Victoria’s Department of Education is installing Zscaler on students’ devices. The device is installed to monitor internal traffic from staff to students at several schools. However, it will not be implemented when students are using their devices from home.
Zscaler SSL root certificate is not only install on school devices but also student’s devices if they connect locally to the school network. Talking to iTnews a department spokesperson said that Zscaler monitoring will stop if students connect to the school network from home.
The spokesperson said, “The Department uses the Zscaler application on all Department-owned computers and devices as part of cloud-based security measures when accessing the internet. This certificate acts as an extra safety measure by helping to determine if a website is safe to open while using the school’s internet.”
He further added that it is the responsibility of the department to prioritize staff and student health. This means protecting them online.
Protect against the deliberate or accidental transmission of confidential data
Zscaler ensures web browsing and online activity protection and detects malware hiding in HTTPS traffic. Moreover, Gartner principal analyst Bjarne Munch believes the increase in remote working has led to an increase in cloud-based applications. These applications require permanent security solutions.
He added, “To gain better control on who can access specific applications and have access to various types of Internet content we are now also seeing an increased focus on zero trust network access, as this enables individual security policies.’’
NSW Department of Education
Likewise, the NSW Department of Education also uses Zscaler’s SSL inspection. However, not on devices at school but to inspect at home. As part of Covid locked down, NSW Department entered into contract to use Zscaler’s private access network in 2020. Under this contract, the corporate staff connects to the Department’s network remotely.
NSW Department of Education spokesperson said, “ZPA records user access activity, in accordance with cyber security best practice. When corporate users access the corporate environment remotely.’’

