Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. Google is pretty clear about what is included for educational use in their products, through what they deliver for Google Apps for Education. This seems to be one of the drivers for the inclusion of the Play store into this set. Many companies, such as Google, turn a blind eye to the use of certain personal products when it comes to education ... and you even find their evangelists promoting the use of personal products ... but the company will tend to come back and quote you the T&Cs if you ask them a direct question about using it ... rather say an outright yes or no. A good number of private / independent schools are within a charitable trust, so many will argue that this sets them outside of the commercial sector, and this would be a healthy arguing point if challenged. Google, like Apple, are doing a fair bit of promoting sets of their products as part of the delivery of personal devices. If you are going down a 1:1 scheme this fits in well, but it makes it hard to manage on class sets of machines using schools generated and controlled accounts. Ok, I know ... not a clear yes or no, but I'll go and ask a friendly Google Trainer (there are a few who lurk on here) to see if there is a better answer.
  2. Are there any fellow NAACE members who could drop me a quick PM?
  3. Out of interest, does this academy group manage primary, secondary and special school?
  4. Chapter and verse is as follows ... or at least one careful perspective To meet DPA principle 7 you should take all reasonable organisational and technical measures to secure data. Normally this would mean that the only people who should know the password of a user is the user themselves. The school should have the ability to change the password or prevent the user change their password, should they need to complete any legitimate investigation of use or breach of school policies. This is done through this methodology so that the school is reasonably sure that any activity on an account is from that user, and there are no or few opportunities for others to use the account. If others have access to the account you cannot be sure who has done anything with it, risking principles 2, 5 and 7, as well as making it difficult for law enforcement agencies to investigate any breaches of the law (computer misuse act, child protection investigations, etc). There are times when you might want a need a list though, and these should be considered appropriately. In some schools the class teacher may be required to have ready access to the password for users in their class, due to the age or ability of the learners. This should be treated sensitively by that teacher. The teacher might not be given trusted delegation to change passwords as this can be deemed an admin task and outside of the teacher's role / work. A central list might need to be maintained to be a trusted person within the school for this to be referred back to. The storage of this central list must also be treated sensitively. The main reasons you don't tend to have the central store is audit and accountability. Other reasons why schools seek to have the list is to allow any designated member of staff to have access to specified user areas. This might be provided alternatively by the use of permissions on file storage. If you are operating on an cloud based solution that does not offer this level of delegation then again the central list might be deemed the appropriate way to manage risks. Key to all this? Risk analysis, and taking justifiable and appropriate actions, and ensuring that any changes to risk are dealt with accordingly. I am not saying that the central policy is right, just that it needs to fit around *your* analysis! and that of the SIRO in the school.
  5. I resemble that remark! I mean resent! I am far cuter than those fluffy cats ... and nowhere as annoying as nyan cat!
  6. Traffic lights are a Hazard, and you always approach a Hazard with caution. Generally this means proceed at a constant speed if it is safe to do so, whilst considering all other Hazards (weather conditions, is it a crossing point, etc). There will be times when you have to speed up (within the constraints of the legal speed limits) once you are committed to passing through the lights, eg if they start to turn amber and it is unsafe to slow down to a clear stop before passing the stopping line. It is considered safe practice to slow down when approaching a Hazard, to allow you sufficient time to assess it. When you slow down you become a Hazard yourself and must also take this into account. See ... driving is an example that blokes *can* multi-task!
  7. 5 for me ... And I am feeling a bit more stressed than usual at the moment too!
  8. I only turned up because people had gone missing from uk.education.schools-it! Thanks for letting us all play in you sandpit, Chris ... It has been, and still is, a blast.
  9. The ire about the Keynote upgrade (or a downgrade in respects to some functionality) has resulted in a number of people going back to the previous version. Whilst the iOS version improves, the dumbing down of the desktop version to fit into the online and iOS versions is a massive frustration. Publishers of 3rd party themes are finding that some of the features break their themes and templates, which cannot be fixed now. Users with significant catalogues of presentations (e.g. churches, museums, etc) are finding even just opening the keynote file is adjusting it so that it cannot be open in the previous version (thank $deity for time machine). Seriously Apple ... after not updating iWorks properly for ages, you now b0rk the desktop version to the point of folk wanting to go back to Powerpoint? Chatting to one unnamed Apple employee last week, he has had to rebuild over 75% of his materials he uses for presentations to customers. I asked one person at an Apple Store yesterday over whether it was worth doing and he was quite clear that Apple's recommendation is that you always make use of the newest version of the software ... though he (and many others) do recommend spending some time to make sure that *all* your files, themes, templates, etc will work on the new version before you upgrade ... and then it is obviously our choice if we go ahead an upgrade. I translate that as, "It *will* break things ... don't do anything until you are sure about how much it breaks and whether it is worth the pain!"
  10. Of course he is a little sweetie ... surely every remembers the big grin he gets every year at BETT when he knows it is face paint friday and he gets to play again!
  11. The term 'e-safety compliant' is a bit of a misnomer here because there is not an accreditation or standard at the moment for emails services in schools. The best you can say is that it meets your needs against a rigorous risk assessment covering a range of safeguarding requirements. This, however, means you have to work out what your requirements are as a school and the check O365 meets them. There are lots of good blog posts on the UK Education cloud blog on Microsoft. Have a search through for those covering IL-2 compliance, segregation of GALs and routing of messages, the use of language filters, etc. Then also look at the 3 services you get with O365 (ExchangeOnline, LyncOnline, SharePointOnline) and decide which services give you which tools that may have more risks than others. Do you need students to have Lync? How do you feel about students and staff having an online storage space that you have no technical control over? To some extent there are no obviously right or wrong answers ... and also remember that technology does not have to solve all your problems on its own ... Policy and procedure also cover a lot, but you have to accept that if you provide a service and force learners to use it then you have a large element of responsibility for actions on it, even outside of school premises and hours.
  12. I'm looking around at some simple options for managing a WP install where all media and content is unavailable unless you are authenticated. Most plug-ins I have so far have resulted in once you have the link to a media file it is directly available if you post the link publicly / share it. Going down the IP lockout route isn't appropriate, and it has to tie into the standard WP authentication page to allow others to administer users. Any advice appreciated.
  13. I love the idea that I might have an attitude that I am superior to others because I am an iPhone user ... Most people tell me it is because I am a geek. However, the truth is simpler than that. I have an an attitude that I am superior to others because ... I AM SUPERIOR!!! Bow down before my awesomeness! Then again, my Lumia 920 is as good in most ways as my iPhone 4S, not as good in some and better in others ... but I still dig out my Sony Ericsson P800 to use occasionally, because I like tech and because I can!
  14. It will vary from school to school but generally the NM, and others with full access to the main admin account which can access everything, can grant access to everything or change passwords to grant access, are recognised as that they can access everything, but that does not mean they *will* access everything. This is then backed up with an audit trail of password changes, etc so that it is clear who has done what... if needed. In the same way the CPO in the school will have access to sensitive personal data and data labelled as IL4, it does not mean that they will read every little bit of data on every child.
  15. If the Head has admin access and doesn't have a clue about what he might break when fiddling then the school is failing on principle 7, as they know that there is a high risk that something could go wrong. They are not taking all 'reasonable' organisational measures (ie only those that have the expertise, experience and understanding of the data and systems it is housed in). If the Head is trained and certified SysAdmin then it would be reasonable for him to be granted full admin access (or given a separate account with full admin access so that there is a separation of activities between the day job and the elevated access). In the same way, if another member if SLT is an experienced data controller, has a high level knowledge about the MIS then they might have access to a full admin account in there. It should be part of a school's risk assessment when identifying data controllers, and the final decision should be with the SIRO, if you think about it.
  16. Correct, it is not "your" network, but it is "your" password ... and you can cover it under DPA under principle 7. Principle 7 of the Data Protection Act - Guide to Data Protection Sharing your password means you are not taking reasonable organisational measures to prevent accidental damage, ie that someone may delete or move data for which they do not have the understanding, expertise or experience to judge the impact of. I would also cover it under Principle 1 - the processing of data shall be lawful. If access to data is given to someone who does not have the right to process it (ie as part of their job description) then your are in breach of principle 1. And this is before we get into the fact that it would allow for accusations to be made against SLT that they are 'investigating' staff files and there is no clear audit trail to prove it one way or another, meaning that any case of constructive dismissal suddenly gets a massive injection of ammo to throw at the school. Explain to SLT that by doing it all by the book you are protecting them and the school, and should they wish to insist that they know your password they I suggest you give them a dummy account, with minimal delegate admin access whilst using a separate admin account yourself. I would also speak to a union to get advice about being instructed to complete an action that could be potentially harmful to the school and individual employees. In short, don't give them your account, give them another and if you can do as suggested, account details in an envelope, sign the envelope, laminate it, sign the laminate too, then into the safe. Some SLT will want a second copy kept off-site. Do the same again, but the off-site copy has to stay with a nominated and trusted person such as the Chair of Governors, then brought in for a monthly check to show it has not been opened.
  17. An Academy is a school. https://www.gov.uk/types-of-school/overview gives a layman's overview of the types of school and What is an academy? - Schools gives more detail. The Education Act 2011 covers Academies (and gives amendments to the Academies Act 2010) but an Academy is still a school. It my have a charitable arm, a trading arm, federated schools, etc ... and there are relevant domain names which can be used for these, but a school is *not* a business (not even a not-for-profit). Have both domains ... it is not as if it is a lot of extra work to have the .sch.uk domain as a fall back for certain things.
  18. Specific expertise that you get from ASEs and AASPs can be a really good thing. You can find media experts, networking experts, educational app experts, etc ... rather than just people trying to shift boxes. Personal preferences are Solutions Inc, KRCS and Toucan.
  19. Yep, it can be made into a pretty decent website nowadays. Does that value also include the IP for the code for the templates / layouts used?
  20. Five mins to remove an account from Moodle ... And how many accounts might a secondary school have? And what about archiving the personal data, and scheduling for destruction at a later date, including the contribution for decommissioning the hosting server at a later date? I know these are the small things that could be factored into the cost of running a service (which some suppliers do) but then you have schools complaining that these are charges that might never be needed so why should they have to pay them whilst they are using the service with no plans to change? Damned if you do and damned if you don't!
  21. Most schools will have disaster / business continuity plans to cover this, with the support of their insurers, and the LA too (even if no longer an LA school). Often it is a phased approach to getting children back in, concentrating on exam / final years first.
  22. Done and tweeted out. Will FB, etc it later too.
  23. Disclaimers are also for internal reminders for employees about their obligations with regards to communications.
  24. A couple of things to cover here. 1 - the separation of core and end user devices is a common approach (and a fairly good one) but make sure that as you make decisions about suitable tech (hardware and software) for end user devices that you adapt the core tech appropriately. 2 - saying that ... focussing on deciding on tech first is pointless! The amount of tech, services, design and implementation you are looking at *over a set period* (ie likely to be at least 3 years but could be 5) is going to require either a single large tender (EU level possibly, as previously mentioned) or several smaller tenders that will need careful management between them. These tenders have to be based on functional requirements and not tech specific, though you can go down the Single Vendor route (ie a single manufacturer or distributor if the functionality required is not available from multiple sources or there are other contractual reasons for Single Vendor) if you do it carefully. 3 - Free schools can get additional advice about working to build tenders for this sort if thing from EFA. Make use of them as they are a gold mine of information. They have access to expertise from former Becta and PfS staff on this. 4 - don't be scared to go to the DfE framework to buy in a consultant to do this work for you. In the same way you are getting good advice here, there are specialists who write these vision statements / functional requirements / technical specifications. Other consultants are available and a number of them are members. As much as the membership is giving advice for free (based on a lot of real world experience) to get the final requirements complete I would go to a specialist. Procurement in the public sector can be ... interesting! 5 - if you check the Becta archives (available from the National Archives website) you will find 2 helpful documents. These are the IT infrastructure functional requirements and technical specification documents. Whilst out of date now (for both areas) they can give you the back bone of where to start. Don't treat things as a shopping list though ... otherwise you *will* want to buy everything. 6 - don't worry about the Apple/anti-Apple or tablet/anti-tablet discussions. There are times when the functional requirements (ie the curriculum and school ethos is going to be based on a very particular approach) can be driven by key staff wanting to work in a particular way. There is nothing wrong with this if it delivers the required goals of the school, but you just have to be careful that it a) is not in breach of procurement rules, b) is not going to cause difficulties in future years (EG those key staff moving on and new staff have a different drive) and c) is not going to be financially unsustainable. I would recommend you speak to other free schools, schools just coming out of the 5 year IT services within BSF, EFA, groups that link building design/technology/learning together (have a look for work by Prof Stephen Heppell, the LearnSpace project in Northants, etc) and keep asking here for feedback too.
  25. GrumbleDook

    Hwb

    *declaration of interest* When are you both due to come online to Hwb?
×
×
  • Create New...