6.2 Operational Effectiveness

Notes
6.2b. For examples of what your information technology systems might include, see the note to 4.2a(2).
6.2b. Managing cybersecurity includes protecting against the loss of sensitive information about employees, students, other customers, and organizations; protecting assets, including intellectual property; and protecting against the financial, legal, and reputational aspects of breaches. Many sources for general and industry-specific cybersecurity standards and practices are referenced in the Framework for Improving Critical Infrastructure Cybersecurity. The Baldrige Cybersecurity Excellence Builder is a self-assessment tool incorporating the concepts of the Cybersecurity Framework and the Baldrige systems perspective.
6.2c(2). Some education organizations are involved in communitywide efforts to ensure resilience. NIST’s Community Resilience Planning Guide is a resource for communitywide efforts.
6.2c(2). Disasters and emergencies might be short- or longer-term and might be related to weather, climate, utilities, security, or a local or national health or other emergency. The extent to which you prepare for such events will depend on your organization’s environment and its sensitivity to short- or longer-term disruptions of operations. Acceptable levels of risk will vary depending on the nature of your programs, services, supply network, and stakeholder needs and expectations.

Explain-BPEx-criteria-requirements-listed-without-duplications