Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Legislative Cybersecurity topic
No spam. Unsubscribe anytime.
Legislative IT office outlines SOC monitoring, NIST mapping and plans for zero‑trust access
Summary
Legislative Office of Information Technology Services briefed the committee on data‑center arrangements, 24/7 monitoring, Microsoft 365 U.S. data residency, automated inventory and plans to move to zero‑trust and SASE models; the office said it lacked a funded CISO position.
Get email alerts on the Legislative Cybersecurity topic
No spam. Unsubscribe anytime.
Bob Murphy, representing the Legislative Office of Information Technology Services, briefed the committee on the legislature’s cybersecurity posture and plans tied to Senate Bill 291.
Murphy said legislative data centers include on‑capitol facilities and backups hosted at a LightEdge data center in Kansas City, Missouri. He said Microsoft 365 data for the legislature is stored within the United States and that only screened U.S. citizens work at the data centers. The office has implemented automated software tracking for endpoints and is adding scannable barcodes to improve hardware inventory and ticketing.
For protection and detection, Murphy described encryption at rest and in transit for Microsoft 365, password management (Bitwarden), endpoint detection and response, data loss prevention capabilities, a legislative security operations center providing 24/7 monitoring, and insider‑risk management tools. Murphy said the office can perform automated mail purges and has containment playbooks that can isolate a compromised endpoint within about 10 seconds.
Murphy said the office is mapping policies to NIST subcategories, using SCAP and CIS‑CAPPRO assessors for endpoint configuration checks and planning to provide departmental NIST profiles and maturity assessments. He said a fully staffed CISO position is not funded at present because appropriations did not include it; the office continues to pursue strategy, patching, threat intelligence updates and testing.
Committee members asked about constituent emails being delayed by quarantine and Murphy said a new constituent relationship management (CRM) tool approved by the Legislative Coordinating Council is scheduled to go live on Feb. 28 to improve handling of quarantined messages. Murphy also said the office is scheduling collaborative tabletop exercises with CISA after session to test incident response.
Ending: Murphy described zero‑trust and secure access service edge (SASE) architectures as the target for future work; the office plans to keep testing and modernizing to reduce technical debt and improve cloud security.

