Kern County Grand Jury • 2021-2022

Report: City of Bakersfield

Published: December 02, 2021 19 pages
View Original PDF

Findings and Recommendations 8 findings

F1
The City initially did not realize the magnitude of the erroneous filings until numerous employees and retirees informed them of the problem.
No recommendations for this finding
F2
According to California Civil Code, §1798.29, a data breach did not occur.
No recommendations for this finding
F3
The City’s response to the erroneous filing has been adequate, although they should have informed the retirees sooner.
No recommendations for this finding
F4
Because retirees were not informed until four months later, this put them at risk of unnecessarily paying extra taxes, not to mention the risk of identity theft. This is unsettling.
No recommendations for this finding
F5
It is further troubling that the infrastructure of a city as large and prosperous as Bakersfield did not discover the internal source of the error for eight months.
No recommendations for this finding
F6
It is inconceivable that in this age of cybercrime, the City does not have written Policies and Procedures for dealing with data breaches and possible ransomware. A Policies and Procedures Manual will define and mandate the actions to deal with breaches and other information issues regarding sensitive information such as salaries, employee/retiree data.
Related Recommendations (2)
R1
The TS and Finance departments should generate a written Policies and Procedures Manual, by the end of the current fiscal year, which mandates the immediate notification of all employees and retirees of any data breach or erroneous IRS filing. (Finding 6)
R2
The TS and Finance departments should create a written Policies and Procedures Manual, by the end of the current fiscal year; one that defines and mandates action necessary to deal with potential data breaches, malware and ransomware information issues. (Finding 6)
F7
It appears the City’s TS Department is understaffed, to adequately deal with the current onslaught of cybercrime. This places the City in jeopardy of further information breaches.
Related Recommendations (1)
R3
Within the next three months, devote funding to recruit and retain qualified Technology Services staff. (Finding 7)
F8
Current City Finance and TS staff are in dire need of ongoing in-service training on quality control issues regarding the current TS system in use. COMMENTS: The Grand Jury would like to thank the City of Bakersfield for their participation, cooperation and assistance in being available for interviews and providing information for this report.
Related Recommendations (2)
R4
Within the next three months, provide training to TS and Finance staff to deal with the inadequacies of the current information data system. (Finding 8)
R5
Make it a priority to complete the Request For Proposal (RFP) process and implementation of an updated software system. (Finding 8) NOTES: • The City of Bakersfield should post a copy of this report where it will be available for public review. • Persons wishing to receive an email notification of newly released reports may sign up at: www.kerncounty.com/grandjury • Present and past Kern County Grand Jury Final Reports and Responses can be accessed on the Kern County Grand Jury website: www.kerncounty.com/grandjury RESPONSE DEADLINES:  REQUIRED WITHIN 90 DAYS FROM:  PRESIDING JUDGE KERN COUNTY SUPERIOR COURT 1415 TRUXTUN AVENUE, SUITE 212 BAKERSFIELD, CA 93301  TRUXTUN AVENUE, SUITE 600 BAKERSFIELD, CA 93301 Reports issued by the Grand Jury do not identify individuals interviewed. Cal. Penal Code § 929 requires that reports of the Grand Jury not contain the name of any person or facts leading to the identity of any person who provides information to the Grand Jury.

Comments 9