Skip to main content
Schoolyi

Product guides

Security questions for school management, ERP, and SIS

A school management software security question guide covering identity, access, data flows, suppliers, incidents, testing, and operational responsibility.

By Schoolyi Editorial Team10 min read

Treat security as an operating question

A security review should describe how the school will collect, use, access, share, retain, correct, export, and dispose of information. A brochure or general assurance statement may provide useful context, but it does not answer how the proposed workflow behaves for this school, its roles, and its jurisdictions.

Start with the data and decisions in the first phase. List student, guardian, staff, academic, attendance, assessment, fee, payment, document, communication, and support data only where the workflow needs them.

Questions about identity and access

Ask how users are created, verified, changed, suspended, and removed. Define access by role and relationship, then test least privilege with realistic users: teacher, administrator, finance staff, academic leader, family, campus owner, support user, and system administrator.

Ask which actions need approval, whether access is logged, how privileged access is reviewed, and what happens when a staff member changes role or leaves. A permission matrix should identify view, create, edit, approve, publish, export, and administer actions.

  • How is a user or family relationship verified?
  • Who approves a role and reviews it later?
  • Can a user access another campus or sibling record?
  • What is logged for a correction, export, or publication?
  • How is emergency access controlled and reviewed?

Questions about data flows and suppliers

Request a plain-language map of data moving between the platform, payment provider, communication service, identity service, integrations, support tools, backups, and subprocessors. Ask what fields move, for what purpose, under whose instruction, and how a transfer is stopped or corrected.

GOV.UK procurement guidance recommends checking data protection by design and default, minimum necessary data, access control, security measures, subprocessors, breach notification, and data return or deletion. Use those prompts in the contract and implementation review.

Questions about incidents and recovery

Ask who detects an incident, who is notified, what information is supplied, how access is contained, how the school continues critical work, and how the event is recorded. Do not accept an incident promise without a named route, responsibility, and timeframe defined for the contract.

Test backup, restore, export, correction, and reconciliation procedures with controlled data. Recovery is not complete if the system returns online but the school cannot establish which records or messages changed during the interruption.

Ask how the school distinguishes a service outage from a data-integrity incident. The response may require different owners, communications, evidence, and decisions. Include a short tabletop exercise so that staff know where to work temporarily and how to reconcile changes when the service returns.

Security questions should also cover ordinary operations: access reviews, role changes, supplier updates, support access, exports, and the removal of stale accounts. Small control failures can create exposure even when no dramatic incident has occurred.

Questions about assurance and evidence

Ask which security claims are current, what scope they cover, who reviewed them, and what remains the school’s responsibility. Keep legal, privacy, safeguarding, and technical questions distinct so that one certificate is not treated as an answer to every concern.

The U.S. Department of Education data governance checklist provides a helpful structure for quality, access, security, sharing, disposal, and monitoring. Adapt it with qualified advisers to the school’s local requirements.

Approve a bounded security decision

Record the data set, roles, controls, residual risks, evidence, owner, and review date for the proposed phase. If a critical access, supplier, incident, recovery, or retention question is unanswered, narrow or hold the release. Security is an ongoing operating responsibility, not a one-time procurement paragraph.

Keep reading

Related guides

Back to all guides