Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Board reviews first reading of comprehensive cyber security policy and administrative rule

Anderson District 3 School Board · February 9, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Board members and staff reviewed a proposed district cybersecurity policy and a detailed administrative regulation that includes multifactor authentication for key systems, BYOD/guest-network rules, vendor attestations, a data-classification framework, and incident-notification steps including board-chair notification.

The board’s policy committee presented a first reading of a district cyber security policy accompanied by an administrative regulation that captures implementation details.

Miss Gray and committee members said the policy sets expectations while the administrative regulation will spell out specifics that change over time, such as patching frequency, backup retention and authentication baselines. The administrative regulation requires multifactor authentication for Google Workspace accounts, administrative Active Directory accounts, remote access, and public-facing cloud services that host sensitive information.

The regulation adds daily automated backups with daily, monthly and yearly retention schedules and proposes log-retention best practices (regular logs minimum 30 days, alerts minimum 90 days). Staff also added an explicit BYOD (bring-your-own-device) administrative section for employees, contractors and guests, and described a segmented guest VLAN that prevents guest devices from accessing internal systems.

Vendor-security language was strengthened: vendors with system access must provide reasonable documentation or attestation (for example, demonstrating alignment with CIS IG1 or equivalent) and staff said they will incorporate security clauses into contract templates for significant procurements.

The administrative regulation clarifies incident decision authority, naming the superintendent in coordination with the CIO and legal counsel, and now explicitly requires board-chair notification as part of incident response. Staff also added a data-classification framework (restricted, private, public) with encryption and role-based access controls required for restricted data such as student PII and health information.

Committee members discussed operational exceptions and gave a concrete example: to allow a small group of students to use a third-party lockdown browser for testing, IT created a temporary organizational unit that removed browser extensions for the test window and restored them afterward.

Miss Gray asked the board to review the administrative regulation before first reading and to identify any areas needing clarification; no final policy vote was taken. The board will return for formal action after committee review and any edits.