Wiki source code of REMC1 Standards - Google Gemini FERPA and Cybersecurity
Version 3.1 by Josh Hiner on 2024/06/27 09:16
Hide last authors
| author | version | line-number | content |
|---|---|---|---|
| |
3.1 | 1 | {{toc/}} |
| 2 | |||
| 3 | = {{id name="WARNING:-Google-Gemini-is-only-FERPA-compliant-if-you-have-Google-Ed-Workspaces-and-pay-for-a-license."/}}WARNING: Google Gemini is only FERPA compliant if you have Google Ed Workspaces and pay for a license. = | ||
| 4 | |||
| 5 | * The free version sifts through all your email and documents sucking the data into its public database. | ||
| 6 | * Create a burner personal account if you want to use Google Gemini. Dont use it with your normal Google Email either unless you want it to suck all your emails and drive documents into the public database (including banking, HIPAA, FERPA, PII info etc..) everything then have it cranked out to other public who ask gemini questions. There are people/bad actors who craft questions to try and reveal/pull this info back out etc.. Its an identity theft attack vector. | ||
| 7 | * Here is the REMC1 official template response to Gemini requests - Accurate as of May 2024. Inquiry pending to Google for Ed licensing. | ||
| 8 | ** [[https:~~/~~/docs.google.com/document/d/1Y7O1Yxe9FwbC68NXJBgpq29WhRf-9EJXQAbzJFYdSGI/edit>>url:https://docs.google.com/document/d/1Y7O1Yxe9FwbC68NXJBgpq29WhRf-9EJXQAbzJFYdSGI/edit||data-card-appearance="inline" shape="rect"]] | ||
| 9 | |||
| 10 | = {{id name="How-Gemini-is-Enabled-for-remc1.org-staff"/}}How Gemini is Enabled for [[remc1.org>>url:http://remc1.org||shape="rect"]] staff = | ||
| 11 | |||
| 12 | * June 2024: We have three Gemini licenses all assigned to Josh, Steve, Hayley | ||
| 13 | * Currently its enabled via a security group called GeminiEnable | ||
| 14 | * This group is setup through the admin console NOT [[groups.google.com>>url:http://groups.google.com||shape="rect"]]. You cannot use a [[groups.google.com>>url:http://groups.google.com||shape="rect"]] group to control services it has to be added in the admin console (as of June 2024 -JDH) | ||
| 15 | * Here are the steps utilized to enable. ALSO… I went to admin->clicked on the apps waffle->Gemini->User Access (right hand square pane)->Groups section (middle left pane, click on the arrow by groups), Now select GeminiEnable, Now notice this is where I enforce the setting to ONLY ALLOW USERS WITH A GEMINI LICENSE. This way if someone gets happy and adds more individuals WITHOUT licensing they still wont be able to enable Gemini and feed all remc data into the public engine. | ||
| 16 | * Ok Here are the steps utilized to enable the service via the GeminiEnable group | ||
| 17 | * For this step, you need admin privileges for Groups, Organizational Units (top-level), and Service Settings. Learn more about [[Administrator privilege definitions>>url:https://support.google.com/a/answer/1219251||shape="rect"]]. | ||
| 18 | (% start="1" %) | ||
| 19 | *1. In your Google **Admin console** (at [[admin.google.com>>url:http://admin.google.com||shape="rect"]])... | ||
| 20 | *1. ((( | ||
| 21 | Go to Menu ->apps | ||
| 22 | |||
| 23 | |||
| 24 | |||
| 25 | [[ ~[~[Apps~>~>url:https://admin.google.com/ac/apps~|~|shape="rect"~]~].>>image:url:https://storage.googleapis.com/support-kms-prod/ocGtUSENh4QebLpvZcmLcNRZyaTBcolMRSyl||custom-width="true" original-height="24" src="https://storage.googleapis.com/support-kms-prod/ocGtUSENh4QebLpvZcmLcNRZyaTBcolMRSyl" data-xwiki-image-style-alignment="center" width="250" original-width="24"]] | ||
| 26 | ))) | ||
| 27 | *1. Click the type of service: **Google Workspace** | ||
| 28 | *1. In the **Groups **section, find and select your group (in this case GeminiEnable) | ||
| 29 | *1*. To view the list of access groups, click **Search for a group**. | ||
| 30 | *1*. Search by group name or address. | ||
| 31 | If you don’t find your group, it might be a group created in Google Groups, which can't be used as an access group. | ||
| 32 | *1. On the right, point at the row for the service. | ||
| 33 | *1*. To turn on access, click **Turn On**. | ||
| 34 | *1*. To remove access for the group, click **Unset**. Now, users get the access setting of their organization. However, if the users belong to any other access group with the service turned on, they continue// //to have access to the service. | ||
| 35 | *1*. ((( | ||
| 36 | To set multiple services, check the box for each service and click **On **or **Unset **in the upper right. | ||
| 37 | |||
| 38 | [[image:url:https://storage.googleapis.com/support-kms-prod/m9V2zwjURYzmpV0LnR9rXu2pmKZRIC6vQ2HX||custom-width="true" original-height="157" src="https://storage.googleapis.com/support-kms-prod/m9V2zwjURYzmpV0LnR9rXu2pmKZRIC6vQ2HX" data-xwiki-image-style-alignment="center" alt="Click the Groups list on the left " width="250" original-width="320"]][[image:url:https://storage.googleapis.com/support-kms-prod/QCqT5l1Ss152u4gv4xN6t0scTtCKBvXlhQ7u||custom-width="true" original-height="157" src="https://storage.googleapis.com/support-kms-prod/QCqT5l1Ss152u4gv4xN6t0scTtCKBvXlhQ7u" data-xwiki-image-style-alignment="center" alt="Find the Turn On link next to an app" width="250" original-width="331"]] | ||
| 39 | ))) | ||
| 40 | *1*. Changes can take up to 24 hours but typically happen more quickly. [[Learn more>>url:https://support.google.com/a/answer/7514107||shape="rect"]] |