Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Policy topic

No spam. Unsubscribe anytime.

District hears proposed cybersecurity policy; first reading set for February

Anderson School District 3 Board of Trustees · January 13, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Anderson School District 3 staff presented a proposed, board-governed cybersecurity policy aligned to CIS standards that would require multifactor authentication, immutable off-site backups, vendor security agreements, annual staff training and vendor vetting; first reading is scheduled for February and second reading in March.

Presenter (S5) gave the board an overview of a proposed district cybersecurity policy, saying it would make cybersecurity a board-governed risk and align the district to Center for Internet Security (CIS) standards.

The policy is organized into five areas—identify, govern, protect, detect, respond and recover—and would apply to anyone who touches district systems, not just employees, Presenter (S5) said. "So any vendor, even board members, if you use district resources, like checking your email, it governs that," the presenter said.

Presenter (S5) described key protections the policy would require: multifactor authentication, data encryption, regular patching, endpoint protection, a next-generation firewall, measures to be FERPA-compliant, financial-fraud controls, immutable off-site (air-gapped) backups and an incident response plan. "Immutable just means they're air gapped. You can't get to them online," Presenter (S5) said, describing the backups as an alternative to paying ransom in the event of ransomware.

The policy would also require that every staff member complete cybersecurity training within 30 days of hire and annually thereafter, and that the district run phishing simulations. For third-party vendors, the district would use a vendor-survey process to confirm security practices and whether vendors hold student data, Presenter (S5) said. The presenter noted the district had tightened vendor scrutiny after a PowerSchool-related breach two years earlier.

Board members asked how exceptions and temporary waivers would work. Committee member (S2) asked for an example; the presenter cited an example in which Zoom is unblocked for an off-site speech therapist to connect with students, with the guidance counselor and assistant principal supervising the session. The presenter said the incident response plan will be provided on request but would not be placed in full public policy to avoid exposing sensitive details.

Presenter (S5) said the superintendent and the chief information officer would be accountable to the board for governance, resourcing and reporting, and the board would receive an annual cybersecurity report similar to financial reporting. The first reading of the policy is scheduled for February, with a second reading in March.

The board did not take a final vote on the policy at the meeting; members asked for a copy of the incident response plan and clarification on exceptions and vendor compliance ahead of the first reading.