Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Information Technology topic

No spam. Unsubscribe anytime.

State CIO outlines EIS priorities: cybersecurity, cloud strategy, data-center resiliency and project governance

2521659 · March 5, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Enterprise Information Services Director and State Chief Information Officer Terrence Woods briefed the subcommittee on EIS's mission, cloud and data-center strategy, cybersecurity posture and staffing, and said the agency is moving toward a 70% CIS-controls maturity target for agencies.

State Chief Information Officer Terrence Woods, director of Enterprise Information Services (EIS), presented an overview of EIS priorities, organization and performance measures to the Ways and Means subcommittee on March 5, 2025.

Woods opened by summarizing EIS's mission and said, "we act on our mission, we aim for our vision, and we stand on our values," framing the presentation around service, transparency, and security. He told the committee EIS is prioritizing mature governance, cloud strategy and brokerage services, data governance, cybersecurity, and legacy-system modernization.

Cloud strategy, data center resiliency and energy considerations

Woods explained "cloud" as remote compute performed by third-party data centers and described the state data center as a private cloud the state operates. He said EIS acts as a broker to help agencies determine whether their systems are best run in the state data center or on commercial cloud platforms such as Microsoft Azure, AWS or Google Cloud. He said architecture, data-transfer costs and application readiness determine the right choice for each system.

On resiliency, Woods said EIS recently moved a resilient site from an out-of-state partner (formerly Montana) to a location east of the Cascades with much larger replication bandwidth, noting the prior backup arrangement used a 10-gigabit link that is insufficient for petabytes of modern data. He said replication capacity now supports significantly higher throughput to improve recovery timelines.

Woods also discussed physical requirements for large data centers, including power and water needs. He described backup generators at the state data center (maintained under contract with a vendor) that can be activated to supply the grid in emergencies and to keep state systems running when utility power is lost.

Cybersecurity and controls

Woods described the state's unified cybersecurity function and the Cybersecurity Center of Excellence the Legislature established. He said EIS performs security assessments, provides intel-sharing with federal partners and local governments, and prioritizes work using a risk-based approach. On performance metrics, Woods said EIS is moving its target to a 70 percent maturity level on the Center for Internet Security (CIS) controls for agencies: "if we can get each agency at 70%, you put yourself in a very good place in terms of cybersecurity and what they say hygiene," he told the committee.

Project oversight, governance and shared services

Woods outlined EIS programs that manage enterprise governance and oversight, including project portfolio performance (P3) and statewide quality assurance. He said EIS enforces independent quality-assurance requirements for projects over $1 million and maintains portfolio managers and assistant state CIOs who work with agencies on governance, requirements and risk mitigation. Woods emphasized the importance of clear agency requirements and front-end governance in avoiding expensive failures and lengthy stabilization periods for large IT projects.

Staffing, recruitment and workplace model

Woods said EIS comprises roughly 285.4 FTE and reported recent improvements in recruitment compared with two years ago. He said EIS requires a minimum of one in-office day per week for staff (a hybrid workplace model); certain operational teams (data center operations, security operations) continue to work on site full time. Woods said EIS has few remote staff outside Oregon following a return-to-office approach and that compensation and benefits together make state jobs competitive for many IT candidates.

Accessibility, GIS and other programs

Woods briefly noted the Oregon Geographic Information Council (GIS) and the e-government program (including vendor Tyler Technologies) that provides web and accessibility tools for agencies. He said most EIS strategic documents are publicly posted and that EIS consults external vendors (Gartner) and national peers (NASCIO) when developing strategic direction.

Committee questions and follow-up

Committee members asked for more detail on how EIS prioritizes agency security (Woods said priorities are risk-based), how cloud vendors are selected (agency requirements, cost and architecture determine fit), and how water and power requirements affect data-center siting. Woods committed to follow-up details where appropriate and emphasized EIS's collaboration with utilities and other agencies on resiliency planning.

Why this matters

EIS manages enterprise technology and security that underpin many state services, from payroll and tax processing to public-facing websites and emergency systems. The committee heard that improved governance, stronger CIS controls, resilient replication capacity and clearer cloud brokerage can materially affect service continuity, cybersecurity risk and costs across state government.

Next steps

The subcommittee paused the hearing for the day and scheduled continuation of the HB 5,002 informational hearing, including further EIS budget discussion and public testimony the following meeting day.