We have a counselor, who used to be an 8th grade teacher, asking for their own google classroom. I've moved into the security facing side of IT for our district and things I read from CISA and reviewing NIST lend me the strong argument that this would be an abuse of google classroom functionality, and open a whole can of worms for staff to request their own classrooms to communicate with students. This counselor wants the entire 8th-grade list of students in one classroom so they can post polls, distribute information, utilize the assignment features, etc. (I first went down the path of WHY they need it - can they just email pdfs, or is there more to it? since we already have distribution groups by grade level, etc.)
The teacher-gone-counselor is tech-savvy and I believe GClassroom could be a benefit, but having all those students in a single Google classroom concerns me. What if this staff member's account was compromised, or their device was compromised, due to negligence while they step out of the room, etc? All of our Google classrooms sync with our Student monitoring solution (Aristotle K12) and it could be a serious disaster too if that were triggered mid-day, ending all other 8th-grade teachers' sessions if he started his own, etc.
I guess another wound here is the "Well they got access, why can't I?" mentality if we give it to one staff member who is not in a teaching role. I don't even know if Google has guidelines prohibiting Classroom use when not in a teacher role - but I wanted to reach out here and see if anyone has some suggestions or concerns about this.
We do NOT have MFA enabled yet - but it is on the docket. I have not had any help getting MFA pushed out to staff or getting any of the higher-ups to solidify a plan or even have a worthwhile discussion about MFA yet.
Am I being too paranoid about the security side of things - or is there really no such this as being too paranoid about having great security, while still focusing on convenience for our end users?