Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Adams County adopts NIST Cybersecurity Framework v2.0 and assigns IT team to lead implementation

Adams County Board of Commissioners · December 29, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Adams County Board of Commissioners unanimously adopted the NIST Cybersecurity Framework Version 2.0 to comply with Ohio House Bill 96, directing the county IT department, working with vendor Freedomlinx, to implement policies and report progress to the commissioners.

Adams County commissioners voted to adopt the National Institute of Standards and Technology Cybersecurity Framework Version 2.0 as the county’s official model for managing cybersecurity risks.

The resolution, moved by Jason Hayslip and seconded by Kelly Jones and adopted by roll call, cites Ohio House Bill 96 as the legislative driver for requiring political subdivisions to maintain a cybersecurity program. The adoption directs the county’s IT department, working under the direction of Freedomlinx, to manage the cybersecurity program and oversee implementation of the framework.

The board authorized the administration to develop and implement the necessary policies, procedures and operational controls to align county systems with the framework and directed that commissioners review and approve any additional policies before county‑wide adoption. The resolution also requires an annual implementation report; the transcript records Marla May, Clerk, as responsible for providing that report to the board.

The commissioners and administration said adopting the framework will strengthen protections for sensitive data and improve resilience against cyberattacks, but the resolution also acknowledges the need for updates to policies, standards and operational practices and implies future resource and staffing decisions will follow. No specific implementation timeline beyond the annual reporting requirement was included in the resolution.