<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ICT in Havering &#187; Data Security</title>
	<atom:link href="http://haveringict.edublogs.org/category/data-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://haveringict.edublogs.org</link>
	<description>HIAS ICT Learning Community - Sharing ideas, Innovating with ICT</description>
	<lastBuildDate>Wed, 02 Dec 2009 18:46:32 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security guidance for schools &#8211; please review existing practice</title>
		<link>http://haveringict.edublogs.org/2008/04/06/security-guidance-for-schools-please-review-existing-practice/</link>
		<comments>http://haveringict.edublogs.org/2008/04/06/security-guidance-for-schools-please-review-existing-practice/#comments</comments>
		<pubDate>Sun, 06 Apr 2008 08:00:31 +0000</pubDate>
		<dc:creator>haveringict</dc:creator>
				<category><![CDATA[Data Security]]></category>

		<guid isPermaLink="false">http://haveringict.edublogs.org/2008/04/06/security-guidance-for-schools-please-review-existing-practice/</guid>
		<description><![CDATA[Security guidance for schools
Recent high level security breaches concerning loss of personal and sensitive information have highlighted the need to update security guidance. This guidance should ensure that similar losses are prevented and minimise the risk of data being misused should media or devices fall into the wrong hands.Data protection legislation means that all those [...]]]></description>
			<content:encoded><![CDATA[<h2><strong><font size="4" color="#333366" face="Verdana"><img border="0" width="96" src="http://tbn0.google.com/images?q=tbn:fREi4EWb8Lfr3M:http://www.freefever.com/freeclipart/clipart/lock.gif" height="116" />Security guidance for schools</font></strong></h2>
<p><font size="1" color="#000000" face="Verdana">Recent high level security breaches concerning loss of personal and sensitive information have highlighted the need to update security guidance. This guidance should ensure that similar losses are prevented and minimise the risk of data being misused should media or devices fall into the wrong hands.</font><font size="1" color="#000000" face="Verdana">Data protection legislation means that all those who hold personal data, whether on paper or electronically, must keep that data secure. Clearly, this also applies to schools. Personal data is defined as any combination of data items that identifies an individual and provides specific information about them, their families or circumstances. This includes names, contact details, gender, dates of birth and so on, as well as other sensitive information such as academic achievements, other skills and abilities, and progress in school. It may also include behaviour and attendance records.</font></p>
<h3><strong><font size="4" color="#333366" face="Verdana">Keeping data secure</font></strong></h3>
<p><font size="1" color="#000000" face="Verdana">Any item that can hold computer information is classed as media. This includes hard drives, CDs, DVDs, printed output, tapes, and memory sticks. Modern media is easy to move so requires extra controls to ensure it is not damaged, stolen or accessed by unauthorised people.</font><font size="1" color="#000000" face="Verdana">All school leaders are advised to review their existing data security policies following recent high profile issues that have led to advice being released by the <a href="http://www.ico.gov.uk/" title="http://www.ico.gov.uk/">Information Commissioner’s Office</a>.</font><font size="1" color="#000000" face="Verdana">Becta is working with the Department for Children Schools and Families (DCSF) and with the Information Commissioner to update existing guidance on information security. In the meantime, school management teams should take urgent steps to ensure data controllers in their institutions follow this guidance:</font><font size="2" color="#000000" face="Symbol"><img width="9" src="//163-000000007E96C98C4271664A9577FBC7CD432186E4C92F00/PicExportError" alt="Right-click here to download pictures. To help protect your privacy, Outlook prevented automatic download of this picture from the Internet. *" height="9" /><font size="1" face="Times New Roman">       </font></font><font size="1" color="#000000" face="Verdana">All data should be kept safe and made available only to those who are authorised to access it. </font><font size="2" color="#000000" face="Symbol"><img width="9" src="//163-000000007E96C98C4271664A9577FBC7CD432186E4C92F00/PicExportError" alt="Right-click here to download pictures. To help protect your privacy, Outlook prevented automatic download of this picture from the Internet. *" height="9" /><font size="1" face="Times New Roman">       </font></font><font size="1" color="#000000" face="Verdana">Do not remove sensitive or personal data from the school premises unless this is part of your school’s security policy, for example where backups are being taken off site. In this case make sure that the media used has been encrypted and is transported securely for storage in a secure location. </font><font size="2" color="#000000" face="Symbol"><img width="9" src="//163-000000007E96C98C4271664A9577FBC7CD432186E4C92F00/PicExportError" alt="Right-click here to download pictures. To help protect your privacy, Outlook prevented automatic download of this picture from the Internet. *" height="9" /><font size="1" face="Times New Roman">       </font></font><font size="1" color="#000000" face="Verdana">When data is required by an authorised user from outside of the school premises – for example by a teacher working from their home – we recommend that they have remote secure access to the management information system (MIS) or learning platform, where this is available. This could be achieved by secure access via the <a href="http://schools.becta.org.uk/index.php?section=lv&amp;rid=11277" title="http://schools.becta.org.uk/index.php?section=lv&amp;rid=11277">UK Access Management Federation for Education and Research</a>. </font><font size="2" color="#000000" face="Symbol"><img width="9" src="//163-000000007E96C98C4271664A9577FBC7CD432186E4C92F00/PicExportError" alt="Right-click here to download pictures. To help protect your privacy, Outlook prevented automatic download of this picture from the Internet. *" height="9" /><font size="1" face="Times New Roman">       </font></font><font size="1" color="#000000" face="Verdana">Protect all desktop, portable and mobile devices, including media, used to store and transmit personal information using approved encryption software. </font><font size="2" color="#000000" face="Symbol"><img width="9" src="//163-000000007E96C98C4271664A9577FBC7CD432186E4C92F00/PicExportError" alt="Right-click here to download pictures. To help protect your privacy, Outlook prevented automatic download of this picture from the Internet. *" height="9" /><font size="1" face="Times New Roman">       </font></font><font size="1" color="#000000" face="Verdana">Delete sensitive or personal data when it is no longer required.</font></p>
<h3><strong><font size="4" color="#333366" face="Verdana">Technical guidance</font></strong></h3>
<p><font size="1" color="#000000" face="Verdana">School leaders should ask their support providers or technical staff to ensure that their institutions are fully adopting and using these standards.</font><font size="1" color="#000000" face="Verdana">Ensure that your institution’s security policy covers how personal information is stored, transmitted or processed and that it is managed and protected accordingly. Use best practice methodologies such as the <a href="http://www.27001-online.com/" title="http://www.27001-online.com/">International Standard 27001</a>.</font><font size="1" color="#000000" face="Verdana">There are many potential solutions available to protect information, using both free and commercial encryption software. Information about encryption solutions can be found at the government and business sponsored website <a href="http://www.getsafeonline.org/nqcontent.cfm?a_id=1104" title="http://www.getsafeonline.org/nqcontent.cfm?a_id=1104">Get Safe Online</a>. The Information Commissioner’s Office recommends that data controllers ensure that any solution meets the current standard of FIPS 140-2 Level 3 approved encryption products.</font></p>
<h3><strong><font size="4" color="#333366" face="Verdana">Further information</font></strong></h3>
<p><font size="1" color="#000000" face="Verdana">More advice on information security can be found on the <a href="http://www.ico.gov.uk/" title="http://www.ico.gov.uk/">Information Commissioner’s website</a>.</font><font size="1" color="#000000" face="Verdana">Advice on data processing and sharing from the DCSF, including guidance on the Fair Processing Notice that schools are required to issue to parents and children, can be found on <a href="http://www.teachernet.gov.uk/management/atoz/d/dataprocessing" title="http://www.teachernet.gov.uk/management/atoz/d/dataprocessing">Teachernet</a>.</font><font size="1" color="#000000" face="Verdana">Becta’s <a href="http://schools.becta.org.uk/index.php?section=lv&amp;catcode=ss_lv_pla_02&amp;rid=11281" title="http://schools.becta.org.uk/index.php?section=lv&amp;catcode=ss_lv_pla_02&amp;rid=11281">Technical specification: institutional infrastructure</a> contains detailed advice on implementing ICT security, including an example security policy document. </font><font size="1" color="#000000" face="Verdana">Becta’s Framework for ICT Technical Support Operations Management (FITS OM) <a href="http://www.becta.org.uk/fits_om/documents/security_adm.pdf" title="http://www.becta.org.uk/fits_om/documents/security_adm.pdf">security guide</a> provides details on how to maintain a safe computing environment in a school.</font><font size="1" color="#000000" face="Verdana">If you have any queries or comments relating to the security of information in schools please email <a href="mailto:engage@becta.org.uk?subject=Information%20security" title="mailto:engage@becta.org.uk?subject=Information security">engage@becta.org.uk</a>.</font></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fhaveringict.edublogs.org%2F2008%2F04%2F06%2Fsecurity-guidance-for-schools-please-review-existing-practice%2F';
  addthis_title  = 'Security+guidance+for+schools+%26%238211%3B+please+review+existing+practice';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://haveringict.edublogs.org/2008/04/06/security-guidance-for-schools-please-review-existing-practice/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
