The filed record
Cybersecurity Incidents at the City and its Agencies and Corporations: Integrated Incident Response Plan is Needed
The Public Gallery wrote no story on this item. What follows is the city’s own record of what happened to it, as filed: nothing on this page is summarised or scored by us.
The decision
2021-04-07 · Toronto City Council · adopted
As filed
City Council on April 7 and 8, 2021, adopted the following: 1. City Council request the Auditor General to provide presentations to City organizations, including major agencies and corporations, on the City cybersecurity reports and lessons learned. 2. City Council adopt the confidential instructions to staff in Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General. 3. City Council request the City Manager to forward Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General to City Division Heads and Chief Executive Officers of major City agencies and corporations and request them to review and implement the confidential instructions that may be relevant to their respective operations.
Show the rest of As filed, 1,238 more characters as filed
4. City Council direct that Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General be released publicly at the discretion of the Auditor General, after discussions with the appropriate City Officials, as it contains information involving the security of property belonging to the City or one of its agencies and corporations and information explicitly supplied in confidence to the City of Toronto which, if disclosed, could reasonably be expected to impact the safety and security of the City and its services. Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General remains confidential at this time in accordance with the provisions of the City of Toronto Act, 2006, as it contains information involving the security of property belonging to the City or one of its agencies and corporations and information explicitly supplied in confidence to the City of Toronto which, if disclosed, could reasonably be expected to impact the safety and security of the City and its services. Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General will be made public at the discretion of the Auditor General, after discussions with the appropriate City Officials.
On the agenda
As the city filed it
Over the past decade, the City of Toronto, like other large organizations, is increasingly conducting business and key operations online in a networked environment. This makes operations more efficient and citizens are served better. The purpose of this report is to communicate security incidents that occurred at a City division and a City organization and to highlight the importance and urgency for the City to have a standard incident management process developed and implemented across City divisions and its agencies and corporations.
Show the rest of As the city filed it, 1,470 more characters as filed
A standard incident management process will enable the Chief Information Security Officer (CISO) to analyze these attacks and develop a coordinated response on any potential cyberattacks. This will enhance City-wide cybersecurity. In a 2019 Report for Action, the Auditor General highlighted the importance and urgency for the City to develop a standard incident management process and implement it across City divisions, agencies and corporations. We have made additional recommendations in one other report entitled "Information Technology Projects Implementation: Information Privacy and Cybersecurity Review of Human Resource System" that is also being tabled at the February 16, 2021 Audit Committee. The confidential report attached provide more details of the nature of incident and management actions. The work performed in relation to this report does not constitute an audit conducted in accordance with Generally Accepted Government Auditing Standards (GAGAS). However, we believe we have performed sufficient work and gathered sufficient appropriate evidence to provide for a reasonable basis to support our observations and recommendations. This public report contains two administrative recommendations. The confidential information and recommendations are presented separately to this report in Confidential Attachment 1. The confidential report will be made public at the discretion of the Auditor General after discussing with appropriate City Official.
Staff recommended
The Auditor General recommends that: 1. City Council request the Auditor General to provide presentations to City organizations (major agencies and corporations) on the City cybersecurity reports and lessons learned. 2. City Council adopt the confidential recommendations contained in Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General. 3. City Council direct that Confidential Attachment
Show the rest of Staff recommended, 714 more characters as filed
1 be released publicly at the discretion of the Auditor General, after discussions with the appropriate City Officials, as it contains information involving the security of property belonging to the City or one of its agencies and corporations and information explicitly supplied in confidence to the City of Toronto which, if disclosed, could reasonably be expected to impact the safety and security of the City and its services. 4. City Council request the City Manager to forward Confidential Attachment 1 to City Division Heads and Chief Executive Officers of major City agencies and corporations and request them to review and implement the recommendations that may be relevant to their respective operations.
Considered
2021-02-16 · Audit Committee · adopted
Decision as filed
The Audit Committee recommends that: 1. City Council request the Auditor General to provide presentations to City organizations, including major agencies and corporations, on the City cybersecurity reports and lessons learned. 2. City Council adopt the confidential instructions to staff in Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General. 3. City Council request the City Manager to forward Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General to City Division Heads and Chief Executive Officers of major City agencies and corporations and request them to review and implement the confidential instructions that may be relevant to their respective operations.
Show the rest of Decision as filed, 540 more characters as filed
4. City Council direct that Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General be released publicly at the discretion of the Auditor General, after discussions with the appropriate City Officials, as it contains information involving the security of property belonging to the City or one of its agencies and corporations and information explicitly supplied in confidence to the City of Toronto which, if disclosed, could reasonably be expected to impact the safety and security of the City and its services.
2021-04-07 · Toronto City Council · adopted
On the record
More from this meeting
- Election of Chair - Audit CommitteeFiled record
- Election of Vice Chair - Audit CommitteeFiled record
- Auditor General's 2020 Annual Report - Demonstrating the Value of the Auditor General's OfficeFiled record
- Auditor General's 2020 Annual Report on the Fraud and Waste HotlineFiled record
- Auditor General's Follow-Up of the Outstanding Recommendations - Status UpdateFiled record
- Getting to the Root of the Issues: A Follow-Up to the 2019 Tree Maintenance Services AuditFiled record