IFS Data Owner and Data Project Manager Guidance
Data Owner Responsibilities
Administrative oversight of department’s IFS licence
Provide a Purchase Order for IFS costs upon the renewal date
Appoint Data Project Managers for all the drives within the Department IFS licence
And notify CSCS to ensure new Data Project Managers are recorded and any training/handover provided
Receive email warnings as maximum capacity reached
Extend storage capacity in the IFS Self-Service Portal by providing a PO
Annual review of Data Project Manager/s to ensure they are correct.
Ensure that data storage chosen meets data classification requirements per https://help.uis.cam.ac.uk/service/security/data-sec-classes
If also acting as Data Project Manager, the “Data Project Manager Responsibilities” listed below equally apply
Data Project Manager Responsibilities
Ensure that data access is provided only to authorised users and those with UMD or Assured computers
Submit requests to CSCS to add/remove access, or administer oneself via Toolkit
Identify additional security groups that may be required and requesting them from CSCS
Ensuring that data in the drive is stored appropriately (according to data classification policy below)
Responding to alerts if drive is possibly running out of space
Annual review of users who have access to data to ensure that it is correct.
Data Owners and Data Project Managers have access to a report of all of their managed Group drives and Security groups. They can access it by going to their Halo home portal, select My reports and open the Group drive(s) on the list.
IFS Cost
IFS is paid for on a per TB basis. 1TB is £150 per year and will be billed to each department. When the renewal comes up each Data Owner will receive an email with information about paying for the licence and data.
IFS Data Quota
Data storage is purchased on a per TB basis. If your IFS drive gets close to its quota, the drives Data Project Manager, and licence Data Owner, will receive an email to that effect. You can instruct your users to do some housekeeping, or increase the space by going to this page https://selfservice.uis.cam.ac.uk/storage/IFS/
Data Classification Guidelines
Data should always be stored in accordance to the University’s https://help.uis.cam.ac.uk/service/security/data-sec-classes. IFS is suitable for Medium impact level 2 data.
IFS Self-Service Portal
Data Owners can access their licence(s) here https://selfservice.uis.cam.ac.uk/account/. In most cases, members of CSCS are added as Data Managers on licences to provide support for IFS drives. If we are removed then this will limit what support we can provide. If a department doesnt want CSCS to assist with the licence, that is fine, just let us know and we can update our records.
New Group Drives
To set up a new IFS drive, the Data Owner of the licence or the Data Project Manager for the new drive should contact CSCS. While Data Owners could create drives via the IFS portal, this misses out crucial steps in setting up and securing the drive. CSCS can do all this for you.
What Data Owners must do - make sure there is sufficient unallocated space on the licence before submitting the request to CSCS. You may need to purchase more space before a drive can be created (whoever creates the drive).
Permissions Models - Securing Your Data
When a drive is created, everyone with access to the drive (that is, the list of users provided to CSCS during its creation) can access everything on the drive.
It is possible to limit folders to specific users. CSCS refer to this as 'Secured Folders'. This means that certain folders can be locked down so only certain people who already access the drive can access the folder. This is only done at the top level, that is, the first list of folders one sees when opening a drive. CSCS does not support folder restrictions any further down the folder structure.
If there are to be lots of restricted folders, especially where the same people will have access, it may be better (and simpler where permissions are concerned) to have a new IFS drive created. The restricted data can be moved to this new drive and the drive can be restricted to only those who need access. This far simplifies permissions and makes it easier to administer.
Resizing Drives
Drives can be resized via the IFS Portal by the Data Owner or CSCS. If increasing the size of a drive, make sure there is sufficient unallocated space. The Data Owner may need to purchase more space before a drive can be made bigger.
If decreasing the size of a drive, the unallocated space can remain in the licence for future use, or can be removed completely. Removing it would reduce the cost of the licence when the renewal comes around. However, it would mean having to purchase more space if creating or increasing drives, so it’s best to be sure that the unallocated space is not going to be needed before removing it.
Deleting Drives
Data Owners can delete drives via the IFS portal, however this only deletes the share the data sits on, it does not remove all the extra parts that make up the IFS drive. Therefore, if Data Owners do delete drives themselves, please inform CSCS so we can remove the rest of the configuration and update our records. Data Owners can also request CSCS to carry out the whole removal process as long as CSCS has access to the licence.
Whoever deletes the drive, be sure that the data has been backed up elsewhere or is not needed before progressing as the data will not be recoverable.
Granting access to IFS data
Access to IFS drives should only be granted where the user is using a UMD or assured computer (one that CSCS has assured or is managed by another IT department).
It is the responsibility of the Data Owner or Data Project Manger (whichever is giving the access) to ensure only people who have a UMD or Assured computer are given access to IFS data.
CSCS can add access - Data Owners or the drives Data Project Manager can submit the Group Drive Access form. Users will not be able to request their own access.
Data Owners can add or remove Data Project Managers from a drive using the Add/Remove Data Project Manager form.
Data Owners and Data Project Managers can add users to drives as well by adding them to the corresponding security group. This process will have been demonstrated when Data Project Managers were added to drives when data was first moved to IFS and will be part of a handover when new Data Project Managers are added. If you would like a refresher, just contact the Service Desk.