating your self - it's fine. Hopefully the above makes sense my wording may not be perfect. Guessing we've had no confirmation if a school must employ a DPO yet?
-
Looking through the blog... the list of problems is exactly how I tackled our ICT Scheme. No matter how big or small it went on a list. Even if I knew it would never be fixed, it would still end up on 'the list'. Going to type up some stuff as I go through it! Few questions: 1. Have you got an almost unlimited pocket to get this working no matter what? I don't mean throw £10,000 at something for the sake of it 2. Why did the decision rest on your shoulders? Shouldn't the priority be T&L. This isn't a grumbly question but it was the biggest mistake we made here. The priority wasn't T&L impact but more cost cutting towards having IT Suites and more 'how we look' to the outside world. 3. Guessing they will be repaired internally - have you considered insurance/warranty? Also make sure you get tough cases for users - this really does cut down a huge amount of damages.... Don't blame you for not being a google/android fan but I would have still got in touch. Also M$ trying to demo SharePoint..... totally feel for you on that one. It's like contacting a supplier for a product and they try to sell you something else. Schools not being negative when visited... sorry we did this. It's the political face and I've sometimes I got a little mad over it. We owe it to other schools to be honest and I refused to be 100% nice about it and give out no negativity. Even to parents I would be honest about the problems we have faced on our schemes. And no they are not miracle devices. It's one of the many reasons why schools went down more and more to devices because they visit a school and see no negativity... If a classroom full of PCs can have negativity - devices certainly can. May 2017 - release Sep 2017. Yes - welcome to my horrid world. This was some more of the big mistakes we made. I pushed for decisions to be made just before or right after Christmas. As for you - going full iPads (we was only a single year of 250).. Oh I would demand we start 6 months earlier - IF everything was in place. Interesting they say you 'almost' can go completely iPad... we was supposed to go complete devices but it never happened. There was too many reasons why.... Also who is paying for all this??????
