Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Supervisors adopt updated cybersecurity discipline steps for county employee handbook
Summary
The Board approved revisions to the county employee handbook's acceptable-use and end-user security policies adding progressive disciplinary steps for repeated security incidents; supervisors discussed how the policy applies to county employees and noted limits where elected officials control their own staff.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
The Pottawattamie County Board of Supervisors approved updates to the county employee handbook to add escalated disciplinary steps for violations of the acceptable-use and end-user security policies.
Chief Information Officer David Baer told the board the changes formalize progressive steps after security incidents: first incident—verbal warning and training; second incident—written warning and training; third incident—loss of system access and training; fourth incident—possible termination. Baer said the change reflects nine IT-run phishing campaigns over the past three years in which 68 people clicked a fake link and 34 disclosed credentials in at least one campaign.
Supervisors discussed whether the policy can and should apply to elected officials and their employees. County counsel and supervisors noted that elected officials generally control conditions of employment for their own staff and that the employee handbook does not override elected-office authority. The county attorney’s office cautioned that restricting an elected official’s access or the access of an elected official’s staff can create legal conflicts and cited a neighboring-county lawsuit as an example of costly disputes when boards and elected officials clash over personnel access.
Board members said the policy provides guidance and that the progressive steps were intentionally discretionary—"may be taken"—to allow supervisors and managers to calibrate discipline to the severity and context of an incident. The board approved the revisions by voice vote.
Why it matters: the changes give county IT clearer guidance and documented progressive discipline for employees who introduce security risk through phishing or other policy violations, while leaving unresolved the separate legal status of elected officials and their staffs.

