| Section 500.09 | Requires a cybersecurity risk assessment that will drive overall program implementation |
| Section 500.05 | Requires that a CISO report directly to the board (this can be a third party) |
| Section 500.02 | Requires implementation a security program including required policies and procedures |
| Section 500.16 | Requires an cybersecurity incident response plan |
| Section 500.17 | Requires notices and submission to the superintendent |
| Section 500.XX | Other various technical requirements such as encryption, Two-Factor Authentication (2FA), Security Monitoring/Penetration Testing, Security Training, Data Retention |