Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Policy topic

No spam. Unsubscribe anytime.

District staff say ADE cybersecurity policy completed; Bentonville already largely compliant

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Presenters said Arkansas'wide K'12 cybersecurity policy was finalized Oct. 1 and will be implemented in three phases; Bentonville staff said the district has already implemented all three phases and recommended adopting the state policy in district procedures.

At the April 15 Bentonville School District Board of Education meeting, information was presented about the Arkansas Department of Education's K'12 cybersecurity policy, required under state law. District IT staff reported the state policy was completed Oct. 1 and that districts are expected to adopt compatible policies.

Mister Nichols, who briefed the board, said the ADE policy implements Arkansas Act 504 requirements and is being implemented in three phases, with phase 1 effective July 1. "This policy is being implement[ed] in 3 phases... Phase 1 is effective July 1," Nichols said, and added that the approved policy provides a common cybersecurity language for districts.

Nichols described six control categories included in phase 1: access control; awareness and training; contingency planning; identification and authentication; incident response; and system and information integrity. He told the board that while the state policy contains some sensitive operational detail the state does not publish publicly, the district had already adopted many of the recommended controls and believes it is in good standing.

Nichols said the district will be asked to adopt the state policy in a later action item (agenda item I) but that tonight's discussion was informational. Board members and staff noted the district had previously implemented cybersecurity measures and had used the ADE policy to "scrub" and align district procedures with the state baseline.

Nichols said a district committee including IT staff participated in state discussions and that the policy will be reviewed annually. He also said districts are not required to publicly post sensitive procedures and asked board members to return printed copies of the policy after review to avoid making operational details broadly available.

The item was informational; the board later voted to adopt several policy updates, including cybersecurity alignment, as part of the consent/action items under agenda item I.