Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
District proposes data governance and IT security policy; HB 124 provisions added
Summary
The Cache County School District presented a consolidated data governance and information security policy that adds staff training, incident response procedures and statutory protections for employee data stemming from recent legislation, the board heard May 1.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Kevin Womack presented a consolidated data governance and information technology security policy that would incorporate prior district plans, a security framework and recently enacted legislative requirements.
Womack said the draft updates include explicit training requirements tied to student data privacy laws, broader coverage of employee data protections, a data access agreement for staff who handle Class 1 data (student and employee PII), and clarified procedures for reporting data breaches to the state. "A big thing that came out of the legislature this year was, I believe it was House Bill 124," Womack told the board, and he said the policy text incorporates provisions limiting sale and improper sharing of employee data and guidance about what the district may require of personal devices.
The draft also defines the cybersecurity framework the district follows (useful for grant applications and cyber insurance) and describes audit and training cadence to maintain compliance. Board members who had previously reviewed the draft with staff offered editorial suggestions and thanked Womack for incorporating changes.
Next steps: staff will refine the policy text per board feedback and return a final policy and procedures for adoption.

