Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Security topic

No spam. Unsubscribe anytime.

Policy committee advances combined data security policy, emphasizes low risk tolerance and expanded definitions

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The committee unanimously advanced a consolidated data security and information governance policy that expands definitions, incorporates Maryland cybersecurity law and clarifies training and recordkeeping expectations; IT staff urged a low risk tolerance and called for expanded behavioral and technical safeguards.

The Frederick County Public Schools Policy Committee voted unanimously to advance a revised, consolidated data security policy that combines prior policy language on data privacy and information security and expands the district’s definitions, governance framework and expected safeguards.

Staff and IT subject‑matter experts told the committee the update responds to evolving state requirements (including the Local Cybersecurity Support Act) and modern cybersecurity practice. The draft broadens the scope beyond student data to include staff, operational and sensitive data categories (e.g., federal tax information, payment card information and health records) and stresses that protecting information is administrative, physical and technical.

Why it matters: The policy touches school and central operations and governs how the district protects large volumes of sensitive data. Staff told the committee the policy underpins a 300‑page written information security program that aligns with the State of Maryland Department of Information Technology and federal frameworks such as NIST.

Committee highlights - Definitions and scope: IT staff expanded definitions to capture different data types and to emphasize behavioral and administrative controls as well as technical measures. - Training and testing: Staff said FCPS requires annual training (via Safe Schools) for all staff and runs mandatory phishing tests; staff reported the district’s most recent phishing failure rate was about 9 percent (improved from roughly 20 percent when the program was paused during COVID) and that repeat failures trigger follow‑up training. - Risk tolerance: IT staff asked the board to state a risk posture. Committee members agreed to incorporate language signaling a low risk tolerance for information security; IT recommended that a low tolerance (target failure/reporting thresholds) guide operational choices. - Governance and audits: Staff said the district maintains a written information security program aligned to Maryland auditing expectations and that the department submits annual data points to MSDE and the Maryland Center for School Safety; drill/incident reporting infrastructure is centralized.

Outcome: The committee approved advancing the consolidated policy to the board with the recommendation to include a clear statement about district risk tolerance and to keep technical detail in regulation or supporting documentation the district can update as standards evolve.