Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. And the funny thing about this ... Capita have been running similar services for a number of customers for years ... quite happily. The rejigging of things to fit in with GovStore and the way that everyone looks at the marketing blurb on cloud ... quite amusing the way certain folk are getting a little vocal about it. As I understand it, this is an improvement on a tried and tested service that has been out there for some time (over 10 years IIRC), available to be connected to via PSN compliant networks if required, and is cost effective for some but not for others ... as has always been the case. Now we are just getting into semantics and theory ... almost, "Hey guys ... if we were all to make a cloud-based solutions together for and MIS wouldn't it be brilliant if..." As for Apps ... are we being asked if there are apps out there that allow for local or networked working, extracting and writing back to a hosted service? Obviously Skype, Netflix, Amazon App, Evernote are all stand-alone utilities?
  2. To be honest, just search for any posts of mine with the words director or strategy in and you are likely to come up with a *lot* of stuff ... too much to condense in here.
  3. Morning all Some of you may have seen that the ICO has been updating their materials again for education. Data Protection Guidance for the Education Sector | ICO The new video is a helpful tool to show SLT, staff and governors. Have a look at the other materials too, and encourage the use of the lesson plans. It is a cunning way of educating staff without them realising as they teach the children. :-)
      • 5
      • Thanks
  4. I have them all!!! They are my precious ... (though I left various spares dotted over Northants ... you just need to chat to a few other schools) ;-) But if CAM want's to ship one out ... :-)
  5. My policy in these situations ... the hardware all gets turned off overnight to reduce damage to the servers and to reduce any fire risk.
  6. The other things that annoys me about this article is that it allows for now development of the use of language, especially where the frames of reference (e.g. long term partnerships rather than marriage) now exist. Access: to access rather than to gain access is used in a number of technical specifications, including RFCs. If language is adapted due to specific need (e.g. technical growth), and with specific definitions, then surely there is no problem? Adultery: the frame of reference used (marriage) needs to be updated. Choice: The stipulation that a choice is only ever made from 2 options is slightly faulty or that it is always singular. There can be a range of options and there may be several choices to be made as a result. A choice of starter, a choice of main course, a choice of pudding and a choice of the implement to wield when getting annoyed. Collide / Collision: All bodies are in motion. The premise that a tree is not moving fails to take into account the earth's orbit, the expansion model of the universe, etc. If he wants to be pedantic then let's get back to basic physics ... the interesting moot court' discussions during A level physics lessons on such things and the several 100 press ups I had to do during RMP training where I would say 'accident' instead of 'collision' when dealing with road traffic scenarios may have also swayed my opinion on this. Disabled: This is a pet hate of mine from days working with children with disabilities. People have impairments. They are impaired. Society denotes their disabilities in a broad range of categories. They are not 'the disabled'. This shorthand reference to a group of people is abhorrent in all areas. Language is part of how society interacts with one another. Again, it just shows how poor his frames of reference are. Livid: This refers to a change of colour due to a blow of shock, often used to describe the discolouration of contusions, which will range from black, blue, red, brow, orange, yellow and even white. Where he refers to the use metaphorically, this is incorrect. It refers to how a blow (mental or physical) might cause discolourations, including the flushing of face (reddening) or draining of colour (paling). The responses to this list on some of the language lists has been amusing ... most agree that the intent is worthy, but the execution lacks a basic understanding of any form of language growth or adaptation for specific needs. Others just agree that being a grammar/language nazi is one way the Daily Fail have of shipping copy.
  7. I did have this out with a friendly journo once ... and he had it nailed down as a response. Yes, to say 'try to do' is the general correct usage, and people will often mean this when they say somethings else. However, when someone refers to 'try and do', it can refer to the fact that an individual attempted something and was successful at it. 'Try and do' signifies the attempt and the success. And then he agreed that this is very rare and most folk are just numpties who can't be bothered to read what they write.
  8. Do you have guidance for staff that if they use the website they are not to then use the client at home / on mobile devices? Do you have guidance on the type of data that it can be used with? Any snippets from AUPs around this would probably be helpful to others.
  9. lol, thanks for that @elsiegee40. Here is a short guide to cloud storage and the use of it by schools. When considering the use of cloud storage there are a number of areas to consider. Under the Data Protection Act the most relevant of the 8 principles is principle 7. In previous years the ICO has talked about reasonable steps, but they now make it clearer that it is 'appropriate' measures, and consideration of this has to be based on the type of data being stored / processes and the likely impact / damage should it be compromised. Translation? Before you decide where you can store things you have to consider what you are storing. When looking at cloud based storage you need to complete a risk assessment of what is being stored, where it is being stored (location of actually servers, company history, T&Cs, etc), what measures are being taken (technical and organisational) to protect it and what are the alternatives? In the past there has been lengthy discussion about the suitability of certain services. Google Apps, Microsoft's Office365, Dropbox and so on. The principles above stay the same. The ICO talks about data being processed outside of the EEA, companies that have signed up the Safe Harbor agreement between US and EU, advice on cloud computing in general and so on. The important differences between private cloud, community cloud and public cloud (and the resulting hybrid model that is possible with some use of all 3) should be considered here. Translation? Putting things in the cloud is fine, but you have to plan what you are doing and take care to make sure about the partner / service you are working with. Previous conversations about the use of dropbox can be summarised in the following points Do we know where the data is? Yes, we now know they use Amazon storage based in the US. If the Data is outside of EEA can we still use them? DropBox have now signed Safe Harbor so there is nothing there stopping you anymore. Is it safe? Yes, for a given value of 'safe' ... the data when stored it is not so much how the data is transferred, or how it is stored when it gets there ... more a case of how is access controlled. Thhis takes us back to the 'appropriate technical and organisational measures' part of the DPA. Now let's look at what considerations should be taken for *any* cloud based service. This is not a definitive check list, but it is a darned good place to start from chatting with most folk. Check where and how the data is stored. Consider if it is within EEA or in US and with Safe Harbor signed. If it is with a US company who has signed Safe Harbor but there is no guarantee the data is held in EEA or US then you have to consider the locations where it is stored and the impact any local laws there may have (e.g is it stored in Australia, Brazil, Thailand, etc and do any local laws mean data could be seized differently to if UK / EU / US laws were applied?) and how this affects you. What are the guarantees around the company? Anyone can set up a service but do you trust the company? Have they passed any security audits? If they are a specific education company do you need to consider DRS checks? Now the data is stored outside of the school what are the restrictions on access / processing? Technical? Organisational? What are your audit trails for this? Bringing it back to DropBox again ... the main concern here is how the data is accessed and cached on local drives. Is the account a 'personal' account that is being used? What guarantee that you can control the data should that personal account no longer have the right to access the data? Scenario 1 - HoD needs data to be shared with teachers in her department. She has a DropBox account, as do others. She uploads a coursework logging spreadsheet into a shared folder and others access / complete it. A member of staff leaves so that access needs to be removed. Who removes it? As the service used is personal then it has to be the HoD? Is she aware of this? Scenario 2 - HoD needs data to be shared with HoDs for other departments to target intervention children. The spreadsheet will contain reasons for intervention, including details of personal circumstances (which can include Sensitive, Personal Data). A member of staff is suspended due to allegations ... how is that data then secured? The school has no oversight of the methods used to share the data and is reliant on all staff taking ownership of controlling data. The audit trail for this is horrendous! Scenario 3 - The same data is being shared between HoDs. One HoD installs the client on their home computer which is used by all family members. At this point the school has not control over how the data is controlled. Guidance is needed to be provided (using organisational measures rather than technical measures) but again, the audit trail on this is horrendous. Scenarion 4 - The same data is being shared between HoDs. One HoD installs the client on a personal mobile device. The device is then stolen. Is this a data breach? How was the device encrypted? Can it be remotely wiped? The above scenarios would make most people shy away from using *any* cloud service ... but actually, the ways of dealing and mitigating the risk is pretty much the same as if you are using school hosted services. Make sure that your AUP for staff covers the use of cloud services and the personal responsibility that each member of staff has to ensure that they only share data by controllable means. The school needs to assess whether their staff have a good understanding of Data Protection and Information Management, and then they can chose appropriate training as well. Make sure staff understand what levels of data are being processed. DPA talks about two levels, Personal Data and Sensitive Personal Data. Becta also worked on the use of Business Impact Levels and the UK Govt still gives advice around this too. CESG has the specific information if needed. When using email make staff understand what sort of data can be shared on that service. Good practice is to store the data in a controlled location and email the link to it, rather than emailing the file around. This is also good practice for managing mailbox size too. win-win! Where cloud storage and email are accessed on a device then make sure it is encrypted, secure and wipeable. If desktops the physical security is taken into account, for laptops the device encryption, but for mobile devices (phone / tablets) there is a strong level of importance on device encryption, strong passphrase for access and the ability to remotely wipe. It might be that tablet devices need to have 3G access purely to allow them to be remotely wiped. The company position on how this is dealt with on personal devices (and the audit trail for verification too). So, back to the question. Can you use DropBox? Yes ... but make sure you consider the above 4 points, factor in the cost (both technical and organisational) for implementing it (and yes, that includes training, checking staff personal devices, etc), the politics involved (not usually dealt with by NMs but by SLT ...) and the timescales involved. Make sure that SLT know and understand that this is to do with the application of a Law within the school ... and that you are not being negative or trying to stop people doing things ... Look at alternatives. Remote access to school systems so that the data never leaves your walled garden are very good but can get very expensive. Instead of using personal tool have a look at verified cloud based services. Some have not licence costs (O365) but you then get limitations on it being a free service, shared with others ... and you have to factor in school staff time on it, and other have a cost but you then know that the service is backed up by SLAs, etc (declaration of interest ... I do work for such a cloud-based service!). I hope this covers off most of the areas you needed to look at, answered some of the questions that might arise within the school too.
  10. You *do* need it in the AUP as you are keeping staff informed, gaining their acceptance and understanding of how and why things are set up in a particular way. If you don't include things like this you are not helping yourself or the school. It is not *all* about the technology, but also about the education of users ... oh, and PR too.
  11. On a note about personal mobile devices being used to access emails, etc ... Within your AUP you must point out that these devices must be encrypted, secured with a complex passphrase (4 digit pass code or being able to follow a greasy, sliding trail on the screen is *not* good security) and, where possible, set to autowipe after x failed attempts to log in. Staff should give permission for routine checks to see that this is in place on personal devices, and should it not be then that device will be blocked from accessing the service. These are the *reasonable* technical and organisational measures that can be put in place to protect data (DPA principle 7). If staff don't like the IT staff doing checks then you increase the technical measures (VDI, etc) but the school accepts that this increases the capital and operational costs of the service.
  12. That is only because ZH has run out of cats / drummers / minions (delete as appropriate)
  13. The Hamster needed feeding / he hit it with a hammer / another pony was sacrificed to the Elders of the Internet / suitable excuse of your choice ;-)
  14. Creative Commons is a good place to look for this.
  15. This scenario has been talked about a number of times and it has just been a case of waiting for it to happen. The response from some firms is 'come and get it', meaning that they will release it if there is a physical presence in the country where it is being held ... on the basis that the law enforcement for that country will then turn round and say, "sorry, you cannot take it as that would breach Data Protection laws." This will be interesting to watch.
  16. There are also some interesting things that happen when a home device, logged in on an O365 account on the A2 plan, tries to buy the O365 home premium package so that at least they have the active iPad app at home (with the other benefits). If the purchase is made directly with MS through a family's personal LiveID then that is what it gets registered to. If purchased on the iPad it 'can' register it against the AppleID ... and if that is not associated with MS services at all then it is a pain to get it sorted. In the end I got a refund from Apple and went direct to MS. MS Education are looking into this as well and there will be advice around the whole area coming soon.
  17. PM quals/experience are a must for SBMs. Probably second only to mind reading!
  18. You can use any domain really, just not one of the restricted domains (from RFC 6761 or RFC 6762). I know quite a number of people who use .internal or short names to do with their business (.shop, .car, etc) ... but with domains being opened up by ICANN people are finding things like .info, .name and so on being real domains ... ... I know one museum that is having fun and games over .info with the parish council, who run a local information service. At the moment there is not a clear internal domain for production environments it is down to the Sysadmin to consider what the risks are. O365 doesn't really care, to be honest, and the guide from EduTech covers that side.
  19. Sorry to but in here, but can I make reference to the use of .local for an internal domain. .local - Wikipedia, the free encyclopedia Probably too late for you to change it but anyone who finds this thread and is building a new domain and O365 into it can people follow the standards?
  20. They are from different branches. Welsh, Cornish and Breton are Brythonic Scottish Gaelic (usually pronounced as if saying 'gallik'), Irish and Manx are Goidelic When you get to Irish you then get the official language, and then the dialects ... and getting someone from The Pale and from the Aran Islands to talk to each other leaves them arguing (usually over a pint or two) about the best way to say good afternoon! Then again, you can get the same between North and South Wales.
  21. The educational need is the ability to learn a language. If you learn one that is actively needed now there is no guarantee it will be needed in the future, so the idea is to give the skills to learn and the ability to understand how language can be associated to culture. In the same way coders can often use multiple languages, there is a healthy train that most people can be polyglots ... the first language learnt is often key to this and chat to any group of MFL specialists and you can spark a riot about which should be the first language learnt.
  22. It was more a reference to those with 250+ devices on XP needing a premier contract for support ... if we have any members with *that* many devices still on XP then they really do have an issue. Yes, most will be covered and looking forward to hearing from the first member who contact CCS to ask for it all.
  23. Support available for certain eligible groups in the public sector. More info from Crown Commercial Services. Custom Support | Crown Commercial Service
×
×
  • Create New...