Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Navajo County adopts updated IT security policy suite to meet state audit requirements
Summary
The Board unanimously approved a revised IT security policy suite that consolidates and modernizes prior county policies (from 18 to 16), emphasizes governance, multi-factor authentication, incident response, data classification, and staff training to meet compliance and audit needs.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
County IT staff presented an updated IT security policy suite and the Board of Supervisors voted unanimously to approve the revisions.
Tom Franklin told the board the consolidated package shrinks the prior suite of 18 policies (approved in June 2018) into a streamlined set of 16 that are meant to align with current security standards and state audit expectations. He described policies that cover governance and roles; security-by-design for procurement and development; system maintenance; training and phishing awareness; incident response and contingency planning aligned with the county continuity-of-operations plan; media and physical protection; account and access management; and data classification and encryption.
“These policies aren’t just best practices. They help us meet state audit requirements and demonstrate our commitment to compliance and security,” the presenter said. The presentation emphasized multi-factor authentication for privileged accounts, monthly phishing exercises, routine testing of incident response plans, and the need to pair policies with clear procedures for day-to-day operations.
Vice Chair made a motion to approve the revised policy suite; Supervisor Benally seconded. All supervisors voted in favor and the motion passed unanimously.
What happens next: With board approval the updated policies replace those adopted in 2018. Staff will implement procedures, continue training, and maintain the policies as living documents to reflect evolving risks.
