Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Brook Park council adopts cybersecurity policy to meet Ohio law

Brook Park City Council · December 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The council unanimously moved to adopt Resolution 29-2025, implementing a cybersecurity policy aligned with Ohio Revised Code §9.64 and national frameworks; members said the measure meets the Jan. 1 compliance deadline.

Brook Park City Council on Dec. 16 adopted Resolution 29-2025, a citywide cybersecurity policy the administration said is required under Ohio Revised Code section 9.64.

The measure, introduced by Councilman Dufour and Mayor Orcutt and described in the resolution as consistent with the 2025 Cyber Ohio Local Government Cyber Standards, directs the city to implement a cybersecurity program that includes regular risk assessments, employee training, incident response and recovery planning, and periodic policy review.

Council moved to suspend the normal rules and adopt the resolution during the meeting. Thanking staff for meeting the deadline, Councilman Dufour said, “This is mandated by the Ohio revised code that we have this policy in place by January 1,” and praised the administration’s work to put the policy together.

The resolution declares the measure an emergency so it takes effect immediately upon passage if it receives the affirmative vote of at least five council members; the council recorded the motion to adopt and the resolution passed under suspension of rules. The measure also directs that related incident records and security documentation be treated as confidential security records under the cited statute and exempt from public-records disclosure as provided by ORC §9.64.

City officials said the policy will be filed with the clerk’s office and will align with nationally recognized frameworks such as the NIST Cybersecurity Framework and CIS controls. The council’s action does not include technical implementation details in the public record, consistent with language in the resolution stating that specific details that could create undue risk will be withheld from the public record.

The council did not provide a full, name-by-name roll call in the available transcript for publication; the transcript shows the motion to suspend and adopt passed and councilmembers thanked administrators and staff for meeting the statutory deadline. The policy is intended to establish ongoing risk management, incident response capacity, and regular reporting and review requirements to reduce cyber risk to municipal operations.

Council President Salvatore said the adoption demonstrates the city’s commitment to protecting municipal data and services; the city will continue to develop the technical details and procedures consistent with the adopted policy.