Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Audit committee recommends WISP adoption after Canvas outage; CIO describes precautions

Vermont States Colleges Audit Committee · May 11, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Following a Canvas outage and reported security incident at the platform provider, the Audit Committee reviewed college protections, heard that integrations were disconnected as a precaution, and voted to approve and recommend a Written Information Security Program (WISP) to the board.

The Vermont State Colleges Audit Committee heard a non‑agenda briefing on a recent Canvas outage and related security concerns and subsequently reviewed a Written Information Security Program (WISP) that the committee recommended to the board.

Wilson Garland, chief information officer, told the committee that Instructure, the company that operates Canvas, is still investigating a recent security incident and that it appears some customers “potentially had some of their data compromised.” Garland said access to Canvas has been restored, the colleges temporarily disconnected some systems that integrate with Canvas as a precaution, the colleges engaged an external security firm, and IT staff are monitoring network traffic while awaiting further details from Instructure.

“Canvas is the system that we use to host our courses,” Garland said, noting that students and faculty were returning to the system to complete coursework. Garland described ongoing measures: extra traffic monitoring, temporary disconnections of integrations that touch sensitive student information, annual tabletop exercises, and third‑party penetration testing. He said social‑engineering testing will be added to this year’s pentest.

Trustee comments: President Judy commended communication from IT leadership and said she had not heard of major problems on campus. Trustee Silverman asked whether external testing results should be presented to the audit committee; Garland said some material test results could be shared in executive session.

Meg Waltz, deputy chief information officer, presented the WISP—a consolidated document that sets out responsibilities, role‑based access controls, password and multifactor authentication expectations, employee training obligations, protections for wired and wireless networks, and incident‑response steps. Waltz told the committee that the WISP formalizes practices that already existed and that it should resolve the prior audit finding about outdated written policies.

Chair Trustee Zeller moved that the committee approve and recommend the WISP for board authorization; Trustee Silverman seconded. The committee approved the recommendation by voice vote; no roll‑call tally was recorded.

Next steps: the committee will expect an annual review of the WISP and periodic reporting on significant security testing outcomes; the committee did not go into executive session following the briefing and adjourned.