Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I've really got to sort out tagging from posts made on the @posts account.

I've really got to sort out tagging from posts made on the @posts account.

Scheduled Pinned Locked Moved Uncategorized
edtechprivacydigitalsecurity
7 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • simon@bne.socialS This user is from outside of this forum
    simon@bne.socialS This user is from outside of this forum
    simon@bne.social
    wrote last edited by
    #1

    I've really got to sort out tagging from posts made on the @posts account. This is highly relevant for #EdTech #Privacy and #DigitalSecurity

    douglevin@infosec.exchangeD 1 Reply Last reply
    0
    • simon@bne.socialS simon@bne.social

      I've really got to sort out tagging from posts made on the @posts account. This is highly relevant for #EdTech #Privacy and #DigitalSecurity

      douglevin@infosec.exchangeD This user is from outside of this forum
      douglevin@infosec.exchangeD This user is from outside of this forum
      douglevin@infosec.exchange
      wrote last edited by
      #2

      @simon @posts have you seen https://trust.instructure.com? Not defending the company, but we’ve been tracking as it also affects US primary/secondary schools - among many others.

      simon@bne.socialS 1 Reply Last reply
      0
      • douglevin@infosec.exchangeD douglevin@infosec.exchange

        @simon @posts have you seen https://trust.instructure.com? Not defending the company, but we’ve been tracking as it also affects US primary/secondary schools - among many others.

        simon@bne.socialS This user is from outside of this forum
        simon@bne.socialS This user is from outside of this forum
        simon@bne.social
        wrote last edited by
        #3

        @douglevin @posts Interesting thanks! Rather brings into question the value of all those assessment processes.

        douglevin@infosec.exchangeD 1 Reply Last reply
        0
        • simon@bne.socialS simon@bne.social

          @douglevin @posts Interesting thanks! Rather brings into question the value of all those assessment processes.

          douglevin@infosec.exchangeD This user is from outside of this forum
          douglevin@infosec.exchangeD This user is from outside of this forum
          douglevin@infosec.exchange
          wrote last edited by
          #4

          @simon @posts Can’t ever guarantee that you’ll not be a victim of cybercrime. 100% secure is simply not a thing.

          We need to learn more about how they were comprised - and for how long - to better judge.

          Having said that - to date - their response has seemed competent and quick and forthright, which is not something I see much (as someone who has tracked education cyber incidents for a decade).

          As details emerge (the incident was discovered less than a week ago), I may of course revise my views.

          simon@bne.socialS 1 Reply Last reply
          0
          • douglevin@infosec.exchangeD douglevin@infosec.exchange

            @simon @posts Can’t ever guarantee that you’ll not be a victim of cybercrime. 100% secure is simply not a thing.

            We need to learn more about how they were comprised - and for how long - to better judge.

            Having said that - to date - their response has seemed competent and quick and forthright, which is not something I see much (as someone who has tracked education cyber incidents for a decade).

            As details emerge (the incident was discovered less than a week ago), I may of course revise my views.

            simon@bne.socialS This user is from outside of this forum
            simon@bne.socialS This user is from outside of this forum
            simon@bne.social
            wrote last edited by
            #5

            @douglevin @posts Oh for sure yeah. There's clearly value in going through good assessments even if something goes wrong later. I just mean it might make people question their value as marketing tools. As you say, knowing what went wrong is vital — would be bad if the compromise relates to something that was specifically evaluated under one of these programs.

            douglevin@infosec.exchangeD 1 Reply Last reply
            0
            • simon@bne.socialS simon@bne.social

              @douglevin @posts Oh for sure yeah. There's clearly value in going through good assessments even if something goes wrong later. I just mean it might make people question their value as marketing tools. As you say, knowing what went wrong is vital — would be bad if the compromise relates to something that was specifically evaluated under one of these programs.

              douglevin@infosec.exchangeD This user is from outside of this forum
              douglevin@infosec.exchangeD This user is from outside of this forum
              douglevin@infosec.exchange
              wrote last edited by
              #6

              @simon @posts I take all those audits/assessments as signifiers of a potentially strong cybersecurity program, but none are perfect - and, in some cases, they are indeed simply performative. More about trying to manage risk - and even liability, if it comes that - than any sort of guarantee.

              When regulators review the incident - at least here in the US - they’ll try to determine if the company took ‘reasonable, steps to safeguard the data in their care. That’s a slippery word - and one that keeps many a lawyer employed.

              douglevin@infosec.exchangeD 1 Reply Last reply
              0
              • douglevin@infosec.exchangeD douglevin@infosec.exchange

                @simon @posts I take all those audits/assessments as signifiers of a potentially strong cybersecurity program, but none are perfect - and, in some cases, they are indeed simply performative. More about trying to manage risk - and even liability, if it comes that - than any sort of guarantee.

                When regulators review the incident - at least here in the US - they’ll try to determine if the company took ‘reasonable, steps to safeguard the data in their care. That’s a slippery word - and one that keeps many a lawyer employed.

                douglevin@infosec.exchangeD This user is from outside of this forum
                douglevin@infosec.exchangeD This user is from outside of this forum
                douglevin@infosec.exchange
                wrote last edited by
                #7

                @simon @posts whelp, looks like - as they say - another shoe dropped with Canvas - at least here in the US. Hearing reports of anything new in your parts?

                1 Reply Last reply
                1
                0
                • R relay@relay.infosec.exchange shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups