The filed record
Outstanding Cybersecurity Recommendations from Auditor General Reports - Chief Information Security Officer Status
The Public Gallery wrote no story on this item. What follows is the city’s own record of what happened to it, as filed: nothing on this page is summarised or scored by us.
The decision
2021-07-14 · Toronto City Council · amended
As filed
City Council on July 14, 15 and 16, 2021, adopted the following: 1. City Council request the Auditor General to report to the November 2, 2021 meeting of the Audit Committee with an update on outstanding cybersecurity recommendations from Auditor General reports. 2. City Council request the Chief Information Security Officer and relevant City division heads to accelerate the implementation of outstanding cybersecurity recommendations from Auditor General reports and to accelerate compliance with cybersecurity standards.
Show the rest of As filed, 2,004 more characters as filed
3. City Council request the Chief Technology Officer to expedite the implementation of high-priority cybersecurity recommendations. 4. City Council direct the City Manager to advise the Auditor General on the status of implementation of all high and medium-risk threats, within one week of the timelines outlined in Table 2 in the report (June 22, 2021) from the Interim Chief Information Security Officer and City Council request the Auditor General to verify the implementation and to report to the Audit Committee as soon as possible thereafter. 5. City Council direct that Confidential Attachment 1 to the report (June 22, 2021) from the Interim Chief Information Security Officer remain confidential in its entirety, as it involves the security of property belonging to the City of Toronto. 6. City Council direct that Confidential Attachment 1 to the supplementary report (July 6, 2021) from the Auditor General be released publicly at the discretion of the Auditor General, after discussions with the appropriate City Officials, as it contains information involving the security of property belonging to the City of Toronto or one of its Agencies and Corporations. Confidential Attachment 1 to the report (June 22, 2021) from the Interim Chief Information Security Officer remains confidential in its entirety in accordance with the provisions of the City of Toronto Act, 2006, as it pertains to the security of property belonging to the City of Toronto. Confidential Attachment 1 to the supplementary report (July 6, 2021) from the Auditor General remains confidential at this time in accordance with the provisions of the City of Toronto Act, 2006, as it contains information involving the security of property belonging to the City of Toronto or one of its Agencies and Corporations. Confidential Attachment 1 to the supplementary report (July 6, 2021) from the Auditor General will be made public at the discretion of the Auditor General, after discussions with the appropriate City Officials.
On the agenda
As the city filed it
The Auditor General reviews the implementation status of recommendations made through her audit and investigation reports. The results of the review are reported to City Council through the Audit Committee. The Auditor General has conducted a number of audits since 2015 to assess cybersecurity controls of the City's IT infrastructure, systems, and applications. As per the Auditor General's latest report, there are 43 recommendations related to cybersecurity that have not been fully implemented.
Show the rest of As the city filed it, 4,672 more characters as filed
The Office of the CISO currently has access to 28 of those recommendations through the audit tracking tool, TeamMate. At its meeting on April 7 and 8, 2021, City Council adopted Item AU8.5, Auditor General's Follow-Up of the Outstanding Recommendations - Status Update, without amendments and without debate. http://app.toronto.ca/tmmis/viewAgendaItemHistory.do?item=2021.AU8.5 At its February 16, 2021 meeting, the Audit Committee recommended that: "City Council request the Chief Information Security Officer to report to the May 31, 2021 meeting of the Audit Committee on the implementation status of all outstanding cybersecurity-related audit recommendations, including: a. high priority recommendations where there are still significant risks; b. risks being faced by the City of Toronto as a result of not implementing audit recommendations; c. a risk assessment identifying the impact of the risks after considering any current vulnerabilities; d. any other security risks being faced as a result of the changing cyber threat landscape; and e. short-, medium-, and long-term plans identifying what needs to be done to reduce the risk level for the City of Toronto in an expedited fashion." The Office of the CISO has conducted an assessment based on the above criteria and this report provides an update on the status of high priority outstanding recommendations. As the May 31, 2021 Audit Committee meeting was cancelled, this report is being tabled for the July 7, 2021 Audit Committee meeting. This report pertains to the 28 high priority cybersecurity recommendations currently accessible to the Office of the CISO in TeamMate. The Office of the CISO will continue its assessment of the remaining recommendations, including an assessment of additional security risks related to the changing cyber threat landscape. The Office of the CISO will report on these additional recommendations at the next Audit Committee meeting. The Office of the CISO (OC) has assessed the residual risk of the high priority recommendations based on remediation progress and compensating controls in the current environment. In summary, 3 of the recommendations have been fully implemented. Additionally, the OC has determined that 21 of the 28 recommendations remain on track to be implemented within 2021 (short and medium terms). The assessment has identified 13 high risk recommendations plus 3 additional risks the City faces due to the continuously changing cyber threat landscape. Due to the recent global attacks on the critical infrastructure, it's therefore extremely important that the implementation of these recommendations be expedited. Table 1 below captures the status of all 28 recommendations* as shown in TeamMate and their associated risk ratings based on the risk assessment (*as of June 22, 2021): Category High Risk Medium Risk Low Risk Total Cyber Risk Program 3 1 2 6 Policies and Standards 4 1 5 Threat Management 5 1 6 Technical Standards 4 1 1 6 Awareness and Training 2 2 Fully Remediated 1 2 3 TOTAL 13 7 8 28 Table 2 below highlights the associated remediation timeline for open recommendations: Remediation Timeline High Risk Medium Risk Low Risk Total Short Term (September 30, 2021) 6 3 4 13 Medium Term (December 31, 2021) 5 1 2 8 Long Term (September 30, 2022) 1 3 4 TOTAL 12 7 6 25* * 3 recommendations are fully implemented. Other Major Risks (in addition to open recommendations) The ever-evolving cyber threat landscape can create new and unexpected challenges for the City. Social engineering, ransomware and increased use of third party software are some other major cybersecurity risks that could impact the City's critical infrastructure in the near future. Management Actions The following actions are underway in partnership with the Technology Services Division (TSD) to reduce the cyber risk exposure at the City: Short Term - On boarded cybersecurity vendor partner and MSSP (managed security services provider), in partnership with TSD, to help standardize cybersecurity policies, procedures, tools and threat management practices across the City. Medium Term - Implementing cybersecurity controls along with logging and monitoring tools across all City divisions (IT infrastructure, systems and applications). Long Term - Achieve long term cyber maturity tied back to ISO 27001/NIST Frameworks, implement Threat Risk Assessments (TRA) and Cyber Risk Assessments (CRA) on an ongoing basis. Additionally, the City should continue to work on projects such as Microsoft 365, Privileged Access Management (PAM) and Cloud Security implementation to limit the risks emerging from access controls, third party software and cloud computing.
Staff recommended
The Interim Chief Information Security Officer recommends that: 1. City Council direct that Confidential Attachment 1 remain confidential in its entirety, as it involves the security of property belonging to the City of Toronto.
Considered
2021-07-07 · Audit Committee · amended
Decision as filed
The Audit Committee recommends that: 1. City Council request the Auditor General to report to the November 2, 2021 meeting of the Audit Committee with an update on outstanding cybersecurity recommendations from Auditor General reports. 2. City Council request the Chief Information Security Officer and relevant City division heads to accelerate the implementation of outstanding cybersecurity recommendations from Auditor General reports and to accelerate compliance with cybersecurity standards.
Show the rest of Decision as filed, 754 more characters as filed
3. City Council request the Chief Technology Officer to expedite the implementation of high-priority cybersecurity recommendations. 4. City Council direct that Confidential Attachment 1 to the report (June 22, 2021) from the Interim Chief Information Security Officer remain confidential in its entirety, as it involves the security of property belonging to the City of Toronto. 5. City Council direct that Confidential Attachment 1 to the supplementary report (July 6, 2021) from the Auditor General be released publicly at the discretion of the Auditor General, after discussions with the appropriate City Officials, as it contains information involving the security of property belonging to the City of Toronto or one of its Agencies and Corporations.
Clerk’s note
The Audit Committee recessed its public session to meet in closed session to consider this item, as it relates to the security of property belonging to the City of Toronto and the safety and security of property belonging to the City of Toronto or one of its Agencies and Corporations.
2021-07-14 · Toronto City Council · amended
On the record
More from this meeting
- 2020 Audited Financial Statements - Consolidated City, Sinking Funds, and Consolidated Trust FundsFiled record
- The City of Toronto Audit Findings Report for the Year Ended December 31, 2020Filed record
- Obligatory Reserve Funds (Deferred Revenues) and Reserves and Council-Directed Reserve Funds (Accumulated Surplus) as at December 31, 2020Filed record
- Financial Statements for the Year Ended December 31, 2020 - AgenciesFiled record
- Status of the Financial Statement Audits of the City's Agencies and Corporations for the Year Ended December 31, 2020Filed record
- Auditor General's Status Report on Outstanding RecommendationsFiled record