Jump to content

Ephelyon

Members
  • Posts

    3,274
  • Joined

Everything posted by Ephelyon

  1. How was the attack vector for this server exposed - RDP? Are there multiple instances of this event or just the one?
  2. I can see the OP's logic with splitting the domains, but it seems analogous to the old curriculum/admin network model in that it's generally thought too unwieldy for modern use. However, a workable scenario in which a compromise in security on the pupil side does not affect operations on the other, be it "all staff" or simply "admin staff", would certainly be very interesting to hear more about. However, as long as you have trusts, the infrastructures are never truly separate and, having observed a security breach that arose from inappropriately-configured trust permissions (first rule of endpoint security: never assume there hasn't been a cock-up upstream), I would imagine the benefits to security are less than might be expected as you have only made something harder to achieve, not impossible.
  3. So I think we are broadly in agreement about the potential uses there. Could there be any merit in introducing a framework - not an obligation - around some form of "general contractual terms" that are widely regarded, built up through peer assessment along the lines you suggest, as "sound for educational use". These might not include, for example, the kind of contract we have recently been bitten by, which stipulates a three-year rollover if three months' notice of cancellation is not given with no obligation for the supplier to provide renewal reminders. Would the BSI also be interested in introducing such frameworks for technical staff's CPD opportunities within education? These (often) being a very different ballgame from standard practice within industry...
  4. I think they mentioned programming in that context more specifically, which is an entirely separate issue. Here there is a group of pupils that are allowed access to Python and the Eclipse IDE as part of my effort to maintain the balance, but being aware of ways to begin using IDEs to compromise a single workstation and then attack from there, I'd be wary of giving it to the whole school. Well worth a separate debate though. Back on topic (and apologies for dragging us off), I had a thought about this last night. Could there be any mileage in using such a framework to create some (limited) degree of "guideline pricing", a little bit like an RRP? This could have been useful in the case of the primary schools featured on Panorama last year (more here), if the Heads and SLTs concerned had had access to an index of "average market pricing" for such devices, causing alarm bells to ring immediately. Naturally there would be no obligation for any school to buy from the featured suppliers, but at least it would mean that if non-technical managers are looking to procure devices of a sort they haven't dealt with before (or even technical staff - photocopiers certainly aren't my forte!), there would be a way of checking whether a particular supplier is quoting vastly inflated prices in an attempt to fleece them.
  5. All I can say to that, and having read the Royal Society's report, is that when I am evaluating risk around system security issues, "indemnity" will come into it but is not one of my real prime factors. At its most basic level, the concept of "risk" to me engenders the concept of "consequences". A risk assessment is a matrix for glorified probability evaluation, but the reason why we perform them is because of the consequences of each risk, if not managed correctly. Consider little Johnny who takes issue with little Freddy and wants to beat him up but doesn't want to risk it on the school yard. If system security is lax to the extent that he is able to compromise the MIS and find out Freddy's address, the consequence is violence between children. Consider a teacher under investigation for an allegation that (for the sake of argument) will later prove to be false. If system security is lax to the extent that other staff or pupils are able to access areas where confidential minutes, pupil disclosures, OHU reports etc on the incident are stored, the consequence may well be loss of a teacher's career. In both cases, whether or not it's my neck that would ultimately be on the line, I may be the first and last defence against that and it is my ethical obligation to ensure that these things can't happen. While standards around who is at fault in the event of a security breach may assuage certain people in certain scenarios, it does not obviate the main issue. Now, a standard around how technical staff's concerns in such regards could be reduced ALARP by means of support for their skills, experience and responsibilities could go a long way towards progressing the situation, however...
  6. Crispin, is it worth asking if this is what the proposed PAS standard around child online safety from last year has turned into? Personally I was more interested in the other work Becta did than the procurement side of things; that was tragedy of its loss. The Government didn't like the procurement standardisation so threw the whole baby out with the bathwater. Also, might it be worth taking a look at The IT Index from ProBrand? This was an attempt at doing something similar with a single supplier's products and it seems to work quite well, we've used it a few times.
  7. Bear in mind that if a child has a data plan on a smartphone or tablet, and has signal, there's nothing you can do about inappropriate browsing or texting while they're not using your WiFi.
  8. Hmmm... my best price for e.g. an Epson EB-485WI of that ilk has been £1,150 so far... mind if I ask where you're sourcing yours from?
  9. I think the point about deskilling is a valid one but it's not all bad. Sometimes the focus of where the most skill is needed just shifts, and as @broc has said, we are in another iteration of that. Yes, there is less focus on setting up individual machines in the same way one might have had to deploy them using 98/ME (without the ZAK or something like RM Connect 2.3)... but back then we didn't have things like virtualisation, elastic service provision or redundant SANs on the cards either. Or at least, not what the modern equivalents of certain mainframe-era ideologies turned out to be. I have to say I don't miss painstakingly installing Rise of the Robots off 22 floppies though! Plus, as fun as it was at the time (when I was about 9) to be insisting that DOS was damn well going to load itself into the Upper Memory Block, and that I wanted Expanded Memory and I wanted it now... I wouldn't want to be doing that with all 300-odd workstations at this school. But when you get past all that, you're into a different skillset: that of running a managed environment, which is only possible to begin with because we moved on from doing everything manually everywhere to automating it across nodes (which was the later-generation equivalent of not needing to automate it because everyone connected from a dumb terminal to a single mainframe, or a cluster of them). Having seen a VAX cluster in operation once, it's truly a sight to behold if your inner geek was born in the 80s! Running an IT resource for a school often means basically doing the CIO/CTO role. Not for all of us, but for many. That's a skill in itself; understanding the organisation and its needs is a skill in itself. Personally I take the view that that's the natural progression for us. Plus, if the world is going to entrust more and more of its resources to the technical people who push the buttons, it really ought to hope that the prerequisite of already being in the position to understand a client organisation (any client organisation) and its goals, should be a bare minimum standard for recruitment. That's what I want to see our profession become anyway. People who can all do that, without needing to report to a teacher just to make sure they understand what it's all about... because they already do and that's a given. It's a way off yet but it's achievable, and it could count as the kind of reskilling that we've been talking about in this thread.
  10. Which was also my point about always describing IT as "support". Across the different roles, some of it is "supporting" while other areas involve "doing".
  11. I meant things like this: VMware KB: Enhanced vMotion Compatibility (EVC) processor support It's come a long way recently, but the Notes section near the bottom shows there are still some manual steps to be taken sometimes.
  12. Better hope their processor architectures are compatible!
  13. It's a well-written article, and I must say I do agree 100% with the points on mobile tech dumbing down levels of user expertise. The author's journey in IT from his first machine onwards is also very similar to my own, except mine was a 486SX 25MHz with DOS 5 and Windows 3. But I think it misses the point in some areas. First of all, what exactly is wrong with having experts in different areas to meet the diverse needs of the general populace? If I have a medical problem I go to a doctor... if I have a legal problem I go to a lawyer... if I have a problem with my car, I take it to a mechanic... just as if I were my mechanic and I had a problem with my computer, I might take it to someone like myself. The rhetoric I see spouted in this article is of the same manner I've heard before from people who THEN go on to say we should all be self-sufficient in society and anyone who isn't is a failure and not worth bothering with. And yes, I have actually heard such idiotic views from people who really ought to know better. Secondly, I must say I take my hat off to this guy. He is clearly one of those IT teachers who is ACTUALLY tech-savvy and could in fact do a Network Manager's job, though clearly in his school it's okay for that not to be a full-time post. Not griping as it's perfectly true that this can be the case in some schools. Wouldn't be here, but every school is different. The only problem I have with this view is that these people are, I'm afraid, very much in the minority. I'm not trolling all the really good IT teachers out there because I know they do exist, I just wish there were more of them (and I think sometimes so do they) - just as many on the TES forums lament that there should be more "good" IT pros in education. Whether I am right, or whether they are right, either way, could be debated for hours... either way, shortly before the end of term I had to painstakingly show our two IT teachers how to insert a segment of code - provided by the exam board - into an HTML document pre-generated by Mediator, as specified in the syllabus they're supposed to be teaching the kids! Thirdly, parents expecting their football/car-crazy sons to learn how to edit the Registry to stop something auto-loading on logon is simply not realistic. Also, just... "it really is fun and you get to feel like a hacker"... sorry to burst your bubble, mate, and this is coming from a fellow technophile, but do you honestly think 99% of people out there would actually WANT that? Got you beaten up at my school. Fourthly, whether or not we choose to exclude... yes, we do need to prevent pupils hacking the system. I used to know people who sold... that's right, SOLD... what I'd now know to be sensitive personal information on other pupils/teachers they'd illicitly acquired from the school system, for "sundry purposes" I'm sure. Sod their education, that's not happening on my watch and it's 100% fair enough. What precious details they don't learn at school, they can make up at college. But now I'm "the block to T&L" again... :/
  14. Plus the demand from everyone else for more and more automation (once they jumped on our bandwagon) was enormous, otherwise we might've lasted a while longer...
  15. Oh I know, it's just ironic that it would happen to us in particular, as not so long ago we were at the forefront of the tech movement that began to change all that with other professions. Now it's our own turn I suppose...
  16. I recall that Head at Berkhamsted saying three years ago that this would happen, with all the other rumours and industry predictions that have been flying around since. I think all we can do is be cautious about our longer-term career prospects, while not buying into every bit of cloud-hype we read. I think the most ironic thing is that IT Departments that were previously innovators in decades past would have advocated replacing people with computers to save money, improve efficiency etc... yet it's now those same computers (but managed by someone else) that are threatening to take our own jobs away! Maybe we just had it coming.
  17. Well, if you go down the career route that a PRINCE2 course suggests you won't be in support, but management.
  18. Well certainly, as I wrote in the third link, there should be no element of "versus" in play at all. Where there is, trouble will soon follow regardless of which other CxO it is. In my current workplace, I have been the primary driver behind almost all new ICT initiatives for the past three years since I became NM. One of the first things I did was to propose replacing all the computers in one of our suites as an NQT had just started teaching there and they took 20 minutes to log on. The NQT didn't propose it; SLT didn't propose it; I did. If I hadn't proposed a move to electronic registration (and behaviour management) two years ago, we'd probably still be wheeling around paper registers. The purchase and adoption of Securus came from me. The requirement for an e-safety policy was identified by me as well as having heavy involvement in drawing it up. My involvement saved £9K from the parental engagement portal project. The idea for a new VLE, including product selection, came from me. Backup and DR, the establishment of a Strategic User Group, moving the pupils to the staff Exchange system, implementing site-wide wireless, a tablet trolley, managed printing... I wasn't just doing the technical side, the entire initiatives came from me too. This isn't an "oh look at me!" post; it's about saying that in some organisations, the IT people are the ones who drive development, for whatever reason. In others, leaders or other groups do that and the IT people carry it out. Both approaches can work but it shows how in some cases IT staff can be "enablers" and in others they can be "drivers" themselves. It depends how the organisation works and the positions that different people hold. I'd like to see more schools where the senior IT staff demonstrating this capacity are recognised as "leaders" too, along with senior finance, personnel and site staff who can be in a position to do similar things. The concept that teachers are the only ones who can become leaders in the education sector is an outdated one. It also depends on its ethos; leaders some organisations are more "snooty" about technical types than others. I've been lucky and grateful in mine for how much they've allowed me to develop my innovative side, although sometimes I feel frustrated that I'm not paid for the strategic role but basically doing it regardless. I say this in support of @pcstru's point about DevOps as in order to get these initiatives through - as IT staff - I've had to do a lot of the "interface" work that it requires. And indeed, while it's not brilliant for recognition or remuneration, I get the feeling that SLT knows that and therefore that my job is pretty secure. Therefore I'd agree that those of us who aren't doing this already may well need to start in the future, just to keep our usefulness and our jobs, though then there's the potential challenge of dealing with those on SLT who think they can do it better... and this idea of "managing upwards" starts to come into play.
  19. Here's a different kind of reflection, then, from Roger Clarke: http://www.rogerclarke.com/II/SAH-12.html I like his article very much. Supporting @localzuk's point, CIO.com also had this to say: The Power of IT Drives Businesses Forward - CIO.com In response to a similar question on Answers.com, I myself wrote this: Do you believe that IT drives business or that business drives IT
  20. Absolutely. A lot of people like to believe they are the innovators and we're just here to do the technical bit to make it all work, and that can be true, but we all know it can work the other way round as well. It's very true that the IT Department will often have a broader overview of the entire organisation than some (though not all) senior management types, as they can be more focused on achieving certain goals, not the totality of the picture.
  21. The sysadmin role isn't support though, or shouldn't mainly involve support anyway (we live in hope). To be honest I've had these worries for as long as people have been banging on about the cloud. I appreciate its benefits but frankly putting an infrastructure together, designing a system, integrating services and etc is something that, as a sysadmin, *I* enjoy doing and wanted to do for my career. Then I get accused of standing in the way of progress and advised to take my skills to a datacentre... but we all know there won't be anywhere near as many of those jobs going. In fact, if you watch for about a minute and a half from 7:00 of this video, Kirk and McCoy do a very good job of summing up pretty much how I (and many others I know) feel about the cloud (context: someone wants to install a computer on the Enterprise that would do most of Kirk+crew's jobs): Star Trek: Playing At God (2/12) - YouTube
  22. Ephelyon

    Admin AUP

    Nice to see that Georgetown have taken it seriously enough to actually write one! Good practice that should certainly be spread around I think.
  23. Predictions like this were being made some years ago too, though that doesn't mean these can't be right. Personally I find it depressing in the extreme...
  24. For staff, we use their staff code (i.e. initials). For pupils, we use: Intake year + First initial + Middle initial (if they have one) + Surname So that would be 13JBSmith for example. No duplicates at all for the past two years. We use a report on Accepted Pre-admissions in SIMS to automatically generate accounts over the summer before September. I have the script to do all this if anyone is interested.
×
×
  • Create New...