Understanding School Cybersecurity: How to Start & Stay Safe
If you’ve been following Avertere's blogs, you likely know a thing or two about online threats aimed at educational settings like schools. But,...
2 min read
Jack Britton Aug 31, 2023 3:29:39 PM
If you’ve been following Avertere's blogs, you likely know a thing or two about online threats aimed at educational settings like schools. But, sadly, we’ve noticed that many school IT and Security departments are a bit behind. They often think, “Who would target a school?” Well, the answer is, many people would, and they do. So, what should you focus on to keep your school safe? Let’s break it down.
The first step in ramping up your school's cybersecurity is adopting a recognized security framework. We at Avertere recommend starting with the Center for Internet Security (CIS) Version 8. This framework aligns with important CISA Cross-Sector Cybersecurity Performance goals and can serve as your blueprint for safeguarding school IT systems.
CIS is a nonprofit organization with two decades of experience in providing globally recognized security guidelines. They also offer a Risk Assessment Methodology (CIS-RAM) and a handy Controls Navigator. These tools can help you understand the risks you face and what investments you need to make to mitigate those risks. If this sounds complicated, don’t worry—Avertere is here to help you get started.
Now, if you go to the CIS Navigator page, you’ll notice a list of 18 critical security areas, 3 implementation groups, and a total of 153 safeguards. Don't let this overwhelm you. To begin, you only need to focus on a subset of these: CISv8 Implementation Group 1, which outlines 56 safeguards aimed at establishing "essential cyber hygiene."
Here’s how to simplify things:
When you click on the carrot (^), you'll see "Mappings to other frameworks" listed underneath.
What does this mean? It means you’ll see how this safeguard aligns with other security frameworks like CISA, NIST, or MITRE. This is super helpful because it shows that implementing this one safeguard helps you meet multiple security goals at once. Plus, you get a sense of how universally important this safeguard is across different frameworks.
Your school's IT and Security department can indeed secure your digital assets effectively. Start by understanding the risks we’ve talked about in previous blogs and establish a Risk Management program based on CIS-RAM. Try to reach basic cyber hygiene as laid out in the CISv8 guidelines.
If you find this info helpful, remember to subscribe and follow Avertere. Reach out to us for more guidance and learn about “no-cost” programs that can further secure your school.
Stay safe! 🛡️
If you’ve been following Avertere's blogs, you likely know a thing or two about online threats aimed at educational settings like schools. But,...
Greetings, K12 School champions! Our recent explorations, “How to Spot Cyber Threats that Could Harm Schools” and “Cyber Threats to Edu Cloud...
In a previous blog, we delved into identifying cyber threats to schools and how they cause impact using MITRE ATT&CK. Today, we narrow down our focus...