Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Board approves county Information Security Program, including AI use guidance
Summary
The Board approved a new Information Security Program and suite of policies covering audit logging, access control, incident response, patch management and a new AI policy guiding permissible uses, data handling and accuracy checks for generative tools.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The Board approved a countywide Information Security Program and associated policies presented by Information Security Officer Joseph Fouts. The program, based on NIST frameworks, establishes objectives for confidentiality, integrity and availability of county data and sets standards for logs, email retention, acceptable use, multifactor authentication, access control, incident response, patch management and hardware lifecycle.
A notable addition is an AI policy that frames generative AI as a productivity tool while outlining safeguards: employees must consider the sensitivity of uploaded documents, verify accuracy of AI outputs, and follow prohibitions against uses that would perpetuate bias or violate CJIS/HIPAA/IRS requirements. The policy specifies Microsoft Authenticator as the approved MFA app and sets timelines for critical patch deployment (2–7 business days). Board members praised the policy’s thoroughness and approved it by voice vote.
