Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

State cybersecurity office expands enterprise monitoring and security operations; committee holds executive sessions on vulnerabilities

5448031 · July 22, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

OITS and the Kansas Information Security Office briefed the panel on expanded enterprise security tools, an emerging 24/7 security operations center and ongoing deployments of endpoint and vulnerability-management tools; because discussion touched on sensitive system details, the committee recessed into executive session.

The Legislative Post Audit Committee received a technical briefing from Office of Information Technology Services (OITS) and the Kansas Information Security Office (KISO) about an expanded statewide cybersecurity service model, the deployment of enterprise monitoring tools and plans to staff a 24/7 Security Operations Center (SOC).

Jeff Maxon, OITS chief information officer, described OITSservice model work to document agreements with individual agencies and to clarify which services OITS provides across diverse agency IT environments. He told the committee OITS is working toward completed written service agreements for each agency by the end of the year to remove uncertainty over responsibilities for account management, desktop support, patching and other operational services.

John Godfrey, the state chief information security officer, described KISO operations and ongoing deployments. Godfrey said KISO had grown to 42 FTEs with an approximate annual budget of $11 million (fiscal 2024) including general fund and off-budget appropriations. He summarized core enterprise security services the office now provides at no cost to agencies, including security-awareness training, enterprise log aggregation and monitoring, endpoint detection and response (EDR), endpoint management, fire-wall engineering, network intrusion prevention and incident response coordination. Godfrey said the SOC is being staffed to provide round-the-clock monitoring and incident response, and he provided a sense of the data volume the SOC ingests and monitors: "We collect and monitor... somewhere between 8 and 14,000,000,000 logs a month," he said, underscoring the scale of statewide monitoring.

Godfrey described a shift toward continuous, endpoint-level scanning for vulnerabilities rather than periodic network scans, and he noted KISO depends on agencies to give it the ability to install monitoring agents on agency devices or to allow agencies to operate the tools themselves. The briefing explained the two-part vulnerability process: (1) identification and reporting using KISO-provided or agreed tools, and (2) remediation (patching) which remains primarily an agency IT responsibility. Godfrey said KISO is deploying privileged-access management (PAM) tools, extending EDR coverage (about 20,000 endpoints already) and deploying endpoint management (roughly 17,000 endpoints currently visible) to increase visibility and response speed.

Committee members asked technical and oversight questions. Because the briefing and subsequent discussion covered security-sensitive details, the committee recessed into closed executive session under K.S.A. 75-4319(a) to discuss security posture and audit findings in a manner that would not reveal vulnerabilities publicly. The committee later held additional closed sessions that included security discussions with external agencies (for example, the City of Topeka and a set of state agencies previously audited). After the closed sessions, committee leadership signaled no immediate public action was taken but emphasized continued oversight and follow-up of KISO and OITS work.

The briefing and the executive sessions signaled both expanded statewide investment in cybersecurity and legislative interest in ensuring adequate agency cooperation, data access for monitoring and clear service agreements so the division of technical responsibility is explicit. Auditors and KISO officials said continued attention and follow-up will be needed to validate results of the SOC, vulnerability remediation and agency-level patching and configuration.