Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the It Security Policy topic

No spam. Unsubscribe anytime.

Council reviews draft IT physical-security policy; staff say goal is to secure printed and digital records

5119819 · July 2, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

City staff presented a physical and environmental security policy for information systems that emphasizes locked storage for sensitive printed records and physical access controls for servers; council discussion was informational and no vote occurred.

City information-technology staff presented a draft physical and environmental security policy at the Shelbyville mayor and city council study session that addresses physical access to servers and printed records as part of the city's broader information-security program.

An IT director (identified in discussion as Kate) described the policy as “just another line of the policies demanded by the state,” and said the document outlines physical controls to keep sensitive information secure. The director summarized the policy as measures to prevent unauthorized people from accessing hardware or printed files and to require that HR and medical records be securely stored whether in paper or electronic form.

The director said the policy also covers operational requirements for server rooms, including air conditioning and backup power, and described the core guidance as a practical set of measures: “keep sensitive stuff in a locked drawer or behind a locked door,” as phrased in the meeting record.

City Manager Scott Collins and council members asked clarifying questions but the study session did not include a council vote or adoption of the policy. The draft remains under review and will be processed through the city's normal policy-approval channels.

Why it matters: physical security complements cybersecurity by protecting servers and printed records from unauthorized physical access; adopting the policy would document requirements for staff handling of protected records and for facility infrastructure supporting servers.

What’s next: staff will continue to refine the draft and present it for formal consideration at a subsequent meeting; no formal action was taken at the study session.