Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Council adopts NIST‑based cybersecurity policy after utility board approval
Summary
The council adopted resolution 26‑72 and policy P26‑01 to reorganize the city's cybersecurity documentation around the NIST framework (identify, protect, detect, respond, recover), consolidating overlapping requirements and clarifying governance and responsibilities.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Patrick Poole presented a reorganization of Coldwater's cybersecurity policy designed to consolidate a sprawling library of documents into a single governance framework based on the National Institute of Standards and Technology (NIST) cybersecurity framework. Poole told council the goal is to reduce overlap—cutting roughly 500 overlapping requirements to about 150—and make responsibilities clearer and more actionable for staff (Patrick Poole, speaker 11).
The Utility Board previously approved the policy and Poole asked council to adopt resolution 26‑72 and policy P26‑01 to implement the new governance structure. Council moved, supported and carried the resolution without recorded opposition.
Poole said the revised policy groups controls in the five NIST buckets (identify, protect, detect, respond, recover) with a central "govern" function to document roles, responsibilities and annual assessments. The adoption places the new policy into effect for city departmental implementation and future annual assessments.

