Enable breadcrumbs token at /includes/pageheader.html.twig

With Students Back to School, CISA Provides Cybersecurity Tools for Districts

The cyber agency lays out a road map for school security.

Post Labor Day, schools across the nation are underway. Thanks to the Cybersecurity and Infrastructure Security Agency (CISA), this school year, districts have new tools to address cybersecurity and add protections.

CISA’s Scott Breor, acting executive assistant director, infrastructure security, who led the development of the tools designed for kindergarten through 12th grade schools (K-12), spoke to SIGNAL Media in an interview.

In addition to the K-12 tools, Breor—a former naval aviator and special adviser to the chief of naval operations—also prepares CISA’s tools and training to mitigate threats to critical infrastructure and public gathering events, including resources for physical security, unmanned arial system threats, active shooter preparedness, federal facility security, bomb threat management, suspicious activity reporting, nonconfrontational techniques, vehicle ramming and insider threats.

Breor noted that the number of cyber attacks to schools is only growing. Last year, cybersecurity companies identified about 4,400 cyber attacks to schools per week, mostly ransomware attacks. Several years ago, between 2018 and 2021, that number was 1,300 cyber incidents. He cautioned that the numbers only reflect what was reported.

“It could be far greater than that,” Breor said. “What we predominantly see is ransomware, that is always making the news, but business email compromise, data breaches, denial of service. Those are just a few examples.”

Now, school districts have detailed resources to help them assess, protect and defend digital assets at their schools, as part of CISA’s K-12 School Security Guide Product Suite. The tool set includes eight objectives:

  • Protect the login credentials of students and personnel.
  • Safeguard student and personnel devices and other assets.
  • Perform, verify and test backup tools for saving critical data.
  • Develop and exercise a cyber incident response plan.
  • Utilize available cybersecurity training and awareness campaigns at all levels.
  • Protect sensitive data.
  • Prioritize further near-term efforts and investments in alignment with the full list of applicable CISA cross-sector cybersecurity performance goals.
  • Develop a customized cybersecurity plan over the long term that leverages the National Institute of Standards and Technology (NIST) Cybersecurity Framework.

For each objective, CISA details actions to take and resources for more information. For example, with increasing identity management and credentialing, the agency has schools implementing multifactor authentication, minimum password strength, account lockout after multiple login attempts, revoking credentials once students and staff leave the district, separation of privileged accounts and timing out after session inactivity.

“With objective one, which is to protect the login credentials of students, we identify what practices can you do that will help protect the login credentials, and then we crosswalk that to references, so they can look at the way we are presenting the material,” Breor noted. “They can look at the way it is presented within the National Institute of Standards and Technology’s Cybersecurity Framework. We want to give them all the information that we think is best to address those concerns, but lay it out as simply as we can.”

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

And while these steps may seem straightforward to cybersecurity professionals, school districts may be in different stages of their information technology security journey and may have limited school resources to address cyber risks.

CISA took a crawl, walk, run approach, Breor said.

“We laid it out across eight objectives that they should look at, and then with that, we identified what we believe are the top four objectives, if they truly are limited,” he said. “It is not always just limited resources, but also if you consider time a resource, you are limited in that respect also.”

From the actions CISA outlined, school districts should then determine their next steps, including conducting cybersecurity assessments, Breor recommended.

“Those are the four areas that they should immediately take a look at and make an assessment against the practices they have in place,” he advised.

In addition, CISA’s policy offers a flexible approach. School districts can develop a plan that is most geared toward their specific cyber risks and incidents.

“One thing we do in the guidance is that we identify those threats against the objectives,” Breor said. “At your school, you might still be at a point where you are really not concerned about email compromise, but your main concern is ransomware. Then in the guidance, look at the objectives. Those objectives are mapped to the cyber threat that they will mitigate or help mitigate, so you can easily see, ‘OK if I'm concerned about ransomware, these are the objectives I need to focus on.’”

CISA also provided a series of trainings for K-12 schools about physical security, cybersecurity and the School Security Guide Product Suite. For school administrators and school-based law enforcement, the agency also offers planning tools and concepts, as well as a gun violence prevention guide.

For the last few years, CISA has been developing the K-12 School Security Guide Product Suite, working with government stakeholders, including the U.S. Department of Education (DOE) and the schoolsafety.gov program.

“One of the areas that we have within CISA’s infrastructure security [division] is that we support the clearinghouse for school safety: schoolsafety.gov,” Breor explained. “After the Marjory Stoneman Douglas [High School] shooting in Parkland [in 2018], President Trump, in his first administration, established a school safety task force.”

Image
Scott Breor, CISA
At your school, you might still be at a point where you are really not concerned about email compromise, but your main concern is ransomware. Then in the guidance, look at the objectives. Those objectives are mapped to the cyber threat that they will mitigate or help mitigate.
Scott Breor
Acting Executive Assistant Director, Infrastructure Security, CISA

Under the task force, CISA worked with officials from the U.S. Department of Homeland Security (DHS); Department of Health and Human Services, DOE and Department of Justice, Breor said.

“The four agencies were asked to take a look at how we can make schools safer and more secure,” he said. “We were tasked to come back with recommendations in 270 days, and our predecessor agency, the National Protection and Programs Directorate, was given the lead to support the [DHS] secretary. We have security advisers in all 50 states and in Puerto Rico, and we have a long history of working with schools, faith-based organizations and, of course, the critical infrastructure community.”

One of their recommendations was to establish a clearinghouse for gratis products, resources and tools for schools to access “all in one place.” The free downloads include resources on enhanced school security, mental health, emergency planning, bullying, substance abuse, as well as cybersecurity, which complements CISA’s K-12 School Security Guide Product Suite.

“To date, we have now 47 states that have partnered with us, and they are all connected to this website, and they are sharing their resources also,” Breor noted. “And we continue to work with the school communities. We listen to what their concerns are, their issues and gaps. They all have different needs with respect to resources. They all have different requirements. We really wanted to develop products that we felt spoke to the cybersecurity threats that they face and present risk mitigation solutions that they could take.”

To create CISA’s K-12 School Security Guide Product Suite, officials also leveraged CISA cyber officials and K-12 educational associations to have the policies peer-reviewed by school representatives and cybersecurity experts.

“The school associations that we maintain a dialog with, the representative schools, they are always willing to provide support when we develop products, whether it is focused on cyber, whether it’s focused on physical security or whether it’s focused on student behaviors,” Breor said.

Additionally, Breor emphasized that they plan on keeping the policy tools current over time.

“I came from the [military] world, and any document over four years old you threw out the window,” he said. “That is my approach here. We are going to update it based on risk. If we see something that is increasingly becoming a concern across the K-12 community that may not specifically be addressed in our guidance, there are various ways we could update the guidance. Or we could develop a product associated to that specific threat and then also make it available at schoolsafety.gov and also at CISA.gov for our K-12 resources.”

Lastly, Breor confirmed that although it is a voluntary program with the schools, CISA expects the tools to reduce cyberattack risks.

“This is not something that we can mandate, but we definitely believe that having this product on the street will help mitigate the risk across the K-12 community,” he noted.

School districts with questions about CISA’s K-12 School Security Guide Product Suite can reach out via email to CISA’s School Safety Task Force (SchoolSafety@cisa.dhs.gov) or a local protective security adviser, which, if not known, can be located through CISA’s regional contacts website.

Comments

The content of this field is kept private and will not be shown publicly.

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.
Enjoying The Cyber Edge?