Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Policy topic

No spam. Unsubscribe anytime.

Clermont County adopts cybersecurity program aligned with state law and CIS controls

Clermont County Board of Commissioners · December 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Clermont County Board of Commissioners adopted the county cybersecurity program (2025 v1.0.0.1) on Dec. 17, 2025, establishing controls, policies and department responsibilities aligned to CIS Controls v8.1 and Ohio House Bill 96; compliance is required of all county departments and elected offices effective 12/17/2025.

Clermont County commissioners on Dec. 17 adopted a countywide cybersecurity program designed to standardize controls, responsibilities and procedures across county departments.

Chris Davis, director of the Information Services Division, presented the Clermont County Cybersecurity Program (2025 version 1.0.0.1, dated Oct. 16, 2025). The program establishes a cybersecurity framework, policies, controls and responsibilities aligned with the Center for Internet Security Controls version 8.1 and states that county policies will comply with Ohio House Bill 96 and applicable regulatory standards, including HIPAA, CJIS, PCI and the NIST Cybersecurity Framework.

The board moved, seconded and adopted the program on a roll call vote, and the program was made effective on Dec. 17, 2025. The resolution requires that all county departments and elected offices comply with the program's requirements as detailed in the document.

County staff said the program adds sections on warranty against findings for recovery, no outstanding tax liability and no collusion for vendor agreements, and clarifies compliance expectations for departments that handle regulated data. Commissioners did not express additional policy amendments during the meeting; staff will take the next steps to publish the program and update internal procedures and training to meet the new requirements.