Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Information Security topic
No spam. Unsubscribe anytime.
Skagway finance committee debates mandatory biometrics and scope in proposed device policy
Summary
The finance committee reviewed Resolution 25-18 to amend personnel policy by reference to an electronic communications and mobile-device policy after a cyber risk assessment found security gaps; members asked to exclude assembly members, remove proprietary vendor names, and make biometrics optional.
Get email alerts on the Information Security topic
No spam. Unsubscribe anytime.
The Skagway finance committee on Aug. 5 reviewed a proposal to amend the municipality’s personnel policy so it incorporates an acceptable-use and mobile-device management policy intended to address vulnerabilities identified in a recent cyber risk assessment. Municipal Manager Alex Deetsch told the committee the assessment showed "critical vulnerabilities, including uncontrolled access to municipal data, inconsistent device security, and lack of a policy or guidelines about how municipal employees use municipal IT equipment." Deetsch said the policies were drafted by the IT committee with input from the municipality’s IT contractor to align with standard practices.
Committee members pressed for clearer language on who the policy would apply to after noting that assembly members, volunteers and officials often access municipal systems on personal devices. One assemblymember said the current draft, read literally, could cover "everybody on the assembly who's using their personal device," and requested an explicit exclusion or clarification for the assembly and other elected officials. Deetsch said the intent was for the policy to apply to "people who fall under the personnel policy," i.e., employees, but agreed the language could be clarified.
The draft also includes technical requirements that drew questions. A committee member objected to a provision described in the draft as "mandatory 6 character alphanumeric passcodes with biometric unlock," saying, "I personally do not understand why we have a mandatory biometric standard" and expressing reluctance to require assembly members or staff to share biometric data. The IT contractor explained the draft followed contractor best practices and noted that multifactor authentication is commonly required; Deetsch said the committee could remove or soft‑en the biometric-mandatory language and provide alternatives such as strong passcodes or multifactor options.
Members recommended removing or generalizing proprietary product names listed in the draft (for example, the document references endpoint protection software by name). One assemblymember suggested stating technical requirements ("endpoint protection software or equivalent") rather than naming a specific vendor so the policy does not lock the municipality to a product that may change.
No final vote was taken. Deetsch said staff could prepare alternate language reflecting the committee’s concerns — clarifying that the personnel-policy reference applies to employees (not the assembly), making biometrics optional or providing alternatives, and removing proprietary references — and attempt to include that version in the packet for the full assembly meeting.
The committee’s discussion highlights the municipal tension between tightening cybersecurity after a risk assessment and limiting policy language so it does not unintentionally regulate elected officials or bind the municipality to specific vendors. The item was set to appear on the assembly agenda with a possible revised draft.
