WHAT TO REVIEW
12 technology areas that deserve a real assessment
A useful assessment should show leadership where child-related technology risk actually sits, which existing controls are already available, who owns them, and what should be fixed first before the organization buys additional tools.
Identity lifecycle
Staff, volunteer, contractor, seasonal-user, and administrator accounts; joiner/mover/leaver process; shared accounts; privileged access.
MFA and authentication
Whether important cloud, email, administrative, finance, and data systems use stronger authentication and secure recovery.
Devices and BYOD
Managed laptops and phones, personal-device access, updates, endpoint protection, encryption, screen locks, and local data.
Child-data inventory
Rosters, parent contacts, photos, video, medical or allergy information, attendance, location, payment, and other sensitive information.
Access and retention
Who needs each data set, where excessive access exists, how old records are removed, and whether data remains after a program ends.
Communication channels
Email, text, chat, social media, group platforms, personal accounts, disappearing messages, logging, and escalation paths.
Vendor and app risk
Registration, payments, learning, sports, background screening, cloud storage, communication, and other third-party systems.
AI tool use
Approved AI tools, staff use, child-data restrictions, training settings, human review, and whether sensitive records are entering consumer AI systems.
Backups and recovery
What is backed up, who can restore it, whether recovery has been tested, and how cloud data or critical files would be recovered.
Incident readiness
Account compromise, phishing, lost devices, inappropriate access, data exposure, vendor incidents, escalation, preservation, and communications.
Security awareness
Staff and volunteer training on phishing, impersonation, passwords, sensitive data, AI use, and how to report concerns quickly.
Evidence and accountability
Policies, owners, access reviews, vendor records, training evidence, incident records, and proof that controls operate over time.