Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Vida Oversight topic

No spam. Unsubscribe anytime.

VIDA oversight: JLARC flags network and security concerns; CIO says progress on staffing and infrastructure

Joint Legislative Audit & Review Commission · November 7, 2024
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

JLARC continued oversight of VIDA and VITA services, noting improvements and remaining concerns about network reliability and security patching. Virginia's CIO reported staffing increases, network upgrades, and a fast response to a global CrowdStrike outage.

Kimberly Sarte of JLARC gave a brief oversight update on VIDA (VITA), saying agencies report that the multi‑supplier service model has "generally improved" but that some agencies still experience network outages and have purchased their own vulnerability scanning because of inconsistent VIDA practices.

"The quality of the infrastructure services has largely improved," Sarte said, but she added that JLARC will continue monitoring network performance and security scanning and patching practices.

Robert Osmond, Virginia's chief information officer and head of VIDA, told the commission VIDA has rebuilt staff levels (from roughly 200 to about 290), refreshed major vendor contracts, and made substantial network upgrades. Osmond said VIDA tightened vulnerability management standards from 90 days to 30 days and has added roughly 30 cybersecurity professionals to the team.

Osmond described VIDA's response to a global CrowdStrike outage: his office and agency partners remediated more than 1,000 servers and manually touched about 20,000 workstations over a single weekend while handling about 4,000 help‑desk tickets to restore critical services. He said VIDA is pursuing application modernization, shared services (for example the Virginia permit transparency initiative), and cloud‑based efficiency measures, and that the enterprise identified approximately 123 legacy systems in need of modernization with an estimated cost of about $477,000,000 over multiple years.

JLARC said it will continue routine oversight of VIDA's network reliability and security work and requested updates on remediation and patching targets.