Preparing for a Florida school district cybersecurity audit
Published September 4, 2026
The Florida Auditor General's operational audits of district school boards include a review of information technology controls, and the findings in that section have a familiar shape from one district to the next. This article describes the recurring finding areas, what the auditor asks for in each, and how to have the records ready before the request.
Nothing here predicts what an auditor will find at your district or promises a clean report. The audit is the auditor's judgment. What a district controls is how complete and how current its records are when the request comes.
The recurring finding areas
Privileged and elevated access. The auditor asks for a current listing of accounts with administrator or full update rights in each significant system, the date that listing was last reviewed, and who signed off on the review. The finding, when it comes, is usually that the review was not done, was not documented, or left accounts in place that no longer needed the access.
Access to sensitive personal information. Which roles can reach records holding personal information about students and staff, and whether those roles were reviewed. The question is not whether the data is protected in general but whether the district can show who can reach it and that someone checked.
Terminated employee access. How quickly accounts are disabled after someone leaves. The record that answers this is the termination list next to the directory: separation date, account disable date, and the exceptions explained. The number the auditor is interested in is the lag between the two.
Comprehensive IT risk assessment. Whether the district has assessed the risks across its whole technology environment, rather than for one system, and when. A dated assessment against a recognized framework is the record.
Documented IT security standard. The adopted policies and written procedures, with versions and the date each was last reviewed. An inventory of what exists, with dates, answers this before the auditor has to ask for each document.
Incident response plan. A current written plan for what the district does when something goes wrong, and the date it was last exercised. A plan that has never been practiced draws a finding even when it is well written.
Disaster recovery. A recovery plan and the date of the last successful test in which data was actually restored from backup. As with incident response, the test date is what the auditor looks for.
Why the same findings keep coming back
Each of these areas depends on a routine, not a project. Access reviews, termination reconciliation, restore tests, and plan exercises all have to happen on a schedule and leave a dated record each time. A district that does each of them once, in the month before an audit, has a record with one entry. A district that does them quarterly has a history, and a history is what closes the finding.
Small IT departments are not short on the practices. They are short on the time to document them. The gap between "we do this" and "here is the dated record that we did this" is where most findings live.
A preparation checklist
- Pull the administrator listing for each significant system and record the review date and the reviewer. Do this quarterly from now on.
- Reconcile the termination list against the directory for the last year. Record the lag and explain each exception.
- Complete a dated assessment against NIST CSF 2.0 or the CIS Controls, covering the whole environment.
- Inventory the policies with version numbers and review dates. Note which ones are overdue.
- Schedule a tabletop exercise for the incident response plan and record the date, the scenario, and who took part.
- Run a restore test of a real system and record what was restored, when, by whom, and the result.
- Keep every record in a place a colleague could find. The audit request often lands on someone other than the person who did the work.
Where DistrictReady fits
DistrictReady's Auditor General readiness pack is organized around these same finding areas, one section each, with the district's own assessment answers, the evidence it holds, and any gaps flagged in place rather than left out. It is not an audit opinion and it does not determine whether the district meets any requirement. It puts the records in the order the auditor asks for them.