October’s focus will be on training programs. The most robust cybersecurity plans focus on process, people, and technology, which means that staff and students need security awareness training. Additionally, employees must be educated regarding laws and district policies that protect sensitive information. In New York State, this “best practice” is required.
Q: How are we complying with Ed law 2D part 121 regulations that require training be provided annually to all staff and officials with access to protected data?
Q: What topics are we covering in the training?
Q: How does the district track that training has been completed?
Q: Do we provide role-specific cyber training to any employees whose roles might lead them to be specifically targeted by cyber criminals?
Q: Do we have a specific process or method for users to report phishing emails? How is that communicated to staff?
|