The filed record
Establishment of the City's Cyber Security Program to Enable Vulnerability Assessment and Penetration Testing
The Public Gallery wrote no story on this item. What follows is the city’s own record of what happened to it, as filed: nothing on this page is summarised or scored by us.
The decision
2019-07-16 · Toronto City Council · adopted
As filed
City Council on July 16, 17 and 18, 2019, adopted the following: 1. City Council request the City Manager, the Chief Information Officer and the City Clerk to co-ordinate and develop standard incident management procedures including communication protocols to address incidents involving cyber attacks/information breaches; the incident management procedures and communication protocols should be liaised across the City, including agencies and corporations, and should include: a.
Show the rest of As filed, 710 more characters as filed
guidelines describing the sequence of actions that should take place as soon as staff become aware of a cyber attack/information breach incident; b. communication protocols detailing key contact names, functions and contact information for staff to receive guidance; c. reports to be completed by the affected organization, detailing the date of incident, systems affected, information compromised, and other relevant details; and d. communications to the media and/or public, where required, including privacy protocols. 2. City Council request the City Manager, in consultation with the Chief Information Officer, to implement appropriate cyber security training which should be mandatory for all City staff.
On the agenda
As the city filed it
This report responds to Audit Committee's request to report on the Information and Technology Division's outstanding audit recommendation wherein the Chief Information Officer was requested to develop a Cyber Security Program that supported ongoing vulnerability assessment and penetration testing using industry standards applied by subject matter experts. The City already has a foundation of cyber security measures in place to protect the City's information technology systems.
Show the rest of As the city filed it, 1,349 more characters as filed
The Auditor General's recommendations will enhance existing cyber security practices and assist with the detection, prevention and responses to future cyber threats. The City launched its formal Cyber Security Program in 2017 to enhance security capabilities given the increasing complexity in cyber security. The objective of this Program is to identify and mitigate IT-related risks that directly affect the corporate technology environment that City Divisions rely upon when servicing the residents and the public who expect the provision of secure and reliable City services. One component of the Cyber Security Program includes the analysis of resources and funding requirements to develop and implement improvements to vulnerability assessments and penetration testing functions. In addition, the City plans to implement new vulnerability management capabilities as part of a strategy to engage a Managed Security Services Provider (MSSP) and develop partnerships with industry experts. Further to the above recommendation, the Chief Information Officer, in collaboration with the Auditor General's Office, will be issuing a comprehensive Audit Report to Audit Committee for its meeting on October 25, 2019. This report will provide a comprehensive review of all audit recommendations (including both public and confidential) received to date.
Staff recommended
The Chief Information Officer recommends that: 1. Audit Committee receive this report for information.
Considered
2019-06-28 · Audit Committee · amended
Decision as filed
The Audit Committee recommends that: 1. City Council request the City Manager, the Chief Information Officer and the City Clerk to co-ordinate and develop standard incident management procedures including communication protocols to address incidents involving cyber attacks/information breaches. The procedures and protocols should include: a. Guidelines describing the sequence of actions that should take place as soon as staff become aware of a cyber attack/information breach incident.
Show the rest of Decision as filed, 688 more characters as filed
b. Communication protocols detailing key contact names, functions and contact information for staff to receive guidance. c. Reports to be completed by the affected organization, detailing the date of incident, systems affected, information compromised, and other relevant details. d. Communications to the media/public, where required, including privacy protocols. The incident management procedures and communication protocols should be liaised across the City, including agencies and corporations. 2. City Council request the City Manager, in consultation with the Chief Information Officer, to implement appropriate cyber security training which should be mandatory for all City staff.
2019-07-16 · Toronto City Council · adopted
On the record
More from this meeting
- Financial Statements for the Year Ended December 31, 2018 - Agencies and Corporations (Part 1)Filed record
- Business Improvement Areas (BIAs) - 2018 Audited Financial Statements - Report No. 1Filed record
- Arenas - 2018 Audited Financial StatementsFiled record
- Community Centres - 2018 Audited Financial StatementsFiled record
- Status of the Financial Statement Audits of the City’s Agencies and Corporations for the Year Ended December 31, 2018Filed record
- Auditor General’s 2019 Status Report on Outstanding Audit Recommendations for City Agencies and CorporationsFiled record