When it comes to cybersecurity readiness, McKaveney presented five questions that small districts and those with limited staffing and budgets should answer. - Do we know what we have, what data we protect and where our biggest risks are? - Are we using basic protections that prevent the most common attacks? - Would we notice if something went wrong? - What do we do if a cyber incident happens tomorrow? - Could we recover learning and operations quickly after an incident or other disaster? Identify Cyber Inventory and Risks CoSN guidance recommends starting with an asset inventory and risk assessment to ensure cybersecurity efforts are directed properly to maximize investments. This could be as simple as a list on a spreadsheet or identifying assets via helpdesk software, McKaveney said. DISCOVER: K–12 schools need a roadmap for effective cybersecurity. Richard Platts, CTO of Allegheny Intermediate Unit in Pennsylvania, said data inventory is just as important as hardware and software inventory. Governance and ownership are a large piece of that. Data ownership is a three-tier system, he said. “Think about your your IEP [Individualized Education Program] management software,” he said. “I've always insisted that that data owner is the special education director. It's a named person who owns that data. They might not do the daily maintenance of that data or the data entry, but at the end of the day, they're responsible for the overall quality of that data to be able to provide services to students.” The next tier down are the data stewards, the people responsible for the maintenance and fitness the data, typically the IT team. “Then you have a lot of other people down there, as general data users, who might be doing the day-to-day data entry or are relying on that data to do their job,”
CoSN2026: Practical <b>Cybersecurity</b> Strategies for Small and Midsize Districts
Read the original article
edtechmagazine.com →