The Public GalleryToronto

General Government and Licensing Committee · 2021-11-30 · 2021.GL27.29

The filed record

Status of Audit Recommendations and Key Cybersecurity Risks

The Public Gallery wrote no story on this item. What follows is the city’s own record of what happened to it, as filed: nothing on this page is summarised or scored by us.

The decision

2021-12-15 · Toronto City Council · amended

As filed

City Council on December 15, 16 and 17, 2021, adopted the following: 1. City Council direct that Confidential Attachments 1 and 2 to the report (November 19, 2021) from the Chief Information Security Officer remain confidential in their entirety, as they involve the security of property belonging to the City of Toronto. 2. City Council request the Chief Information and Security Officer to report to the March 22, 2022 meeting of the General Government and Licensing Committee on the matters identified in the confidential attachment to motion 1 by Councillor Stephen Holyday.

Show the rest of As filed, 366 more characters as filed

Confidential Attachments 1 and 2 to the report (November 19, 2021) from the Chief Information Security Officer and the confidential attachment to motion 1 by Councillor Stephen Holyday remain confidential in their entirety, in accordance with the provisions of the City of Toronto Act, 2006, as they involve the security of property belonging to the City of Toronto.

On the agenda

As the city filed it

City Council requested the Chief Information Security Officer to report to the General Government and Licensing Committee on a biannual basis regarding the City-wide cyber security program. This is the first such report and includes two confidential attachments: - Attachment 1 - Describes the City's Cyber health as seen from three lenses: cyber resilience, cyber maturity, and cyber awareness. - Attachment 2 - Provides an overview of audit remediation status.

Show the rest of As the city filed it, 1,146 more characters as filed

Further, these attachments provide details on: a. Overall cyber health of the organization, the progress made in the past six month and the benefits/efficiencies achieved as a result of the Cyber program implementation, including embedding "cybersecurity by design" principles to support the City's modernization efforts; b. The status of all outstanding audit recommendations that have not been implemented to date, including any increase to the City's cybersecurity risk profile c. Additional supports required to address cybersecurity risks in an expedited manner. Subsequent reports to the General Government and Licensing Committee will include updates on the following: Projects, initiatives, procurement, and operations where cybersecurity requirements or directives were not included in the process The attachments also include highlights of the progress the Office of the Chief Information Security Officer (OC) has made, in collaboration with Technology Services Division and the City's critical infrastructure Divisions, in embedding cyber security risk management practices in their projects, initiatives, procurement, and operations.

Staff recommended

The Chief Information Security Officer, Technology Services recommends that: 1. City Council direct that Confidential Attachments 1 and 2 remain confidential in their entirety, as they involve the security of property belonging to the City of Toronto.

Considered

  • 2021-11-30 · General Government and Licensing Committee · adopted

    Decision as filed

    The General Government and Licensing Committee recommends that: 1. City Council direct that Confidential Attachments 1 and 2 to the report (November 19, 2021) from the Chief Information Security Officer remain confidential in their entirety, as they involve the security of property belonging to the City of Toronto.

  • 2021-12-15 · Toronto City Council · amended

On the record

The item as the City filed it

More from this meeting

The whole meeting