School Security and Safety Checklist
Quarterly security review run by a K-12 site administrator with the district IT director and facilities lead. Covers physical access, network and SIS data protection, FERPA-aligned records handling, staff readiness, and emergency response posture.
Physical Site Security
-
Audit exterior door locks and panic hardware
-
Test classroom interior lockdown locks
-
Review camera coverage and DVR retention
Walk the playback for the main entrance, bus loop, cafeteria, and gym corridor. Confirm retention is at least 30 days per district policy and that timestamps match the bell schedule. Note any blind spots created by recent landscaping or portable classroom moves.
-
Reconcile Raptor visitor management logs
Pull the last 90 days of Raptor sign-ins and cross-check against the sex-offender registry hits, custody alerts, and any vendor badges that never signed out. Front desk should flag patterns of after-hours pickups.
-
Inspect perimeter fencing and gates
-
Record physical security audit findings
Capture the headline result and attach the walkthrough photos. A 'Critical' finding triggers the work-order escalation later in this checklist; routine findings go to the regular facilities queue.
-
Submit emergency facilities work order
For any critical finding (broken exterior lock, breached fence, dead camera at a primary entrance), open a same-day work order with the district facilities director and notify the SRO. Do not wait for the standard ticket queue.
Network and SIS Security
-
Confirm CIPA-compliant content filtering is active
Verify the filter (Securly, GoGuardian, Lightspeed, or equivalent) is enforcing on student devices both on-network and off-network. CIPA non-compliance puts E-rate funding at risk.
-
Review PowerSchool and LMS access roles
Pull the role report from PowerSchool (or Infinite Campus / Skyward) and the LMS. Disable accounts for staff who left at the last close-out, and confirm substitutes only hold limited-scope roles.
-
Verify MFA on staff SSO accounts
Pull the MFA enrollment report from ClassLink or Clever SSO. Any staff member with SIS or grade-book access who is not enrolled gets a personal email and a 5-business-day deadline before the account is locked.
-
Patch firewall and review IDS alerts
-
Audit shadow-IT apps for COPPA compliance
Pull the list of new apps requested by teachers since the last review. Each app handling student PII needs a signed Data Privacy Agreement (DPA) on file before classroom use. The common gap is a teacher signing the class up for a tool whose TOS has no school-consent path.
Collects list -
Issue cease-use notice and replace the app
Email the affected teachers, copy the principal, and direct them to a vetted alternative from the district's approved tools list. Notify the Data Privacy Officer so the incident is logged for the annual FERPA report.
Student Records and Data Protection
-
Verify SIS backups restored successfully
Don't trust the green checkmark — pick a test record and confirm the most recent backup actually restores. The IT director keeps the restore log; attach the latest entry below.
Collects file -
Audit FERPA directory-information opt-outs
Pull the opt-out list and confirm yearbook, athletics, and PTO communications honor it. A photo of an opted-out student in the yearbook is a textbook FERPA complaint.
-
Review custody flags on transcript releases
Spot-check the registrar's last 20 transcript releases against the custody flags in the SIS. Releases to non-custodial parents without consent are the most common FERPA breach in transcript workflows.
-
Confirm cum-file retention schedule compliance
State retention rules typically require cumulative folders held until the student turns 26 (varies by state). Premature shredding is a violation; over-retention is a privacy risk. Confirm the records officer signed off on this year's destruction list.
-
Lock down IEP and 504 document repositories
Frontline IEP, SEAS, or eSPED access should be limited to the IEP team, case manager, and assigned service providers. General-education teachers see the accommodations summary, not the full evaluation. Audit the access list for any current students.
Staff Readiness and Background Checks
-
Confirm fingerprint clearance for all active staff
Pull the HR clearance report. State rules vary; many states require renewal every 5 years. Substitutes whose clearance lapsed cannot be in classrooms — give Frontline (Aesop) the do-not-assign list the same day.
-
Verify mandatory reporter training completion
Vector Solutions (SafeSchools) tracks completion. Every staff member must individually understand that the CPS reporting obligation is personal — telling the principal does not satisfy the law. Document the cohort completion rate.
Collects number -
Run FERPA refresher for front-office staff
Front desk handles the highest volume of records-release requests and is the most common breach point. Cover directory-information rules, custody flags, and the no-link-sharing rule for student spreadsheets.
-
Update Title IX coordinator training records
Coordinator, investigators, and decision-makers need current training documented and posted publicly per the regulation. Confirm which framework (2020 or 2024 rules) currently applies in your jurisdiction.
-
Enforce clear-desk policy in main and counseling offices
Walk the main office, counseling suite, and nurse's office after hours. Student schedules, IEPs, medical records, and discipline files left visible are a FERPA exposure. Lock cabinets and monitor screens with privacy filters.
Emergency Preparedness and Recovery
-
Review the Comprehensive School Safety Plan
Confirm the CSSP reflects current building layout, current admin team, and current SRO assignment. Outdated room numbers and stale staff names are the typical findings during a state safety review.
-
Test the InformaCast mass notification system
Send a silent test page to phones, classroom speakers, and digital signage. Verify the test reaches portables and the gym, the two locations where notifications most often fail.
-
Run the quarterly ALICE lockdown drill
Coordinate with the SRO and notify the district before the drill. Time the door-securing, debrief with staff, and capture which classrooms had latch or radio issues for the facilities work order list.
Collects list -
Schedule a remediation drill within two weeks
A failed drill requires a re-drill on a tight timeline. Notify the district safety director, document the gap (radio dead zone, locked-from-outside classroom, missing roster), fix it, and re-run.
-
Confirm offsite SIS recovery infrastructure
If the building is unavailable, the SIS, payroll, and communications must come up at the district office or the cloud-hosted DR site within the RTO. Verify the last failover test date with the district IT director.
-
Sign off on the quarterly security review
The principal, district IT director, and facilities lead jointly sign off. Attach the summary memo for the superintendent's quarterly safety report to the school board.
Collects list Collects signature Collects file
Use this template
Copy it to your account, customize the steps, and run it with your team in minutes.
Browse hundreds of free templates across every team and industry.
Back to template libraryRelated templates
More workflows your team can run.
Run School Security and Safety Checklist with your team
Customize the steps, assign roles, set a schedule, and keep a complete record for every run.