Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the It Policy And Cybersecurity topic
No spam. Unsubscribe anytime.
Waukesha City IT Board unanimously approves five IT policies; staff to align policies with CIS controls
Summary
The Waukesha City Information Technology Board approved five existing policies and directed staff to begin aligning the city's IT policies and procedures with the Center for Internet Security(CIS) 18 controls starting in March 2025.
Get email alerts on the It Policy And Cybersecurity topic
No spam. Unsubscribe anytime.
The Waukesha City Information Technology Board on Feb. 5 unanimously approved five existing IT policies and heard that staff will begin aligning the city's policies and procedures with the Center for Internet Security (CIS) 18 controls.
The board approved the policies as presented and will continue work through 2025 to map current policies to CIS Implementation Group 1, then IG 2, to formalize procedures and help support regulatory compliance, staff said.
Greg Viness, an IT staff representative, read a message from a staff member named Chris explaining the plan: "The Center for Internet Security, CIS, has a set of 18 controls that they call the community defense model or CDM that have become industry best practices when it comes to good cyber hygiene. These controls map to a wide variety of formal risk management frameworks, which when followed by organizations help with regulatory compliance such as PCI, DSS, CJIS, HIPAA, and, Critical Infrastructure Protection Standards... Starting in 2025, I plan to align all of our IT policies, cyber processes, and procedures to, IG 1 and then IG 2, which will help my staff focus their attention on the most important steps to defending the city's network from attacks." Viness said the work will begin in March.
The five policies read into the record and approved were: the PCI DSS-related policy, the antivirus (malware defense) policy, the B-20 software-usage policy identified as the acceptable use policy, the change-management policy, and the email policy. Board members agreed to reapprove the current set as a baseline and to return proposed language changes and missing policies to the board as they are revised.
Board discussion touched on several implementation points. Service-provider management was highlighted as a key gap to address because third-party vendors and cloud services (for example, hosted databases) present common attack vectors, a board member said. Staff noted the city uses a vendor assessment questionnaire that asks prospective vendors about antivirus, patching, and perimeter protections.
Board members also discussed routine network logs and password practices. Viness said the city's firewalls produce many logged attempts to access systems and that such attempts are common. He noted the city currently enforces 16-character passwords with complexity requirements and has moved to allow FIDO keys so password rotation is not mandatory for users who use those keys.
Motion and vote: The chair moved to approve the five policies "as attached" (PCI DSS, antivirus, B-20/software usage/acceptable use, change management, and email policy); the motion was seconded by Mister Gruters and passed unanimously. The meeting transcript does not record a roll-call vote.
Staff said many of the controls are already in place and that the CIS alignment exercise is intended to formalize and, where necessary, minimally adjust policy language. The board directed staff to continue the work and return revised policies for review and approval as they are completed.
The board had no further business and adjourned later that evening.
