Cyber Security

Cyber Security Awareness Month

Cyber Security FAQ

Frequently asked cyber security questions and how TASS keeps your school's data secure.
Data Security 3

Staying Cyber Resilient

How does TASS keep your school's data secure?

At TASS, we take cyber security seriously, and for good reason. In today's digital age, safeguarding your school's data and privacy is vital. We understand the importance of keeping your data secure, and that's why we go the extra mile to ensure your peace of mind. Continue reading for some frequently asked questions about how TASS keeps your data safe and some other industry tips and tricks on cyber security.

Cyber Security

Frequently Asked Questions

Who is responsible for the security and setup of staff accounts?

Your school is responsible for maintaining TASS and its users. To ensure secure access to your TASS system, we recommend reviewing permissions and access points regularly. We also recommend disabling accounts as soon as possible when staff, students, or parents leave the school.

When it comes to managing user permissions in TASS, there can be a lot to unpack. We have linked some resources to learn more about applying security permissions in TASS.web and Portal Security Permissions for the Staff Portal.

How do we control what users can and can’t see in our TASS system?

Within TASS, permission groups can be created for the different products and define permissions for individual users or groups of users. This ensures that only authorised staff can access relevant data to them. Your school is responsible for managing the users and user permissions within the software.

TASS also has a built-in audit system and change logs for your peace of mind.

What happens to our school’s data if there is a disaster or unexpected event that results in data loss?

If your system is self-hosted, the data backups are managed by your school. However, if you are a TASS Cloud customer, disk images are taken daily and backed up for 30 days, and database backups are taken daily and stored for 365 days. If your school needs to recover its TASS system from a backup and is hosted with TASS Cloud, the maximum expected data loss is 24 hours.

I want to do some testing within our TASS system but don’t want to risk using live data, what can I do?

A common practice that many schools have in place is a test or development instance of TASS. This allows users to test the product without running the risk of altering any live student or school data. If you would like to learn more about test environments, click here or reach out to our Technical Services team.

What industry compliance standards does TASS comply with?

TASS has been certified against ISO27001 since 2021, and in 2024, we were re-certified to the latest 27001:2022 standard. TASS undergoes annual external audits, and internal audits are conducted via an internal audit schedule.

In the event of a security incident, how does TASS act on the issue and respond to customers?
TASS maintains internal policies and procedures, such as a Disaster Recovery Plan, a Business Continuity Plan, and an Incident Response Procedure, which details our methods for managing incidents. TASS engages with the school in a way that is appropriate for the particular incident, typically via a phone call or by submitting a ticket.
If there is an issue with our system, such as unexpected downtime or hardware resources, how does TASS assist with this process?
If your school operates a self-hosted system, the school itself manages all associated infrastructure. For TASS Cloud customers, the Technical Services team receives infrastructure alerts for CPU, disk usage, DNS, and other monitoring tools. Internal ticketing alerts are sent to the TASS Cloud team, enabling us to offer timely and proactive support to schools. Additionally, TASS Cloud customers benefit from extra support for cloud infrastructure beyond regular business hours.
What can we do to ensure our key staff are well equipped for Cyber Security?

As a large portion of data incidents can be traced back to human error, ensuring your staff understand cyber security can be one of your most important lines of defence. When it comes to upskilling your staff with TASS-specific security, our Professional Services team can offer tailored training sessions for system administrators. For general cyber security tips and tricks, there is a sea of information out there; check out our blog, where we recap some of our top resources!

We are a TASS Cloud customer, where is our data hosted?

At TASS, we utilise Amazon Web Services (AWS) for our cloud hosted customers. Your school data is hosted locally on AWS Servers located in Sydney, Australia.

Hosting made breezy!

TASS Cloud Hosting

Cloud Hosting Services provides a fully managed, secure platform for running your school's critical TASS system. 

TASS is certified against the world's best-known cyber security standard, ISO27001:2022, For information security management systems and provides active monitoring and maintenance by a team of TASS experts.

Cloud Hosting Services is offered across four tiers, to allow you to select the environment that matches your school's operating requirements. To learn more about TASS Cloud Hosting, click the link below!

Cloud-Header