Education Law 2-d requires educational agencies to adopt a policy on data security and privacy that aligns with the state’s data security and privacy standard. The Department adopted the National Institute for Standards and Technology Cybersecurity Framework (NIST CSF) Version 2.0 as the standard for educational agencies. NIST CSF 2.0 organizes cybersecurity activities into six core functions that help education organizations manage risk, protect data, and strengthen system reliability and resilience.
The NIST CSF 2.0 tool was developed to enable school districts to track their work on the NIST Cybersecurity Framework. The tool provides a means for assessing the district's current profile against the RIC One community profile for Ed Law 2-d compliance.
RIC One, in collaboration with NYSED and statewide stakeholders, developed the NYS K-12 NIST CSF 2.0 Community Profile to support consistent and practical cybersecurity practices across New York State's K-12 education community. NIST CSF 2.0 was reviewed to identify outcomes most relevant to NYS K-12 educational agencies with a focus on addressing common and high-impact cyber risks, achievability, and operational relevance.
In addition to aligning the community profile, the NIST 2.0 Tool includes an area for recording evidence of the current profile, action plans for reaching the target, tracking changes, and providing downloadable reports.
To log into the NIST 2.0 Assessment Tool, please go here.
If you do not have a district administrator account and would like one, please reach out to our service contact!
NIST CSF Version 1.1 Resources