Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, July 1, 2013

IT Security in K12 – Looking at the 2013-14 School Year

As many primary schools look forward to the end of the current school year, and develop priorities for what needs to be addressed during the summer lull, many districts are finding that it’s time to take a new look at computer or IT security. The impact of new mobile technologies, the cloud, and a new generation of threats has changed the landscape.

Yet, it’s a very broad topic and there are potentially far more issues to deal with than there is time to resolve them. And not all EdTech security activities have the same value to the district. So choosing the best activities to spend time on is a clearly critical. In this blog I’ll list some of what I think the most important things that might be put in place this summer, so that they’re ready to roll out come August/September.

One of the things that I think K12 can do that mimics what we see in larger organizations is to have a written policy of what is allowable use of technology within the school or on the school network. This goes for personal as well as school owned devices. Having students and their parents sign the policy will make sure that it’s at least been read by one of them. The key is not to use this policy as a club to beat wayward users, but to set expectations of what the technology should be used for. It should also be regularly reviewed by EdTech, administration, teachers, students, and parents for changes/modifications. You may even get lucky and find a parent with some expertise in this area that can help you complete the first version that much more quickly.

One of the most important changes in the security suites that we often load on school computers is the movement from installed software to cloud based services that do automatic updating, checking, and administration. For a small monthly fee, the EdTech staff no longer has to spend scarce time and resources doing manual evaluation of the security installed on each PC. The cloud services not only insure that the security tools are running, but automatically update them for the latest viruses and malware. This allows EdTech professionals to focus on more important tasks and projects.

This may seem overly technical, but what this entails is putting software on the servers that will only allow the applications that you have chosen to run. Rather than other security products that try to outlaw or “blacklist” all the malware, whitelisting is simply making a list of what is allowed to run, and denying everything else. This can be done on PCs too, but it’s difficult to keep updated. On servers it’s a very useful security tool that requires little administration. There are a number of vendors that offer whitelisting tools, and most have educational discounts.

So that’s the three things that I think are good steps toward a more secure district that can easily be implemented over the course of the summer. Of course, there are other steps you may take, and if you think they could help us all, please post it in the comments.


View the original article here

Monday, November 12, 2012

Exploding a Common K-12 Technology Security Myth

Top Mac Malware

By virtue of the time I’ve spent in the PC industry since its earliest days, it’s not unusual for friends on School Committees or Education Boards to ask me some of their key questions as they make decisions on the technology that will be used in their schools.  Not surprisingly, in the last few years, many of the questions deal with security and privacy.  And this is where the myth in question comes in:  It’s the myth that Apple’s Macintosh “doesn’t get viruses” or “doesn’t get malware”.  It’s not true.  In fact, given that most Macs have no security software, guess where some virus writers are now focused? (OK, now cue the flames from the Mac faithful).

Rather than get all emotional, let’s stay with the facts and the requirement to have a secure environment for K-12 computing.  The reason that I think exploding this myth is very important is that this false sense of security has created a situation where too many Macs in K-12 have little or no protection.  Worse, too often the savings from forgoing security on Macs is part of the justification for paying more for them.

Starting with viruses, the reality is that Mac viruses have emerged.

While not as prevalent as viruses on the Windows platform, they still exist.  From OSX.Iservice, designed to enlist Macs into DDOS attacks, to OSX.RSPlug.D, which was a downloader, there are actual viruses out there.  Despite the vast difference in numbers and attack vectors, the reality for elementary schools is that you need to have anti-virus in place for Macs, just like for other systems.  Infections on Macs are less common but, how much risk are you willing to take that you won’t get hit?  To me the answer is not much.  With all the file sharing and collaborative work common in schools, a virus exploit in one system is going to spiral out of control quickly.

And the reality is that Mac malware is catching up.  Before we get into the Mac-specific malware details, for those in the K-12 space running mixed environments, it’s important to note that based on recent research by Sophos, 20 percent of Macs are harboring Windows malware. So Windows PC getting “sick” from unprotected Macs is common.  As for Mac-only malware, the latest research shows 2 to 3 percent of Macs have Mac malware on the system.  The FlashBack botnet gets a lot of attention, as it infected well over half a million systems, but “Fakeware,” like fake anti-virus tools designed to get credit card numbers when you “buy” them, are increasing in numbers, as well.

I’m not saying that you should or shouldn’t buy any specific brand of computer.  Rather, I’m telling you that if you think one brand is better because it doesn’t get infected, you’re wrong.  And any perceived benefits or cost savings from this myth are mythical, as well.  In my opinion, working with technology partners that understand that security is essential, and not something left to an incorrect piece of conventional wisdom, is what you need to remember.

Image source


View the original article here

Saturday, November 10, 2012

Exploding a Common K-12 Technology Security Myth

Top Mac Malware

By virtue of the time I’ve spent in the PC industry since its earliest days, it’s not unusual for friends on School Committees or Education Boards to ask me some of their key questions as they make decisions on the technology that will be used in their schools.  Not surprisingly, in the last few years, many of the questions deal with security and privacy.  And this is where the myth in question comes in:  It’s the myth that Apple’s Macintosh “doesn’t get viruses” or “doesn’t get malware”.  It’s not true.  In fact, given that most Macs have no security software, guess where some virus writers are now focused? (OK, now cue the flames from the Mac faithful).

Rather than get all emotional, let’s stay with the facts and the requirement to have a secure environment for K-12 computing.  The reason that I think exploding this myth is very important is that this false sense of security has created a situation where too many Macs in K-12 have little or no protection.  Worse, too often the savings from forgoing security on Macs is part of the justification for paying more for them.

Starting with viruses, the reality is that Mac viruses have emerged.

While not as prevalent as viruses on the Windows platform, they still exist.  From OSX.Iservice, designed to enlist Macs into DDOS attacks, to OSX.RSPlug.D, which was a downloader, there are actual viruses out there.  Despite the vast difference in numbers and attack vectors, the reality for elementary schools is that you need to have anti-virus in place for Macs, just like for other systems.  Infections on Macs are less common but, how much risk are you willing to take that you won’t get hit?  To me the answer is not much.  With all the file sharing and collaborative work common in schools, a virus exploit in one system is going to spiral out of control quickly.

And the reality is that Mac malware is catching up.  Before we get into the Mac-specific malware details, for those in the K-12 space running mixed environments, it’s important to note that based on recent research by Sophos, 20 percent of Macs are harboring Windows malware. So Windows PC getting “sick” from unprotected Macs is common.  As for Mac-only malware, the latest research shows 2 to 3 percent of Macs have Mac malware on the system.  The FlashBack botnet gets a lot of attention, as it infected well over half a million systems, but “Fakeware,” like fake anti-virus tools designed to get credit card numbers when you “buy” them, are increasing in numbers, as well.

I’m not saying that you should or shouldn’t buy any specific brand of computer.  Rather, I’m telling you that if you think one brand is better because it doesn’t get infected, you’re wrong.  And any perceived benefits or cost savings from this myth are mythical, as well.  In my opinion, working with technology partners that understand that security is essential, and not something left to an incorrect piece of conventional wisdom, is what you need to remember.

Image source


View the original article here