Policy 3540 – Cybersecurity Management and Planning

The District believes in a safe environment for all learning.  The creation, implementation, monitoring, and periodic updating of a District Cybersecurity Plan concerning the identification, prevention, detection, and response to cybersecurity threats and any actual cybersecurity incidents affecting the District is essential. The Cybersecurity Plan shall be consistent with this policy, which is focused on (1) fostering continuous improvement in the area of cybersecurity; (2) identifying and using benchmark-informed and risk-informed practices; and (3) establishing evaluation and accountability mechanisms in the area of cybersecurity management.

Key Administrative Responsibilities

The Chief Information Officer shall have primary administrative responsibility for the District’s Cybersecurity Plan, including all of the following:

  1. Establishing an initial version of the Plan by no later than December 1, 2026.
  2. Except as otherwise expressly directed by the Board, administration will provide periodic status reports as follows:
    1. Periodically notifying the Board of substantive updates/modifications to the Cybersecurity Plan.
    2. A report will be provided at least once annually (planned for August/September) beginning in the 2027-28 school year; either in writing and/or as a presentation at a Board meeting.
  3. Providing recommendations to the Board regarding funding in the District’s annual budgets and regarding other resources that are identified as necessary for the District to be able to maintain current cybersecurity measures, implement additional near-term priority items, and make progress on long-term initiatives and goals. The Board acknowledges that resource limitations can affect the District’s ability to make desired progress toward achieving specific cybersecurity priorities and goals.
  4. Participating in the District’s periodic evaluation of cybersecurity insurance options that may be available to the District.

Expectations for the District Cybersecurity Plan

The District’s Cybersecurity Plan will:

  1. Address significant cybersecurity risks in a risk-informed manner that considers the goals, measures, and strategies set forth in the following:
    1. The Cybersecurity Framework (CSF) published and maintained by the National Institute of Standards and Technology (NIST), using version 2.0 or later.  The Plan shall address each of the core functions of the framework.
    2. The Cross-Sector Cybersecurity Performance Goals (CPGs) published and maintained by the federal Cybersecurity and Infrastructure Security Agency (CISA).
  2. Prioritize the timely near-term implementation and/or ongoing monitoring and enhancement of cybersecurity measures that are considered to be high-impact measures relative to the applicable resource requirements (i.e., not cost-prohibitive), as validated within the NIST Cybersecurity Framework, the CISA Cybersecurity Performance Goals, and/or other expert resources. Such measures should address the key cybersecurity functions of identifying threats and vulnerabilities, protecting against threats and vulnerabilities (i.e., incident prevention), incident detection, and incident mitigation (i.e., response and recovery).
  3. Include cyber incident response procedures, initially prioritizing response procedures that address at least (1) data breaches, (2) ransomware attacks, and (3) loss of access to operationally critical systems.
  4. Identify additional cybersecurity measures that, even if not currently in place or planned for imminent implementation, the District should pursue during a 1-year to 3-year time horizon. The Plan shall track the District’s current status and future progress with respect to such measures, including identifying any evaluation, planning, or implementation steps that are being taken, as well as any barriers that may be inhibiting or preventing progress.
  5. Identify long-term goals and initiatives that will enhance the District’s position with respect to cybersecurity management and cybersecurity practices. The Plan shall track the District’s current status and future progress with respect to such long-term goals and initiatives.
  6. Continuously evolve over time to increase the Plan’s alignment with relevant portions of the NIST Cybersecurity Framework and the CISA Cybersecurity Performance Goals.

Administration will operationalize the management of the District’s approach to cybersecurity in a manner that (1) identifies, prioritizes, and invests in the near-term implementation, monitoring, and enhancement of the most impactful cybersecurity measures, within applicable resource constraints; and (2) builds, over time, to demonstrate an increasingly more sophisticated, comprehensive, integrated, and effective strategic approach to cybersecurity management.


Legal References:

  • Wisconsin Statutes
    • Section 19.65 [mandate to establish rules of conduct and training for employees involved in the management of personally identifiable information]
    • Section 134.98 [a state “data breach” statute that requires certain covered entities to provide notice of unauthorized acquisition of certain personal information]
  • Federal Laws
    • 34 C.F.R. Part 99 [regulations implementing the Family Educational Rights and Privacy Act (FERPA), including the expectation found in 34 C.F.R. §99.31(a)(1)(ii) that schools must use reasonable methods to ensure that school officials obtain access to only those education records in which they have legitimate educational interests]
    • 34 C.F.R. §300.623 [confidentiality safeguards regarding IDEA-related records]
  • Other Federal Resources

Cross References:

Adoption Date: September 22, 2026