Skip to main content

NCDPI K-12 Cybersecurity Program

Announcements

  • National Student Privacy & Data Security Spring Webinar Series
    • Day 1: FERPA 101 and Data Security Best Practices
      • April 10th, 2024, 2-4pm
      • Covers the basics of FERPA and provides training on current data security best practices for education data systems
      • Register Here
    • Day 2: FERPA 201 and Transparency
      • April 17th, 2024, 2-4pm
      • Dives into scenarios faced by schools and districts and highlights PTAC’s research on transparency
      • Register Here
    • Day 3: Incident Response and Vetting Educational Technology
      • April 24th, 2024, 2-4pm
      • ET leads participants through a simulated data breach and explores how to assess online educational technology for privacy protections and general FERPA compliance
      • Register Here

The K-12 Cybersecurity Program was founded and is funded by NCDPI to increase the cybersecurity posture for the PSUs

Overview

In 2021, NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state so that PSU and NCDPI stakeholders have greater visibility into the people, processes, and technologies deployed and have a measurable way to determine whether those efforts are sufficient and correct for current and future needs.

The goal is to help all PSUs achieve essential cyber hygiene!

PSUs can find more details about the premium current services and resources provided by the program below AT NO COST to the PSUs

In addition, the K-12 Cybersecurity Program has several partners with related services and resources available to the PSU community:

  • NCLGISA IT Strike Team – The IT Strike Team is a group of NCLGISA members that volunteer their time and talents to help out in times of need. The Strike Team has partnered with NC Emergency Management to provide IT support where needed in time of disaster but is also available to any NCLGISA member who needs more resources to address emergency issues.
  • North Carolina National Guard – The North Carolina National Guard CSRF mission is to conduct defensive cyberspace operations to support mission requirements as directed by The Adjutant General or Governor. Specifically for North Carolina, the CSRF provides cyber security assistance to State, Local, and Critical Infrastructure providers.
  • NCDPI NC Digital Learning Plan – Framework for growth and continuous improvement in the area of Digital Teaching and Learning for NCDPI, public school units and schools across the state. View data, action steps and metrics for the state’s Digital Learning Initiative.

Management

The K-12 Cybersecurity Program is composed of cross-functional heterogeneous teams to work on tasks and deliverables of the projects. These teams will adapt and evolve over time, but identifying key members will be extremely important to getting the project started with good momentum. The teams should include representatives from all organizations that will interface with the Cybersecurity Program.

  • Cybersecurity Executive Committee (CEC)
    • The purpose of the executive committee is to provide the priority and policy advisory for the project and ensure the alignment of state agency and legislative requirements.
  • Cybersecurity Core Teams (CCT)
    • The core set of teams and organizations that collectively work together as part of the NCDPI K-12 Cybersecurity Program in providing the umbrella of cybersecurity services and resources for the PSUs
      NCDPI, Friday Institute, MCNC, NCJCTF, NCDIT
  • Cybersecurity Advisory Council (CAC)
    • The CAC consists of PSU cybersecurity leaders who meet monthly to discuss relevant threats, updates, and innovations. Overall focusing on supporting PSUs and NCDPI in improving the K-12 cybersecurity posture.

Key Program Contact
NCDPI K-12 Cybersecurity Team
k12cybersecteam@dpi.nc.gov

Strategy – Framework

NCDPI has aligned the K-12 Cybersecurity Program strategy with the
NIST Cybersecurity Framework (CSF) 2.0 and its 6 Core Functions

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

NCDPI will support a variety of countermeasures, composed of people, processes, and technologies, across the 6 functions of the CSF to reduce cybersecurity risks to PSU assets.

Strategy – Controls

Since the inception of the K-12 Cybersecurity program, NCDPI has leveraged the Center for Internet Security (CIS) Critical Security Controls as a guide for specific and actionable ways to thwart the most common attacks, with the goal of supporting PSUs to achieve CIS implementation group 1 level. The CIS Controls are a relatively short list of high-priority, effective defensive actions that provide a starting point for enterprises seeking to improve their cyber defense. NCDPI also leverages applicable Security and Privacy Controls from NIST NIST SP 800-53r5 to support the program’s purpose and vision.

Key Program Outreach and Engagements