alan-turing-institute / data-safe-haven

https://data-safe-haven.readthedocs.io
BSD 3-Clause "New" or "Revised" License
60 stars 15 forks source link

Accessing UK Data Service #806

Closed jemrobinson closed 4 years ago

jemrobinson commented 4 years ago

The UK Data Service have some requirements about access to "Special Licence" data which we would like to meet. These are listed here and summarised below:

thobson88 commented 4 years ago

I confirm that the current Operating Systems of both my organisational/institutional machine and local home PC/laptop have all recommended security updates applied. I confirm that the current Operating Systems of both my organisational/institutional machine and local home PC/laptop have anti-virus software installed and updated.

@sysdan Could I ask a couple of specific questions about the Chromebooks used for remote log in via the Tier 3 VPN (as per #542):

sysdan commented 4 years ago

@thobson88

do they get OS updates?

Yes, the do and it is enforced centrally. The also do daily checks for new updates

do they have anti-virus installed and, if so, does it get updates?

No anti-virus is installed.

thobson88 commented 4 years ago

No anti-virus is installed.

@sysdan Thanks. As this appears to be the only sticking point for accessing the UKDS data, I'd like to find out about the feasibility of installing anti-virus on a Turing Chromebook.

For instance, this Bitdefender Android app is available from the google Play store, which means it could (I think) be installed on a Chromebook.

On a technical level, could this installation be done remotely by one of the IT team? (and with automatic updates?)

getcarter21 commented 4 years ago

To be clear when you use the Turing Global Protect VPN it also has a AV module and Threat Protection running on the Palo Alto Firewall https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention.html https://www.paloaltonetworks.com/products/secure-the-network/wildfire

Auto Updates are active on the Palo Firewall

thobson88 commented 4 years ago

Thanks @getcarter21. To clarify, we're aware that the model for Chromebook access via the VPN is secure and makes installing anti-virus on the machine redundant, but the terms of the UKDS service require that we check a box with the following text:

I confirm that the current Operating Systems of both my organisational/institutional machine and local home PC/laptop have anti-virus software installed and updated. Please keep proof of these using a screen capture of the anti-virus computer status.

We're just looking for a way to be able to justifiably tick this box. Are you saying we can do that? (ideally including an anti-virus screenshot)

getcarter21 commented 4 years ago

Hi @thobson88 we may be able to get the Sophos client/app on a Chromebook. We need to test and let you know.

thobson88 commented 4 years ago

@getcarter21 that sounds like a great solution (if it works!).

I know that @fedenanni already has a Chromebook and would be happy to help if you need a guinea pig for the test.

getcarter21 commented 4 years ago

@thobson88 Yeah have pushed out Sophos Intercept X for Mobile to all Turing Chromebooks. We are now looking to see if we can manage the Sophos app via our Sophos Cloud Management portal

thobson88 commented 4 years ago

@fedenanni are you able to see Sophos on your Chromebook, and get a screenshot?

fedenanni commented 4 years ago

@thobson88 @getcarter21 hi both! here attached a couple of snapshots.

This appeared when I turned on the Chromebook

Screenshot 2020-09-30 at 09 53 43

I can see the app installed

Screenshot 2020-09-30 at 09 54 16

Inside the app (I had to click "agree" to the policy thing) I see this

Screenshot 2020-09-30 at 09 58 45

And more details if I click

Screenshot 2020-09-30 at 09 58 30

I hope this is useful!

thobson88 commented 4 years ago

Thanks @fedenanni. Your first screenshot should do nicely. Worth keeping a look out for updates and getting screenshots of those too.

fedenanni commented 4 years ago

@thobson88 no prob - if it's something official I can get a proper screenshot and not a photo with my phone :D

fedenanni commented 4 years ago

@thobson88 lol - I can't take screenshots as the functionality is disabled, I hope those photos are enough. I also have this

Screenshot 2020-09-30 at 10 46 17
thobson88 commented 4 years ago

We now have measures in place to satisfy all of the UKDS requirements which are set out in a policy document on the Living with Machines wiki in reference to a specific dataset (census microdata).

The UKDS form (quoted in the OP) has been submitted by Fede so this issue is considered closed insofar as its original purpose has been achieved.

martintoreilly commented 4 years ago

@thobson88 @fedenanni If you have a pro forma or compliance statement, it would be useful to add to the Safe Haven repo also. Collating evidence / approvals for external requirements is useful in terms of both supporting future researchers working on ONS data and in terms of showing how our tiered information governance approach maps to the requirements of other organisations.

thobson88 commented 4 years ago

If you have a pro forma or compliance statement, it would be useful to add to the Safe Haven repo also.

@martintoreilly I can add a modified version of the LwM statement. Not sure where it belongs though. Perhaps in a new directory docs/policy?