Short answer: a school emergency operations plan should be available to the people who must prepare, respond, and recover, but that does not mean every map, contact list, system detail, student record, or response procedure should be broadly accessible. New Jersey school leaders need a documented way to classify plan information, approve access, share it securely with authorized partners, test the plan without exposing sensitive details, and remove access when a role or vendor relationship changes.
This guide replaces an older incident-focused article that repeated unverified breach details and school vulnerability examples. It does not reproduce leaked documents, identify school weaknesses, or claim that one technology can prevent violence or a data breach. It provides a safer operating framework for New Jersey districts, nonpublic schools, emergency partners, and technology providers.
How this guide was prepared
Reviewed: August 19, 2026. The planning requirements and operating recommendations below are grounded in current New Jersey Department of Education, CISA, SchoolSafety.gov, and U.S. Department of Education student-privacy resources. School leadership and qualified legal, privacy, public-safety, emergency-management, and accessibility professionals must interpret the duties that apply to a specific institution.
- Source boundary: this page links to responsible government agencies instead of repeating third-party breach reporting as fact.
- Security boundary: it discusses governance and controls, not site-specific vulnerabilities, tactical response details, floor plans, camera locations, access credentials, or student information.
- Service boundary: Rivell can support authorized technology, cybersecurity, communications, access-control, surveillance, backup, and documentation work. The school retains policy, legal, emergency-command, student-record, and risk-acceptance authority.
- Verification rule: confirm current state requirements, district policy, partner agreements, system configuration, and evidence before treating any control as complete.
Start with New Jersey’s planning requirement
The New Jersey Department of Education planning page states that school districts must maintain a school safety and security plan, develop it locally with law enforcement, emergency management, public health, and other stakeholders, and review it annually. It points to N.J.A.C. 6A:16-5.1 and the state’s minimum requirements. This guide does not summarize those requirements as legal advice. Use the current state material and the school’s responsible professionals as the controlling references.
The NJDOE Office of School Preparedness and Emergency Planning describes an all-hazards program spanning mitigation, preparedness, response, and recovery. That lifecycle is a better model than treating the plan as a file that is reviewed once and forgotten. Technology controls should support the locally approved plan and the people accountable for it.
Classify plan information before selecting a sharing tool
A single emergency-plan folder can contain information with very different disclosure and access needs. Build a written classification rule first, then map each document, drawing, roster, contact list, procedure, and evidence record to an approved class. Avoid labeling everything confidential because that makes the label meaningless. Avoid treating an entire plan as public because some parts are appropriate for broad awareness.
| Information class | Possible examples | Control question |
|---|---|---|
| Public awareness | Family communications, general preparedness information, reunification expectations that leadership approves for release | Has the communications owner approved the exact public version? |
| Internal operational | Role assignments, training material, exercise schedules, internal contact workflows | Which job functions need access, and for how long? |
| Restricted safety | Site-specific diagrams, response details, protective-system information, sensitive partner procedures | Can authorized responders get the current version without exposing it to unrelated users? |
| Student or personnel record | Information tied to identifiable students, families, employees, accommodations, health, discipline, or other protected records | Is access and disclosure approved under the institution’s current legal and privacy rules? |
| Security evidence | Access reviews, test results, incident logs, configuration records, corrective actions | Who can inspect the evidence, and what retention rule applies? |
Control access by role, not by possession of a link
Store controlled material in an approved system with named accounts, multifactor authentication where supported, role-based permissions, version history, logging, and a documented owner. A shared link that anyone can forward is not equivalent to approved access. Group permissions should be tied to current job functions, partner roles, and time limits rather than broad convenience groups.
Use a joiner, mover, and leaver process. Grant only the approved collection or folder, review access after role changes, and remove accounts and external shares promptly when work ends. Test emergency access separately: the plan must remain available during a network, identity, power, or primary-site disruption without creating an unmanaged duplicate that never receives updates.
The U.S. Department of Education’s K-12 data-security resource hub distinguishes privacy obligations from specific technical controls and directs education agencies to safeguards appropriate to their records and systems. Its data-security checklist treats people, process, technology, governance, and the data lifecycle as one program.
Make partner and vendor sharing explicit
Emergency planning depends on collaboration, but collaboration should not produce permanent uncontrolled copies. For each police, fire, emergency-management, public-health, consultant, software, security, or IT relationship, document what may be shared, why it is needed, who may receive it, where it may be stored, whether downstream sharing is permitted, how changes are communicated, how incidents are reported, and how access and copies are removed at the end.
Do not assume a vendor’s general security statement proves the controls used for the school’s actual environment. Request current evidence for account protection, administrative access, encryption, logging, backups, data location, retention, deletion, subcontractors, incident notification, support access, and contract exit. The school and its counsel determine which contractual and legal terms are required.
Connect cyber, physical, and operational controls
CISA’s K-12 cybersecurity guidance prioritizes multifactor authentication, remediation of known exploited vulnerabilities, tested backups, exercised incident response, and security training, then recommends building toward a mature program. The CISA K-12 School Security Guide uses a systems-based, layered approach to physical security. Neither source says that one product removes the need for governance, people, policies, training, and response.
Apply that principle to connected cameras, access control, visitor systems, alarms, communications, sensors, and screening equipment. Define the business owner, technical administrator, monitoring role, responder, evidence custodian, support provider, and decision authority. Record the behavior when a device, integration, account, network segment, power source, or vendor service is unavailable.
Rivell’s related planning resources cover managed IT for education, cybersecurity services, the broader business cybersecurity solutions overview, access control, and video surveillance. These services can support an approved program; they do not replace the school’s statutory, emergency-command, or student-privacy responsibilities.
Run the plan as a controlled lifecycle
- Assign ownership. Name the accountable plan owner, section owners, system owners, approval authorities, and authorized partner roles.
- Inventory and classify. Locate current and duplicate copies, identify sensitive elements, and record the approved system of record.
- Approve access. Map roles to information classes, require named accounts, document external sharing, and establish expiration and review dates.
- Protect and recover. Configure identity, permissions, logs, backups, offline or alternate access, restoration testing, and incident escalation.
- Exercise safely. Test roles, communications, decisions, technology dependencies, and recovery without exposing restricted content to unnecessary participants.
- Correct and reissue. Track findings, approve changes, retire superseded copies, notify authorized holders, and verify that the current version is reachable.
- Review on schedule. Align the annual state review with more frequent access, vendor, backup, and system checks based on risk and change.
The SchoolSafety.gov emergency-planning resource points schools to a collaborative process for developing, implementing, and refining emergency operations plans. NJDOE’s resources page connects that federal planning guide to New Jersey’s minimum requirements.
Evidence to review each quarter and after material change
| Control area | Evidence | Decision question |
|---|---|---|
| Plan inventory | System-of-record list, owner, version, classification, approved copies | Can leadership identify the current authoritative version? |
| Access | Users, groups, guests, public links, privileged roles, last review, removals | Does every account still have a current approved purpose? |
| External sharing | Partner register, agreements, recipients, expiration, copy-return or deletion evidence | Are partners working from the current version under defined rules? |
| Recovery | Backup status, immutable or separated copy where approved, restore test, alternate-access test | Can authorized staff retrieve an intact current plan during disruption? |
| Exercises | Approved scope, attendance, observed gaps, corrective owner, due date, retest | Did the exercise test the workflow without unnecessarily distributing sensitive details? |
| Technology change | Configuration, integration, account, network, logging, support, acceptance, rollback records | Did the change alter plan assumptions, access, evidence, or recovery? |
Prepare for a suspected exposure without inventing facts
If a plan or related record may have been exposed, preserve relevant logs and evidence, limit further access using the approved incident process, notify the authorized incident and leadership roles, determine what information and people may be affected, and obtain qualified legal and privacy guidance before making notification conclusions. Do not publish sensitive contents to prove that exposure occurred. Do not state that no unauthorized person accessed data unless the investigation supports that conclusion.
The response should also examine identity, devices, shared links, third-party access, email forwarding, downloads, backups, and printed copies. Track containment, investigation, required communications, recovery, corrective actions, and validation. Rivell’s data backup and recovery planning can support the technical portion of an approved continuity program.
Frequently asked questions
Should a school emergency plan be public?
Some awareness and family-communication material may be approved for public distribution, while site-specific safety information, protected records, and operational details may require restricted handling. The school and its qualified authorities should classify and approve each information set rather than apply one rule to every part of the plan.
Is password protection enough for a plan file?
A password can be one control, but schools should also evaluate named identity, multifactor authentication, role-based access, sharing restrictions, version control, logs, backup, recovery, access review, and removal. The exact design depends on the approved system and risk.
How should first responders receive plan information?
Use the locally approved process and agreements developed with the responsible emergency partners. Define authorized recipients, current versions, secure delivery, updates, emergency availability, and what happens to old or local copies.
Can a managed IT provider own the school safety plan?
A provider can administer approved technology and produce evidence within a written scope. School leadership and its legal, privacy, emergency-management, and public-safety authorities retain the decisions and responsibilities that cannot be delegated to a technology vendor.
Does security technology prevent school violence or data exposure?
No single camera, access-control system, screening device, cybersecurity product, or platform guarantees prevention. CISA’s guidance treats security as a layered system of people, policy, training, technology, assessment, response, and improvement.
Turn the plan into an operating record
Start with the authoritative plan, current NJDOE requirements, an information inventory, named owners, and the approved partner list. Then verify the technology and evidence supporting access, communications, physical controls, backups, recovery, and incident handling. Schools evaluating physical detection should also review Rivell’s concealed weapons detection technology guide and public-safety technology readiness checklist.
Request a school technology and security planning review to map the approved program to accounts, networks, communications, access control, video, backups, documentation, testing, and long-term support. Rivell will not publish site-specific vulnerabilities or substitute a technology proposal for the school’s responsible authorities.