REMC1 Standards - Google Gemini licensing FERPA and Cybersecurity

Version 7.1 by Josh Hiner on 2024/06/28 11:20

WARNING: Google Gemini is only FERPA compliant if you have Google Ed Workspaces and pay for a license.

  • Gemini free version is NOT TO BE ENABLED in any remc1 google workspaces (remc1.net, remc1.org or any other in the future).
  • Furthermore no REMC1 org data is to be fed into any employee’s personal gemini free access or anyone else’s Gemini instance (outside REMC1’s licensed FERPA safe enabled Gemini). Gemini free is currently disabled in remc1.org and can only be enabled if you have a license to utilize Gemini along with group membership (see below/next section).
  • The free version sifts through all your email and documents sucking the data into its public database.
  • Create a burner personal account if you want to use Google Gemini. Dont use it with your normal Google Email either unless you want it to suck all your emails and drive documents into the public database (including banking, HIPAA, FERPA, PII info etc..) everything then have it cranked out to other public who ask gemini questions. There are people/bad actors who craft questions to try and reveal/pull this info back out etc.. Its an identity theft attack vector.
  • Here is the REMC1 official template response to Gemini requests - Accurate as of May 2024. Inquiry pending to Google for Ed licensing.

How Gemini is Enabled for remc1.org staff (only with an assigned license)

  • June 2024: We have three Gemini licenses all assigned to Josh, Steve, Hayley
  • Currently its enabled via a security group called GeminiEnable
  • This group is setup through the admin console NOT groups.google.com. You cannot use a groups.google.com group to control services it has to be added in the admin console (as of June 2024 -JDH)
  • Here are the steps utilized to enable. ALSO… I went to admin->clicked on the apps waffle->Gemini->User Access (right hand square pane)->Groups section (middle left pane, click on the arrow by groups), Now select GeminiEnable, Now notice this is where I enforce the setting to ONLY ALLOW USERS WITH A GEMINI LICENSE. This way if someone gets happy and adds more individuals WITHOUT licensing they still wont be able to enable Gemini and feed all remc data into the public engine.
  • Ok Here are the steps utilized to enable the service via the GeminiEnable group
  • For this step, you need admin privileges for Groups, Organizational Units (top-level), and Service Settings. Learn more about Administrator privilege definitions.
    1. In your Google Admin console (at admin.google.com)...
    2. Go to Menu ->apps

      https://storage.googleapis.com/support-kms-prod/ocGtUSENh4QebLpvZcmLcNRZyaTBcolMRSyl

       Apps.

    3. Click the type of service: Google Workspace
    4. In the Groups section, find and select your group (in this case GeminiEnable)
      • To view the list of access groups, click Search for a group.
      • Search by group name or address.
        If you don’t find your group, it might be a group created in Google Groups, which can't be used as an access group.  
    5. On the right, point at the row for the service.
      • To turn on access, click Turn On.
      • To remove access for the group, click Unset. Now, users get the access setting of their organization. However, if the users belong to any other access group with the service turned on, they continue to have access to the service.
      • To set multiple services, check the box for each service and click On or Unset in the upper right. 

        Click the Groups list on the left Find  the Turn On link next to an app

      • Changes can take up to 24 hours but typically happen more quickly. Learn more

REMC1 June 2024 Google Gemini Order

  • Amusingly enough Mike Richardson is still listed as the contact. I’ll have this fixed for our next CDW order