Apple and Windows Device Security Recommendations: Difference between revisions

 
(34 intermediate revisions by 3 users not shown)
Line 1: Line 1:
{{abox
{{AboxNew
| name         = iOS Devices
| name = Apple and Windows Device Recommendations
| summary      =  
| learning =  
| for_employees = Yes
| instruction =  
| for_students  = Yes
| community = x
| for_parents  = Yes
| summ = Recommendations for Apple and Windows devices at Riverdale
| cat1          =  RCS Software and Services
| maintained = DIS
| cat2          =
| year = 2023-2024
| maintained   = DIS
| year         = 2022-2023
}}
}}
__TOC__


=Apple Help and Documentation=
=Apple Devices=
Apple provides a wealth of support documentation and online manuals for devices on their website.  
 
=== General Resources ===
Apple has excellent documentation for their device line-up. If you are looking for general resources related to your device, we recommend you start here.  


*[http://www.apple.com/support/ipad/ iPad]
*[http://www.apple.com/support/ipad/ iPad]
Line 19: Line 20:
*[https://www.apple.com/watch/ Watch]
*[https://www.apple.com/watch/ Watch]


=Best Practices=
=== Best Practices ===
===Backing up your iOS device===
 
It is a good idea to back up, or sync, your iOS device to a [https://support.apple.com/en-us/HT211229 Macintosh] or [https://support.apple.com/en-us/HT212156 Windows] laptop or desktop computer or to [https://support.apple.com/en-us/HT211228 iCloud]. Both the iOS device and laptop or desktop can be supplied and/or managed by Riverdale.
==== Back-up iOS or iPadOS Device ====
It is a good idea to back up, or sync, your iOS/iPadOS device to a [https://support.apple.com/en-us/HT211229 macOS] or [https://support.apple.com/en-us/HT212156 Windows] laptop or desktop computer or to [https://support.apple.com/en-us/HT211228 iCloud]. Both the iOS device and laptop or desktop can be supplied and/or managed by Riverdale.


To retain the integrity of your iOS applications, settings and personal data, it is essential to frequently backup, or sync, the device to your computer. Sync must either be done over the USB cable, or through Wi-Fi  syncing to a single computer. You should choose to '''encrypt''' the backup file for your device as an additional security precaution. You will find the checkbox for this option on the Summary page for the device when it is connected. If you do not encrypt the iTunes backup, all saved passwords for email and other accounts cannot be restored.
To retain the integrity of your iOS applications, settings and personal data, it is essential to frequently backup, or sync, the device to your computer. Sync must either be done over the USB cable, or through Wi-Fi  syncing to a single computer. You should choose to '''encrypt''' the backup file for your device as an additional security precaution. You will find the checkbox for this option on the Summary page for the device when it is connected. If you do not encrypt the iTunes backup, all saved passwords for email and other accounts cannot be restored.


===Loss and Theft protection===
==== Loss and Theft protection ====
To enable you to find a lost or stolen school-owned iPhone or iPad, you are required to enable the '''Find My iPhone (iPad) service''' using your iCloud account. When this service is enabled, you will be able to track your device, as well as remotely clear it of all data.
To enable you to find a lost or stolen school-owned iPhone or iPad, you are required to enable the '''Find My iPhone (iPad) service''' using your iCloud account. When this service is enabled, you will be able to track your device, as well as remotely clear it of all data.


Full instructions on how to enable and utilize the '''Find My iPhone (iPad) service''' will be found at [https://support.apple.com/explore/find-my-iphone-ipad-mac-watch Apple Support - Find My iPhone, iPad, Mac and iWatch.]
Full instructions on how to enable and utilize the '''Find My iPhone (iPad) service''' will be found at [https://support.apple.com/explore/find-my-iphone-ipad-mac-watch Apple Support - Find My iPhone, iPad, Mac and iWatch.]


===Passcode Security===
==== Passcode Security ====
The single-user design of iPads and iPhones enables the retention of passwords for Riverdale Google accounts, as well as any other logins to personal email, banking and ecommerce sites. Many mobile applications retain downloaded confidential data in readable format. Because of the mobile nature of these devices, the opportunity for theft or loss is greatly increased. As a result, deliberate or accidental access to confidential information, as well as outright malicious intent towards the safety of your data can occur. It behooves any mobile RCS user to protect access to important School services by using a more secure passcode.  
The single-user design of iPads and iPhones enables the retention of passwords for Riverdale Google accounts, as well as any other logins to personal email, banking and ecommerce sites. Many mobile applications retain downloaded confidential data in readable format. Because of the mobile nature of these devices, the opportunity for theft or loss is greatly increased. As a result, deliberate or accidental access to confidential information, as well as outright malicious intent towards the safety of your data can occur. It behooves any mobile RCS user to protect access to important School services by using a more secure passcode.  


Line 44: Line 46:
*Set the '''Require Passcode''' to 15 minutes or less.
*Set the '''Require Passcode''' to 15 minutes or less.
*Set '''Simple Passcode''' to OFF - this option may be disabled if Riverdale has placed a more complex passcode requirement.
*Set '''Simple Passcode''' to OFF - this option may be disabled if Riverdale has placed a more complex passcode requirement.
**This setting will then ask for you to enter a more complex password which can contain upper & lower case letters, numbers, and punctuation marks. At the very least, create a passcode which follows the [http://knowledge.riverdale.edu/index.php?title=Change_My_Passwords#Password_Requirements requirements for your Riverdale Domain password.]
**This setting will then ask for you to enter a more complex password which can contain upper & lower case letters, numbers, and punctuation marks. At the very least, create a passcode which follows the [https://howdoi.riverdale.edu/wiki/Create_a_Strong_Passphrase requirements for your Riverdale Domain password.]
***Using your Riverdale Domain password is '''''not recommended''''' for this passcode. See this page on [http://secure.wikimedia.org/wikipedia/en/wiki/Shoulder_surfing_%28computer_security%29 Shoulder Surfing] for more information on this recommendation.
***Using your Riverdale Domain password is '''''not recommended''''' for this passcode. See this page on [http://secure.wikimedia.org/wikipedia/en/wiki/Shoulder_surfing_%28computer_security%29 Shoulder Surfing] for more information on this recommendation.
*Optionally, select the '''Erase Data''' setting to erase all data on the iOS device after 10 failed passcode attempts. If you use this setting, make sure to backup and sync your iOS device on a regular basis. After the '''Erase Data''' mechanism is invoked, the iOS device will be wiped clean and you will need to restore the settings & applications from your laptop/desktop or through iCloud.
*Optionally, select the '''Erase Data''' setting to erase all data on the iOS device after 10 failed passcode attempts. If you use this setting, make sure to backup and sync your iOS device on a regular basis. After the '''Erase Data''' mechanism is invoked, the iOS device will be wiped clean and you will need to restore the settings & applications from your laptop/desktop or through iCloud.
== Windows Devices ==
=== General Resources ===
We recommend running '''Windows 11''', which is the latest operating system from Microsoft: [https://www.microsoft.com/software-download/windows11 Download Windows 11]
=== Best Practices ===
==== Logging In ====
'''Windows Hello''' is a secure way to get instant access to your Windows 11 devices using a '''PIN, facial recognition, or fingerprint'''. You'll need to set up a PIN as part of setting up fingerprint or facial recognition sign-in, but you can also sign in with just your PIN. These options help make it easier and safer to sign into your PC because your PIN is only associated with one device. Information about: [https://support.microsoft.com/en-us/windows/learn-about-windows-hello-and-set-it-up-dae28983-8242-bb2a-d3d1-87c9d265a5f0 Windows Hello]
==== Protect Your Data ====
Windows has a [https://support.microsoft.com/en-us/windows/back-up-your-windows-pc-87a81f8a-78fa-456e-b521-ac0560e32338 backup feature] in the operating system, but we generally recommend storing your data on Riverdale's Google Drive. We back up your RCS GDrive for you!
==== Antivirus ====
The Windows operating system comes with [https://en.wikipedia.org/wiki/Microsoft_Defender_Antivirus Windows Defender]. This is a functional and well regarded antivirus product, and it's free. On Riverdale managed laptops, we deploy Sophos antivirus, which is managed via Sophos Central.
==== Keep Your Device Up-to-Date ====
It's best practice to keep Windows up-to-date via [https://support.microsoft.com/en-us/windows/update-windows-3c5ae7fc-9fb6-9af1-1984-b5e0412c556a Windows Update] and to update drives from the manufacturer (Dell, HP, Lenovo, etc). Drivers from the manufacturer can be found on their respective Support page. They often provide a "device scanner" tool that takes inventory of your machine and only applies the updates/drivers that it's missing.
281

edits