Laserfiche WebLink
�j <br /> Elk = Request for Action <br /> River <br /> To Item Number <br /> Mayor and City Council 9.2 <br /> Agenda Section Meeting Date Prepared by <br /> Worksession June 15, 2015 Tina Allard, City Clerk <br /> Item Description Reviewed by <br /> Policy for Ensuring Security of Not Public Data Cal Portner, City Administrator <br /> Reviewed by <br /> Action Requested <br /> Review policy and direct staff on changes. Policy will be approved on a future regular meeting agenda. <br /> Background/Discussion <br /> The legislature made changes to the data practices law regarding access to Not Public Data. Some of <br /> these changes came about due to many of the breaches highlighted in the news media in recent years. <br /> The city is mandated to establish additional security measures "...ensuring data that is not public is only <br /> accessible to persons whose work assignments reasonably require access to the data..." <br /> What this means is the city needs to develop a policy designed to prevent employees from accessing not <br /> public data unless they have a legitimate work reason to do so. <br /> The policy covers the following: <br /> 1. Who must follow the policy <br /> • City employees <br /> • Firefighters <br /> • Volunteers <br /> • Appointed/elected officials <br /> • City vendors and consultants <br /> 2. How the city secures data <br /> • Protected folder structures on shared network drives <br /> • Locking offices/file cabinets <br /> • Password protection of computers, tablets, and phones <br /> • Shredding documents before disposal <br /> 3. Responsibilities of supervisor's and employees <br /> 4. Breach investigation process with step-by-step procedures and letter templates for staff. <br /> 5. Requirements for preparing a final report. <br /> 6. Annual security assessment of Personal-Information. Personal-Information is defined in state law as a <br /> person's name kept in combination with a social security number, driver's license, or account <br /> numbers with passwords or access codes. <br /> Financial Impact <br /> N/A <br /> Attachments <br /> ■ Draft Policy P u w E e E D s r <br /> Template Updated 4/14 INAWREJ <br />