Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

IT director briefs board on phishing, vendor data privacy and large data exchanges

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

District IT staff told the board phishing remains the top threat, that email-based attacks increased in October, and described the district's use of a student-data privacy consortium and a software catalog to manage vendor risk.

District IT staff presented the board with a cybersecurity and data-privacy briefing that highlighted observed threats, a month-to-month increase in email-borne threats, and the district's approach to vendor data-privacy management.

Key points presented: - Phishing remained the district's most significant threat in October, with an observed near-50% increase in email-related threats versus the prior reporting period. - Malware and identity attacks were also notable items of focus. - IT staff reported a reduction in overall internet traffic while observing more threat activity during the month.

Data-privacy and vendor-management details: - The district participates in the Student Data Privacy Consortium and follows its model agreement and best practices to vet vendors that receive student data. - The district maintains a software catalog (a vendor/product registry) that lists approved products and helps staff and families check whether a vendor (for example, the student information system) is on the approved list. - IT reported 125 active data-privacy agreements and over 1,100 products cataloged. In the prior 30 days the district exchanged about 12 terabytes of data with cloud providers; Google was the largest recipient in the sample list presented.

Why it matters: the briefing underscored the volume of third-party data sharing done to run instruction and district services, and the board heard how the district attempts to reduce risk through standardized data-privacy agreements and vendor cataloging.

Administration's next steps: continue monitoring threat trends, maintain and expand vendor data-privacy agreements, and pursue staff training and catalog maintenance.

Quotations (verbatim from meeting): "Phishing is still the most significant threat that we see." โ€” IT presenter (paraphrased in the briefing) "We have currently 125 active data privacy agreements. We have over 1,100 products listed in that catalog." โ€” IT presenter

The board asked clarifying questions; IT staff offered to share more detailed metrics over time and explained that the district typically declines to do business with vendors that do not meet the consortium's privacy requirements.