Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Council reviews new cybersecurity policy; staff will remove 'budgetary constraints' language and require staff sign-off
Summary
City IT leadership brought a detailed cybersecurity policy for council review; staff said they will remove wording about 'budgetary constraints,' require employee sign-off and training, and use progressive discipline for repeat violations, while confirming compliance with state law.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
The council reviewed a proposed cybersecurity policy presented by the city CAO (Jason Emmick, speaker 27) and IT Director John Monofusco (speaker 9). The policy, created to comply with state statutory requirements, is the city's first formal cybersecurity policy and runs to more than 100 pages of supporting material.
Council members raised questions about language in the policy referencing "budgetary constraints." IT Director Monofusco acknowledged the concern and said he would remove that parenthetical language and circulate an amended draft. He also said staff will work with HR to ensure all employees receive a copy of the policy, complete cybersecurity training, and sign to acknowledge receipt. "Yes, all employees will be receiving a copy...and sign off on it as well as their cyber security training," Monofusco said. Council members emphasized the critical nature of IT protections and asked staff to ensure consistent funding and progressive discipline for serious violations. Administration representatives confirmed contingency planning and tabletop testing are in place but redacted the specifics for security reasons.
