djrscally
Members-
Posts
447 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by djrscally
-
It's pointless anyway - it's the recipient that needs to have an S/MIME cert in order for you to send them an encrypted email so buying them yourself just lets other people who use s/mime send you one, it doesn't let you send them to anyone else. And few people would know how to fetch your cert in order to send you an encrypted mail anyway.
-
Not that I'm aware of.
-
We have this role. I have a sort of attendance overview dashboard thingy that gives the attendance figures with a fortnightly trend chart, a slicer and a link to the full summary report that they use. Want the .rdls? They will also need the "Roll Call Absences" so they can send messages to parents of absent students and the "Lessons not Taken" one so they can see which teachers didn't do their registers yet. The "everything is so much easier in SIMS" thing settled a bit for our staff when we built a widget giving them quick links to other aspects of Progresso so they didn't have to go through the whole menu structure to get there, like this: That's kinda geared towards teachers because our attendance officer doesn't particularly complain about stuff being more difficult in Progresso, but maybe something similar would help - I gather there's something like that built into SIMS that maybe they're missing.
-
Student Name and GDPR
djrscally replied to CommodoreS's topic in Data Protection & Information Handling
It's not automatically true. Whether some piece of personal data can be displayed or not depends on a range of factors including the nature of the data itself, the level of risk that someone unauthorised will see it, the severity of someone unauthorised seeing it (I.E. what harm it might cause), the context behind the decision to display it, when it is (term time or holidays, because this changes the level of risk) and so on. -
This thread's title promised a far more interesting discussion than it delivered.
-
Is this because the copier is end of life or something? If so, how are the copiers supplied? If they're not owned by the school but are rather supplied 'as a service' I think unless the service agreement specifies that there'll be a charge for this kind of thing, the company would probably be obliged to securely wipe the drive anyway. If it's not EoL why would you replace the hard drive in a copier?
-
[Progresso]: New pupils - Data import and CTF challenges
djrscally replied to Ditto's topic in MIS Systems
I actually don't do this myself so not 100% sure, but doesn't the CTF process let you untick particular sections like contacts? We pay for the LEA to sort admissions for us, which makes this really pretty easy because they give us an ATF containing all our joiners from their DB which is usually nicely up to date. I do have to go and ask for it every year though. -
Whoops! School lost unencrypted USB!
djrscally replied to hardtailstar's topic in Data Protection & Information Handling
Well, you obviously can't have encryption keys committed to memory so they're "written down" somewhere; but presumably that somewhere has some hefty access controls. -
Whoops! School lost unencrypted USB!
djrscally replied to hardtailstar's topic in Data Protection & Information Handling
Is it in poor taste if we run a sweepstake on the fine amount? -
Our MIS is a web application (Progresso); so access is available at home...or anywhere else for that matter. Access from home on encrypted laptops owned by the school is fine provided they're doing it over a secure channel. Regarding no use of single sign on - we actually do use it, taking the view that it's a lower risk than password overload causing people to sticky-note them to their screens. It's one of the solutions recommended by the NCSC. https://www.ncsc.gov.uk/guidance/password-guidance-simplifying-your-approach
-
Right - we'll explore that. That's really helpful, thank you.
-
By "Folders", you mean just the folders the User has set up? We must have missed something then - couldn't figure out how to do that!
-
Emails will obviously contain a ton of personal data that needs to be kept within a retention period. We think that it's too much of an administrative burden for staff to be expected to manually clean an inbox however, so what we intended to do was an automatic rolling deletion such that emails would be automatically binned after 12 months. Where this is coming unstuck is in an easy method for staff to flag emails that they know need to be around for longer than that to be exempt from the rolling delete - we use O365 and Exchange and can't find anything except an "In Place Archive" that gets saved. This is quite annoying to use, particularly since the "Archive" button in Outlook doesn't actually send emails to this Archive. How are you guys handling retention and emails?
-
We have to be honest had a lot of people with difficulty opening these. There seems to be two problems: 1) User issues. People just don't expect this kind of thing and we're getting a lot of people just lock up and say "I don't know how to open this". Generally when I've called and asked them to walk me through the problem, there is no actual problem. We're building a sort of "opening the email" crib sheet that people can just fire off when they get people saying they can't open it in the first instance. 2) Issues with network security deleting attachments or preventing them from being opened; this one has happened to recipients in banks and so on, the older style of O365 encryption sends the secure portal as a HTML attachment which their networks won't allow them to open. If you get it upgraded to the newer version, it uses a link instead of the attachment which I think has helped. EDIT: Do people who use Egress/GalaxKey have these problems too?
-
The easy answer to this is "Yes". Alright the GDPR doesn't technically say they must be, but realistically if the ICO finds out they're not and have personal data on you'll be getting fined. If you're getting fight back on it I would trawl through the ICO's list of enforcement actions, download all the reports of hefty fines where people lost media that wasn't encrypted and send those to her. Like... https://ico.org.uk/action-weve-taken/enforcement/crown-prosecution-service/ https://ico.org.uk/action-weve-taken/enforcement/humberside-police/
-
It's obviously automated decision making, but it's not making a decision about personal data (unless the data is on the webpage in which case it's been made public anyway) ...right? I think that clause exists for stuff like job sites scanning a CV for keywords before deciding whether or not to pass it on to the company.
-
So far on the 25th May: 1 I'm disappointed.
-
Office 365 includes a secure email system, so you're already paying for one. EDIT: wrong link before, meant this one: https://support.office.com/en-us/article/set-up-new-office-365-message-encryption-capabilities-7ff0c040-b25c-4378-9904-b1b50210d00e?ui=en-US&rs=en-US&ad=US
-
-
Staff Pigeon holes - confidential letters
djrscally replied to psydii's topic in Data Protection & Information Handling
I would say this is broadly secure enough.* Remember; you can't actually stop your employees maliciously stealing all the data that they want, and that's on them. All you have to be doing is taking appropriate steps to keep it secure, and I'd argue that as long as the room with the pigeon holes is controlled access to staff only (I.E. members of the public can't just wander in) then having confidential documents be in clearly marked opaque envelopes is enough to say you took appropriate steps to protect the data inside. *The caveat is that the exact answer depends on the nature and quantity of the personal data that's being delivered in this way, but I think for most things (certainly everything I've ever received through work) it would be ok.
