Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Security topic

No spam. Unsubscribe anytime.

Committee hears technical briefing on CJIS controls, data residency for Google licenses

Oxnard Finance and Governance Committee · July 29, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Deputy CIO Andy Ansurian briefed the committee on the FBI CJIS Security Policy requirements (18 programs across three pillars) and said the Google Assurance Plus component will enforce US data residency, vendor backgrounding, and audit trails for criminal-justice data.

During the discussion of the Google licensing agreement, deputy CIO Andy Ansurian walked committee members through how the FBI CJIS Security Policy's controls map to software, vendors, and operational processes.

Ansurian explained CJIS compliance requires 18 programs across three pillars: managing who has access to CJIS systems, protecting physical assets and planning for emergencies, and securing technology and vendors. "The 1st pillar is managing who has access to the CJIS systems," he said. He described personnel security, access control, audit monitoring and supply-chain risk as specific programmatic controls. Regarding the proposed Google contract, Ansurian said the Assurance Plus add-on would allow the city to control data residency "meaning, if we put data on the Google Cloud, it'll stay within The United States" and provide audit trails and background checks for vendor staff who access criminal-justice information.

Committee members pressed staff on whether the Google component is a full CJIS solution or part of a broader set of controls; staff said multiple vendors and internal procedures are used together to meet CJIS requirements and emphasized continual auditing and annual review. The briefing underscored that meeting CJIS standards is an ongoing process rather than a one-time configuration change.