Protecting confidential, sensitive and personal data
- Good practice in information handling: Data security dos and don’ts - BECTA Guidance
BECTA have written this guide for anyone working in a school, college or university who collects, manages, transfers or uses data about learners, staff or other individuals during the course of their work.
- Kirklees Information Security Guidance for Staff
Helping you safeguard Council, school and pupil information and ICT equipment. Kirklees Guidance for Staff January 2010.
This Information Security Policy document summarises what is expected of all school staff in the course of their duties and while on school premises in relation to information security and computer equipment.
It provides the information necessary to enable staff and others to meet their general responsibility to safeguard the school's information and other assets. It is anticipated that schools will adapt the document to reflect their own circumstances in order to produce their own Information Security document. It has taken account of the guidance from BECTA and others. It also includes a number of practical ways in which schools and individuals can protect their data and prevent accidental loss, disclosure and misuse.
*Just added*
- Information risk management and protective marking
A guide for staff and contractors tasked with implementing data security
This document is one of a series of good practice guides to help schools, colleges and universities protect personal and sensitive data. Building on good practice from industry and central government, these guides describe procedures and possible technical and operational solutions that can help organisations reduce the risks of data security incidents and comply with current legislation.
Creating a secure USB memory stick using Truecrypt
The following documents are provided to help create and use encrypted USB memory sticks for carrying sensitive data. The software chosen is Truecrypt, a free encryption programme, which is also recommended in the BECTA guidelines below. It is recommended that a school technician creates a set of memory sticks for use in school as it involves some technical expertise.
- Setting up an encrypted USB memory stick using Truecrypt
- Using a USB memory stick protected by Truecrypt
Good practice in information handling in schools. Keeping data secure, safe and legal. September 2008
Recent high level security breaches concerning loss of personal and sensitive information have highlighted the need to update security guidance . This guidance should ensure that similar losses are prevented and minimize the risk of data being misused should media or devices fall into the wrong hands.
The guidance also includes several accompanying good practice guides which provide a description of the procedures and suggest possible technical and operational solutions that can assist schools in minimising the risk of data security incidents and complying with existing legislation. These good practice guides should be read by school network managers and those responsible for implementing technical solution.
Good Practice Guides :
- Good practice guides (modified April 2009)
- Keeping data secure, safe and legal is a summary document for network managers, senior leaders or staff with a responsibility for securing data. It outlines the key measures organisations should adopt.
- Dos and Don’ts is a common sense guide that senior leaders can make available to staff to ensure everyone within an organisation knows how they should be helping keep data secure.
http://schools.becta.org.uk/index.php?section=lv&catcode=ss_lv_saf_dp_03&rid=14734
- Data encryption
- Audit logging and incident handling
- Secure remote access
http://schools.becta.org.uk/index.php?section=lv&catcode=ss_lv_saf_dp_03&rid=14734
Additional guidance on security related issues.
- Useful information on encryption
- Secure wireless networks
- Protecting your laptop from theft
- Doing backups
- Guidance on the use of Biometrics systems in schools