Garnet River Logo

We bring a multi-disciplinary (technical/legal) approach to help schools implement, measure, and maintain a multi-disciplinary security architecture

Platform available through Nassau BOCES (CoSer 602.066/566)

With the adoption of Part 121 of New York State Ed Law Section 2-D, school districts are now required to meet a set of standards around school data security and privacy, including:

  • Protection of personally identifiable information (PII)
  • Publication of a school data security and privacy Parents’ Bill of Rights
  • Adoption of a data security and privacy policy
  • Application of the NIST Cybersecurity Framework
  • Compliance with third-party contractor agreements for use of products and/or services
  • Delivery of annual privacy and security awareness training to all employees
  • Disclosure of a complaint process
  • Following reporting and notification procedures in the event of unauthorized disclosure
  • Appointment of a Data Protection Officer to oversee implementation of Ed Law 2-D requirements

These are all good things. Student data is a target, and Ed Law 2-D, Part 121 demands schools meet the above requirements by conducting an assessment and developing a gap analysis.

BUT…IS THE CHECKLIST ENOUGH?

We bring a multi-disciplinary (technical/legal) approach to help schools implement, measure, and maintain a multi-disciplinary security architecture

Platform available through Nassau BOCES (CoSer 602.066/566)

With the adoption of Part 121 of New York State Ed Law Section 2-D, school districts are now required to meet a set of standards around school data security and privacy, including:

  • Protection of personally identifiable information (PII)
  • Publication of a school data security and privacy Parents’ Bill of Rights
  • Adoption of a data security and privacy policy
  • Application of the NIST Cybersecurity Framework
  • Compliance with third-party contractor agreements for use of products and/or services
  • Delivery of annual privacy and security awareness training to all employees
  • Disclosure of a complaint process
  • Following reporting and notification procedures in the event of unauthorized disclosure
  • Appointment of a Data Protection Officer to oversee implementation of Ed Law 2-D requirements

These are all good things. Student data is a target, and Ed Law 2-D, Part 121 demands schools meet the above requirements by conducting an assessment and developing a gap analysis.

BUT…IS THE CHECKLIST ENOUGH?

If the work being done is strictly administrative and designed to meet certain standards by certain dates, the answer is a resounding no.

Data security is a journey, not a destination. Education and training, the principle of least privilege, and individual responsibility must be an ongoing priority

Garnet River is already helping other districts meet and surpass the standards. We can help your district do the sameeven if a private or out of state school.

At Garnet River, we help school school districts navigate this journey. Some need to comply with NYS Ed Law. Some are required to do so by insurance companies. Others simply value the data security of their students and staff and do not want to be on the wrong end of a breach. Regardless of your situation, we emphasize the basics, but we complement them with a strong information security program, technical tools, and sound policy…all while mapping progress and remediating issues along the way.

Photo of kids working on laptops, emphasizing need to have a school data security program
Garnet River Logo

The best relationships start with a simple conversation. Let’s talk!

Photo of kids working on laptops, emphasizing need to have a school data security program

The best relationships start with a simple conversation. Let’s talk!

OFFERINGS

Cybersecurity Platform

  • NIST Framework
  • Assessment Scoring
  • Gap Analysis
  • Threat Feed
  • Visual Reports
  • Remediation Support

General Services

  • Security Architecture
  • CISOaaS
  • Policies & Procedures
  • Security Scanning
  • Vulnerability Analysis
  • MS-ISAC Set-up
  • Tabletop Exercises

Products

  • Yubico (MFA Devices)
  • Software Catalog
  • Albert Security Operations Center (SOC)
Photo of kids working on laptops, emphasizing need to have a school data security program

The best relationships start with a simple conversation. Let’s talk!

OUR PROCESS

Step 1: Measure

  • Introductory conversation to identify objectives and review existing systems and supports
  • Conduct efficient data privacy and security assessments

Step 2: Identify

  • Evaluate district’s compliance with NIST CSF Framework and Part 121 requirements
  • Gap analysis consultation & review

Step 3: Document

  • Present current state of existing policy and documentation; identify vulnerabilities and threats
  • Develop action plan and risk management report

Step 4: Act

  • Remediate security and privacy gaps through prioritized alignment with NIST CSF Framework and action plan

  • Review and report

Our K-12 PracticeTeam

Headshot of Garnet River CEO and President Steve Richards

Steve Richards

CEO & Program Leader

Photo of Garnet River CISSP and K-12 Data Security VP Michael Weisberg

Michael Weisberg

CISSIP, VP of Information Security

Photo of Garnet River Cloud/Infrastructure practice lead and K-12 data security program technical architect Mike Donnelly

Mike Donnelly

Technical Architect

Photo of Garnet River k-12 data security program information security engineer Nate Tunningley

Nate Tunningley

Information Security Engineer