Member Resource Guide
The Member Resource Guide provides links to a variety of websites* on school risk management and loss control.
School Safety
- Five Facts About Mass Shootings in K-12 Schools (USDOJ)
- Collaborating With K-12 Administrators: Engaging Leadership in School Emergency Operations Plans (USDOE)
- Community Relations Service: Educational Organizations (USDOJ)
- Preventing and Responding to Bias and Hate Incidents in K-12 Educational Settings: A Toolkit for School & Community Leaders (USDOJ)
- Protecting Kids Online
- Additional SchoolSafety.gov Resources
Safety
- Consumer Product Safety Commission
- National Fire Protection Association
- National School Safety and Security Services
- North Carolina Office of the State Fire Marshal
- Occupational Safety and Health Administration
Security & Violence Prevention
- National Association of School Resource Officers
- National Association of School Safety and Law Enforcement Officials
- North Carolina Department of Public Safety
- University of Colorado-Boulder Center for the Study and Prevention of Violence
Terrorism
Emergency Management
Cyber Security
Center for Internet Security Critical Security Controls Version 8
The CIS Critical Security Controls (CIS Controls) are a prioritized set of safeguards to mitigate the most prevalent cyber-attacks against systems and networks. They are mapped to and referenced by multiple legal, regulatory, and policy frameworks. Movement to cloud-based computing, virtualization, mobility, outsourcing, Work-from-Home, and changing attacker tactics prompted the update and supports an enterprise’s security as they move to both fully cloud and hybrid environments.
Cybersecurity and Infrastructure Security Agency Vulnerability Scanning
CISA’s Vulnerability Scanning (VS) is persistent “internet scanning-as-a-service”. VS service continuously assesses the health of your internet-accessible assets by checking for known vulnerabilities, weak configurations—or configuration errors—and suboptimal security practices. VS service also recommends ways to enhance security through modern web and email standards.
U.S. Department of Education K-12 Digital Infrastructure Brief: Defensible & Resilient
This product provides K-12 districts across our communities a starting place to understand the importance of securing our digital infrastructure and provides steps schools can take today to keep their systems safe.
Nationwide Cybersecurity Review
The NCSR is a no-cost, anonymous, annual self-assessment. All states (and agencies), local governments (and departments), tribal nations, and territorial (SLTT) governments are encouraged to participate. It is designed to measure gaps and capabilities of SLTT governments’ cybersecurity programs and is based on the National Institute of Standards and Technology Cybersecurity Framework.
Protecting Our Future: Partnering to Safeguard K-12 Organizations from Cybersecurity Threats
This report provides recommendations and resources to help K-12 schools and school districts address systemic cybersecurity risk. It also provides insight into the current threat landscape specific to the K-12 community and offers actionable steps school leaders can take to strengthen their cyber posture.
NC Department of Information Technology Information & Risk Management Services
The Enterprise Security and Risk Management Office offers several services to help executive branch agencies develop, deliver and maintain a cybersecurity program that safeguards data and supporting infrastructure against unauthorized use, disclosure, modification, damage or loss.
Cybersecurity Resources for PSUs by Shannon Tufts
Shannon Tufts is an expert on the intersection of law and technology in the public sector, cybersecurity, cloud computing, social media, and strategic IT investments, as well as CIO leadership and development.
Reporting a Cybersecurity Incident:
- NC Department of Information Technology
- NC Emergency Management 24-Hour Watch Center: NCEOG@ncdps.gov or at 1-800-858-0368
- NCLGISA Strike Team: itstriketeam@nclgisa.org or (919) 726-6508 (monitored 24/7)
- FBI Internet Crime Complaint Center (IC3)
If you have a situation involving financial fraud, please contact the FBI first because there is a ~72 hour window for fraud recovery before it is moved off-shore. - NC Department of Justice
- Identity Theft Protection Act, N.C.G.S. Chapter 75, Article 2A
- Data Breach Notification to Affected Persons Requirement, N.C.G.S. § 75-65 (applicable to public schools through N.C.G.S. § 132-1.10)
- Prohibition on ransomware payments, N.C.G.S. § 143-800
- Requirement that cybersecurity incidents be reported to NCDIT, N.C.G.S. § 143B-1379(c)
Other Related Links
Athletics, Physical Education, and Recess
Student Health
Weather and Natural Disasters
*NCSBA and NCSBT do not endorse any aspect of any of the websites listed under and/or on the webpages of any of the above headings, including but not limited to the applicability or truthfulness of the websites’ content or reliance thereon. NCSBA and NCSBT expressly disclaim any and all liability arising out of or in any way related to the websites, navigation to or from the websites, and the acts or omissions of the organizations which websites are listed under and/or on the webpages of any of the above headings.