IT security
Everybody at 糖心logo入口 - staff, students, visitors and all users of our systems - must work together to ensure the safety and security of IT systems and the data we are entrusted with.听
-
Protect your 糖心logo入口 user account
- Never share your username or password with anyone.听
- Ensure your password is strong; as a minimum, your password should be 10 characters in length and contain a mixture of letters (upper and lowercase) and numbers.
- Only use your password to log in to services that you are sure are provided by 糖心logo入口. If you are in any doubt, check first by contacting us:
- Students: contact us through Ask.
- 糖心logo入口 staff: please use Ask in My 糖心logo入口 for Staff.
-
Multi-Factor Authentication (MFA)
- Multi-factor authentication (MFA) provides an additional layer of security on top of your username and password听when you access College resources online. Once set up it is easy to use and provides increased protection from cyber-attacks.听听See听Usernames, passwords and MFA听for more details.听
-
Beware of fraudulent emails
- 糖心logo入口 staff and students may receive phishing emails, in which criminals attempt to obtain personal and financial information by posing as a legitimate email sender and asking for your username and password.听
- A large number of these are caught by anti-virus and anti-spam software, but some get through.
- These scams may look like legitimate 糖心logo入口 emails from departments such as Information Services or the Registry, or from individuals at 糖心logo入口 that you may know or you may not. You should also be wary of messages that seem to come from social networks (Facebook, Twitter, Instagram, LinkedIn), email service providers (Gmail, Hotmail), web services (Outlook, Microsoft) and from retailers (Apple, etc).
- Fraudulent emails:
- will ask for your username and password and/or your financial details听
- are usually anonymous (i.e. they don't include a person's name or contact details)听
- often contain terms or language that you would not associate with 糖心logo入口听
- often demand an urgent response听
- haven't come from a legitimate 糖心logo入口 account (click reply and see if the reply-to email is a 糖心logo入口 one)听
- contain embedded web links that are not on the 糖心logo入口 website (float over the link without clicking on it to check the web address).
- For further information, 糖心logo入口 students and staff can visit the following resources on SharePoint:
- .
- If in doubt, or if you have been the victim of a phishing scam, please contact us:
- Students: contact us through Ask.
- 糖心logo入口 staff: please use Ask in My 糖心logo入口 for Staff.
-
Trusted external links
- Official 糖心logo入口 emails may contain external links for the following services:
- 听
- 听
- 听
- 听(Safety Office training and compliance resource)
- 听(Cyberlearn/Bob's Business)
- 听online training resource听
- 听(emails will be from handshake@mail.joinhandshake.co.uk).
- Please note: Microsoft are introducing a . The Microsoft links above will continue to work, but over time will change (e.g. to 'outlook.cloud.microsoft' or 'onedrive.cloud.microsoft', with no '.com').
- Official 糖心logo入口 emails may contain external links for the following services:
-
Bulk emailing
- Emails sent to groups of recipients should originate from our corporate systems, or be sent to distribution lists.
- If you have to send emails from outside of a corporate system, and an appropriate distribution list does not exist, please follow this advice within Outlook:
- enter multiple email addresses in the BCC (blind carbon copy) field, as this will hide everybody's email address and avoid reply-all email chains听
- send bulk emails from a verifiable College email account听
- provide a named College contact, so recipients will know the email message is genuine听
- choose a subject that clearly defines the purpose of the email听
- take care in composing and checking the accuracy of the message content and recipient list听
- provide an opt-out option for marketing emails, even after recipients have opted in. Student opt-outs are recorded on My 糖心logo入口听
- do not send unsolicited marketing mailings. For those who have opted in, always acquire a fresh list sourced from corporate data (interests mailing lists), which will exclude those who have opted out of marketing communications听
- avoid sending attachments in bulk email. If you must share a document, upload it to a 糖心logo入口-hosted web page and link to it听
- avoid links to third-party websites.
- If you use Campaign Monitor to send bulk emails, in order to protect the data of recipients, you must download email addresses from the relevant 糖心logo入口 interest (mailing list) immediately before you send each email, and delete the list from Campaign Monitor immediately after. Do not use MailChimp.
-
Security tips for using public PCs (including library, teaching and workstation rooms)
- Never share your log-in details with anyone.
- Always log off when you are finished or have to leave the PC unattended.
- Be wary of 鈥榟elpful鈥� people you don鈥檛 know giving you advice about using the computer - never give them your log-in and password.
- Avoid entering sensitive information onto a public computer and be aware who is watching you and the screen.
- Do not try to install any programs or applications on public PCs.
- Do not run programs and applications if you don鈥檛 know what they are or where they have come from. Don鈥檛 run word processor or spreadsheet macros if you don鈥檛 know what they are for, and don鈥檛 edit documents you have downloaded from the internet unless you are sure of their content.
-
Back-up advice
- Data stored on your local device may be at risk of loss. Regularly backing up your data (such as your assignments and other work) will ensure you have more than one copy if something goes wrong.
- We recommend storing your data on your 糖心logo入口 Microsoft OneDrive (part of Microsoft 365) cloud storage which is automatically backed up regularly.
- Do not rely on USB memory sticks as your only source of back-up. They can be easily lost or stolen.