Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Council hears gaps in cybersecurity and records-retention procedures; no policy adopted
Summary
Council members and residents raised concerns about the absence of a written citywide cybersecurity policy and inconsistent departmental practices; council agreed to continue discussion and invite IT and security contractors to a future meeting.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Council members reviewed departmental reports on personnel files, building security and network procedures and acknowledged gaps in written cybersecurity policy and records-retention practices.
A council member (S7) said she had not seen any cybersecurity training or policy in the materials she received and asked whether the city had written procedures. Several department representatives and council members agreed procedures are inconsistent across departments, with unlocked files, shared accounts and unclear access rules noted in the packet review.
The mayor (S1) and council suggested inviting the IT support person and the contractor responsible for physical security ("asset level security") to a future meeting so staff can explain backup and retention practices. During discussion, a question arose about how long security camera footage is retained; one speaker (S9) recalled "24 hours" but confirmed uncertainty and the council asked staff to check the retention policy with the security provider.
No motions were made on cybersecurity during the special meeting; the item was listed for further discussion on a future regular council agenda so the city can gather its IT support and security vendor for clarifying testimony.
What to watch: Council requested written policies and consistent department procedures; staff were asked to provide more information on backup, access controls and video-retention policies at a future meeting.

