Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the General Government It Budget Cybersecurity topic
No spam. Unsubscribe anytime.
State IT officials tell Ways and Means subcommittee cybersecurity posture improving but below target; data center uptime near 99.98%
Summary
Department of Administrative Services officials briefed the Ways and Means subcommittee on HB 5002 about Enterprise Information Services' cybersecurity progress, data governance efforts, data-center availability and proposed budget reductions and policy packages.
Get email alerts on the General Government It Budget Cybersecurity topic
No spam. Unsubscribe anytime.
Enterprise Information Services officials told the Joint Committee on Ways and Means Subcommittee on General Government on March 6 that the state's cybersecurity and data programs are improving but remain below internal targets as budget pressures force program reductions.
Terrence Wood, state chief information officer, told Co-chair Smith and the committee that the enterprise’s goal is to meet 70% of the Center for Internet Security (CIS) 8.1 and cloud addendum controls across agencies. “The goal was 40%. We moved the target up to 70% in 2023,” Wood said, and reported the enterprise average at roughly 49% in 2024 and about 50.8% at the time of testimony.
The committee heard a technical explanation from Ben Gresgere, the state chief security officer, who said the CIS assessment covers roughly 54–56 controls and that some gaps reflect basic cyber hygiene, such as incomplete inventories of software and hardware. “We would not let an agency have a serious security gap and then simply walk away from them,” Gresgere said.
Wood and Gresgere asked the committee for support for tools and professional services that would help agencies raise the enterprise score. Wood agreed to provide the committee with more-detailed, itemized steps and charts showing agency-level weaknesses at an upcoming work session.
On infrastructure, Wood reported the data center’s availability target and performance. The presentation listed a target of 99.9% availability for 2024 and an actual of 99.98%. Wood explained that 99.98% availability equates to only a small amount of unplanned downtime: “we have not been down more than 17 seconds on a daily basis or on a yearly basis, no more than 1 hour and 44 minutes,” he said, and described that record as a noteworthy improvement for data center services.
Wood also reviewed accomplishments and planned work: consolidation of EIS campus offices, enrollment of roughly 29,000–30,000 mobile devices in enterprise mobile device management, continued investment in resilient backup site planning in Bend, and steps to modernize legacy applications and support agencies moving to cloud services. He said the enterprise is adjusting procurement and stage-gate procedures to accommodate vendors and agencies that use agile development.
On budget, Wood said the EIS general government budget (GRB) presented for the committee was about $349,000,000, with roughly 49–50% of that directed to data center services. He described a 10% reduction exercise that targeted items across program areas — including professional services, points of presence, deferred maintenance, vendor support and some Microsoft 365 support hours — and said the agency would return to the committee with vacancy status on positions that appear on the reduction list.
Wood outlined several policy action packages (POPs) the agency requested in HB 5002, including sustaining geospatial imagery funding (listed in testimony as “1.7”), a security managed services package, web application firewall funding, and two data-governance-related POPs: one to fund a small coordinated data governance pilot tied to homelessness outcome reporting (referenced as 3 FTE for “2.8”) and another to assess secure enterprise data integration and infrastructure planning. He said the POPs are intended to improve information sharing and reduce staff time spent on ad hoc integration work.
Committee members pressed for clarity about which reductions would be least harmful to operations and asked whether EIS could find large general-fund savings if required. Wood said reductions could be found but he would need to return with analysis of the operational impact. Senators asked for an itemized plan to reach the 70% CIS control target and for details about tools and costs the agency is requesting.
The presentation also included discussion of emerging risks such as artificial intelligence tools being used by adversaries; Wood warned the committee the state would need vendor assistance and additional talent to manage those evolving threats.
The subcommittee did not take formal action during the hearing. Members asked EIS to provide additional detail on the 10%-reduction list (including which positions are vacant) and to bring a prioritized list of POPs and the agency’s proposed steps to reach the 70% cybersecurity target.
