Jump to content

djrscally

Members
  • Posts

    447
  • Joined

  • Last visited

Everything posted by djrscally

  1. Don't quite understand this objection, they can just record the values they filled in to the form in their FOI requests log. You don't have to have an exact carbon copy of the bytes that were sent in response to the FOI, just as long as you know that a) You responded and b) the information you supplied.
  2. More likely they just wouldn't twig that it's easier for you to aggregate the responses if they're provided in a numerical format - not everyone wears an analysis hat so they probably just wouldn't realise why you want it that way. Requesting responses via a form of some kind (whether Google or a custom one as in this case) when you're making requests to a large number of authorities with the intention of building a large dataset is pretty reasonable, and doesn't invalidate the request by any means (though I agree the lack of contact information without accessing a link probably did make it technically invalid) - authorities don't have to use your preferred format though, and may have good reason not to do so, so you probably ought to acknowledge that possibility in the request and give a "second best" preference like an Excel sheet or something.
  3. Yeah it's now GIAS. And as the way they remind you to maintain it is by disabling your access to Secure Access, K2S and S2S unless you click "Yes this is up to date" every couple months I'm guessing that most people just hit that button when they need to get into those systems. Not that I do that of course...
  4. Professional experience rather than any particular qualification. We're appointing a known member of staff though. If we'd recruited externally we might have done it differently.
  5. Technically no but in practice very likely yes. You have no way to set up the controls and protections that are really needed to safeguard personal data being dealt with via email, no way to audit your staff to check their compliance with your policies. I would open a new discussion with management that says they're almost certain to have liabilities down the line arise from this. Check the ICO's "Actions we've taken" pages for fines to schools; they're almost exclusively for messing up personal data via email; without a managed system you're going to be blindsided by that at some point, it's practically certain.
  6. Did you get a play with it at BETT? They're rolling out a new UI - significantly less 80's USSR.
  7. You can't enforce it on leaving; better to do what you can immediately. We've got IT support providing a "Data deletion" service and told staff they need to bring their USBs/Hard Drives to ICT with all the personal data dropped into a particular folder, and we'll have IT use sdelete to clean that out. That should mitigate it somewhat, but some is always going to slip through, so like you say it'll have to be in one of the policies they sign on joining that they won't store personal data on their own kit. Has to be on joining because realistically, who's gonna sign anything when you're leaving a job anyway?
  8. On this vein then; how much personal information in an email triggers the need to encrypt it? Any?
  9. Advanced have started running Progresso up for GDPR. Update this Friday gives us: An 'anonymise' button to bin all the identifiers off a staff/student record Pages to record consent Pages to record SARS and right to be forgotten requests More granular control of the API so you can restrict a particular company's access to only those records where the "This student consents to share their data with 3rd parties" is ticked No granular deletion yet, but I think that's a quite nice start.
  10. Nope; it's automatic. Past the initial setup and the occasional blip there's no staff input from the school required.
  11. Groupcall Xporter handles this ably for everyone non-SIMs.
  12. Bitlocker is the encryption thingy, but there's a group policy you can set that says "If it's not bitlockered, make it read-only". Not sure how that policy treats the hardware encryption things though.The actual setting as quoted in help articles as " Deny write access to removable drive not protected by Bitlocker"...which sorta hints that they're useless. Also shuts out competing encryption software like luks or veracrypt, which is kinda annoying for cross-compatibility. https://blogs.technet.microsoft.com/askcore/2010/02/16/cannot-save-recovery-information-for-bitlocker-in-windows-7/ Boo microsoft, you suck.
  13. Stick to your guns. If you decide to allow USBs, enforce encryption on them as a blanket measure. Side note; those massive drives they're carrying round that belong to them - I feel like that's probably something that needs nipping in the bud also. Obviously you can encrypt it, but it's theirs so they keep it when they leave. When they stop working for you they'll still have access to all the data that's stored on there. So our policy is going to be; USBs will be read only for the vast majority of staff, so they can happily use their personal drive to create lesson plans at home and bring them in. If they really need to store personal data on one, we'll supply an encrypted one so that a) it's safe and b) when they leave, we get it back.
  14. Check out the IRMS toolkit. Page 37 has their sort of proforma retention period: IRMS Schools Toolkit - Information and Records Management Society
  15. In contrast, my exams guy refuses to use our MIS for seating internal exams as he reckons it's easier to do it the old fashioned way!
  16. Sort of. You can import Roll Call data, but not Lesson Attendance data. Importing Roll Call data is in Data | Import Data | Import Tool, set the Area field to "AM PM Attendance". I think your CSV just needs Learner Code, Date, a column saying "AM" or "PM" and the mark. However, I'd be very surprised if the data manager there will let teachers have access to that tool as it's a pretty powerful (read; 'easy to break stuff') bit of the system. With that and the fact you can't do lesson attendance anyway, I suspect it's not much help I'm afraid. The right answer is to get the IT department to fix the connectivity. With a cloud system, some sort of redundancy is a must.
  17. Weird. What template does it select? Probably something weird with that.
  18. No problem. Are you on the new version with the Protect button then? Ours is the old style, works slightly differently (not integrating the Azure Information protection). Is there a way to revoke emails that are sent protected? That's the only feature of things like Egress and GalaxKey that is missing from the O365 version I think.
  19. We'll be making them read only anyway, but few if any will ever encrypt them as opposed to just switch to OneDrive. So it's kinda shutting the barn door after the horse has bolted. Because of wear levelling? You can just overwrite all empty space with 0's rather than target the specific file for deletion. That might not be NSA safe, but it should certainly stop any filthy casuals recovering anything.
  20. Hello fellow travellers on the magical GDPR journey. What are you doing about people with school data on existing USB sticks, that aren't encrypted? My plan is to have IT (who I suspect are liking me less and less each day) run a "we'll secure delete all the personal data for you" service, where Staff just bung all the personal data on their USB sticks into a particular folder, and then bring it to IT who can just sdelete.exe that directory. Not super sure that's good enough though...maybe with some auditing to track everyone who uses a thumb drive over the next few weeks and make sure they all bring it in to be cleansed?
  21. If they want a Year Group timetable, I just use Combined View. I haven't tried to make a Progresso report for that as I get asked for it so infrequently. I fit the full timetable on a single A3 sheet though and it's totally readable. I can send you the Timetable and Cell styles if you like. For Departmental master timetables they either get the Combined view with Teachers by Department, or a Progresso report that does the same thing but can drop into Excel, depending on which they're used to and want. I can send you the report if you like.
  22. We use the Statement of Entry report, which includes date, time, room and seat. Should be in Examinations section called "AL_rpt_Candidate Statement of Entry"
  23. Kind of hard to answer as I've only direct experience with Progresso and CMIS, so I don't know all the annoying problems the others have but that you don't see until you've used it for a while. The one that I liked the most at BETT was iSAMS, I thought it had a good combination of ease of navigation and intuitive-ness (what's the word I'm looking for here...?) which will please the teachers and support staff mightily and then the configuration for assessments and behaviour and so on seemed reasonable. Also it uses SSRS which is a really powerful reporting tool, so I can do anything I need to do with the data. Also also; it didn't look like it was made by the late 80's USSR, which is nice. So; I'd start by looking there. Would need a more in-depth go at it to say I'd buy it though.
  24. Not sure about checking whether emails were sent via TLS or not.For the S/MIME question; I doubt whether it's worth going down this route. The problem it is the recipient who needs to have a certificate in order to send an encrypted email to them, and there's fairly scant chance of getting them to set one up (assuming they're outside your organisation. If they're inside your organisation you're probably already covered by TLS and encryption at rest on the servers anyway)
  25. Yeah ok I'm stealing this idea. It's included in all 3 Education plans, including A1: https://technet.microsoft.com/en-us/library/mt844095.aspx
×
×
  • Create New...