Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Auditors urge stronger IT security practices; district says MFA and phishing simulations already in place
Summary
Auditors recommended bolstering cybersecurity (MFA, staff training, vendor oversight, backups). The management letter acknowledged these risks and the district's response noted existing controls including MFA and phishing simulations.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
In a management letter accompanying the audit, the auditors highlighted information‑technology security as an area of increasing risk for school districts. The letter recommended ongoing monitoring of cyber threats, regular staff training on phishing/social‑engineering, multi‑factor authentication (MFA) for critical systems, clearer vendor‑security terms in contracts, and annual backup and recovery testing.
The AFR and management letter also included a written management response stating the district currently monitors cyber threats, has implemented MFA for major platforms, conducts phishing simulations and training, vets vendors for data‑privacy agreements, and performs routine backup testing. The auditors listed these items as control recommendations to reduce the risk of operational disruption and data exposure.
