Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity It Audit topic
No spam. Unsubscribe anytime.
SLPS compliance audit finds past IT gaps; district outlines corrective steps and a cybersecurity plan
Summary
A review of 2020 and 2022 technology audits showed prior gaps in password policy, endpoint management, unsupported operating systems and documentation for emergency‑connectivity devices; the district described ongoing corrective actions and said it will publish a comprehensive cybersecurity plan in mid‑2025.
Get email alerts on the Cybersecurity It Audit topic
No spam. Unsubscribe anytime.
The board received an update on two technology audits (a 2020 cybersecurity assessment and a 2022 year‑end audit) and the district’s response to recommendations, including changes to password policy, endpoint management, system‑imaging and inventory controls.
Dr. Hubbard, the district’s director of compliance and internal audit, summarized recurring observations from external auditors: password rules that did not meet contemporary best practices, administrator passwords that had been shared, inconsistent antivirus updates, incomplete group‑policy hardening, out‑of‑date systems and gaps in documentation for devices issued under the Emergency Connectivity Fund. The auditors also found lapses in retaining signed equipment-use agreements for some devices.
District technology staff reported a series of corrective steps taken or underway: stronger password requirements and periodic change intervals; use of Intune to manage and randomize local administrator passwords; deployment of Sophos for endpoint protection; migration or upgrade of unsupported Windows 10 systems to Windows 11 or cloud services; weekly vulnerability scans; and work toward an inventory‑based software assessment database. The district said two items remain pending but that many actions are complete or ongoing.
Miss Mitchell and other technology leaders said the district is developing a comprehensive cybersecurity plan aligned to U.S. Department of Homeland Security guidance and expects to publish a more detailed plan and timeline in July 2025. "We are in the midst of that work," Mitchell said. Board members asked for specifics about which information‑security policies would be published and for assurances about ongoing vulnerability scanning and contract controls.
On older Emergency Connectivity Fund devices, the district said devices were at end of life, reimbursement requests had been completed and device‑tracking systems (MOSAIC/Absolute/Mosul referenced in the presentation) are now in use to ensure devices are assigned and tracked.

