Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Policy topic

No spam. Unsubscribe anytime.

Columbia County updates information security policy to align with NIST revisions

3293085 · May 14, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

County staff presented a revised information security policy adopting principles from the National Institute of Standards and Technology (NIST) cybersecurity framework update to emphasize governance, risk management and interagency collaboration.

Columbia County staff presented and the committee approved a revision to the county’s information security policy to reflect recent National Institute of Standards and Technology guidance.

Mr. Blanchard said the county uses NIST as the basis of its policies and that NIST issued a major revision last year that increased emphasis on governance and risk management. "We have increased emphasis on collaboration. It introduced risk management concepts as part of cybersecurity. We have enhanced guidance for reporting on our cybersecurity activities," Mr. Blanchard said. Staff also removed legacy material from older NIST documentation.

Why it matters: Updating county policy to reflect federal standards helps align internal controls, incident reporting and governance with widely accepted best practices and may affect how departments share cybersecurity responsibilities.

Details and next steps: The county described the change as a policy update with no direct fiscal cost. The committee approved the policy change on consent; staff characterized the revision as better aligning county practice with NIST v2 guidance and improving reporting and governance around cybersecurity.