Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Technology Policy topic

No spam. Unsubscribe anytime.

North Kingstown committee reviews tech policy revisions on vendor agreements, APRA and cybersecurity

North Kingstown School Committee · October 28, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The North Kingstown School Committee and district staff spent the bulk of a regularly scheduled meeting reviewing four interrelated technology policies, focusing on transparency about vendor terms, public‑records exposure of district email and plans to strengthen cybersecurity.

The North Kingstown School Committee and district staff spent the bulk of a regularly scheduled meeting reviewing four interrelated technology policies, focusing on transparency about vendor terms, public‑records exposure of district email and plans to strengthen cybersecurity.

Assistant Superintendent Rob Ezinati said the district often must accept third‑party vendor terms of service for curriculum tools and recommended language to ensure parents are told when the district accepts such agreements on behalf of student or staff accounts. "A big one that's gonna come up is Google. Google changes their user agreements all the time," Ezinati said, adding the change is intended to increase transparency when the district must agree to terms to keep a curriculum tool available.

Why it matters: Committee members and staff said parents and staff currently may not realize that some district accounts live under vendor agreements and that little notice is provided when terms change. Committee members pressed administration to make that process explicit in the responsible‑use draft so parents are alerted when a curriculum‑related product requires district acceptance of a vendor agreement.

Attorney Andrew Henness explained that district email is subject to public‑records requests under the state process commonly described in the meeting as APRA (Access to Public Records). "If a student record identifies the student, then it's going to be confidential… it either doesn't get provided or redacted," Henness said. He added that non‑student, staff‑to‑staff email could be reviewable and that the policy should make the public‑records rule clear to staff and families. Committee members asked administration to add explicit policy language noting that communications on NKSD accounts may be subject to review.

The committee also discussed the Child Internet Protection Act (CIPA) and how federally‑required filtering language interacts with district responsible‑use language. Staff said the CIPA text is mandated for districts that accept certain federal funding for internet access; the committee agreed to reduce duplication and clarify where CIPA‑required language must remain.

Log‑on usage and guest Wi‑Fi prompted extended debate. Some committee members argued guest access should be limited to school‑related purposes — for example, enabling ticket scanning or communicating about a child — while others noted public events and limited cell service at facilities mean guests often need temporary access. Staff proposed consolidating the log‑on/guest‑Wi‑Fi language into the overarching responsible‑use policy and adding a carve‑out for event‑related access.

On cybersecurity, staff recommended language changes to the Written Information Security Program (WISP). The draft replaces the term "two‑factor authentication" with "multi‑factor authentication" and ties future additional safeguards to guidance from the National Institute of Standards and Technology (NIST) so the district can adopt evolving best practices without repeatedly amending policy. "I chose the NIST organization because… if we're gonna abide by one, that's probably the safest," a staff presenter said. The committee discussed vendor due diligence (SOC 2/WISP assessments), the scope of protections (staff and student accounts), and whether the district can require vendor security documentation before purchasing services that handle student data.

Staff training and recordkeeping also drew questions. The draft calls for annual security awareness training and tracking of who completed it; staff said a formal rollout was planned but not yet completed. "This has been one that we've been enacting with staff as events come up… this does need to be a more formal training that we send out beginning of every year," a staff presenter said.

What's next: Committee members asked administration to clarify which policies will be merged (log‑on usage with responsible use), to add explicit APRA language, to define "authorized users," and to return with redrafted, consolidated language. No formal votes were recorded on the policy changes during the session.

Ending: The committee agreed to continue refining the language and return the consolidated drafts for further review at a future meeting.