Showing posts with label k-12. Show all posts
Showing posts with label k-12. Show all posts

Wednesday, May 11, 2011

Managing iDevices in the K-12 Enterprise

The iThis or iThat has been a major topic of discussion in several recent individual and group meetings. I completely understand why and this post isn't about debating the pros and cons or the reasons for all of the fuss. I do want to make a quick point and mention a few company names in this post.

First, a general point to be made here: Countless times, I've seen districts try to save money on the front end only to kill themselves in man-hours on the back end when new initiatives and technology are implemented. My opinion is always subject to change, but I see two options for a K-12 CIO facing an implementation of iDevices in their environment:

Option 1 - the 'minimalist' approach - Set the expectation from the beginning that you'll get them on the network and make sure they can access the Internet. Anything else is up to the user. By "anything", I mean anything related to behavior issues, app purchasing and deployment, repair (since they can't be repaired by your staff), etc. I know some reading this will say "there's no way that will work", but I would at least put that option on the table. Face it, others often assume that you CAN manage all of those app and behavior issues at the tech staff level, so let's at least get the thought (or the reality) out there in discussion that your staff not be responsible for these things.

Option 2 - the truly managed approach - I've been to a couple of sessions by Apple staff. They'll admit that, as it pertains to proper enterprise deployment and management, they're learning as well. These devices are being used in ways they didn't originally imagine. I heard several references to wikis and posts made by other administrators and to non-supported software and processes to perform tasks. Putting a large number of these devices into an enterprise is not an easy task. It isn't something that everyone else has figured out. There isn't a 'standard' way of doing it. I would submit that, at least for now, the 'truly managed' approach involves some third-party enterprise software to assist with iOS management.

See my point? Try to either get OUT of the business of managing these devices or fully commit and truly get IN the business and insist on some sort of third-party tool to help you work more effectively and, with any luck, keep your sanity. Here are a few companies mentioned in a session I attended yesterday:

Absolute Manage
by Absolute Software - says it will help you "...manage the PC, Mac and iOS devices in your deployment from a single interface.

Casper Suite by JAMF Software - says it integrates with VPP and it's "...the only client management solution developed exclusively for the Apple platform."

AirWatch - Looks to be focused on mobile devices and also mentions the Android OS, Windows Mobile and BlackBerry.

MobileIron - I'm struggling with their web site at the moment but their site mentions a server you would install along with an app for the device. It says you can recommend apps and ensure that users can only run authorized apps.

I'm not saying any of those products are wonderful or terrible, but I am saying that all of the discussion I'm hearing makes me believe that district tech leaders either need to help set a policy that puts them in a "connect it and forget it" mode with these devices or else they should push hard for a software product like one of these mentioned that may be able to help you effectively manage these devices.
[Image - Courtesy: National Science Foundation]

Tuesday, May 3, 2011

Thoughts on TMG and Internet filtering in general

As many of our school districts are looking at implementing Microsoft's Threat Management Gateway, now is as good a time as any to put a few thoughts together:

With the penetration of 3G handheld devices in hands of many high school students and staff, some districts are rightly questioning the effectiveness of ANY content management solution in an environment where a personal device cannot be monitored. That said, school districts are obligated by CIPA and (in our case) state law to do something in an effort to prevent access to inappropriate material.

At this point, it gets difficult for many districts. Depending on the expectations that have been set over years of content filtering and management, classroom teachers and administrators often expect the technology department to stop any inappropriate access from occurring. Technology leaders know that this is not possible. With time, opportunity and motivation, virtually any filtering solution can be defeated or bypassed. If the expectation has been set from the beginning that these matters are handled in the classroom, then the changing landscape of devices and methods of access may not have a huge impact on the prevention of inappropriate access since it would still be attempted and dealt with at the classroom level.

As our districts are considering Threat Management Gateway, I've noticed a few things that are worthy of note. First, the URL filtering is a subscription-based add-on that is referred to as the "Web Protection Service." This service provides subscriptions not only to URL-based categories but also to malware filtering. Issues with malware have become very important to our technical staff due to time spent cleaning up infected devices.

Note also that SP1 enabled certain features such as URL override and reporting enhancements, including a detailed "user activity report." My first reaction is that these enhancements should have been in the native product rather than a Service Pack, but the fact remains that they are now included and that's a positive development.

In fact, I think that generally sums up my initial thoughts about TMG. If a school district is simply trying to meet the letter of the law and wants a solution that can filter URLs based on categories and can potentially help with malware, TMG might be a fine solution. Some districts have paid for much more expensive and elaborate solutions that allow for robust reporting and real-time monitoring of particular users. I'm not trying to slander the TMG product and imply that it cannot do these things, but there's a reason that these other companies charge a premium and I can only assume that it's due to some advanced features, perhaps ease of use, etc. If you desire some of these advanced features, other products may fit your specific needs.

I'm inclined to compare this market to the old debate of VMWare and Hyper-V in the virtualization market. VMWare was earlier to market and has a strong reputation in this market. Microsoft's Hyper-V offering was later to market and, at least initially, might not have had all of the features that the VMWare suite had. At the time, one could market higher cost for higher quality while the other marketed a lower-cost product that provided all of the features that many customers might want. I think this is how I would currently categorize TMG. It provides many of the features (if not all) that many customers in this market desire.

At any rate, all of this is subject to change but it's what was on my mind at the moment. This and 50 cents would have bought you a soft drink several years ago. :)

Tuesday, July 6, 2010

The Crystal Ball

As I look ahead to the next school year for our districts, I thought I'd take a moment to mention a few trends that we'll all likely face in the next year or two. We're already seeing some of these topics coming up in some districts, but I feel like these trends will continue and accelerate:

* $$$ and doing more with less (or withOUT) - I mentioned Title IID concerns a year ago and they have come to pass, so there will be less federal money for education technology. Kentucky's budget for 7/1/10 through 6/30/12 called for technology funding cuts and that will have a large impact from the state perspective. And then - THEN - it seems that our state may have a $200-$300M shortfall (after these passed budget cuts, mind you) if we don't receive a federal Medicaid funding match. That could mean that we face further budget cuts during this budget cycle. I don't enjoy hearing about and talking about budget cuts any more than you do, but I emphasize these to point out that the cuts are real and we're going to feel them. I have school districts that are cutting staff and hard decisions will also have to be made regarding replacement of aging technology. As one example, a district is considering replacement of some devices with the NComputing 'virtual' computers. As stated in the title for this section, there's no doubt that districts will be trying to do more with less and, with all of the fat trimmed from budgets, I feel like some will be forced to make the tougher decisions to do without resources, whether those be personnel, new hardware or new software.

* Even MORE controversy as boundaries are crossed - I could link hundreds of articles to make my point, but I'll limit myself to a single link and humbly ask that you make the time to read this New York Times article on school districts being pulled into difficult issues related to technology use and abuse. I have several districts who have noted that they're getting called weekly on Facebook-related issues. I know of staff members who have been questioned about their curious choice of Facebook profile picture and/or status, particularly when some of their 'friends' are students. I know of districts who have had to deal with their users posting very inappropriate content to sites like these. The instinct for district leadership is to call the CIO when something occurs, because it's on the Internet and a computer was used. As the article points out, what do you do when the issue didn't occur on school grounds or with school property? Some parents will demand the district to intervene while others would claim their rights have been violated if the district were to intervene in a personal situation. The lines are blurring and it's making the K-12 CIO's job more difficult.

* More personal devices in the classroom - If you think about it, the first two bullets make this one almost inevitable. In most cases, the money isn't there to buy district-owned devices for everyone. More and more high-schoolers (and younger) are carrying personally-owned devices that have tons of functionality. While we will certainly wrestle with boundaries, inappropriate use, Internet filtering and other issues, I feel like some districts will also look to take advantage of these devices. They are resources that many kids are carrying, that CAN be used in positive ways and that the kids really want to use.

I'm sure there are other things on the horizon (eBooks, for example), but these have been on my mind as of late. Agree, disagree or add topics of your own. Take care!

Thursday, June 10, 2010

What do you do in the summer?

That question gets posed from outside the education community, with the general assumption being that everyone vacations all summer long if they work in the K-12 education environment. Not true. Furthermore, I think the assumption is that the K-12 technology coordinators and staff are simply in charge of "keeping the computers running". Sure, there are computers to replace and re-image. That doesn't even scratch the surface of everything these departments are asked to deal with during the summer and throughout the year. Here's my off-the-cuff stab at a list, and I'm sure that this isn't exhaustive:

Printers
Copiers
Web site creation and maintenance
Televisions
DVD
Media distribution servers/solutions
Digital cameras
Camcorders
Handheld computers and smartphones (both district-owned and personal)
Projectors
Wireless slates/pads
Interactive whiteboards
Student response systems
Student Information System
Instructional software of various types
Food service software
Point-of-sale hardware
Asset tracking software and hardware
Library management software
Internal district finance hardware/software
Servers to run all of this and more
Software licensing compliance for all of this
Switches and electronics in the wiring closets
Running and terminating cable for all of this to connect
Wireless environments (ever-growing) to support mobility desires
Security cameras
Badge ID systems for the user base
Building security (so those badges can be used for building entry)
Automatic lighting (in some cases, yep)
A/C needs for the data center(s) (this hardware generates tons of heat)
Support for Student Technology Leadership Program
Assistive and adaptive technology (for special needs cases)
Telephone systems (voicemail, handsets, trunk line configurations, etc)
Video distribution systems (cable TV and other local media)
Wide-area network connecting all schools to one another
Antivirus software for all workstations
Ensuring proper OS updates/patching of all workstations
Web filtering hardware/software, updates and ongoing issues
Facebook and social networking issues (significant enough for separate mention)
Establishing policy on things like personal device use (cellular, computers)
Crafting and updating a district technology plan for all of this
Professional development for staff so THEY understand all of this
Managing maintenance agreements for some/all of this
Having a system to track/manage work orders that might be called in on any of this
Keeping track of grant opportunities to assist with some of this
Dealing with vendors who constantly try to sell some/all of this
Managing the E-Rate program, which ties to critical federal funds

As I said, I'm sure this isn't an exhaustive list, but it's a good start. Some of these items are a job unto themselves. Some can take up a huge amount of time when/if something goes wrong. There's plenty to do throughout the year and, if these folks are taking a bit of time off during the summer, it's well-deserved. More likely, their time away is brief due to the fact that the best time to update/replace most of these components is during the summer while school is not in session. For you IT workers out there, if you're dreaming of having your toes in the sand, I hope you don't read this and awake with a fear that you're in quicksand...

Monday, March 22, 2010

Privacy and user rights - a few 'horror stories'

As our group discussed Acceptable Use Policies last week, someone suggested that it might be useful to have a few of the 'horror stories' to share with others. Sadly, they're very easy to find and I thought I'd take a moment to highlight three that I've heard about. Each of these highlight certain 'gray areas' surrounding a staff member's desire to gain some information. Students were put in precarious positions and, in each of these cases, lawsuits resulted. Some (if not all) of these cases are ongoing and any comments are not meant to pass judgment on any parties involved; rather, I'm simply highlighting the circumstances surrounding the situation and pointing out that today's use of technology requires us all to be knowledgeable and respectful of the rights of others...

* Quite recently, the Lower Merion School District in Pennsylvania was sued over the remote enabling of a webcam on a district-issued laptop computer. The case alleges that a student was disciplined at school with a webcam-based photograph (taken while the student was at home with the laptop) being used as evidence for the discipline. Privacy issues are being cited and there's some debate over who knew about the potential to remotely activate the webcams, how was this feature used, etc.

* A few years ago, cheerleaders at a high school in Pearl, MS were asked to relinquish their Facebook passwords to their cheering coach. One student did so and her private Facebook email was accessed. This information was shared with others in the district and the student was disciplined for some of the contents found. A lawsuit has been filed and this case will help determine whether school administrators have the right to request access to these private conversations.

* Closer to (my) home, a school district has been sued over the review of contents of a confiscated student cell phone. According to the suit, the phone slipped out of the student's pocket. Administrators read the content of text messages on the phone and the student was expelled. The lawsuit claims that this was an illegal search of private property.

Those are a few examples and I'm sure you can cite others as well. This shows the need we have as technology leaders to become more aware of district policies and lead be learning and educating our own staffs about what can and cannot be done as it pertains to these new technology devices and tools.