By Brett Winterford on Sep 23, 2009 twelve:36 PM
Filed beneath Safety
The world's "most hostile computing environment".
The NSW Section of Education is employing asset-tracking computer software, RFID tags, and BIOS-embedded filtering smarts to roll out 240,000 netbook pcs into what CIO Stephen Wilson calls "the most hostile setting it is possible to roll personal computers into" - the neighborhood substantial school.
The rollout of Lenovo netbooks, funded under the Federal Government's Digital Training Revolution initiative, is often a massive logistical and IT safety challenge, as well as the solution Wilson and his group has put collectively to fix these issues could properly be applicable to any company IT division.
Over 4 many years,
Microsoft Office Pro 2007, some 240,000 Lenovo netbooks is going to be presented to college students in year 9. The netbooks could be stored right up until 12 months 12, or permanently need to the pupil end his / her research on the school. Netbooks can also be being offered to teachers.
To get receipt from the netbooks,
Windows 7 License, students and dad and mom are asked to sign kinds by which they acknowledge their obligation to take care of the machines and rely on them appropriately.
They are armed with the enterprise edition in the new Windows 7 running system, Microsoft Workplace,
Office 2010 Activation, the Adobe CS4 imaginative suite, Apple iTunes, and material geared to college students. Although the netbooks are loaded with many a huge selection of dollars of application, 2GB RAM and a six-hour battery, the cost to the NSW Department of Training is less than $500 a unit.
Underneath the covers in the netbooks - and within the network that controls them - lies a great deal more smarts to ensure that the total cost of ownership of each machine does not blow out.
Wilson said that while private schools and other states have taken a "carte blanche" approach to handing out laptops as part with the Digital Education Revolution, the DET rollout is "among the more systematic, automated and paperless" projects ever embarked upon.
Security smarts
At the physical layer, each netbook is password-protected and embedded with monitoring software program on the BIOS level of the machine.
That is administered through an enterprise services bus, which also connects the Remedy suite for asset management,
Windows 7 Pro, Active Directory for authentication and Aruba's Airwave for wireless network management.
If a netbook were to be stolen or sold, the section can remotely disable it above the network. Even if the hard drive in the machine was swapped out or the running program wiped, it would be useless to unauthorised users.
Already, it has noted the loss or damage of just six netbooks out of the 20,000 rolled out since August - and have tracked a teacher utilizing their device on a field trip in New Zealand.
While there is really a serial number and barcode on each computer, the division said that thieves or students might be able to remove them. To combat this,
Office Professional Plus 2007 Key, it is making use of passive RFID chips on every machine that will enable them to be identified "even if they were dropped in a bathtub".
Being passive, an RFID reader needs to be within close proximity in the device to read it. (Active RFID transmitted a signal back to base.)
The section used the AppLocker functionality within Windows 7 to dictate which applications are installed.
Web access on the netbooks is filtered according to a corporate protection policy (utilizing McAfee's SmartFilter technology) plus an additional SOCKS-based proxy client, which provides web filtering with the network layer.
The devices also use Microsoft's Forefront Antivirus technology.
Upgrades
With such a huge fleet of pcs in the hands of pupils, Wilson said it would be "unrealistic" for the department to offer technical support for software applications.
The netbooks were built so that the section can remotely upgrade and patch the devices above a wireless network.
It used Microsoft's Technique Centre Configuration Manager tool to distribute software down to devices.
The update service switches off once a college student finishes 12 months 12.
Wilson said there was no way such a large fleet of machines could be managed at such low cost without the smarts embedded within Microsoft's new operating technique.
"There was no way we could do any of this on XP," he said. "Windows 7 nailed it for us."