<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Information Security – information so secret, nobody’s heard of it…</title><link>http://blogs.msdn.com/b/ukschools/archive/2008/06/18/information-security-information-so-secret-nobody-s-heard-of-it.aspx</link><description>Last week I wrote that the Becta advice on “Information Security Guidance for Schools” had been updated, effectively banning schools from taking student data out of the school. A few readers commented on the news –‘impossible’ and ‘worried’ came up –</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Information Security – information so secret, nobody’s heard of it…</title><link>http://blogs.msdn.com/b/ukschools/archive/2008/06/18/information-security-information-so-secret-nobody-s-heard-of-it.aspx#8617316</link><pubDate>Wed, 18 Jun 2008 19:31:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8617316</guid><dc:creator>sprince</dc:creator><description>&lt;p&gt;It's wonderful how BECTA pump out this advice so readily. Unfortunately we tax payers are paying some ridiculous amount of money for these people to produce it.&lt;/p&gt;
&lt;p&gt;For example, this statement:&lt;/p&gt;
&lt;p&gt;&amp;quot;When data is required by an authorised user from outside of the school premises – for example by a teacher working from their home –they must have secure remote access to the management information system (MIS) or learning platform.&amp;quot;&lt;/p&gt;
&lt;p&gt;Is that guidance? Subtracting their favourite buzzwords, it doesn't add up to much. For example, the majority of learning platforms they have endorsed in THEIR OWN accreditation programme do not mandate an https login and some don't even have it as an option! Are we saying that &amp;quot;secure remote access&amp;quot; now means &amp;quot;needs a password&amp;quot;? I'm getting that feeling.&lt;/p&gt;
&lt;p&gt;They then put the nail in the coffin with:&lt;/p&gt;
&lt;p&gt;&amp;quot;The Information Commissioner’s Office recommends that data controllers ensure that any solution meets the current standard of FIPS 140-2 approved encryption products&amp;quot;&lt;/p&gt;
&lt;p&gt;which was also in the original document released straight after the missing discs incident. Not terribly helpful really.&lt;/p&gt;
&lt;p&gt;First off, BitLocker - possibly the most applicable and well-known technology in this area - has only had FIPS 140-2 validation for 3 weeks (since 2008-05-22 according to csrc.nist.gov). BECTA don't feel the need to specify a level either (BitLocker reached level 1 of 4). Are the staff of schools and LAs expected to trawl through this drivel and search through the vast NIST archives to find out if their copy of Winzip can encrypt to a high enough standard? I'd say that's unrealistic and will be ignored by at least 99.9% of schools. Remember, the people most likely to put school data at risk are not those that run the network and know what the word encryption means!&lt;/p&gt;
&lt;p&gt;It all smacks of someone fresh off a degree course putting a document together in a hurry on a topic they have no prior experience of. I get that feeling regularly from BECTA tbh - heavy on (mostly incorrect/irrelevant) detail; light on common sense.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8617316" width="1" height="1"&gt;</description></item><item><title>re: Information Security – information so secret, nobody’s heard of it…</title><link>http://blogs.msdn.com/b/ukschools/archive/2008/06/18/information-security-information-so-secret-nobody-s-heard-of-it.aspx#8615791</link><pubDate>Wed, 18 Jun 2008 14:01:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8615791</guid><dc:creator>arichards</dc:creator><description>&lt;p&gt;Interesting you can't find anything on the Hannigan reports.&lt;/p&gt;
&lt;p&gt;I emailed BECTA directly once your first blog appeared to ask them for clarification. I received a very nice response saying my email had been passed to the relevant department.&lt;/p&gt;
&lt;p&gt;However I think that department was the 'Bermuda Triangle' because I haven't heard anything since.&lt;/p&gt;
&lt;p&gt;It's OK publishing guidelines that reference other material, but shouldn't they then gives us at the coal face access to those referenced documents.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8615791" width="1" height="1"&gt;</description></item></channel></rss>