CISA ships K-12 cyber resource package aligned to NIST framework
The getting-started guide is for administrators who don't know what MFA is; the 57-page implementation guide is for the practitioner who has to build the program. That split is the quiet concession that most districts still lack dedicated cybersecurity staff.
TL;DR
CISA released a K-12 Cybersecurity Foundations Resource Package on Aug. 12, bundling a getting-started guide for non-technical school administrators, a 57-page implementation guide for practitioners, and companion videos. The package maps its eight cybersecurity objectives to CISA's cross-sector Cybersecurity Performance Goals and the NIST cybersecurity framework, and advances Executive Order 14239 on state and local preparedness. It builds on the agency's 2023 K-12 report and toolkit, which were developed under the 2021 K-12 Cybersecurity Act, a statutory lineage that acknowledges what CISA has been saying since 2023: K-12 is target-rich and cyber-poor.
The package's structure is the editorial statement. CISA split the guidance into two tracks: one for administrators who may have never configured an authenticator app, and one for the security practitioners who already have. That bifurcation captures the actual state of K-12 cybersecurity better than any threat briefing could. More than one cyber incident per school day, on average (that's the baseline CISA itself cites) and yet most districts don't employ a dedicated cybersecurity professional.
The getting-started guide walks through four objectives: understanding prevalent threats, implementing basic protections, developing incident response, and building toward a mature program. It's written for people whose day job is running a school system. The implementation guide drills into four additional objectives (governance, asset management, continuous monitoring, and supply chain risk) each mapped explicitly to CPGs and the NIST CSF. That mapping matters: it gives a district's IT lead something to show a superintendent or school board, connecting tactical actions to a federal framework that carries weight in budget conversations.
The video companions and two-page fact sheets are the multiplier. CISA knows that a 57-page PDF, however well-structured, doesn't reach a superintendent between meetings. The fact sheets distill eight objectives into something that fits on a single sheet of paper, the format that actually gets read.
Nick Andersen, CISA's acting director, framed the package as advancing the agency's broader school safety mission. The connection to EO 14239 is real but thin, the executive order is about state and local preparedness writ large, and this package is one deliverable among many. The more meaningful lineage runs through the 2021 K-12 Cybersecurity Act, which required CISA to study the problem, and the 2023 "Protecting Our Future" report that followed. This package is the operationalization of those recommendations, three and a half years after the statutory mandate. For a sector that averages a cyber incident every school day, that's not fast. But the material is specific, free, and written for the people who actually have to use it.
Published ·Deep Fathom