Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Policy Rfq topic

No spam. Unsubscribe anytime.

Town and school to issue RFQ for consolidated technology policies after cybersecurity review

5775188 · September 16, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Officials said they will issue a real request for qualifications to write and consolidate town and school technology policies and procedures after a cybersecurity assessment, with the goal of producing formal, board-adopted policies and a scheduled periodic review cycle.

Town and school officials said they will release a request for qualifications to hire a consultant to write and consolidate technology policies and procedures for the town and schools. Anne Galati, assistant superintendent for finance and operations, and other staff said the RFQ will cover cybersecurity and related policy areas identified in a recent assessment, and that the work is intended to produce formalized, board-adopted policies and procedures.

Staff said they will outsource the policy writing rather than use a state contract; they described the procurement as a "real RFQ" to ensure a comprehensive, holistic review. The consultant that conducted the earlier cybersecurity assessment has posted a public report on the school technology department website, staff said. Committee members discussed the balance between producing a single, comprehensive cybersecurity policy (much of which may be available in prewritten templates) and grouping policy updates by priority given budget and time constraints.

Staff said the RFQ scope remains under development and has not yet been released; they will return with a refined scope to the committee. The consultant engagement is expected to create a baseline of policies that the town and schools can maintain, with a proposed major review every other year to update policies as technology changes. Credit-rating agencies, insurers and auditors were cited as external parties that have asked for evidence of IT security policies, which staff said contributed to the priority of formalizing written controls.

Richard Ducci and other committee members offered to review the public cybersecurity findings and provide input. Staff noted there are public and confidential parts of some security assessments; staff will determine how much of the consultant materials can be shared publicly with the committee and the general public.

No formal RFQ release or contract award was voted at the meeting; staff described next steps as scope refinement and an upcoming planned RFQ.