The Public GalleryToronto

Audit Committee · 2019-06-28 · 2019.AU3.12

The filed record

Establishment of the City's Cyber Security Program to Enable Vulnerability Assessment and Penetration Testing

The Public Gallery wrote no story on this item. What follows is the city’s own record of what happened to it, as filed: nothing on this page is summarised or scored by us.

The decision

2019-07-16 · Toronto City Council · adopted

As filed

City Council on July 16, 17 and 18, 2019, adopted the following: 1. City Council request the City Manager, the Chief Information Officer and the City Clerk to co-ordinate and develop standard incident management procedures including communication protocols to address incidents involving cyber attacks/information breaches; the incident management procedures and communication protocols should be liaised across the City, including agencies and corporations, and should include: a.

Show the rest of As filed, 710 more characters as filed

guidelines describing the sequence of actions that should take place as soon as staff become aware of a cyber attack/information breach incident; b. communication protocols detailing key contact names, functions and contact information for staff to receive guidance; c. reports to be completed by the affected organization, detailing the date of incident, systems affected, information compromised, and other relevant details; and d. communications to the media and/or public, where required, including privacy protocols. 2. City Council request the City Manager, in consultation with the Chief Information Officer, to implement appropriate cyber security training which should be mandatory for all City staff.

On the agenda

As the city filed it

This report responds to Audit Committee's request to report on the Information and Technology Division's outstanding audit recommendation wherein the Chief Information Officer was requested to develop a Cyber Security Program that supported ongoing vulnerability assessment and penetration testing using industry standards applied by subject matter experts. The City already has a foundation of cyber security measures in place to protect the City's information technology systems.

Show the rest of As the city filed it, 1,349 more characters as filed

The Auditor General's recommendations will enhance existing cyber security practices and assist with the detection, prevention and responses to future cyber threats. The City launched its formal Cyber Security Program in 2017 to enhance security capabilities given the increasing complexity in cyber security. The objective of this Program is to identify and mitigate IT-related risks that directly affect the corporate technology environment that City Divisions rely upon when servicing the residents and the public who expect the provision of secure and reliable City services. One component of the Cyber Security Program includes the analysis of resources and funding requirements to develop and implement improvements to vulnerability assessments and penetration testing functions. In addition, the City plans to implement new vulnerability management capabilities as part of a strategy to engage a Managed Security Services Provider (MSSP) and develop partnerships with industry experts. Further to the above recommendation, the Chief Information Officer, in collaboration with the Auditor General's Office, will be issuing a comprehensive Audit Report to Audit Committee for its meeting on October 25, 2019. This report will provide a comprehensive review of all audit recommendations (including both public and confidential) received to date.

Staff recommended

The Chief Information Officer recommends that: 1. Audit Committee receive this report for information.

Considered

  • 2019-06-28 · Audit Committee · amended

    Decision as filed

    The Audit Committee recommends that: 1. City Council request the City Manager, the Chief Information Officer and the City Clerk to co-ordinate and develop standard incident management procedures including communication protocols to address incidents involving cyber attacks/information breaches. The procedures and protocols should include: a. Guidelines describing the sequence of actions that should take place as soon as staff become aware of a cyber attack/information breach incident.

    Show the rest of Decision as filed, 688 more characters as filed

    b. Communication protocols detailing key contact names, functions and contact information for staff to receive guidance. c. Reports to be completed by the affected organization, detailing the date of incident, systems affected, information compromised, and other relevant details. d. Communications to the media/public, where required, including privacy protocols. The incident management procedures and communication protocols should be liaised across the City, including agencies and corporations. 2. City Council request the City Manager, in consultation with the Chief Information Officer, to implement appropriate cyber security training which should be mandatory for all City staff.

  • 2019-07-16 · Toronto City Council · adopted

On the record

The item as the City filed it

More from this meeting

The whole meeting