Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
IT director briefs board on phishing, vendor data privacy and large data exchanges
Summary
District IT staff told the board phishing remains the top threat, that email-based attacks increased in October, and described the district's use of a student-data privacy consortium and a software catalog to manage vendor risk.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
District IT staff presented the board with a cybersecurity and data-privacy briefing that highlighted observed threats, a month-to-month increase in email-borne threats, and the district's approach to vendor data-privacy management.
Key points presented: - Phishing remained the district's most significant threat in October, with an observed near-50% increase in email-related threats versus the prior reporting period. - Malware and identity attacks were also notable items of focus. - IT staff reported a reduction in overall internet traffic while observing more threat activity during the month.
Data-privacy and vendor-management details: - The district participates in the Student Data Privacy Consortium and follows its model agreement and best practices to vet vendors that receive student data. - The district maintains a software catalog (a vendor/product registry) that lists approved products and helps staff and families check whether a vendor (for example, the student information system) is on the approved list. - IT reported 125 active data-privacy agreements and over 1,100 products cataloged. In the prior 30 days the district exchanged about 12 terabytes of data with cloud providers; Google was the largest recipient in the sample list presented.
Why it matters: the briefing underscored the volume of third-party data sharing done to run instruction and district services, and the board heard how the district attempts to reduce risk through standardized data-privacy agreements and vendor cataloging.
Administration's next steps: continue monitoring threat trends, maintain and expand vendor data-privacy agreements, and pursue staff training and catalog maintenance.
Quotations (verbatim from meeting): "Phishing is still the most significant threat that we see." โ IT presenter (paraphrased in the briefing) "We have currently 125 active data privacy agreements. We have over 1,100 products listed in that catalog." โ IT presenter
The board asked clarifying questions; IT staff offered to share more detailed metrics over time and explained that the district typically declines to do business with vendors that do not meet the consortium's privacy requirements.

