Score: +1 (1/1/0)
San Diego County Grand Jury • 2023-2024

NOV 18 2024 By: T. Cutts, Deputy Cybersecurity in SAN Diego School Districts*

Published: November 18, 2024 15 pages
View Original PDF

Findings and Recommendations 7 findings

F1
The San Diego County Office of Education provides high-quality cybersecurity readiness tools and services to county school districts at no or very low cost.
Related Recommendations (1)
R1
School districts provide cybersecurity training to all staff members, at least annually, by the beginning of the 2026-2027 school year.
F2
The best practice for cybersecurity training in school districts is annual training for all staff and students.
Related Recommendations (1)
R2
School districts provide cybersecurity training to all students, at least annually, by the beginning of the 2026-2027 school year. School districts implement a phishing awareness training solution for all staff members
F3
Preventable human behavior is the main cause of successful cyberattacks.
Related Recommendations (1)
R3
by the beginning of the 2026-2027 school year.
F4
Multi-factor authentication is the most effective cybersecurity technical measure to reduce successful cyberattacks.
Related Recommendations (1)
R4
School districts implement multi-factor authentication for all staff members by the beginning of the 2026-2027 school year.
F5
Successful organizations often have a role or position that is identified as responsible and accountable for the planning, resourcing, and execution of cybersecurity activities.
Related Recommendations (1)
R5
School districts designate a single individual as Cybersecurity Lead responsible for cybersecurity readiness in the district by the beginning of the 2025-2026 school year.
F6
A school district leadership's knowledge of cybersecurity issues can positively influence a district's cybersecurity readiness.
Related Recommendations (1)
R6
School districts require the Cybersecurity Lead to provide an annual report to the school board and the SDCOE on the state of cybersecurity readiness by the beginning of the 2025-2026 school year.
F7
Obtaining cyber insurance helps a school district to both prepare defenses against and recover from cyber-attacks.
Related Recommendations (1)
R7
School districts acquire and maintain cyber insurance coverage by the beginning of the 2025-2026 school year. SDCOE creates a methodology, training, and report template to support a school district's

Additional Recommendations 2

These recommendations are not explicitly linked to specific findings.

Agency Responses 1

Government agencies' official responses to this report's findings and recommendations. Click on a response to see the structured breakdown.

* This report's PDF did not contain easily extractable text and required Optical Character Recognition (OCR) for analysis. There may be minor errors in the extracted findings and recommendations due to OCR limitations with scanned documents.