Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the It Cybersecurity Device Policy topic

No spam. Unsubscribe anytime.

Committee directs staff to advance municipal device and communications policy after cybersecurity briefing and police concerns

Skagway Municipality Civic Affairs Committee · January 22, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

After a cybersecurity risk assessment and public comment from a police officer about CJIS and privacy, the Civic Affairs Committee voted to direct staff to proceed with a municipal electronic communications and device policy; treasurer and clerk described Apple ID management and subpoena procedures.

The Civic Affairs Committee voted to direct staff to proceed with proposed updates to the municipality's personnel policy related to electronic communications and mobile devices after a presentation by Borough Treasurer Heather Rodig and a public comment from Officer James Michaels raising privacy and CJIS concerns.

Rodig said the draft policy, developed over two years with the IT committee and following a 156-page cybersecurity risk assessment, would allow municipal devices to be managed centrally (municipal Apple IDs, app controls through Apple Business Manager) while providing options for employees to use personal devices with defined parameters. "We are going to assign each person their own skyway.org Apple ID ... and then we'll use our Apple, business manager to manage what apps they can download on their phone that are legal," Rodig said.

Officer James Michaels, speaking in public comment, warned the draft as written could allow a municipality to "seize a personal device for inspection" and said that municipal phones often contain CJIS-protected material such as crime scene photos and intelligence; "That's not gonna happen," he said, urging clearer limits on who could access devices and under what authority. Rodig and Clerk Steve Burnham responded that device access would be governed by subpoena or legal process, that a separate privacy/personal information policy will follow, and that CJIS protections are being considered separately.

Burnham described how municipal Apple IDs, backups and iCloud/Dropbox workflows work and pointed out that actions like restoring a destroyed device are observable to the employee (notifications and two-factor codes). He said the clerk's office would support implementation for boards, commissions and staff but would not itself manage all departmental device use.

The committee subsequently voted to direct staff to continue work and proceed with bringing the draft policy and related resolution to the personnel policy for assembly consideration. The vote was carried by voice.

What happens next: staff will continue drafting the device policy and the complementary privacy/PPI and CJIS-related policies, pursue grant funding for policy drafting as described in the meeting, and prepare assembly-level materials.