Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the It Security Policies Operations topic

No spam. Unsubscribe anytime.

Franklin Technology Commission reviews IT security policies, CJIS role realignment and cloud migrations

2461034 · February 28, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Commission reviewed proposed NIST/CJIS‑aligned media protection and physical environment policies, approved an internal CJIS role realignment, and received updates on PBX cloud migration, body camera cloud storage and desktop deployment issues.

The Franklin City Technology Commission on Feb. 24 reviewed draft media protection and physical environment security policies tied to NIST and CJIS controls, accepted departmental CJIS role realignments and heard technical updates about phone, video and endpoint deployments.

Director Jim Matelski asked commissioners to review bundled policy documents (media protection, physical environmental security and technical controls) and return comments by March 5 so staff can produce a consolidated redline. He said the policies aim to satisfy CJIS 5.9.5 requirements and stressed the need for documented procedures for removable media, encrypted drives and decommissioning.

Why it matters: the Police Department’s CJIS obligations require strict controls on authentication, media handling, physical access and audit logging. Matelski said the city is updating roles and procedures to comply with revised CJIS guidance and to centralize security authority within IT for enforcement.

CJIS role changes and technology operations

Matelski briefed the commission on a CJIS role realignment approved by Police Chief Craig Lerman: Captain Daniel Morris retired and Jason Ireland has been promoted to police captain and will act as the CJIS terminal agency coordinator / local agency security officer; Matelski will be the CJIS systems officer (CSO) and agency security officer (ISO); Cindy Behnke will remain in her CJIS agency coordinator role. Matelski said, “Within the role, the director of IT now has full authority to set and implement all security policies and procedures at the Franklin Police Department.”

Operational updates and capital timing

IT reported the PBX migration to a cloud phone provider (RingCentral) is near completion and the police department’s telephony was ported to the cloud with no reported dispatch outages. The commission was told a contract approved Feb. 18 will migrate squad and body‑worn video from local WatchGuard storage to Motorola’s cloud; staff estimate this migration will eliminate an immediate need to provision roughly 56 terabytes of local storage that had been forecast for 2026.

Hardware, licensing and deployment notes

Matelski described several operational constraints: ArcGIS named subscription licensing may increase costs; a fingerprint capture hardware refresh is planned for 2026 as older units reach end of life; new Windows 11 Lenovo desktops experienced a display driver bug that was mitigated by switching to AMD Adrenaline drivers; and because Intune/Office 365 cloud authentication is not yet usable, new laptops and desktops are being provisioned manually.

Policy review process and next steps

Commissioners asked for a lighter review process; Matelski said staff will briefly introduce each policy and accept written feedback before the next meeting. He asked that comments be emailed to him by March 5 so staff can consolidate redlines. The commission also discussed physical controls such as card readers for City Hall, wiring cabinet locks, data‑center temperature and fire‑suppression limitations, and documented destruction procedures for hard drives.

Ending

The commission scheduled follow up: commissioners will return comments on policies by March 5, and IT will present consolidated redlines and a relaunch plan (Office 365 feasibility) at the next meeting. Matelski emphasized that policy, vendor vetting and a clear discovery phase must precede significant new cloud or security rollouts.