Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the It Cybersecurity topic

No spam. Unsubscribe anytime.

District IT presents data governance, cybersecurity progress to school board

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The district systems administrator reported on the ConVal data governance plan, inventory of vendor contracts, recent cybersecurity work and next steps including two‑factor authentication, phishing training and plans to migrate critical systems to hosted services.

Mark Schaub, the district systems administrator, briefed the Contoocook Valley School District School Board on the district’s data governance plan and recent cybersecurity work.

Schaub outlined the statutory origin of the plan — RSA 189:66 (as referenced in district materials) — and said the plan requires an inventory and review of software applications, privacy procedures, incident response and vendor standards. The district joined the Student Data Privacy Consortium to centralize vendor contracts and approvals and has used LearnPlatform to maintain an internal inventory of systems.

He described steps taken since 2019: moving critical systems (PowerSchool, Infinite Visions and others) to hosted vendor solutions where appropriate, encrypting and backing up local data, updating firmware on network hardware, replacing end‑of‑life servers and battery backups, tightening Wi‑Fi controls and piloting single‑sign‑on and two‑factor authentication for administrative accounts. Schaub said the district also worked with its managed firewall vendor to tighten inbound traffic rules and is piloting phishing‑simulation training to build staff awareness.

Schaub noted the district had a playbook for incident response that was relevant during the PowerSchool data breach; he said the district’s insurance and cybersecurity legal resources were engaged through that process. He described ongoing tasks including an internal cybersecurity audit, device inventory management in PowerSchool, documentation of onboarding/offboarding procedures and procedures for responding to Google Vault and public records requests.

Board members asked about phishing simulations and testing practices; Schaub confirmed the district is implementing practice phishing campaigns and ongoing staff training. The board did not take a formal vote on the presentation; the session was a progress report and direction to continue the work and return with recommended next steps and costs as needed.