Arkansas K-12 · Act 504 of 2023

Is your district actually compliant with Act 504?

Arkansas law now requires every public school district to have real cybersecurity policies, staff training, and a security posture it reviews and maintains. Check off what you already have — and watch how Red Garrison and Huntress close every gap, item by item.


Red Garrison — your experts

Writes state-aligned policies, runs risk assessments & penetration testing, delivers training, builds your incident-response plan, and manages it all for you.

Huntress — the platform

The always-on technology Red Garrison deploys underneath: 24/7 endpoint, identity, logging, and awareness-training protection.

0%
0 of 12 in place
Check the boxes below. Every item you can't check is a gap Red Garrison + Huntress can close for you.
Close my gaps — book a review →
1Policies on paper
Technology-resources / acceptable-use policy adopted
Defines authorized use of district devices, networks, and accounts; prohibits circumventing security.
Covered byRed Garrison · Policy Development
Cybersecurity policy aligned to State Cyber Security Office standards
Not a generic template — mapped to the state's required standards.
Covered byRed Garrison · Policy Development
Policies reviewed and updated on a set cadence
Board-approved, dated, and scheduled for periodic review — not filed and forgotten.
Covered byRed Garrison · Ongoing Advisory
2People trained
All staff trained on both policies
Every employee, not just IT — documented completion you can show in an audit.
Covered byRed Garrison · Training DeliveryHuntress · Managed SAT
Recurring phishing-awareness training
Ongoing, K-12-appropriate, with results tracked over time.
Covered byRed Garrison · Phishing SimulationsHuntress · Managed SAT
Training records retained for audit
Dates, attendees, and content kept on file.
Covered byRed Garrison · Audit DocumentationHuntress · SAT Reporting
3Controls in place
Multi-factor authentication on email & remote access
Staff logins protected beyond passwords.
Covered byRed Garrison · Setup & ConfigHuntress · Managed ITDR
Endpoint detection & response (EDR) on district devices
Modern monitored protection, not legacy antivirus.
Covered byHuntress · Managed EDRRed Garrison · Deployed & Managed
Centralized logging retained for compliance
Security events captured and stored long enough to investigate and report.
Covered byHuntress · Managed SIEMRed Garrison · Deployed & Managed
4Posture maintained
Regular risk assessment / vulnerability evaluation
You know what's exposed — before an attacker does.
Covered byRed Garrison · Year-Round Pen Testing
Written incident-response plan, tested
Who does what in a breach — documented and rehearsed.
Covered byRed Garrison · IR Planning
Breach notification / reporting process ready
Rapid, documented notification aligned with state requirements.
Covered byRed Garrison · IR ConsultingHuntress · 24/7 SOC

Let Red Garrison close the gaps

Book a 20-minute Act 504 readiness review. We'll walk your checklist, confirm your gaps, and show you the fastest path to compliant — with Red Garrison and Huntress doing the heavy lifting.

Book my readiness review → Talk to us about compliance

Informational only; not legal advice. Requirements summarized from Arkansas Act 504 of 2023 (Ark. Code § 25-1-128) and Arkansas DESE guidance; confirm your district's obligations with the Arkansas Division of Elementary and Secondary Education and the State Cyber Security Office. Huntress product names are trademarks of Huntress Labs Incorporated.