Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the It Governance And Physical Security topic
No spam. Unsubscribe anytime.
City takes back door-access rollout amid security concerns and raises IT governance questions
Summary
The Technology Commission heard that the Johnson Controls door-access control system at City Hall contains security and configuration flaws; IT will retake oversight and ask the vendor to fix integration and operational gaps.
Get email alerts on the It Governance And Physical Security topic
No spam. Unsubscribe anytime.
IT Director Jim Matoski told the commission on Oct. 22 that the City Hall door-access control project implemented by Johnson Controls has security, integration and procurement problems and that the IT department is reclaiming oversight of the project from the Department of Administration.
Matoski said the vendor'installed virtual machine running the door-control software (C•Cure, virtual appliance) uses a local SQL Express instance rather than the city's centralized SQL server, runs services under a vendor account instead of a dedicated service account, and includes an auto-login that Matoski called a "violation of security policy." He said Johnson Controls had been informed of the concerns and a comprehensive discussion was scheduled for Nov. 7.
The practical impact: the current implementation requires manual account and card creation in a separate database rather than integrating with the city's Active Directory/Entra ID. No door-access badges had been issued at the time of the meeting. Matoski described scheduling and after-hours locking as unresolved: meetings that run late require door controls to be open for the duration, and the current design lacks an agreed mechanism to lock all doors once a meeting finishes.
Procurement and project management concerns: The project was moved from IT to the Department of Administration earlier in the capital-improvement process because physical door modifications would have triggered state-mandated procurement and construction bidding. Matoski told the commission that handing the vendor responsibility for the procurement made sense but that the delivered implementation did not meet the stated security and operations requirements; he said, "I'm taking this back, and this is now going to be re-discussed and re-evaluated." The Johnson Controls rollout also omitted full police-department integration that would allow dispatch to lock or unlock city doors in an active threat.
Broader governance discussion: Commissioners spent substantial time discussing whether the city should rename the IT department to reflect security responsibilities (proposed name examples: Technology and Security Management) and whether the city needs a dedicated technical analyst/business analyst or project-manager role to evaluate technology elements of cross-department projects. Matoski and commissioners emphasized that projects that "touch the network" should be reviewed by IT and that a recurring failure mode is projects proceeding without thorough technical acceptance testing.
Next steps: IT will hold the Nov. 7 meeting with Johnson Controls, assess integration with Active Directory/Entra ID, and return to the Technology Commission with findings and a remediation plan. Commission members urged the city to consider assigning a project resource to review technology components of cross-department capital projects and flagged that obtaining a permanent staff resource will require budgeting decisions.
Ending: Commissioners agreed to follow the Johnson Controls remediation closely and asked IT to report back after the Nov. 7 vendor meeting. The discussion concluded with a broader recognition that technology, security and project management resources must be clarified in the city's organization and budgets.

