Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Vendor Management topic

No spam. Unsubscribe anytime.

Board highlights vendor risks and says vendor assessments are required

Waukesha City Information Technology Board ยท February 5, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Board members flagged third-party/vendor risk during the IT policy review, citing cloud and building-management systems as vectors for attacks; staff confirmed use of a vendor assessment questionnaire to vet security practices.

Board members warned that service providers are often the weak link in local government cybersecurity and asked staff how vendors are vetted.

"Service provider is gonna be like, that's where people get get hit, like, AWS databases and stuff like that or, you know, the air conditioning management that got targeted," a committee member said while urging attention to service-provider risk. Greg Viness said the IT team uses a vendor assessment sheet that asks vendors to describe antivirus, update cadence, external border protections and other security controls.

The board discussed that while the city can control its own network and write policies for internal operations, many third-party services fall outside direct control and require contractual and procedural safeguards. Greg described the assessment as a standard part of vendor onboarding and noted staff will reference those answers in future policy alignment work.