The internet safety policy is the written backbone of CIPA compliance — the document that turns your school internet safety rules from custom into commitment. This guide covers what the policy legally must contain, gives you a section-by-section structure a district can adapt, walks through the public-hearing requirement, and shows how to wire the policy to the filter and acceptable use agreement that make it real.
The law names the topics an internet safety policy has to cover. Your document can say much more, but it cannot say less than this.
How the institution restricts minors' access to material that is obscene, child sexual abuse material, or harmful to minors — in practice, a statement that a technology protection measure blocks these categories on all computers minors use, on campus and on managed devices off campus.
The safety and security of minors when using email, chat rooms and other direct electronic communications — today that includes messaging inside learning platforms, collaborative documents, and chat features embedded in games and AI tools.
Measures against hacking and other unlawful online activities by minors — account security expectations, prohibitions on circumventing the filter, and consequences aligned with the student code of conduct.
Safeguards against unauthorized disclosure, use and dissemination of personal information regarding minors — increasingly important as students encounter ungoverned AI tools that invite them to paste in exactly that information.
The technology protection measure itself: what the filter blocks, for whom, and under what procedure it can be disabled for adults engaged in lawful use. This is where the policy and the filter configuration must line up word for word.
For schools, the policy should also record the commitments added by the Protecting Children in the 21st Century Act: monitoring minors' online activity and educating students about appropriate online behavior, social networking safety, and cyberbullying awareness and response.
Under the Children's Internet Protection Act, a school or library taking E-Rate discounts on internet access must adopt and enforce a written internet safety policy. It states what the institution protects students from, how, and who is responsible.
It is not the same thing as your filter settings, and it is not the same thing as the acceptable use agreement students sign. The policy is the governing document; the filter and the AUP are two of the instruments that carry it out.
A filter shows what your network does today; the adopted policy shows what your governing body committed to, on what date, after hearing from the public. When the two match, compliance is easy to see. When they diverge, every other question gets harder.
If CIPA itself is new to you, read What Is CIPA? first; this guide assumes the basics.
There is no mandated format, which is both freedom and trap. This structure keeps the required elements visible, separates federal minimums from local choices, and gives an auditor a document they can navigate in minutes.
Why the policy exists, the legal context in one paragraph, and exactly who and what it covers: students, staff, guests; school networks, school accounts, and school-managed devices wherever they connect — including at home.
Short, plain definitions of the terms the policy relies on: minor, technology protection measure, obscene material, harmful to minors, direct electronic communications, managed device. Borrow the law's language for legal terms rather than paraphrasing it.
State that a technology protection measure blocks obscene material, child sexual abuse material and material harmful to minors for all users, with the harmful-to-minors standard applied to minors. Name the blocked content categories at the level of policy, not vendor screen names, so the document survives product changes.
Describe access tiers — by grade band and for staff — and the procedure for adult unblocking for bona fide research or other lawful purposes: who may authorize it, how it is logged, and how long it lasts. Include the process for teachers to request site exceptions.
The institution's school internet safety rules for email, chat, messaging and collaborative platforms; expectations for respectful conduct; and the prohibition on sharing personal information about oneself or others without authorization.
Define what monitoring means in your institution: supervision norms in classrooms and labs, scheduled review of category-level filtering reports, alerting on high-risk categories, and the boundaries — what the district deliberately does not collect. Written boundaries build trust and prevent scope creep.
Commit to instruction on appropriate online behavior for each grade band, explicitly covering social networking safety and cyberbullying awareness and response, and name who is responsible for delivering and documenting it each year.
A short section reserving the district's authority to categorize and restrict new classes of online services — generative AI tools being the current case — under the same principles, so each new technology wave does not require reopening the whole policy.
Record the public notice and hearing, the adoption date and adopting body, the review cycle, and how violations are handled through existing conduct codes. This section is where an auditor looks first — make the dates impossible to miss.
CIPA requires that the internet safety policy be adopted after reasonable public notice and at least one public hearing or meeting where the proposal can be addressed.
Publish notice through your normal public channels, far enough ahead to be "reasonable." Name the policy explicitly on the agenda — not buried in "consent items."
A regularly scheduled board meeting satisfies the requirement when the policy appears as an identifiable item on the published agenda and the minutes reflect that it was presented and discussed.
Record discussion and the adoption vote in the minutes. File notice, agenda and minutes together with the adopted text. The most common failure is holding a hearing and keeping no evidence.
The bar is procedural fairness, not a town-hall spectacle: the community must have a genuine chance to know about the policy and speak to it before it takes effect. A regularly scheduled board meeting satisfies the requirement when the policy appears as an identifiable item on the published agenda and the minutes reflect that it was presented and discussed.
A policy that lives in a binder while the filter lives in a console will drift apart within a year. The fix is traceability.
Every enforcement claim in the policy should map to a named, checkable thing in the filter — a blocked category set, a grade-band policy, an off-campus enforcement setting — and every behavioral rule should appear in the acceptable use policy students and staff actually sign. Category-based filtering makes the mapping natural, because policy language and filter language finally share a vocabulary. See our CIPA-compliant web filter for how districts implement that mapping.
Category-based filtering makes the mapping natural, because policy language and filter language finally share a vocabulary. Category-level reporting then closes the loop.
Districts often maintain one document and assume it covers both jobs. The two overlap, but they answer to different audiences and different requirements.
| Internet safety policy | Acceptable use policy (AUP) | |
|---|---|---|
| Primary audience | The institution, its board, and reviewers | Individual students, staff and families |
| Legal role | Required by CIPA for E-Rate participants | Not itself a CIPA requirement — but the natural enforcement vehicle |
| Adoption process | Public notice and hearing, board adoption | Administrative issue-and-sign, typically annual |
| Content focus | What the institution blocks, monitors and teaches | What the individual user may and may not do |
| Change frequency | Stable; revised every few years with a hearing | Refreshed routinely as tools and expectations shift |
Keep them as two documents with one owner. The internet safety policy states commitments at the level of principle and category; the AUP translates them into first-person rules a fourteen-year-old can understand. When the policy changes, the AUP inherits the change at its next annual refresh — and because only the policy carries the hearing requirement, routine AUP updates stay administrative instead of triggering a public process every autumn.
The best internet safety policies we see share the same traits — and none of them is length.
The "honest" trait deserves emphasis. Boards sometimes adopt aspirational language — monitoring practices grander than anyone performs, education programs no one scheduled — on the theory that ambition looks good. In a compliance document the opposite is true: every sentence is a promise a reviewer can test. Write down the program you run, run the program you wrote down, and revise the words when the practice legitimately improves.
Adoption is the legal milestone, but enforcement is what the certification actually attests.
Within a few weeks of the board vote, publish the policy where families can find it and summarize it in student handbooks in age-appropriate language.
Brief staff — especially the difference between the school internet safety rules students must follow and the procedures staff use for exceptions and adult unblocking.
New-hire onboarding and the annual AUP signature cycle are the natural moments to keep awareness current without extra meetings.
Once a year, someone reads the policy next to the filter configuration and the AUP and files a short note confirming they still agree — or listing what changed.
Walk through each enforcement claim in the policy and verify the filter configuration matches — blocked category sets, grade-band policies, off-campus enforcement settings, and SafeSearch rules should mirror the adopted text exactly.
Ensure the acceptable use policy reflects every behavioral rule in the internet safety policy. Students and staff should sign the updated AUP at the next annual refresh cycle so all three documents stay aligned.
Pair that reconciliation note with the artifacts from our CIPA compliance checklist and the funding-side records described in E-Rate and CIPA funding, and your policy becomes the index to a compliance program that can be inspected on any given Tuesday.
We map every commitment in your internet safety policy to enforced categories, off-campus coverage and audit-ready reports — so the words your board adopted describe the network you actually run.