Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Judicial Cybersecurity topic

No spam. Unsubscribe anytime.

Audit finds Colorado Judicial Department needs to align with statewide cybersecurity policies

2790432 · March 26, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A public report on the cybersecurity resiliency audit recommended the Colorado Judicial Department adopt statewide information security policies (CISPs) developed by the Governor's Office of Information Technology or seek a statutory change; judicial leaders agreed and the committee moved to executive session for confidential findings.

The Legislative Audit Committee reviewed a public cybersecurity resiliency audit of the Colorado Judicial Department that concluded the department's interpretation of its statutory obligations for information security differs from the state's chief information security officer and recommended resolving that inconsistency.

"Our audit identified 1 problem at judicial related to statutory requirements," Anders Ericsson, principal at audit firm EideBailey, told the committee during the public presentation. The public report recommended that the Colorado Judicial Department "utilize the Colorado information security policies developed by the governor's Office of Information Technology's chief information security officer as the foundation" for the department's security policies, or alternatively seek statutory change to remove judicial from the statutory definition of "public agency."

Matt Devlin, chief IT auditor at the Office of the State Auditor, said the combined public and confidential audit reports together contained 46 recommendations; judicial agreed with all of them and had implemented one recommendation at the time of the hearing. "Overall, we issued a total of 6 audit findings, each having multiple recommendations for a total of 46 audit recommendations that the department agreed to, all of them," Devlin said.

A representative from the Judicial Department responded to the public finding and accepted the recommendation. "We agree with recommendation number 1. The judicial department will, of course, continue to submit our annual, cybersecurity plan to the Office of Information Technology in compliance with statute features," the department representative told the committee.

Scott Sutherland, manager of information security for the Judicial Department, emphasized the department's need to balance its independent operation with robust cybersecurity. "As always, audits provide an opportunity to learn, grow, and evolve. We sit here in agreement with all 46 recommendations. We come to the table having implemented 1 of them with the remaining 45 already in flight," Sutherland said.

Committee counsel advised that additional, sensitive findings be discussed in executive session under section 24-6-402, and the committee voted to enter executive session to review the confidential material.

The public report said auditors tested the Judicial Department's security practices against industry standards and statutory criteria and focused on six core cybersecurity functions: governance, identification, protection, detection, response and recovery. Auditors concluded the department's differing interpretation had limited the adoption of the statewide Colorado information security policies (CISPs) and recommended alignment or statutory clarification to achieve the intended security maturity.

The public portion of the audit concluded with the committee approving release of the public cybersecurity resiliency report; members then moved into executive session for discussion of the remaining, sensitive findings.