Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Columbia County updates information security policy to align with NIST revisions
Summary
County staff presented a revised information security policy adopting principles from the National Institute of Standards and Technology (NIST) cybersecurity framework update to emphasize governance, risk management and interagency collaboration.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Columbia County staff presented and the committee approved a revision to the county’s information security policy to reflect recent National Institute of Standards and Technology guidance.
Mr. Blanchard said the county uses NIST as the basis of its policies and that NIST issued a major revision last year that increased emphasis on governance and risk management. "We have increased emphasis on collaboration. It introduced risk management concepts as part of cybersecurity. We have enhanced guidance for reporting on our cybersecurity activities," Mr. Blanchard said. Staff also removed legacy material from older NIST documentation.
Why it matters: Updating county policy to reflect federal standards helps align internal controls, incident reporting and governance with widely accepted best practices and may affect how departments share cybersecurity responsibilities.
Details and next steps: The county described the change as a policy update with no direct fiscal cost. The committee approved the policy change on consent; staff characterized the revision as better aligning county practice with NIST v2 guidance and improving reporting and governance around cybersecurity.

