Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Judicial Cybersecurity topic

No spam. Unsubscribe anytime.

Audit finds Colorado Judicial Department's interpretation of state cybersecurity policy differs from state CISO's guidance

5698569 · March 26, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A performance audit found the Colorado Judicial Department's interpretation of the statewide Colorado information security policies (CISPs) differs from the state chief information security officer's interpretation, and auditors recommended resolving the conflict by adopting the CISPs or seeking statutory change.

A discretionary performance audit of cybersecurity resiliency at the Colorado Judicial Department found one public-area issue: the department's interpretation of its obligation to the statewide Colorado information security policies (CISPs) differs from the interpretation of the state chief information security officer.

The auditors said the CISPs were issued under state statute for all public agencies and that judicial's differing interpretation left the department without a consistent baseline for information security maturity. Anders Erickson, a principal with the contracted audit firm IdeBailey, told the committee the public report contains a single public finding recommending that "the Colorado Judicial Department should resolve conflicting interpretations of its statutory requirements by utilizing the Colorado information security policies ... as the foundation upon which judicial's information security policies and procedures are built," or alternatively seek statutory change to remove judicial from the definition of a public agency.

Steven Vasconcellos, the Colorado State Court Administrator, said judicial agrees with the recommendation. "We agree with recommendation number 1," he told the committee, and said the department will continue to submit its annual cybersecurity plan to the Governor's Office of Information Technology and will consult with OIT while incorporating CISPs as the foundation for judicial policies.

The audit team said the full engagement produced a total of 46 recommendations (one public finding and five additional confidential findings) and that the confidential findings and details were discussed in executive session under the statutory provision authorizing closed discussion of specialized security details.

Ending: The committee voted to release the public report and then moved into a closed executive session to review the confidential findings; the Judicial Department agreed to adopt the CISPs as described in its response to the public recommendation.