Jump to content

GrumbleDook

Edu Supporters
  • Posts

    12,876
  • Joined

Everything posted by GrumbleDook

  1. It is a hoard ... Dragons don't have to have a hoard made of gold ... for some it might be screws, or cables or adaptors. For others it might be books (we all know some librarians who are dragons, don't we?), and for a rare few it might be something special ... seriously rare things that need to be protected and nurtured ... yes, some of us have (or have had) hoards made up of knowledgeable and capable users. Small hoards, usually, but with care and nourishment you can use them to create other such users. Eventually you might end up with a school full of them. Ah ... well ... I can dream!
  2. That is not something I have said, or would ever likely to say. The correct statement would be something like ... "From the present cohort of children that are in the school, what is the likelihood that any one of them would have the skills and knowledge to be able to set up a personal device on our network in such a manner to compromise it, to be able use a school-owned device in a similar manner and what would be the impact of this? What are the mitigating factors in this that are already in play that already work to reduce either the likelihood or the impact?" Security by obscurity is a poor piece of mitigation, but focussing on that is not the be all and end all. Again, I don't think anyone is downplaying that internal vectors are extremely valid concerns. Again, it is a risk management. When we talk about zero-trust architecture, I tend to go back to the 10 principles from the 2019 NCSC zero trust architecture design principles. There is no limit on what provides the authentication, except what you have deemed appropriate for your network based on the other principles. As I keep saying (and will keep on saying), your risk analysis may be different to others. That is not saying you are right or wrong, or other are right or wrong ... just that you have differences.
  3. And this is not security by obscurity. This is looking at a risk, looking at the level of risk based on the context and mitigating actions (at this point some folk might add obscurity as a mitigation, but that would not be relevant here) and then seeing where the risk sits within the risk acceptance criteria the organisation has. The assumption that is being made is that there is the same level of risk between staff accounts and children's accounts, and that there are the same levels of risk between secondary and primary children. This is before we get into the structure and configuration of the organisation's systems ... and how that can vary to a massive degree. Ignoring risks is also a different matter. I don't think anyone is advocating that.
  4. It is a risk management exercise. As long as you complete the exercise, log it, justify the decision and have a regular review/intervention process there is not much else that can be said or done. The same threats/vulnerabilities can easily produce different risk levels depending on the school. You are right to raise it, but it is a given way of having some risk mitigation for this area. Context, as always, is key.
  5. GlobalView might be ok for some things (Cyren is a member of IWF), but does it give you granular enough control so that staff devices get X access, and children get Y .... and SLT get Z! Time based controls? Are you looking just to block, or to monitor and proactively support the school? Who will have day-to-day control over what can be accessed on devices and how do they check/ask for changes? Will staff devices be supported outside of the school environment? What reports will SLT get? DSL? Have the expressed a need or requirement? Once you have run down on the requirements, you can have a better idea of what is needed ... balancing that a small school is small, have litte time or resource to let it become a chore!
  6. Students *CAN* be viewed as customers, but that is a bloody stupid scope that misses out a significant portion of risk, effectively making the scheme almost pointless. Ok ... I'll get my coat
  7. There are a number of standards and schemes used across the globe, in the same way that CE+ is within the UK. I'd be happy to see if I can get a session running about the Forthcoming Global Education Security Standard, which can flag against CE+, ST4S (AU/NZ), NIST 80-171, CSF, ISO27001 and so on. I would definitely support a group for CE and CE+
  8. If you are storing on a cloud service, ensure that you cover the areas such as transfer to 3rd countries within your DPIA. Ensure that anything stored has adequate encryption and that you control the keys. Also remember that anything converted to paperless still has to conform with yout retention schedule, so it is not a case of scan to PDF and forget.
  9. We all need to accept that phones get banned within school. When we look at what we are doing here, it is based on risk assessment for a very specific scope. Other areas of school life also need risk assessments and there are times when risk treatment for one area (MFA via staff phones) increases risks in other areas (staff use of phones for photos, etc… so holding unsecured personal data on a personal device). After it is balanced out you cannot reduce the risk in one area by increasing it in another. It is not that safeguarding trumps things, it is about risk in particular scenarios. Whilst I agree that NCSC should *not* have a lower grade of scope to let schools fit in, schools need to recognise that this is not done in a silo.
  10. If looking at Data Retention, then it is likely that the relevant individual files would have been deleted before the drive went out of action, unless it is part of decommissioning some hardware or a hardware failure. The destruction is only to ensure that nothing is recoverable in any way.
  11. I am concerned about everyone saying that they want chocolate on/in/with their cookie. No, no, no, no, NO! You have a bit of cookie with your chocolate. Of course, if that means I get a giant cookie, then it *has* to mean I also get a massive amount of chocolate. Priorities, people!
  12. I think this is a valid discussion, for language and how the use of it varies depending on audience is a key element to transparency. Some terminology used may seem impersonal and even clinical, but that has been done to ensure clarity around the separation in activities affecting individual people. Going back to how this affects the original query, the language used to explain why someone visits/uses Google Workspace for Education may seem opaque but essentially it is to take part in activities as set out by the school. Where cookies are essential to allow that to happen, they can be deemed strictly necessary. Where any cookies are not essential (eg any linked to AdTech or used purely for the benefit of the provider) then they have to be clear and the lack of consent cannot affect how the site works. This is one reason why many of us have concerns about staff pushing children to online resources that are full of adverts, drop cookies that are not strictly necessary even before any cookie message comes up and who try to get consent (under both PECR and GDPR) to use cookies and the personal data gathered from it. There are other things that could be discussed here (linking into the recent Human Rights Watch report) but they could end up as discussions full of materials from significant areas of research that I would poorly explain. Once I’ve found a better and clearer way of explaining it I will happily come back to this discussion, but my earlier explanation is the best I can do right now.
  13. Turn off the use of GWfE and M365 for authentication against 'third parties', unless you add them to an authorised list. https://www.mydataprotection.world/blog/data-protection/looking-at-a-least-access-approach-from-both-a-data-protection-and-safeguarding-point-of-view/ gives my thoughts on it and a link at the bottom to a supporting guide.
  14. Also remember that it is not the privacy policy/notice you are looking for, but a Data Processing Agreement. It may be in the PN or in a contract/terms of service … but a PN is often more about what the company will need to run as a business … not what they process on your behalf.
  15. I just wanted to let members know that @maturelady aka Lynne Taylor recently passed away. I know some on here had had many direct interactions with her over the years. https://lynne-taylor-1952-2022.muchloved.com/ She was someone who worked across many areas in education, and her drive shaped a number of things we take for granted now. It was a blast working with her and for her ...
  16. Most of the online services you use will involve a Data Processing Agreement. These will vary but the idea is that you need to get these reviewed by your DPO. https://www.youtube.com/c/GDPRinSchools has arange of videos that could help you out here. Remember, when you say 'permission' you are likely to be talking about the lawful basis of Consent. This is rarely the appropriate one when dealing with schools, and so you need to look at what the purpose is of using the different sites. https://classroom.cloud/data-processing-agreement/ is a good DPA to have a look at for an idea of what questions you need to ask yourself and the vendor in question. So, it is more a case of letting the DPO know what is being used, ensuring that the DP Lead is looking at DPAs to get the right information together and that any risk assessments are being done, where appropriate. It is likely to be a case that your DPO is having this conversation with your DP Lead, but it might simply not have cascaded down to you. Ask your DP Lead what information *they* need so that it can be discussed with the DPO.
  17. Have you approached your DPO for advice on this?
  18. There is no harm in asking for the clarification. If $EMoS doesn't want to wade through the humdrum school community stuff and just see what they need, then that makes everyone happy. Keep gathering the information whilst you ask the question (you could pause the time but that is not likely to help here) so there is no issue.
  19. The example you give would have the personal data of ... $EMoS was emailed on given date/time by $NP2. Did it contain any instructions or items that $EMoS could respond to? Even in the negative? If an outside person could see a copy of this email, would they be able to infer any further information about the $EMoS ... such as they were employed by the school? You are looking for reasons to reduce the response by making a presumption about what the individual wants. You can go back and clarify the request, pointing out that there are a raft of 'general' school level comms that where issued or are they looking specifically at emails relating to $EMoS and the noted individuals directly?
  20. Me, Me!!!! I am missing the 1,000,000 mug and the latte glass. edit Turns out I am missing the other insulated mug too.
  21. Because customisation takes time ... and a lot of time to maintain. Service Desk engines are more than just job lists or job tracking. Good ones help provide so much more. To some extent though, you use what you need.
  22. I also use PrivacyPro from Disconnect as a SmartVPN, handy as it allows me to specifically target trackers, cookies and fingerprinting. I still have PiHole on my list of things to set up as well ... as with others, for IoT and other devices.
  23. This is a really good list and a perfect way to start to help quantify things for your SLT. Some members will have already had to deal with some of this, so do people think anything is missing at all? Is anybody willing to DM and share some info (if you can't do it publicly)?
  24. Having the wrong date on them is going to be a pain when it comes to managing your Records Management Retention Schedule. I'd see what you can do about that otherwise you are going to have a problem when it comes to trimming down and deleting records.
  25. Not so much in the policy, more a case of your retention schedule. Another plug for the templates from IRMS.
×
×
  • Create New...