|
June’s focus will be on vulnerability management:
Q: "Do we have a clearly defined and regularly-updated vulnerability management program that aligns with CISA Cybersecurity Performance Goals (CPGs) and the NIST Cybersecurity Framework (CSF)? Can you provide a summary of our current CPG implementation status, specifically regarding vulnerability identification, prioritization, and remediation?"
Q: "What is our established patching cadence for critical systems and applications, particularly those exposed to the internet or containing sensitive student/staff data? How do we ensure timely remediation of vulnerabilities, especially those identified as ‘high’ or ‘critical’ severity?"
Q: "Beyond automated scanning, what manual or third-party assessments (e.g., penetration testing, external audits) do we conduct to identify vulnerabilities that automated tools might miss? How frequently are these conducted, and how are their findings integrated into our overall vulnerability management strategy?"
Q: "How do we track and report on our progress in reducing the overall attack surface and vulnerability exposure? What metrics can we use to demonstrate the effectiveness of our vulnerability management efforts to the school board and other stakeholders?"
Q: "What resources (budget, staffing, training) are needed to mature our vulnerability management program further in alignment with evolving threats and CPGs? Are there any significant gaps or challenges we face in consistently identifying and remediating vulnerabilities across our diverse school environment?"
|