LAO
The 2022-23 Budget: Cybersecurity at the California Community Colleges
Read the report at Legislative Analyst's Office ↗
The 2022-23 Budget:
Cybersecurity at the
California Community Colleges
MARCH 2022
Summary. The Governor’s budget provides California Department of Technology (CDT) and
a total of $100 million Proposition 98 General federal government. In addition, CDT and the
Fund ($25 million ongoing, $75 million one time) California Military Department (and, in some cases,
for the California Community Colleges (CCC) to third party vendors) conduct audits to bolster
upgrade their cybersecurity. Of the proposed state agencies’ compliance with cybersecurity
funding, $92 million would be allocated to standards. In contrast, the state does not require
colleges, with the remaining funding intended for community colleges to follow specific standards,
specified systemwide services. We recommend and community colleges are not routinely subject to
the Legislature approve $23 million ongoing oversight or audits of their cybersecurity programs
for more district cybersecurity staff and direct and processes. As locally governed entities,
the Chancellor’s Office to develop an allocation community colleges also make their own decisions
method for these funds that ensures a minimum about budgeting for technology and data security,
level of funding for each district. For the remaining including setting their associated staffing levels
$2 million ongoing, we recommend requesting and deciding how much to spend on hardware
better information, particularly on the roles and and software purchases. Colleges typically use
responsibilities of each of the proposed systemwide apportionments (general-purpose monies) to fund
service providers. For the $69 million in one-time cybersecurity costs.
funding proposed for the colleges, we recommend CCC Information Security Center Offers Some
the Legislature direct the Chancellor’s Office to Assistance to Colleges. Though colleges manage
develop an allocation method that accounts for their own information security, certain systemwide
not only colleges’ enrollment size but also their resources and tools are available to them through
current level of cybersecurity preparedness. the CCC Technology Center, which is administered
We also recommend requiring the Chancellor’s by Butte College. This center is funded by the
Office to submit certain documentation that could state through a technology categorical program
help guide legislative decisions regarding the supported with ongoing Proposition 98 General
remaining one-time funds as well as any future Fund. In 2016-17, the center added a division, the
cybersecurity funding. Information Security Center, focused primarily on
cybersecurity issues. In 2021-22, the Information
Introduction
Security Center is receiving $3 million ongoing
In this post, we provide background on
Proposition 98 General Fund from the categorical
cybersecurity issues at CCC, describe the
program. The Information Security Center’s services
Governor’s proposal to provide funding for
include making available sample security plans
various cybersecurity upgrades, provide our
for colleges to adopt, offering vulnerability scans
assessment of the Governor’s proposal, and make
and risk analyses, providing recommendations
associated recommendations.
to colleges in the event of a data breach, and
enhancing colleges’ security monitoring and
Background
“threat intelligence” (knowledge that helps identify
Colleges Are Largely Responsible for Their
security threats). The funding also supports a CCC
Cybersecurity. The state subjects most state
systemwide committee that discusses current
agencies, including the CCC Chancellor’s Office,
cybersecurity threats facing colleges.
to cybersecurity standards developed by the
2022-23 Budget Series
1
Colleges Have Seen a Recent Surge in Fraud Colleges Would Have to Meet Certain
Attempts. CCC has a common online admissions Requirements to Receive Funds. Although not
application known as CCCApply. The Chancellor’s specified in budget or trailer bill language, the
Office contracts with the CCC Technology Center to Chancellor’s Office indicates that it plans to require
administer the application platform. Colleges upload districts to meet certain requirements as a condition
completed applications and process them. Through of receiving any of the proposed ongoing or one-time
CCCApply, bad actors attempt to submit fraudulent cybersecurity funding. Specifically, colleges would
applications—sometimes hundreds at a time at be required to (1) complete an annual cybersecurity
multiple colleges using automated technology. self-assessment based on state and national
Upon acceptance, these bad actors can register for standards and identify needed improvements;
classes, allowing them potentially to gain access (2) submit quarterly status updates on progress
to certain financial aid benefits. Though some toward meeting state and national standards;
fraudulent activity occurred prior to the pandemic, (3) submit a monthly report on any incidents of
such attempts increased notably with the availability application, enrollment, and financial aid fraud; and
of a significant amount of federal relief funds for (4) submit a report of all cybersecurity incidents
student emergency financial aid. that resulted in a breach of personally identifiable
Colleges Face Other Threats to Information information or disruption of services (such as
Security. Colleges maintain databases with sensitive through ransomware). The Chancellor’s Office
information on students (and their families) and indicates that these requirements would be made
staff. In addition, colleges operate other technology through both systemwide guidance and changes in
such as e-mail and phone systems. These types of CCC regulations.
systems are routinely the subject of cyberattacks, Budget Includes Two Proposed Positions at
ransomware, and other malware of varying scales. the Chancellor’s Office in Support of Initiative. In
Recently, several community colleges reported addition to the $100 million Proposition 98 General
major cyberattacks on their information and other Fund, the Governor’s budget includes a proposal
technology systems. to add two new positions at the Chancellor’s Office
and an associated $314,000 non-Proposition 98
Proposal
General Fund to support CCC cybersecurity efforts.
Governor Proposes a Package of This staffing proposal is part of a larger package
Cybersecurity Upgrades for Colleges. The of staffing proposals that we analyze in a separate
package totals $100 million Proposition 98 General post, The 2022-23 Budget: CCC Chancellor’s
Fund, consisting of $25 million ongoing and Office Staffing.
$75 million one time. The $25 million ongoing is
Assessment
primarily for college cybersecurity staffing, whereas
the $75 million one time is primarily for security Given State’s “Fifty Percent Law,” Merit to
network upgrades, general security software, Having an Ongoing Cybersecurity Categorical
and anti-fraud technology. Of the proposed Program. Given the highly sensitive nature of
funding, $92 million would be allocated directly the data that colleges maintain, together with the
to colleges. The Chancellor’s Office would award recent cyberattacks, colleges have a local interest
the remaining $8 million via contracts with certain in dedicating staff to cybersecurity issues and
districts to provide specified systemwide services putting in place robust defensive systems. Colleges,
and oversight. The main goal of this package of however, receive no state funding specifically for
proposals is to enhance colleges’ information these purposes. Moreover, under state law, colleges
security to protect against enrollment scams and must use at least half of their general-purpose
hacking. A secondary goal is to improve the user funding on salaries and benefits of classroom faculty
experience for students applying to CCC. Figure 1 and aides. Spending on other college staff, including
details the various components of the Governor’s information technology (IT) personnel, counts against
CCC cybersecurity package and describes how the 50 percent requirement, as do other costs,
funds would be allocated for each component. such as anti-fraud software licenses and consulting
2022-23 Budget Series
2
services with cybersecurity experts. Colleges that Merit to Enhanced Ongoing State-Level
fall below the 50 percent mark can be subject Role for CCC Cybersecurity Issues... Beyond
to financial penalties by the Chancellor’s Office. bolstering local cybersecurity staffing on an
Because of this law, some colleges might refrain ongoing basis, we believe a stronger state-level
from using sufficient apportionment funding to role also is worth considering. While CCC has
achieve adequate ongoing cybersecurity protection. an advisory committee to discuss cybersecurity
Given this consideration, we think the Governor’s threats and incidents systemwide, community
proposal to provide ongoing cybersecurity colleges currently lack a strong central information
categorical program funds, which would not be hub to detect patterns and promote coordination.
subject to the fifty percent law, is reasonable. Colleges do not have to report incidents of
Figure 1
Governor Provides Mix of Ongoing and
One-Time Funds for Local and State-Level Purposes
Proposition 98 General Fund (In Millions)
Proposed
Description Amount Purpose of Funding Funding Allocation Method
Ongoing Funds
District cybersecurity staff $23.0 Hire staff to monitor and combat Funding for each district. (No
cyberattacks and fraud. (Districts with specific formula is proposed.)
limited access to these staff may share
staff on a regional basis.)
Statewide cybersecurity teams 1.0 Contract with independent consultants Chancellor’s Office to contract
to assess district compliance with with a district to administer on
cybersecurity standards. behalf of CCC system.
System-level oversight 0.5 Provide direction and oversight to district Chancellor’s Office to contract
(and regional) staff and statewide with a district to administer on
cybersecurity teams on cybersecurity behalf of CCC system.
standards and incidence response. Provide
support to colleges needing assistance.
CCCApply operations 0.5 Cover hosting and maintenance costs. Chancellor’s Office to contract
with CCC Technology Center
(Butte College).
Subtotal ($25.0)
One-Time Funds
College network security upgrades $40.0 Obtain assessments of system vulnerabilities. Funding for each college based
Purchase hardware and software to on enrollment size, with larger
prevent cyberattacks. colleges receiving a larger
amount.
College enrollment anti-fraud 29.0 Purchase fraudulent application detection Funding for each college based
technology software. Provide anti-fraud training for staff. on enrollment size, with larger
colleges receiving a larger
amount.
CCCApply upgrades 5.0 Redesign platform (with input from student Chancellor’s Office to contract
focus groups), adding and testing security with CCC Technology Center
features. Streamline number of questions (Butte College).
applicants are required to answer. Add
capacity to report data on applicants that
started but did not complete application.
CCCApply training 1.0 Once CCCApply upgrades are completed, Chancellor’s Office to contract
provide training to college staff. with a district to administer on
behalf of CCC system.
Subtotal ($75.0)
Total $100.0
2022-23 Budget Series
3
cyberattacks or suspected fraud to the Chancellor’s preparedness and anti-fraud detection capabilities.
Office. This is the case even though scams Whereas some colleges have staff dedicated
and cyberattacks often target multiple colleges to cybersecurity and relatively sophisticated
simultaneously. Currently, districts also do not defensive systems in place, other colleges rely on
need to show that they are either meeting state and IT generalists that lack expertise in cybersecurity.
national cybersecurity standards or have adopted Potentially, the state could strategically allocate
plans and are making progress toward meeting funding, including the proposed one-time funding,
these standards. Providing more state direction to assist colleges in obtaining a certain level of
and support in these areas could lead to overall cybersecurity preparedness.
improvements in colleges’ cybersecurity programs ...But Opportunities to Improve How One-Time
and processes. Funds Would Be Allocated to Colleges. The
...But Potential Issues With How New Governor’s proposed approach of allocating the
Oversight and Support Model Would Work. one-time funds to colleges based on enrollment size
The Governor’s ongoing cybersecurity components has some merit, as potential cybersecurity and fraud
include (1) creating statewide cybersecurity risks can increase based on the technology usage
teams, (2) funding a system-level entity that at a college. A better approach, though, would be
oversees both local colleges and the statewide to base allocations on need as well—providing more
cybersecurity teams, and (3) providing two new funding to colleges that need more cybersecurity
positions at Chancellor’s Office. This approach upgrades. Though there currently is no inventory of
creates a complex organizational structure in where each college is relative to state and national
which exactly what functions and role each entity standards and what each would need to do to meet
would have is unclear. In some cases, the roles standards, the Chancellor’s Office is in the process
and responsibilities of the various entities appear of identifying the current preparedness level for each
to overlap. For example, under the Governor’s college. The Chancellor’s Office believes it might
proposal, the statewide cybersecurity teams would have the initial inventory prepared by June 2022.
monitor colleges’ compliance with cybersecurity Such an inventory could be used to track need and
standards. Yet, the system-level oversight entity allocate a share of 2022-23 funding accordingly.
also would be charged with monitoring standards Governor Proposes One-Time Funds for
and providing support to colleges, in addition to Ongoing Purposes. Though some initial one-time
providing direction and oversight to the statewide funding could help with initial cybersecurity
cybersecurity teams. Moreover, the Chancellor’s upgrades among colleges, much of what the
Office indicates it too would be charged with Governor has proposed as one-time costs are more
overseeing the statewide cybersecurity teams. likely ongoing costs. Typically, a college would
We also have concerns that the administration’s be expected to undergo independent security
proposal could create a conflict of interest for assessments every few years, pay for network
the system-level oversight entity, which, as security and anti-fraud software licenses annually,
characterized by the Chancellor’s Office, would and make network upgrades periodically. As a result
help colleges with implementation while at the same of these factors, the proposed level of ongoing
time monitoring and holding colleges accountable funding for college cybersecurity and anti-fraud
for what they implement. Moreover, it is unclear if detection likely is underestimated. Importantly, the
the Chancellor’s Office’s goal is for the statewide administration and the Chancellor’s Office have
cybersecurity teams to assess all colleges annually not yet identified what they believe to be entailed
or instead some subset of districts, with a focus on in terms of funding to ensure colleges have a
high-risk colleges. minimum level of ongoing cybersecurity and fraud
Merit to Funding Cybersecurity Upgrades detection. Lacking clarity in this area, the existing
at Colleges... Based on anecdotal information, budget back-up is inadequate, as it neither clearly
the Chancellor’s Office has heard that community distinguishes one-time from ongoing costs nor
colleges vary in terms of their cybersecurity includes detailed cost estimates.
2022-23 Budget Series
4
Administration Has Provided Incomplete $314,000 non-Proposition 98 General Fund)
Information on CCCApply Proposal. The pending receipt of better information. Specifically,
Governor’s cybersecurity packages includes we recommend the Legislature request the
$6 million one time primarily to upgrade administration and Chancellor’s Office to clarify
CCCApply’s anti-fraud features and provide related the specific role and functions of: (1) the existing
college training, as well as $500,000 ongoing staff at the Information Security Center, (2) the
for hosting and maintenance of the redesigned proposed statewide cybersecurity teams, (3) the
portal. We concur with the administration that proposed system-level oversight body, and (4) the
such enhancements are warranted and would have proposed two additional cybersecurity positions at
systemwide benefits for colleges and students. The the Chancellor’s Office. As part of this reporting,
amounts proposed by the administration, however, the Chancellor’s Office should clarify how the
have only been partially justified. Specifically, of statewide cybersecurity teams would prioritize their
the $6 million proposed for one-time purposes, work and how much workload they are expected to
the administration has only provided workload accomplish annually given the proposed funding.
justification for $3.4 million. The remaining Modify Allocation Methodology of One-Time
$2.6 million in proposed costs either have no Funding for Colleges. We recommend the
backup details or are labeled in documents Legislature appropriate the $69 million in
provided to our office as “TBD” (to be determined). one-time funding for the colleges but direct the
The administration does not provide any backup Chancellor’s Office to allocate this funding in a
on how it estimated the ongoing cost. Without way that accounts not just for enrollment but also
such information, the Legislature is unable to for need, with less prepared colleges receiving
determine whether the proposed amount is justified somewhat more funding than more prepared
to accomplish the administration’s objectives colleges of the same size. Colleges could use their
for CCCApply. allocations for independent security assessments,
network upgrades, software licenses, and related
Recommendations
technology costs. The Chancellor’s Office’s initial
Approve Funds for College Cybersecurity
inventory of colleges’ cybersecurity preparedness
Staff. As a starting point, we recommend the
levels could be used as a basis for the allocation
Legislature approve the $23 million in ongoing
of the one-time funds. As discussed below,
funding for district cybersecurity staff. We think
we recommend requiring the Chancellor’s
the state has an interest in making sure every
Office to work with districts and submit certain
district has at least one staff person dedicated to
information to the Legislature prior to release of the
cybersecurity. Multi-college districts, however, may
one-time funding.
warrant more funding. We recommend directing
Use Additional Information From Chancellor’s
the Chancellor’s Office to develop an allocation
Office to Guide Allocation and Future Funding
method for these funds that ensures a minimum
Decisions. Specifically, we recommend requiring
level of funding for each district while accounting
the Chancellor’s Office to submit documentation
for any other relevant factors. (Districts with existing
on (1) the basic requirements for colleges to
cybersecurity staff could be permitted to use
achieve a minimum level of security, (2) estimates
their allocations to increase their number of staff
of the associated one-time and ongoing costs,
or improve their cybersecurity preparedness in
and (3) a proposed formula for distributing the
other ways.)
one-time funding to colleges in accordance with
Request Better Information on Proposed
size as well as identified needs and costs. We
State-Level Structure. We recommend
recommend requiring the Chancellor’s Office to
the Legislature postpone consideration of
provide this documentation to the administration
the $1.8 million in ongoing funding for the
and Legislature by October 15, 2022, with the
proposed state-level cybersecurity structure
findings informing release of the one-time funds
($1.5 million Proposition 98 General Fund and
as well as potential 2023-24 budget decisions.
2022-23 Budget Series
5
With better information, the Legislature not only Direct Administration to Provide Cost
could identify how much one-time funding colleges Detail for CCCApply. Given the administration
need but also the annual amount of state funding has provided workload justification for only
needed to cover colleges’ ongoing cybersecurity $3.4 million in costs for CCCApply, we recommend
costs. If more ongoing funding is provided in the the Legislature treat this amount as a starting
future, we recommend the Legislature consider at point. We recommend the Legislature direct the
that time how best to allocate the additional funding administration to provide full justification for the
among colleges. Ideally, over the next few years, remaining $2.6 million one-time funding it proposes
the Chancellor’s Office and colleges will learn more as well as the $500,000 in proposed ongoing
about the main risk factors underlying cyberattacks costs. The Legislature could give the administration
and enrollment fraud, such that the Legislature can until the May Revision to provide such information
align funding increases with those risk factors and and use it to determine the amount to provide
potential cost drivers. for 2022-23.
2022-23 Budget Series
6
2022-23 Budget Series
7
LAO PUBLICATIONS
This post was prepared by Paul Steenhausen, with assistance from Brian Metzker, and reviewed by Jennifer Pacella
and Anthony Simbol. The Legislative Analyst’s Office (LAO) is a nonpartisan office that provides fiscal and policy
information and advice to the Legislature.
2022-23 Budget Series
8