Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Board approves reorganized cybersecurity policy modeled on NIST framework
Summary
CBPU approved a reorganized cybersecurity policy intended to consolidate and simplify over 500 overlapping control requirements into a document aligned with the NIST framework; staff will forward the policy to city council for final consideration.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Pat Poole presented a reorganized cybersecurity policy and asked the Coldwater Board of Public Utilities to approve the document for forwarding to city council. Poole said the CBPU's current cybersecurity strategy dates to 2019 and that the utility has accumulated dozens of policy documents that are difficult for staff to navigate.
Poole said the proposal maps controls into the NIST framework domains (Identify, Protect, Detect, Respond, Recover) with an additional "Govern" domain to tie responsibilities together. He described the goal as reducing duplication, clarifying responsibilities, and making controls more actionable and searchable; staff estimate consolidating overlapping requirements from over 500 to roughly 50 control items.
A motion to approve the reorganized cybersecurity policy was made, supported and approved by voice vote. Pat Poole confirmed that if the board approved, staff would send the policy to the city council for final consideration at the council meeting on Monday.
The board did not request substantive edits during the meeting; the transcript records one board member thanking Poole and then moving approval. The policy adoption at the board level is a forward step; final authority rests with the city council per the standard review process.

