The Children's Museum needs to make sure that the door to the basement where the incoming connection is remains locked. This will ensure that the incoming connection can not be tampered with by unauthorized personnel.
The server needs to be in a locked cabinet in the mechanical room and the mechanical room itself also needs to remain locked. This will prevent tampering and theft.
It would be helpful to have some type of equipment locks on the workstations so that peripherals are tied together as a theft deterrent.
The server needs to have specific user accounts and passwords to allow only certain people access to certain information.
The MOZY backup system also needs to be implemented and used correctly to make sure that backup data can be maintained in a secure location.
There should also be a policy put in place detailing how equipment and information is to be kept secure.