Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Device Policy topic
No spam. Unsubscribe anytime.
Will County committee debates new device, privacy and cybersecurity language for personnel policies
Summary
Will County’s ordinance‑review committee discussed draft edits to chapter 36 that would require antivirus on devices used for county email and internet access and clarify privacy expectations for electronic communications.
Get email alerts on the Cybersecurity Device Policy topic
No spam. Unsubscribe anytime.
Will County’s ordinance-review committee spent substantial time on proposed edits to chapter 36 of the county code that would clarify employee privacy expectations and require cybersecurity protections for devices that access county systems.
Committee members pressed staff for specifics about when employees must install antivirus software, whether the rule applies to personal phones and tablets as well as county-issued devices, and how multi‑factor authentication (MFA) fits with a requirement that “any personal device that has access to the county Internet or email must have an antivirus software installed” in the draft. Committee member Freeman asked whether the changes meant employees must install software on personal phones; Tim Hendricks, of the County Board Office, said the ICT rollout of a physical MFA key “will in part assist in that, but it will not necessarily remedy the situation. It's not an antivirus software.”
The drafter, identified in the meeting as Phil Mach (staff), told members the language intends two separate protections: (1) a requirement that devices used for county business run antivirus recommended by the information‑technology department to reduce accidental introduction of malware, and (2) a statement that intentional introduction of malware would be criminally prosecutable “pursuant to state statutes.” Mach and members agreed to change wording from “personal computer” to “personal device” and to insert the word “county” before Internet or email to make clear the rule targets devices that access county systems.
Members also discussed operational details but did not adopt a binding technical standard at the meeting. Mach said IT can publish a short list of recommended antivirus packages and that the county’s MFA rollout would add a layer of security but not replace antivirus. Chief of Staff Falke and other speakers reiterated IT’s preference that county business be conducted on county‑issued devices, noting they can be monitored and managed more easily.
No formal action or vote was recorded to adopt the technical specifications during the meeting; committee members directed staff to revise the draft wording to clarify (a) that the antivirus requirement applies to devices used for county business, (b) that recommendations will come from the IT/ICT department, and (c) that intentional introduction of malware is subject to criminal prosecution under state law.
The committee also asked staff to add language acknowledging MFA rollout and to coordinate with ICT on a communications plan that would provide recommended products and instructions for employees who choose to access county email from personal hardware.
The matter will move forward to the county executive for inclusion in the next consolidated draft of the code for executive committee review, subject to further editing on the technical points requested by members.

