Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Parma council adopts cybersecurity policy to comply with Ohio House Bill 96; IT director outlines reporting, management roles

Parma City Council · December 16, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Council moved Resolution 215-25 to adopt a municipal cybersecurity program required by Ohio House Bill 96; IT Director Roger Poole described mandatory reporting, upper-management oversight and that procedures will be internal.

Parma City Council voted to adopt a citywide cybersecurity policy to comply with Ohio House Bill 96, moving the resolution through committee and placing it on third reading as amended.

Roger Poole, the city’s IT director, told the Governmental Operations Committee that House Bill 96 created a new requirement for political subdivisions to adopt a cybersecurity policy and that the city’s policy "is actually and will always be a work in progress because conditions change." He explained the policy establishes a cybersecurity program and directs upper-management participation to evaluate the city's cybersecurity posture and readiness. Poole said the policy requires incident reporting to state agencies, including the auditor and the Ohio Department of Homeland Security, which have resources to assist in the event of an incident.

Council members sought clarification about scope and operations: whether the policy would be periodically reviewed (Poole said yes, with upper-management meetings), whether city devices are up to date (Poole said "all of the city's computers are updated to Windows 11"), and how multifactor authentication is being applied to Office 365 accounts (Poole described device/app and telephone options and said two‑factor authentication is enforced for cloud Office 365 users when a new device is used).

Auditor and council members stressed that procedures implementing the policy will be developed internally and are not public record, and that the auditor’s office will continue to review compliance. The committee voted to send the resolution to third reading and the full council later passed the amended resolution.

Next steps: upper management will periodically review cybersecurity posture, the city will formalize procedures (internal), and staff will continue coordinating with audit and safety departments to align implementation.