Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the It Security Policies topic
No spam. Unsubscribe anytime.
Board approves revised IT acceptable-use and access-control policies
Summary
The county approved two IT administrative policies revised to NIST standards after audit findings; staff will distribute them to employees and require signature on hire.
Get email alerts on the It Security Policies topic
No spam. Unsubscribe anytime.
McCoy Hawkins, of the Graham County IT department, presented two revised administrative policies for board approval: an Acceptable Use Policy and an Access Control Policy. Hawkins said the policies were updated with contractor assistance to align with NIST standards and to respond to findings in the county financial audit.
"These are currently in place today. These are revisions that we had a contractor help revise these with, the contractor worked with Allison to bring these up to NIST standards," Hawkins said. He added that the policies establish expectations employees sign at hire and that corresponding procedures will be maintained by IT and do not require board approval.
A supervisor asked whether the policies would be distributed to employees; Hawkins said they will be "redone at some point in the future to everybody" and indicated the policies were going into effect.
The board voted to approve the IT Acceptable Use Administrative Policy number 2025-1 and the IT Access Control Administrative Policy number 2025-2.
Why it matters: the policy updates respond to audit findings and set security and access-control standards intended to protect county data and systems.
Details and context: Hawkins said the policies reflect current practices and that procedures supporting the policies exist within IT. The county plans to notify employees and obtain the required acknowledgments.
What’s next: IT will finalize distribution and employee acknowledgement procedures and begin implementation.

