Laserfiche WebLink
Oty <br /> Elk Request for Action <br /> R.iVer <br /> To Item Number <br /> Mayor and City Council 9.2 <br /> Agenda Section Meeting Date Prepared by <br /> Worksession June 15, 2015 Tina Allard, City Clerk <br /> Item Description Reviewed by <br /> Policy for Ensuring Security of Not Public Data Cal Portner, City Administrator <br /> Reviewed by <br /> Action Requested <br /> Review policy and direct staff on changes. Policy will be approved on a future regular meeting agenda. <br /> Background/Discussion <br /> The legislature made changes to the data practices law regarding access to Not Public Data. Some of <br /> these changes came about due to many of the breaches highlighted in the news media in recent years. <br /> The city is mandated to establish additional security measures "...ensuring data that is not public is only <br /> accessible to persons whose work assignments reasonably require access to the data..." <br /> What this means is the city needs to develop a policy designed to prevent employees from accessing not <br /> public data unless they have a legitimate work reason to do so. <br /> The policy covers the following: <br /> 1. Who must follow the policy <br /> ■ City employees <br /> ■ Firefighters <br /> ■ Volunteers <br /> ■ Appointed/elected officials <br /> ■ City vendors and consultants <br /> 2. How the city secures data <br /> ■ Protected folder structures on shared network drives <br /> ■ Locking offices/file cabinets <br /> ■ Password protection of computers, tablets, and phones <br /> ■ Shredding documents before disposal <br /> 3. Responsibilities of supervisor's and employees <br /> 4. Breach investigation process with step-by-step procedures and letter templates for staff. <br /> 5. Requirements for preparing a final report. <br /> 6. Annual security assessment of Personallnfoa-mation. Personallnfoa-mation is defined in state law as a <br /> person's name kept in combination with a social security number, driver's license, or account <br /> numbers with passwords or access codes. <br /> Financial Impact <br /> N/A <br /> Attachments <br /> ■ Draft Policy <br /> POWERED 6T <br /> Template Updoted 4/14 INAMIRE1 <br />