Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Byram Hills reviews annual data-privacy report, delays student multi-factor rollout after new state phone rules
Summary
District technology staff presented a yearly update on student data protections, auditing, endpoint safeguards and vendor controls; staff said planned student multi-factor authentication will be postponed because recent state restrictions on cell-phone use in schools create implementation challenges.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Byram Hills Central School District technology staff delivered its annual data-privacy and security report at the May 6 board meeting, describing recent audits, milestones and next steps to limit exposure of personally identifiable information (PII) and to tighten vendor controls. Kevin (technology staff) told the board the district has continued layered technical, physical and administrative protections and is aligning with prioritized guidance for schools.
Kevin said the district has completed a full data-classification exercise and has associated data types with the applications that carry them. "We've done that with every data type across the district," he said, describing work to rate the impact of an external exposure on students, families and operations. He also said the district has reduced the number of active software subscriptions where possible to shrink the district's "exposure profile" and to reduce costs.
The district has continued to operate device-level protections and web and email monitoring, and this year will be among the first local districts to add a managed Security Operations Center (SOC) that provides 24/7 monitoring for anomalous behavior, Kevin said. As an example of SOC work, he said operators would respond if an account began sending an unusual number of messages outside normal business patterns.
Kevin told the board the district previously rolled out multi-factor authentication (MFA) for adult accounts and had planned MFA for secondary student accounts. "We are putting that plan on hold right now because of the recent legislation that passed for the bell-to-bell ban of cell phones within the schools," he said, noting the most practical MFA solution for students currently depends on cell phones. He also said the new legislation requires two separate means of parent-student communication during the school day and that at least one cannot be a cell phone; the district will review current email restrictions used for students through eighth grade to ensure compliance and to address related security implications.
Kevin referenced federal and national guidance explaining school cybersecurity risk, saying the Cybersecurity and Infrastructure Security Agency (CISA) still highlights K–12 schools as attractive targets because of the volume of valuable student data. He said District practice has shifted to applying the Center for Internet Security (CIS) prioritized controls supported by managed IT partner Lyric and that the district previously used NIST 800-53 guidance. He also said the district participates in the School Data Privacy Consortium (SDPC) to speed contracting with vendors that have Ed Law 2-d–compliant agreements.
Board members asked technical and operational questions about alternatives to phone-based MFA (key fobs, district-issued devices) and about vendor contract review cycles. Kevin said vendor agreements are revisited annually and any new features (for example, AI modules) must be added to the vendor's annual compliance attestation. He also said some free federal resources such as MS-ISAC may be at risk if funding changes.
The presentation did not include a board vote. Board members thanked staff for the update and asked staff to return with implementation options on communication and student account authentication as state guidance and policy choices evolve.

