Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Judicial Cyber Audit topic

No spam. Unsubscribe anytime.

Audit finds disagreement over judicial adoption of state cybersecurity policies; judiciary agrees to use CISPs as foundation

Legislative Audit Committee
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A public performance audit found the Colorado Judicial Department’s interpretation of the Colorado Information Security Policies (CISPs) differs from the state chief information security officer’s expectation. Judicial officials agreed to use CISPs as the foundation for their cybersecurity policies and the committee moved to executive session for confidential findings.

Auditors presenting a discretionary cybersecurity resiliency performance audit told the Legislative Audit Committee that the Colorado Judicial Department’s interpretation of statutory requirements for cybersecurity differs from the expectation of the state chief information security officer. The differing interpretations prompted a recommendation that Judicial either adopt the Colorado Information Security Policies (CISPs) as the foundation for its policies or seek statutory change removing Judicial from the statutory definition of a public agency.

Matt Devlin, chief IT auditor at the Office of the State Auditor (OSA), and Anders Erickson of the contracted audit firm outlined the audit scope and said the engagement produced six findings and 46 recommendations in total, with one public finding and five findings placed in a confidential report because they involve sensitive security details. The public finding focuses on conflicting interpretations of the state CISPs and the need for Judicial to align its policies with statute and statewide standards.

Colorado State Court Administrator Steven Vasconcellos told the committee that Judicial agrees with recommendation #1 and will consult with the governor’s Office of Information Technology and incorporate CISPs into Judicial’s annual cybersecurity plan. Vasconcellos said the department already agreed to the audit’s recommendations and has implemented one recommendation with the remainder in progress.

Because the remaining findings involve specialized security details, the committee voted to go into executive session under section 24-6-402 to discuss the confidential report. Clerk instructions were given to halt the usual recording and begin a separate executive-session recording, and visitors were asked to leave the hearing room.

OSA and Judicial emphasized that the work aims to strengthen cybersecurity to preserve access to justice and that Judicial staff have cooperated with auditors. The public audit was released at the hearing; the committee will consider confidential recommendations and implementation timelines during executive session and in subsequent follow-up reviews.