All bodies  ›  Legislative Analyst's Office  ›  The 2022-23 Budget: Cybersecurity at the California Community Colleges

LAO

The 2022-23 Budget: Cybersecurity at the California Community Colleges

Legislative Analyst's Office · lao-4582 · Post · 2022-03-30

Read the report at Legislative Analyst's Office ↗

The 2022-23 Budget: Cybersecurity at the California Community Colleges MARCH 2022 Summary. The Governor’s budget provides California Department of Technology (CDT) and a total of $100 million Proposition 98 General federal government. In addition, CDT and the Fund ($25 million ongoing, $75 million one time) California Military Department (and, in some cases, for the California Community Colleges (CCC) to third party vendors) conduct audits to bolster upgrade their cybersecurity. Of the proposed state agencies’ compliance with cybersecurity funding, $92 million would be allocated to standards. In contrast, the state does not require colleges, with the remaining funding intended for community colleges to follow specific standards, specified systemwide services. We recommend and community colleges are not routinely subject to the Legislature approve $23 million ongoing oversight or audits of their cybersecurity programs for more district cybersecurity staff and direct and processes. As locally governed entities, the Chancellor’s Office to develop an allocation community colleges also make their own decisions method for these funds that ensures a minimum about budgeting for technology and data security, level of funding for each district. For the remaining including setting their associated staffing levels $2 million ongoing, we recommend requesting and deciding how much to spend on hardware better information, particularly on the roles and and software purchases. Colleges typically use responsibilities of each of the proposed systemwide apportionments (general-purpose monies) to fund service providers. For the $69 million in one-time cybersecurity costs. funding proposed for the colleges, we recommend CCC Information Security Center Offers Some the Legislature direct the Chancellor’s Office to Assistance to Colleges. Though colleges manage develop an allocation method that accounts for their own information security, certain systemwide not only colleges’ enrollment size but also their resources and tools are available to them through current level of cybersecurity preparedness. the CCC Technology Center, which is administered We also recommend requiring the Chancellor’s by Butte College. This center is funded by the Office to submit certain documentation that could state through a technology categorical program help guide legislative decisions regarding the supported with ongoing Proposition 98 General remaining one-time funds as well as any future Fund. In 2016-17, the center added a division, the cybersecurity funding. Information Security Center, focused primarily on cybersecurity issues. In 2021-22, the Information Introduction Security Center is receiving $3 million ongoing In this post, we provide background on Proposition 98 General Fund from the categorical cybersecurity issues at CCC, describe the program. The Information Security Center’s services Governor’s proposal to provide funding for include making available sample security plans various cybersecurity upgrades, provide our for colleges to adopt, offering vulnerability scans assessment of the Governor’s proposal, and make and risk analyses, providing recommendations associated recommendations. to colleges in the event of a data breach, and enhancing colleges’ security monitoring and Background “threat intelligence” (knowledge that helps identify Colleges Are Largely Responsible for Their security threats). The funding also supports a CCC Cybersecurity. The state subjects most state systemwide committee that discusses current agencies, including the CCC Chancellor’s Office, cybersecurity threats facing colleges. to cybersecurity standards developed by the 2022-23 Budget Series 1 Colleges Have Seen a Recent Surge in Fraud Colleges Would Have to Meet Certain Attempts. CCC has a common online admissions Requirements to Receive Funds. Although not application known as CCCApply. The Chancellor’s specified in budget or trailer bill language, the Office contracts with the CCC Technology Center to Chancellor’s Office indicates that it plans to require administer the application platform. Colleges upload districts to meet certain requirements as a condition completed applications and process them. Through of receiving any of the proposed ongoing or one-time CCCApply, bad actors attempt to submit fraudulent cybersecurity funding. Specifically, colleges would applications—sometimes hundreds at a time at be required to (1) complete an annual cybersecurity multiple colleges using automated technology. self-assessment based on state and national Upon acceptance, these bad actors can register for standards and identify needed improvements; classes, allowing them potentially to gain access (2) submit quarterly status updates on progress to certain financial aid benefits. Though some toward meeting state and national standards; fraudulent activity occurred prior to the pandemic, (3) submit a monthly report on any incidents of such attempts increased notably with the availability application, enrollment, and financial aid fraud; and of a significant amount of federal relief funds for (4) submit a report of all cybersecurity incidents student emergency financial aid. that resulted in a breach of personally identifiable Colleges Face Other Threats to Information information or disruption of services (such as Security. Colleges maintain databases with sensitive through ransomware). The Chancellor’s Office information on students (and their families) and indicates that these requirements would be made staff. In addition, colleges operate other technology through both systemwide guidance and changes in such as e-mail and phone systems. These types of CCC regulations. systems are routinely the subject of cyberattacks, Budget Includes Two Proposed Positions at ransomware, and other malware of varying scales. the Chancellor’s Office in Support of Initiative. In Recently, several community colleges reported addition to the $100 million Proposition 98 General major cyberattacks on their information and other Fund, the Governor’s budget includes a proposal technology systems. to add two new positions at the Chancellor’s Office and an associated $314,000 non-Proposition 98 Proposal General Fund to support CCC cybersecurity efforts. Governor Proposes a Package of This staffing proposal is part of a larger package Cybersecurity Upgrades for Colleges. The of staffing proposals that we analyze in a separate package totals $100 million Proposition 98 General post, The 2022-23 Budget: CCC Chancellor’s Fund, consisting of $25 million ongoing and Office Staffing. $75 million one time. The $25 million ongoing is Assessment primarily for college cybersecurity staffing, whereas the $75 million one time is primarily for security Given State’s “Fifty Percent Law,” Merit to network upgrades, general security software, Having an Ongoing Cybersecurity Categorical and anti-fraud technology. Of the proposed Program. Given the highly sensitive nature of funding, $92 million would be allocated directly the data that colleges maintain, together with the to colleges. The Chancellor’s Office would award recent cyberattacks, colleges have a local interest the remaining $8 million via contracts with certain in dedicating staff to cybersecurity issues and districts to provide specified systemwide services putting in place robust defensive systems. Colleges, and oversight. The main goal of this package of however, receive no state funding specifically for proposals is to enhance colleges’ information these purposes. Moreover, under state law, colleges security to protect against enrollment scams and must use at least half of their general-purpose hacking. A secondary goal is to improve the user funding on salaries and benefits of classroom faculty experience for students applying to CCC. Figure 1 and aides. Spending on other college staff, including details the various components of the Governor’s information technology (IT) personnel, counts against CCC cybersecurity package and describes how the 50 percent requirement, as do other costs, funds would be allocated for each component. such as anti-fraud software licenses and consulting 2022-23 Budget Series 2 services with cybersecurity experts. Colleges that Merit to Enhanced Ongoing State-Level fall below the 50 percent mark can be subject Role for CCC Cybersecurity Issues... Beyond to financial penalties by the Chancellor’s Office. bolstering local cybersecurity staffing on an Because of this law, some colleges might refrain ongoing basis, we believe a stronger state-level from using sufficient apportionment funding to role also is worth considering. While CCC has achieve adequate ongoing cybersecurity protection. an advisory committee to discuss cybersecurity Given this consideration, we think the Governor’s threats and incidents systemwide, community proposal to provide ongoing cybersecurity colleges currently lack a strong central information categorical program funds, which would not be hub to detect patterns and promote coordination. subject to the fifty percent law, is reasonable. Colleges do not have to report incidents of Figure 1 Governor Provides Mix of Ongoing and One-Time Funds for Local and State-Level Purposes Proposition 98 General Fund (In Millions) Proposed Description Amount Purpose of Funding Funding Allocation Method Ongoing Funds District cybersecurity staff $23.0 Hire staff to monitor and combat Funding for each district. (No cyberattacks and fraud. (Districts with specific formula is proposed.) limited access to these staff may share staff on a regional basis.) Statewide cybersecurity teams 1.0 Contract with independent consultants Chancellor’s Office to contract to assess district compliance with with a district to administer on cybersecurity standards. behalf of CCC system. System-level oversight 0.5 Provide direction and oversight to district Chancellor’s Office to contract (and regional) staff and statewide with a district to administer on cybersecurity teams on cybersecurity behalf of CCC system. standards and incidence response. Provide support to colleges needing assistance. CCCApply operations 0.5 Cover hosting and maintenance costs. Chancellor’s Office to contract with CCC Technology Center (Butte College). Subtotal ($25.0) One-Time Funds College network security upgrades $40.0 Obtain assessments of system vulnerabilities. Funding for each college based Purchase hardware and software to on enrollment size, with larger prevent cyberattacks. colleges receiving a larger amount. College enrollment anti-fraud 29.0 Purchase fraudulent application detection Funding for each college based technology software. Provide anti-fraud training for staff. on enrollment size, with larger colleges receiving a larger amount. CCCApply upgrades 5.0 Redesign platform (with input from student Chancellor’s Office to contract focus groups), adding and testing security with CCC Technology Center features. Streamline number of questions (Butte College). applicants are required to answer. Add capacity to report data on applicants that started but did not complete application. CCCApply training 1.0 Once CCCApply upgrades are completed, Chancellor’s Office to contract provide training to college staff. with a district to administer on behalf of CCC system. Subtotal ($75.0) Total $100.0 2022-23 Budget Series 3 cyberattacks or suspected fraud to the Chancellor’s preparedness and anti-fraud detection capabilities. Office. This is the case even though scams Whereas some colleges have staff dedicated and cyberattacks often target multiple colleges to cybersecurity and relatively sophisticated simultaneously. Currently, districts also do not defensive systems in place, other colleges rely on need to show that they are either meeting state and IT generalists that lack expertise in cybersecurity. national cybersecurity standards or have adopted Potentially, the state could strategically allocate plans and are making progress toward meeting funding, including the proposed one-time funding, these standards. Providing more state direction to assist colleges in obtaining a certain level of and support in these areas could lead to overall cybersecurity preparedness. improvements in colleges’ cybersecurity programs ...But Opportunities to Improve How One-Time and processes. Funds Would Be Allocated to Colleges. The ...But Potential Issues With How New Governor’s proposed approach of allocating the Oversight and Support Model Would Work. one-time funds to colleges based on enrollment size The Governor’s ongoing cybersecurity components has some merit, as potential cybersecurity and fraud include (1) creating statewide cybersecurity risks can increase based on the technology usage teams, (2) funding a system-level entity that at a college. A better approach, though, would be oversees both local colleges and the statewide to base allocations on need as well—providing more cybersecurity teams, and (3) providing two new funding to colleges that need more cybersecurity positions at Chancellor’s Office. This approach upgrades. Though there currently is no inventory of creates a complex organizational structure in where each college is relative to state and national which exactly what functions and role each entity standards and what each would need to do to meet would have is unclear. In some cases, the roles standards, the Chancellor’s Office is in the process and responsibilities of the various entities appear of identifying the current preparedness level for each to overlap. For example, under the Governor’s college. The Chancellor’s Office believes it might proposal, the statewide cybersecurity teams would have the initial inventory prepared by June 2022. monitor colleges’ compliance with cybersecurity Such an inventory could be used to track need and standards. Yet, the system-level oversight entity allocate a share of 2022-23 funding accordingly. also would be charged with monitoring standards Governor Proposes One-Time Funds for and providing support to colleges, in addition to Ongoing Purposes. Though some initial one-time providing direction and oversight to the statewide funding could help with initial cybersecurity cybersecurity teams. Moreover, the Chancellor’s upgrades among colleges, much of what the Office indicates it too would be charged with Governor has proposed as one-time costs are more overseeing the statewide cybersecurity teams. likely ongoing costs. Typically, a college would We also have concerns that the administration’s be expected to undergo independent security proposal could create a conflict of interest for assessments every few years, pay for network the system-level oversight entity, which, as security and anti-fraud software licenses annually, characterized by the Chancellor’s Office, would and make network upgrades periodically. As a result help colleges with implementation while at the same of these factors, the proposed level of ongoing time monitoring and holding colleges accountable funding for college cybersecurity and anti-fraud for what they implement. Moreover, it is unclear if detection likely is underestimated. Importantly, the the Chancellor’s Office’s goal is for the statewide administration and the Chancellor’s Office have cybersecurity teams to assess all colleges annually not yet identified what they believe to be entailed or instead some subset of districts, with a focus on in terms of funding to ensure colleges have a high-risk colleges. minimum level of ongoing cybersecurity and fraud Merit to Funding Cybersecurity Upgrades detection. Lacking clarity in this area, the existing at Colleges... Based on anecdotal information, budget back-up is inadequate, as it neither clearly the Chancellor’s Office has heard that community distinguishes one-time from ongoing costs nor colleges vary in terms of their cybersecurity includes detailed cost estimates. 2022-23 Budget Series 4 Administration Has Provided Incomplete $314,000 non-Proposition 98 General Fund) Information on CCCApply Proposal. The pending receipt of better information. Specifically, Governor’s cybersecurity packages includes we recommend the Legislature request the $6 million one time primarily to upgrade administration and Chancellor’s Office to clarify CCCApply’s anti-fraud features and provide related the specific role and functions of: (1) the existing college training, as well as $500,000 ongoing staff at the Information Security Center, (2) the for hosting and maintenance of the redesigned proposed statewide cybersecurity teams, (3) the portal. We concur with the administration that proposed system-level oversight body, and (4) the such enhancements are warranted and would have proposed two additional cybersecurity positions at systemwide benefits for colleges and students. The the Chancellor’s Office. As part of this reporting, amounts proposed by the administration, however, the Chancellor’s Office should clarify how the have only been partially justified. Specifically, of statewide cybersecurity teams would prioritize their the $6 million proposed for one-time purposes, work and how much workload they are expected to the administration has only provided workload accomplish annually given the proposed funding. justification for $3.4 million. The remaining Modify Allocation Methodology of One-Time $2.6 million in proposed costs either have no Funding for Colleges. We recommend the backup details or are labeled in documents Legislature appropriate the $69 million in provided to our office as “TBD” (to be determined). one-time funding for the colleges but direct the The administration does not provide any backup Chancellor’s Office to allocate this funding in a on how it estimated the ongoing cost. Without way that accounts not just for enrollment but also such information, the Legislature is unable to for need, with less prepared colleges receiving determine whether the proposed amount is justified somewhat more funding than more prepared to accomplish the administration’s objectives colleges of the same size. Colleges could use their for CCCApply. allocations for independent security assessments, network upgrades, software licenses, and related Recommendations technology costs. The Chancellor’s Office’s initial Approve Funds for College Cybersecurity inventory of colleges’ cybersecurity preparedness Staff. As a starting point, we recommend the levels could be used as a basis for the allocation Legislature approve the $23 million in ongoing of the one-time funds. As discussed below, funding for district cybersecurity staff. We think we recommend requiring the Chancellor’s the state has an interest in making sure every Office to work with districts and submit certain district has at least one staff person dedicated to information to the Legislature prior to release of the cybersecurity. Multi-college districts, however, may one-time funding. warrant more funding. We recommend directing Use Additional Information From Chancellor’s the Chancellor’s Office to develop an allocation Office to Guide Allocation and Future Funding method for these funds that ensures a minimum Decisions. Specifically, we recommend requiring level of funding for each district while accounting the Chancellor’s Office to submit documentation for any other relevant factors. (Districts with existing on (1) the basic requirements for colleges to cybersecurity staff could be permitted to use achieve a minimum level of security, (2) estimates their allocations to increase their number of staff of the associated one-time and ongoing costs, or improve their cybersecurity preparedness in and (3) a proposed formula for distributing the other ways.) one-time funding to colleges in accordance with Request Better Information on Proposed size as well as identified needs and costs. We State-Level Structure. We recommend recommend requiring the Chancellor’s Office to the Legislature postpone consideration of provide this documentation to the administration the $1.8 million in ongoing funding for the and Legislature by October 15, 2022, with the proposed state-level cybersecurity structure findings informing release of the one-time funds ($1.5 million Proposition 98 General Fund and as well as potential 2023-24 budget decisions. 2022-23 Budget Series 5 With better information, the Legislature not only Direct Administration to Provide Cost could identify how much one-time funding colleges Detail for CCCApply. Given the administration need but also the annual amount of state funding has provided workload justification for only needed to cover colleges’ ongoing cybersecurity $3.4 million in costs for CCCApply, we recommend costs. If more ongoing funding is provided in the the Legislature treat this amount as a starting future, we recommend the Legislature consider at point. We recommend the Legislature direct the that time how best to allocate the additional funding administration to provide full justification for the among colleges. Ideally, over the next few years, remaining $2.6 million one-time funding it proposes the Chancellor’s Office and colleges will learn more as well as the $500,000 in proposed ongoing about the main risk factors underlying cyberattacks costs. The Legislature could give the administration and enrollment fraud, such that the Legislature can until the May Revision to provide such information align funding increases with those risk factors and and use it to determine the amount to provide potential cost drivers. for 2022-23. 2022-23 Budget Series 6 2022-23 Budget Series 7 LAO PUBLICATIONS This post was prepared by Paul Steenhausen, with assistance from Brian Metzker, and reviewed by Jennifer Pacella and Anthony Simbol. The Legislative Analyst’s Office (LAO) is a nonpartisan office that provides fiscal and policy information and advice to the Legislature. 2022-23 Budget Series 8