print page
< Back
Menu > About EDB >
Forms & Circulars
-
Forms
-
Circulars
< Back
Menu > Curriculum Development and Support >
Major Levels of Education
-
Kindergarten Education
-
Primary Education
-
Secondary Education
< Back
Menu > Curriculum Development and Support >
Assessment
-
Basic Competency Assessment (BCA)
< Back
Menu > Students and Parents Related >
Life Planning Education and Career Guidance
-
Life Planning Education
-
Business-School Partnership Programme
< Back
Menu > Students and Parents Related >
Safety Matters
-
Safety of Students
-
School Bus Services
< Back
Menu > Students and Parents Related >
Non-Chinese speaking (NCS) students
-
Education services for non-Chinese speaking (NCS) students
-
What's new
-
Overview
< Back
Menu > Students and Parents Related >
Programs and Services
-
Programs
-
Services
< Back
Menu > Teachers Related >
Qualifications, Training and Development
-
Qualification
-
Training
-
Development
< Back
Menu > School Administration and Management >
Financial Management
-
About Financial Management
-
Information on Subsidy
-
Notes to School Finance
< Back
Menu > School Administration and Management >
School Premises Related Information
-
Allocation of a School
-
Furniture and Equipment List for New Schools
-
School Premises Maintenance
< Back
Menu > Public and Administration Related >
Public Forms and Documents
-
Public Forms
-
Efficiency Office - Guide to Corporate Governance for Subvented Organisations
< Back
Menu > Public and Administration Related >
Tender Notices
-
Tender Notices
-
Works Tender Notice
Main content start

Information Security in Schools

 

(11/04/2024) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Mobile Device Management (MDM) in Schools [EI0020240261NEW

This course aims to strengthen the participants’ understanding of different Mobile Device Management (MDM) systems and equip them with relevant skills and know-how to provide effective technical support to school.

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020240261&lang=en

(19/03/2024) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Management of Active Directory (AD) in Schools (Advanced Level) [EI0020240214NEW

This course aims to strengthen the participants’ advanced understanding of Active Directory (AD) and equip them with relevant skills and know-how to provide effective technical support to school.

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020240214&lang=en

(07/03/2024) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities - Management of Active Directory (AD) in Schools (Basic Level) [EI0020240213

This course aims to strengthen the participants’ basic understanding on Active Directory (AD) and equip them with relevant skills and know-how to effectively provide technical support to school.

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020240213&lang=en

(01/02/2024) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Management of Webservers and Webpages in Schools [EI0020230587]

This course aims to strengthen the participants’ understanding on managing webservers and webpages and equip them with relevant skills and know-how to effectively provide technical support to school.

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230587&lang=en

(18/01/2024) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Backup and Restoration of Files and Operating Systems in Schools [EI0020230588

This course aims to strengthen the participants’ understanding of backup and restoration of files and operating systems, and equip them with relevant skills and know-how to provide effective technical support to school.

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230588&lang=en

(11/12/2023) STEAM Education Learning, Teaching and Assessment Series: Cyber Security – Cyber Attack and Defence and Technology Crime Information (Online) [CSD020230587

Through introducing cyber-attacks and defence, sharing cases on technology crime and relevant learning and teaching resources, this seminar aims to enhance the participants’ information security awareness and provide them with strategies to defend against cyber-attacks, as well as strengthen support for teachers to nurture student positive attitudes on using the Internet and protect student from cyber crimes.

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=CSD020230587&lang=en

(24/11/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Computer Networking in Schools

 [EI0020230512] 

This course aims to strengthen the participants’ understanding on computer networking in schools and equip them with relevant skills and know-how to provide technical support to school effectively.  Relevant teachers and technical support staff are encouraged to enroll at: 

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230512&lang=en

(9/11/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Learning Management Systems (LMS) in Schools [EI0020230511] 

This course aims to strengthen the participants’ understanding on different learning management systems (LMS) and equip them with relevant skills and know-how to provide technical support to school effectively.  Relevant teachers and technical support staff are encouraged to enroll at: 

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230511&lang=en

(12/07/2023-09/08/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Backup and Restoration of Files and Operating Systems in Schools (Online Self-learning Course) [EI0020230424

This course aims to strengthen the participants’ understanding of backup and restoration of files and operating systems, and equip them with relevant skills and know-how to provide effective technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230424&lang=en

(12/07/2023-09/08/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities - Management of Active Directory (AD) in Schools (Advanced Level) (Online Self-learning Course) [EI0020230423

This course aims to strengthen the participants’ advanced understanding of Active Directory (AD) and equip them with relevant skills and know-how to provide effective technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230423&lang=en

(12/07/2023-09/08/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-System Security in Schools (Online Self-learning Course) [EI0020230422

This course aims to strengthen the participants’ understanding of system security in schools, and equip them with relevant skills and know-how to provide effective technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230422&lang=en

(27/06/2023-25/07/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Computer Networking in Schools (Online Self-learning Course) [EI0020230408] 

This course aims to strengthen the participants’ understanding on computer networking in schools and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230408&lang=en

(27/06/2023-25/07/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Management of Webservers and Webpages in Schools (Online Self-learning Course) [EI0020230409] 

This course aims to strengthen the participants’ understanding on managing webservers and webpages and equip them with relevant skills and know-how to effectively provide technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230409&lang=en

(27/06/2023-25/07/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities - Management of Active Directory (AD) in Schools (Basic Level) (Online Self-learning Course) [EI0020230410] 

This course aims to strengthen the participants’ basic understanding on Active Directory (AD) and equip them with relevant skills and know-how to effectively provide technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230410&lang=en

(14/06/2023-12/07/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Learning Management Systems (LMS) in Schools (1) (Online Self-learning Course) [EI0020230381] 

This course aims to strengthen the participants’ understanding on different learning management systems (LMS) and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230381&lang=en

(14/06/2023-12/07/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Learning Management Systems (LMS) in Schools (2) (Online Self-learning Course) [EI0020230380] 

This course aims to strengthen the participants’ understanding on different learning management systems (LMS) and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230380&lang=en

(14/06/2023-12/07/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Mobile Device Management (MDM) in Schools (Online Self-learning Course) [EI0020230382] 

This course aims to strengthen the participants’ understanding of different Mobile Device Management (MDM) systems and equip them with relevant skills and know-how to provide effective technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230382&lang=en

(02/05/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Backup and Restoration of Files and Operating Systems in Schools [EI0020230300] 

This course aims to strengthen the participants’ understanding of backup and restoration of files and operating systems and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230300&lang=en

(27/04/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Mobile Device Management (MDM) in Schools [EI0020230275] 

This course aims to strengthen the participants’ understanding of different Mobile Device Management (MDM) systems and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230275&lang=en

(25/04/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Management of Active Directory (AD) in Schools (Advanced Level) [EI0020230233] 

This course aims to strengthen the participants’ advanced understanding of Active Directory (AD) and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230233&lang=en

(27/03/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-System Security in Schools [EI0020230273] 

This course aims to strengthen the participants’ understanding of system security in schools and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230273&lang=en

(21/03/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities - Management of Active Directory (AD) in Schools (Basic Level) [EI0020230232] 

This course aims to strengthen the participants’ basic understanding on Active Directory (AD) and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230232&lang=en

(10/03/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Management of Webservers and Webpages in Schools [EI0020230237]  

This course aims to strengthen the participants’ understanding on managing webservers and webpages and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230237&lang=en

(24/02/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Computer Networking in Schools [EI0020230206 ] 

This course aims to strengthen the participants’ understanding on computer networking in schools and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020230206&lang=en

(11/01/2023) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Learning Management Systems (LMS) in Schools (2) [EI0020220512] 

This course aims to strengthen the participants’ understanding on different learning management systems (LMS) and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at: https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220512&lang=en

(16/12/2022) IT in Education Technological Series: Management, Security and Maintenance of School IT Facilities-Learning Management Systems (LMS) in Schools (1) [EI0020220476] 

This course aims to strengthen the participants’ understanding on different learning management systems (LMS) and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220476&lang=en

(13/07/2022-10/08/2022) IT in Education e-Safety Series: Management, Security and Maintenance of School IT Facilities - Management of Active Directory (AD) in Schools (Basic Level) (Online Self-learning Course) [EI0020220356]  

This course aims to strengthen the participants’ basic understanding of Active Directory (AD) and equip them with relevant skills and know-how to effectively provide technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220356&lang=en

(13/07/2022-10/08/2022) IT in Education e-Safety Series: Management, Security and Maintenance of School IT Facilities - Management of Active Directory (AD) in Schools (Advanced Level) (Online Self-learning Course) [EI0020220357]  

This course aims to strengthen the participants’ advanced understanding of Active Directory (AD) and equip them with relevant skills and know-how to effectively provide technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220357&lang=en

(13/07/2022-10/08/2022) IT in Education e-Safety Series: Management, Security and Maintenance of School IT Facilities-Backup and Restoration of Files and Operating Systems in Schools (Online Self-learning Course) [EI0020220358]  

This course aims to strengthen the participants’ understanding on backup and restoration of files and operating systems, and equip them with relevant skills and know-how to effectively provide technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220358&lang=en

(13/07/2022-10/08/2022) IT in Education e-Safety Series: Management, Security and Maintenance of School IT Facilities-System Security in Schools (Online Self-learning Course) [EI0020220359]  

This course aims to strengthen the participants’ understanding on system security in schools, and equip them with relevant skills and know-how to effectively provide technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220359&lang=en

(29/06/2022-27/07/2022) IT in Education e-Safety Series: Management, Security and Maintenance of School IT Facilities - Management of Webservers and Webpages (Online Self-learning Course) [EI0020220276] 

This course aims to strengthen the participants’ understanding of managing webservers and webpages and equip them with relevant skills and know-how to effectively provide technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220276&lang=en

(29/06/2022-27/07/2022) IT in Education e-Safety Series: Management, Security and Maintenance of School IT Facilities - Computer Networking in Schools (Online Self-learning Course) [EI0020220275] 

This course aims to strengthen the participants’ understanding of computer networking in schools and equip them with relevant skills and know-how to effectively provide technical support to school. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220275&lang=en

(15/06/2022-13/07/2022) IT in Education e-Safety Series: Management, Security and Maintenance of School IT Facilities - Mobile Device Management (MDM) in Schools (Online Self-learning Course) ) [EI0020220272]  

This course aims to strengthen the participants’ understanding on different Mobile Device Management (MDM) systems, and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220272&lang=en

(15/06/2022-13/07/2022) IT in Education e-Safety Series: Management, Security and Maintenance of School IT Facilities - Learning Management Systems (LMS) in Schools (Online Self-learning Course) [EI0020220273]  

This course aims to strengthen the participants’ understanding on different learning management systems (LMS) and equip them with relevant skills and know-how to provide technical support to school effectively. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020220273&lang=en

(20/05/2022) Build a Secure Cyberspace 2022 Cyber Security in Simple Ways Webinar 

In the digital era, most of us have access to the Internet world, and have the chance of falling into the online traps and suffer a loss. The Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT), the Office of the Government Chief Information Officer (OGCIO) and the Hong Kong Police Force (HKPF) are jointly organising the Build a Secure Cyberspace 2022 “Cyber Security in Simple Ways” Webinar to explore how to use the Internet safely and prevent cyber-attacks with simple steps. The webinar will invite information security experts to share their experiences and insights on this subject.

 

The information of the event are as follows:

  • Date: 20 May 2022
  • Time: 14:30 - 17:15 (Online registration starts at 14:15)
  • Venue: Webinar
  • Language: Cantonese

For details and registration, please refer to the website at the following link: https://www.hkcert.org/event/build-a-secure-cyberspace-2022-cyber-security-in-simple-ways-webinar

(05/05/2022)  Build a Secure Cyberspace 2022 Fact Check After Receiving, Think Twice Before Sharing Folder Design Contest [EDBCM No. 84/2022] 

EDB ITE Section issued an EDB Circular Memorandum on Build a Secure Cyberspace 2022 “Fact Check After Receiving, Think Twice Before Sharing” Folder Design Contest [EDBCM No.84/2022]

The purpose of this circular memorandum is to inform heads of primary and secondary schools of the Build a Secure Cyberspace 2022“Fact Check After Receiving, Think Twice Before Sharing” Folder Design Contest. All students and teachers of the schools are invited to participate in the captioned activity

(07/07/2021) IT in Education e-Safety Series: Cybersecurity and Safeguards in Schools Webinar [EI0020210384] 
This webinar aims to enhance schools’ awareness on cyber security and the importance of regular vulnerability assessment in schools.

Date : 07 July 2021(Wed)
Time : 9:30 am - 11:00 am
Speakers : Mr Eric FAN, Chairman of eLearning Consortium (eLC), Mr LEE Kin-man, Principal of Salesians of Don Bosco Ng Siu Mui Secondary School, Mr Amika AU, Chief Information Officer from Diocesan Boys’ School, Representatives from Hong Kong Telecom (HKT) 
Participant Group : All principals, teachers and technical support staff in primary and secondary schools  
Venue : Webinar – Participant shall prepare his/her own electronic device (e.g. Desktop, Notebook or Mobile, etc.) with Internet access.

Speaker's presentation slides are as follows:
Presentation by Diocesan Boys' SchoolPDF
Presentation by HKTPDF
Presentation by eLCChinese onlyPDF
(17/08/2020) Cyber Security in Schools Smart Tips
Cyber Security in Schools Smart TipsPDF
(19/08/2020) IT in Education e-Safety Series: Sharing Session on Cyber Security Vulnerabilities of School Networks & Websites and Related Security Measures (Webinar) [EI0020200194]
This webinar aims to enhance schools’ awareness on common cyber security vulnerabilities and the related security measures.
Date: 19 August 2020 (Wed)

Time:  2:30pm -4:00 pm
Speakers: Mr Mat YUEN, Detective Inspector of Police, E-Security Audit and Incident Response Team 1, Cyber Security Division, Cyber Security and Technology Crime Bureau, Hong Kong Police Force, Mr KAM Wai-ming,Stanley, Chairman of Hong Kong Association of Computer Education and Mr KAN Wai-hung, Committee Member of Hong Kong Association of Computer
Participant Group: All principals and teachers in secondary, primary and special schools
Speaker's presentation slides are as follows:
Presentation by HKACEChinese onlyPDF

(30/03/2020) Build a Secure Cyberspace 2020 "Cyber Security Challenges in the Pandemic" Webinar

Build a Secure Cyberspace 2020 "Cyber Security Challenges in the Pandemic" Webinar is jointly organised by the Hong Kong Computer Emergency Response Team Coordination Centre, the Office of the Government Chief Information Officer and the Hong Kong Police Force. In order to prevent the spread of coronavirus, organisations including government, enterprises and schools, ramp up remote working and e-learning. The webinar will invite information security experts to share their experiences and advice on the prevention of related internet security risks associated with remote working and e-learning. The above webinar will be conducted at 2:30 pm on 8 May 2020. For details, please refer to the attachment or the website at the following link: https://www.hkcert.org/my_url/en/event/20050801, you can also complete the registration form (download here) and return it by fax to 2190 9784 or by email to event@hkcert.org.

 

Date : 8 May 2020 (Fri)

Time : 2:30 pm - 5:30 pm

Venue :  Webinar – Participant shall prepare his/her own electronic device (e.g. Desktop, Notebook or Mobile, etc.) with Internet access.

 

(13/01/2020) IT in Education e-Safety Series: Cybersecurity and Safeguards in Schools [EI0020190520]

This seminar aims to enhance the schools’ awareness on cyber security and the importance of regular vulnerability assessment in schools.

 

Date : 13 Jan 2019 (Mon)

Time : 9:30 am - 12:00 am

Venue : W301, 3/F, West Block, EDB Kowloon Tong Education Services Centre, 19 Suffolk Road, Kowloon Tong(Exit E, Kowloon Tong MTR Station)

 

Speaker's presentation slides are as follows:

Presentation by HKTPDF

Presentation by eLCPDF

Presentation by PCPDChinese onlyPDF

Presentation by CISCOPDF

Presentation by HKIRCPDF

Presentation by HKCERTPDF

Presentation by HPPDF

 

(09/12/2019) IT in Education e-Safety Series: Briefing Seminar on Strengthening Information Security Management and Incident Handling in Schools [EI0020190418]

This seminar aims to enhance the schools’ awareness and knowledge of information security management and incident handling issues.

 

Date : 09 Dec 2019 (Mon)

Time : 2:00 pm - 5:00 pm

Venue : WB, 4/F, West Block, EDB Kowloon Tong Education Services Centre, 19 Suffolk Road, Kowloon Tong (Exit E, Kowloon Tong MTR Station)

 

Speaker's presentation slides are as follows:

Presentation by EDB ITE SectionPDF

Presentation by HKCERTPDF

Presentation by HKACEPDF

Presentation by AiTLEPDF

Presentation by HKEdCityPDF

 

(25/09/2019) IT in Education e-Safety Series: Briefing Seminar on Strengthening Information Security Management and Incident Handling in Schools [EI0020190333]

This seminar aims to enhance the schools’ awareness and knowledge of information security management and incident handling issues. 

 

Date : 25 Sept 2019 (Wed)

Time : 14:30 - 17:30

Venue : WP01, Podium, West Block, EDB Kowloon Tong Education Services Centre, 19 Suffolk Road, Kowloon Tong (Exit E, Kowloon Tong MTR Station)

 

Speaker's presentation slides are as follows:

Presentation by HKCERTPDF

Presentation by HKACEPDF

Presentation by AiTLEPDF

Presentation by HKEdCityPDF

Presentation by EDB ITE SectionPDF

 

(24/09/2019) Information Security in Schools - Recommended Practice (Sept 2019)

This document is written for schools’ reference in protecting their information and IT assets when implementing e-learning. Schools are responsible for taking appropriate IT security measures to protect the IT systems and data of their schools. This document recommends common practices on IT security for reference by the schools. Schools may determine on their own requirements and adopt the practices applicable to their own environment. The practices recommended in this document are by no means exhaustive. Schools may also make reference to other IT security measures, such as those listed in the Chapter 12 "Resources of Reference on IT Security" of this document, to protect their IT assets.

 

Information Security in Schools - Recommended Practice (Sept 2019)

(08/04/2019) Build a Secure Cyberspace 2019 "We Together! Secure Data!" Poster Design Contest [EDBCM No.071/2019]

EDB ITE Section issued an EDB Circular Memorandum No. 71/2019 on Build a Secure Cyberspace 2019 "We Together! Secure Data!" Poster Design Contest [EDBCM No.071/2019]

The purpose of this circular memorandum is to inform heads of primary and secondary schools of the Build a Secure Cyberspace 2019 "We Together! Secure Data!" Poster Design Contest. All students and teachers of the schools are invited to participate in the captioned activity.

(22/03/2019) Build a Secure Cyberspace 2019 "Phishing scams? No more!" Seminar

Build a Secure Cyberspace 2019 "Phishing scams? No more!" Seminar is jointly organised by the Hong Kong Computer Emergency Response Team Coordination Centre, the Office of the Government Chief Information Officer and the Hong Kong Police Force. In recent years, there is a rising trend in Internet scams and personal information leakage incidents. To avoid falling victim to these cyber-attacks, it is very important to understand how to protect personal privacy and data assets. The seminar will invite information security experts to share their experiences on this subject. For details, please refer to the attachment or the web site at the following link: https://www.hkcert.org/my_url/en/event/19050301

 

Date : 3 May 2019 (Fri)

Time : 2:30 pm - 5:30 pm

Venue : Lecture Theatre, Hong Kong Central Library, 66 Causeway Road, Causeway Bay, Hong Kong

Audience : SMEs, Schools, NGO, IT Professionals and General Public

Language : Cantonese

Charge : Free (Pre-registration is required.)

 

Download seminar PDFPDF
(15/01/2019) IT in Education e-Safety Series: Seminar on Strengthening Information and Network Security in Schools [EI0020180441]

This seminar aims to enhance the schools' awareness and knowledge on information and network security issues. Information of the seminar are as follows:

 

Date : 15 Jan 2019 (Tue)

Time : 9:30 am - 12:30 nn

Venue : Lecture Theatre, 4/F, West Block, Kowloon Tong Education Services Centre, 19 Suffolk Road, Kowloon Tong

 

Speaker's presentation slides are as follows:

Presentation by AiTLE (Chinese Only)PDF

Presentation by HKSKH Bishop Hall Secondary SchoolPDF

Presentation by HKCERTPDF

Presentation by HKPF*

Presentation by EDB ITE SectionPDF

 

* Presentation slides by HKPF could not be provided.

(24/09/2018) Cyber Security Campaign – Smart Devices Security [EDBCM No.164/2018]

EDB ITE Section issued an EDB Circular Memorandum No.164/2018 on "Cyber Security Campaign – Smart Devices Security" [EDBCM No.164/2018]

The purpose of this circular memorandum is to inform heads of schools about the launch of the "Cyber Security Campaign – Smart Devices Security" organised by the Cyber Security and Technology Crime Bureau (CSTCB) of Hong Kong Police Force (HKPF), and the distribution of the relevant posters and leaflets on the Campaign.

 

Cyber Security Campaign - Hong Kong Police Force Official Website

(20/06/2018) Build a Secure Cyberspace 2018 "Stay Smart, Keep Cyber Scam Away" Video Ad Contest [EDBCM No.101/2018]

EDB ITE Section issued an EDB Circular Memorandum No.101/2018 on "Build a Secure Cyberspace 2018 'Stay Smart, Keep Cyber Scam Away' Video Ad Contest" [EDBCM No.101/2018]

The purpose of this circular memorandum is to inform heads of primary and secondary schools of the Build a Secure Cyberspace 2018"Stay Smart, Keep Cyber Scam Away" Video Ad Contest. All students and teachers of the schools are invited to participate in the captioned activity.

(05/06/2018) Cyber Security and Technology Crime Bureau of Hong Kong Police Force (HKPF) introduced the "No More Ransom" Project

"No More Ransom" Project Website

"No More Ransom" Project WebsiteLeaflet by HKPF

(02/06/2018) IT in Education e-Safety Series: School Websites Secure Sockets Layer (SSL) Protection, Security Risk and Cyber Security Seminar on 2 June 2018 [EI0020180236]

This seminar aims to arouse the schools' awareness and knowledge on information and cyber security issues. Information of the seminar are as follows:

Date : 2 June 2018 (Sat)

Time : 9:30 am - 12:30 nn

Venue : Lecture Theatre, 4/F, West Block, Kowloon Tong Education Services Centre, 19 Suffolk Road, Kowloon Tong

Speaker's presentation slides are as follows:

*Remark: Presentation slides by HKPF & HKITF could not be provided.

(28/05/2018) Cyber Security Campaign (Phase Two) [EDBCM No.092/2018]

EDB ITE Section issued an EDB Circular Memorandum No. 92/2018 on "Cyber Security Campaign (Phase Two)" [EDBCM No.092/2018]

The purpose of this circular memorandum is to inform heads of schools about the launch of "Cyber Security Campaign (Phase Two)" organised by the Cyber Security and Technology Crime Bureau (CSTCB) of Hong Kong Police Force (HKPF), and the distribution of poster and leaflet on the campaign.

(17/05/2018) Useful Links on Website Security

1) Safety centre on "Keep Your Website Safe" (useful information on how to protect websites and secure the data)

2) "HTTPS and Website Security" (Leaflet)

3) "Secure Your Website, Be a Smart Website Owner" (Leaflet) 

For schools that would like to learn more about CSIP and their services, they can approach OGCIO's School Visit programme. The details are available at: https://www.cybersecurity.hk/en/school-visit.php

(14/05/2018) Reminder on IT Security Matter on HTTPS from IT in Education Section, EDB

Google has announced that starting with the release of Chrome 68 in July 2018, its Chrome browser will mark all HTTP sites as "not secure". Any websites if staying at HTTP will be viewed by Chrome users as not secure. In this connection, you may wish to turn your school’s websites/web applications, in particular those Internet-facing, into HTTPS timely in order to avoid undesirable consequences such as worries and queries of students, parents, media and public. Google’s announcement could be found at the following website:

https://security.googleblog.com/2018/02/a-secure-web-is-here-to-stay.html

 
Schools may refer to the following InfoSec website to know more about HTTPS and website security:

https://www.infosec.gov.hk/en

To enable HTTPS on websites for content delivery, schools need to acquire digital certificates for servers. Reference could be made to the following webpage of OGCIO on the recognised certification authorities in Hong Kong:

https://www.ogcio.gov.hk/en/our_work/regulation/eto/ordinance/ca_in_hk/

 
Schools are reminded to take necessary actions to protect their information systems/websites, such as applying the latest security patches recommended by the product vendors, all classified information shall be encrypted while in storage, classified information shall be encrypted when transmitted over an un-trusted communication network (e.g. Internet), implement appropriate access controls, etc. For further information, schools may refer to OGCIO’s InfoSec website at the following link:

https://www.infosec.gov.hk/en/best-practices/business/securing-web-application

 
To enhance schools’ awareness and understanding on information and cyber security issues, a seminar "IT in Education e-Safety Series: School Websites Secure Sockets Layer (SSL) Protection, Security Risk and Cyber Security Seminar (EI0020180236)" will be held on 2 June 2018. Relevant teachers and technical support staff are encouraged to enroll at:

https://tcs.edb.gov.hk/tcs/admin/courses/previewCourse/forPortal.htm?courseId=EI0020180236&lang=en

(15/11/2017) Briefing Seminar on Strengthening School Information Security & Data Protection on 28 & 29 November 2017

AiTLE is working with a number of stakeholders, including HKPF, Cisco, Microsoft and EDB, to organise a seminar on strengthening school information security & data protection. Information of the seminar are as follows:

Date : 28 November 2017 (Tuesday)

Time : 9:30 am - 12:30 nn

Venue : Lecture Theatre, 4/F, West Block, Kowloon Tong Education Services Centre, 19 Suffolk Road, Kowloon Tong

Date : 29 November 2017 (Wednesday)

Time : 2:30 pm - 5:30 pm

Venue : Hall, SKH Saint Benedict's School, 11 Lam Chung Ave, Choi Hung Estate, Kowloon

 
Speaker's presentation slides are as follows:

*Remark: Presentation slides by HKPF could not be provided.

(14/11/2017) Special Attention on Ransomware Attacks Leveraging Remote Desktop Services (RDP) for Infection

We notice that there have been reports of Crysis/Dharma ransomware attacks through RDP recently in Hong Kong, resulting in data being encrypted and inaccessible. TSS are advised to review and take the following preventive measures to protect the computers of your school from ransomware attacks:

 

(a) Block RDP protocol access from the Internet. If remote access from the Internet is unavoidable, additional protection (such as VPN and multiple-factor authentication for the access) should be applied;

(b) Restrict the use of RDP in computers;

(c) Apply the least privilege principle to the account(s) that can remotely access the computer. Do not grant the administrator right unless necessary;

(d) Use strong passwords and change password frequently;

(e) Implement account lockout policy to lock out account after a set number of failed login attempts;

(f) Restrict only specific IP(s) to access the RDP-enabled computers; and

(g) Limit the time period allowed for remote connection.

 

Reference:

Secure the Remote Desktop Services (RDP) for Preventing Ransomware Attack!

https://www.hkcert.org/my_url/en/blog/17110901

CrySIS/Dharma-variant .arena Ransomware Encrypts Victim Data

https://www.hkcert.org/my_url/en/alert/17102401

 

(14/11/2017) Beware of Bad Rabbit Ransomware Spreading

A new variant of ransomware known as "Bad Rabbit" – delivers through a compromised website, tricking a user to download and install a seemingly legitimate but malicious software to infect a computer. It can spread through other vulnerable computers in the same network by using the same technique as PetrWrap (i.e. leverage of the legitimate Windows Management Instrumentation (WMI) service). Users/ Administrators are advised to review and take the following preventive measures to protect the computers of your school from ransomware attacks :

 

1. To protect your computer against the ransomware attacks, every computer user should take the following actions:

(a) Backup important data frequently and keep the backup data disconnected from the computer;

(b) Use strong passwords and change the passwords regularly;

(c) Do not open any suspicious emails, attachments and hyperlinks;

(d) Refrain from visiting suspicious websites or downloading any files from them; and

(e) Check and keep your anti-malware program and signatures up-to-date.

 

2. For network/system administrators, the following preventive measures are advised:

(a) Disable WMI services on computers if they are not necessary for the users;

(b) Block RDP protocol access from the Internet if the access is not necessary; otherwise, apply additional protection, such as VPN and multiple-factor authentication for the access;

(c) Ensure timely patching of computer systems against known vulnerabilities; and

(d) Avoid granting administrative privileges to end users.

 

3. In case a computer is infected, users should take the following IMMEDIATE actions:

(a) Disconnect the network cable of the computer to avoid affecting network drives and other computers; and

(b) Power off the computer to stop the ransomware from encrypting more files.

 

Please refer to the HKCERT alert at URL: https://www.hkcert.org/my_url/en/blog/17102501 to take measures to prevent your network from infection and data loss.

 

(19/10/2017)  WiFi Protected Access II (WPA2) Multiple Vulnerabilities (KRACK)
Multiple vulnerabilities were identified in WiFi Protected Access II (WPA2) which could allow an attacker to conduct a key reinstallation attack (KRACK) on targeted devices that use WiFi. An attacker could decrypt the data or even conduct data tampering in the wireless connection.

 

For details, please visit HKCERT website URL: https://www.hkcert.org/my_url/en/alert/17101701
(28/06/2017)  Beware of Petwrap / NotPetya Ransomware spreading
Please take note to the message from Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT):

 

A new variant of ransomware known as Petwrap / Petrwrap / Petya / NotPetya / Nyetya is spreading quickly. It encrypted victims’ data file and demand for ransom. Some overseas countries were hit. The different names of the ransomware indicate that there is a debate among security experts on where this ransomware is directly related to another known ransomware Petya.

 

The ransomware can be spread via phishing email or via local network.

 

An infected computer uses two methods to attack computers on local network. It uses the EternalBlue exploit previously employed by the WannaCry ransomware to attack computers that have not applied the SMB patch (MS17-010). It also tries to force computers in the local network that it has administrative rights to install the malware.

 

HKCERT likes to alert organizations to take measures to prevent your network from infection and data loss. The centre had issued security alert on the ransomware. Please refer to this URL: https://www.hkcert.org/my_url/en/alert/17062801
(16/05/2017)  How to get an update through Windows Update
For details, please visit Microsoft website URL: https://support.microsoft.com/en-us/help/3067639/how-to-get-an-update-through-windows-update
 (15/05/2017)  Tackling Ransomware and Related Seminar on 17 May 2017

1. A new variant of ransomware known as "WannaCry" (WannaCrypt) is spreading quickly, through a Windows SMB vulnerability (EternalBlue and DoublePulsar). HKCERT was aware that there is a widespread overseas and advised to adopt the attached precaution measures.

(Click here to download the precaution measures in both Chinese and English)

 

2. AiTLE is working with a number of stakeholders, including HKCERT, Microsoft and EDB, to organise a seminar on tackling ransomware for schools. 

Information of the seminar are as follows:

Date : 17 May 2017 (Wednesday)

Time : 5:00 pm - 7:00 pm

Venue : Lecture Theatre, 4/F, West Block, Kowloon Tong Education Services Centre, 19 Suffolk Road, Kowloon Tong

 

Speaker's presentaion slides and notes are as follows: 

 

3. In order to raise public awareness on information and cyber security, the OGCIO recently produced two infographics titled as "Beware of Ransomware Infection" and "Secure Your Home Network Devices" which help to remind your teachers and students to take necessary precautions against ransomware attacks. Schools may download the softcopy of the two infographics from the website at http://www.cybersecurity.hk/tc/resources.php.

 

4. For recommended practices for information security in schools, please refer Information Security in Schools - Recommended Practice.

 

5. Should you have any enquiries regarding handling the issue, please contact the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) by e-mail to hkcert@hkcert.org or by phone on 8105 6060. Besides, you are welcome to contact our technical advisory team at 3698 3594 / 3698 3574 / 3698 3566 / 3698 4148.

(20/02/2017) Infographics from Office of the Government Chief Information Officer (OGCIO)
OGCIO: Infographics on "Beware of Ransomware Infection" and "Secure Your Home Network Devices"
(13/05/2016) Protect Mobile Devices from Ransomware Attacks

Ransomware hits mobile devices and is on the rise. An information security vendor detected 2 896 mobile ransomware programs in Q1 2016, which is 1.4 times of the figure in Q4 2015. The trend is that ransomware attacks keep growing at personal computers (PCs) while spreading rapidly to mobile devices. Facing the trend, every government mobile device user and administrator shall be well aware of the threats and take actions to protect their mobile devices, in addition to protecting their PCs.

 

Ransomware Threats to Mobile Devices

Similar to the threats to PCs, ransomware locks down mobile devices or encrypts data stored in and connected to the devices to defy user access. Payments are then demanded from the users to release the access. Mobile devices could get infected with ransomware in the following ways:

  • Download and install mobile apps that are embedded with ransomware;
  • Open attachments or click links in phishing emails;
  • Click malicious links in or open specially crafted SMS, MMS and instant messages; or
  • Click on a compromised website to trigger a "drive-by" download of ransomware.

 

Impact

Once ransomware infects a mobile device, it sends a fingerprint of the ransomware app, the IMEI or the device’s phone number to a command and control (C&C) server. The C&C server sends back an encryption key for the particular device by which the device can be locked or files on the device can be encrypted. The user would suffer from total denial of access to the mobile device until a factory reset is taken but all data would be lost unless timely backup is available.

 

Recommended Actions

Users and administrators should take the following preventive measures:

 

Users

 

 

Android

iOS

Windows Phone

BlackBerry

 

Data Backup

  • Back up data frequently through the backup software provided by the phone manufacturer.
  • Keep the data backup disconnected from mobile devices.
  • Back up data frequently through iTunes.
  • Keep the data backup disconnected from mobile devices.
  • Back up data frequently through Windows Explorer of Windows 7 or File Explorer of Windows 8 and Windows 10.
  • Keep the data backup disconnected from mobile devices.
  • Back up data frequently through BlackBerry Desktop Software.
  • Keep the data backup disconnected from mobile devices.

 

Apps Security Controls

  • Do not "root" your device to override usage and/or access limitations.
  • Install apps from Google Play Store only.
  • Do not install the app if suspicious permission rights are required.
  • Disable "installation of apps from unknown sources" feature.
  • Enable the "Verify apps" features to check apps when you install them and periodically scan for potentially harmful apps.
  • Do not "jailbreak" your device to override usage and/or access limitations.
  • Install apps from Apple App Store only.
  • Do not install app if suspicious permission rights are required.
  • Install apps from Microsoft Store only.
  • Do not install the app if suspicious permission rights are required.
  • Do not "root" your device to override usage and/or access limitations.
  • Install apps from BlackBerry World only.
  • Do not install the app if suspicious permission rights are required.

 

Security Solutions and Patching

  • Install anti-malware app.
  • Check and keep your anti-malware app and signatures are up-to-date.
  • Install the latest patches for apps and operating system in use.
  • Install the latest patches for apps and operating system in use.
  • Install anti-malware app.
  • Check and keep your anti-malware app and signatures are up-to-date.
  • Install the latest patches for apps and operating system in use.
  • Install anti-malware app.
  • Check and keep your anti-malware app and signatures are up-to-date.
  • Install the latest patches for apps and operating system in use.

 

Web Browsing

  • Enable "Safe Browsing" in Chrome to avoid visit known phishing and malicious sites.
  • Enable blocking of pop-ups.
  • Enable "Fraudulent Website Warning" in Safari to avoid visit known phishing and malicious sites.
  • Enable blocking of pop-ups.
  • Enable "SmartScreen" features in Internet Explorer to avoid visit known phishing and malicious sites.
  • Enable blocking of pop-ups.
  • Enable blocking of pop-ups in BlackBerry Browser.

 

User Practices

  • Do not open any suspicious emails and its attachments.
  • Do not click URL links or open attachments in SMS, MMS, instant messages, or emails from untrusted or suspicious origin.
  • Refrain from visiting suspicious websites or downloading any files from them.

 

Administrators

For B/Ds with mobile device management, the administrators are advised to deploy policy controls to:

(a) Whitelist permitted mobile apps to block unauthorized apps from installation;

(b) Push anti-malware apps installation and update;

(c) Restrict users to download from permitted apps stores only; and

(d) Enforce browser security settings, including anti-phishing and blocking pop-ups.

 

If the mobile device is infected, the user should:

(a) Shut down the device immediately;

(b) Report the case to DITSOs or ISIRTs;

(c) Jot down what have been accessed before discovering the issue;

(d) Remove the SIM card and removable storage media (if applicable) before turning on the device to avoid spreading the malware through mobile network; and

(e) Report to the Police for investigation.

(13/05/2016)  Protect Internet-facing Systems against Unauthorised Administrative Access

The administrative interface (or admin interface) of a system is a usual point of attack by intruders who intend to gain administrator privilege for taking total control of the target system. Exposing the admin interface to the Internet is therefore a risky option. All administrators of Internet-facing systems shall take actions to protect their systems against unauthorised administrative access. The following actions are recommended:

 

(a) Minimise exposure of the admin interface to the Internet

Remote administration through the Internet is generally of higher risk than through the trusted internal network or local console administration. Some admin interfaces may be enabled by default configurations. The administrators should:

  • Examine if any admin interface is enabled and accessible from the Internet; and
  • Disable the admin interface from Internet access if not needed.

 

(b) Step up protection of the admin interface with operational needs

If the operational needs justify the Internet-accessible admin interface, the administrator should step up protection of the access as suggested:

  • Deploy a virtual private network (VPN), such as SSL-VPN for accessing the admin interface;
  • Enforce a strong password policy, such as password complexity, lockout after retries and password aging, or even a two-factor authentication against brute-force password attacks;
  • Restrict only specific host IP addresses for accessing the admin interface and time-limit the access;
  • Rename or revoke default accounts of the admin interface system;
  • Enforce the principles of least privilege and segregation of duties; and
  • Regularly monitor the access or account activities on admin accounts.

 

You are strongly advised to consult and liaise with the technical support of the system(s) operated by your School to review the relevant system and take necessary actions to enhance protection of administrative interface as appropriate.

(14/04/2016) Urgent Updates to fix Multiple Vulnerabilities in Adobe Flash Player

As informed by OGCIO, there are reports that the vulnerability in Adobe Flash Player is being exploited to spread ransomware. Please ensure the Adobe Flash Player and other software, in particular the Anti-virus software, installed at your desktop and notebook computers, are always updated with the latest version. You may wish to go to the official page of Flash Player (https://helpx.adobe.com/flash-player.html) and click "Check Now" button in Step 1 at the above link to check whether the Adobe Flash Player installed at your computer is the latest version. If not, please follow the instructions to download the latest version of Flash Player in Step 2.

(12/04/2016)  Tackling Ransomware

Recently, there are public concerns over IT security in schools, in particular ransomware intrusion via emails. On opening attachments or hyperlinks from fake emails, users may get their workstations infected with the ransomware programs which will encrypt files in their local folders as well as network shared folders that they can gain access to. Hackers will then ask for ransom money for providing a key to decrypt the files. Users would no longer be able to read/open the encrypted files without a decryption key, and the way to salvage the files is to recover them from offline backup. As currently anti-virus software may not be able to detect such intrusion, prevention is of utmost importance. You may wish to know that IT in Education Section has prepared the "IT Security in Schools - Recommended Practice" to help schools handle their general security matters. The document is available on our website (http://www.edb.gov.hk/ited/wifi900) and also attached below for your reference.

 

In relation to the latest ransomware case, schools are advised to take following suggested actions:

(a) BACKUP important data frequently and keep the backup data disconnected from the computer;

(b) DISABLE macros for Microsoft Word, Excel and other office applications by default;

(c) DO NOT open any suspicious emails, attachments and hyperlinks;

(d) REFRAIN from visiting suspicious websites or downloading any files from them;

(e) CHECK and KEEP your anti-malware program and signatures are up-to-date;

(f) INSTALL the latest patches for software in use;

(g) DO NOT connect unauthorised computer resources, including those privately-owned removable storage media, to computers; and

 

In case of suspected infection:

(a) DISCONNECT the network cable of the computer to avoid affecting network drives and other computers;

(b) POWER OFF the computer to stop the ransomware encrypting more files;

(c) JOT DOWN what have been accessed (such as programs, files, emails and websites) before discovering the issue; and

(d) REPORT the case to relevant personnel / organisation, such as ICT coordinator in school, HKCERT, HK Police, etc.