12 responses to findings and recommendations
F1
Illicit fentanyl is sold on the streets and through social media marketed as legitimate pharmaceuticals, or as other drugs laced with fentanyl, or sold as straight fentanyl, leading to exponentially increasing fentanyl addiction and deaths in Orange County. Response: Agrees with the finding.
Response: Disagree Partially
Score: 0
other government agencies. Government agencies are continuously targeted for various reasons such as hacktivism and cyber crime. It is not correct to say the information is not adequately protected. Information systems are protected and monitored. Orange County has a robust Cyber Security Deterrence Program. Continuous improvement in this area is being addressed by way of county wide cyber security assessments and the establishment of a County Cyber Security Joint Task Force (CSJTF). The CSJTF was established to standardize security controls and methodologies across all County departments.
F....
R1
By January 1, 2024, the Orange County Board of Supervisors should charter a multi- agency Task Force to address the fentanyl crisis. (F2, F7, F8, F9) Response: The recommendation has been implemented County agencies including OCSD, Probation, Orange County Superior Court, HCA, Substance Use Treatment Providers, Medically Assisted Treatment (MAT) services and other social service providers are currently working together in both the juvenile and adult populations to address the fentanyl crisis. HC...
Response: Will Implement
Score: +1
implemented. The recommendation will be implemented through the CSJTF and the publishing of the County Cyber Security Policy and Process Manual. By charter, the CSJTF is not due to provide the IT Executive Council the final product for approval until March 30, 2018.
R.2.
OCIT should select, acquire and direct the implementation of computerbased data loss prevention capability by 12/31/2017. This recommendation has been implemented. OCIT has begun the process of Response: implementing county-wide Data Loss Prevention (DLP) through our email system. The policies are designed to prevent transmi...
F2
Illicit fentanyl is a pervasive problem in Orange County. Response: Agrees with the finding.
Response: Disagree Partially
Score: 0
F.3.
Some county cyber attacks come through third-party vendors, who may not always be sufficiently protected.
<b>Agrees with this finding.</b> Third party vendors are now vetted for their security Response: protocols during the procurement cycle and when third party vendors "enter" the County's network, they are subject to County standards.
F.4.
The county has taken a number of steps to safeguard its digital data and systems against cyber attack, but there are a number of actions generally recognized as cybersecurity best practices that still need to be implemented. Partially disagrees wi...
R2
By July 1, 2024, the Orange County Board of Supervisors, the Orange County District Attorney, and the Orange County Sheriff should lobby the California State Legislature to add fentanyl to the list of drugs subject to penalty enhancements in felony drug convictions and to add statutory authority for judicial admonishments when drug dealers and traffickers are convicted of fentanyl-related crimes. (F4, F5,
Response: Requires Analysis
Score: 0
implementing county-wide Data Loss Prevention (DLP) through our email system. The policies are designed to prevent transmission of sensitive information such as credit card information, personally identifiable information (PII) and health record information. The County Privacy Officer is leading the effort to develop the DLP policies in collaboration with County departments.
R.3.
The county should review, update and standardize all employee and contractor exit procedures to ensure the security of countywide sensitive information by 12/31/2017. This recommendation requires further analysis. A...
F3
Drug dealers use social media to sell fentanyl and other drugs. Social media business models impede law enforcement investigations. Response: Agrees with the finding. The Board of Supervisors agrees with the finding and add that current federal laws also impede investigations.
Response: Disagree Partially
Score: 0
protocols during the procurement cycle and when third party vendors "enter" the County's network, they are subject to County standards.
F.4.
The county has taken a number of steps to safeguard its digital data and systems against cyber attack, but there are a number of actions generally recognized as cybersecurity best practices that still need to be implemented. Partially disagrees with this finding. As mentioned earlier, cybersecurity Response: measures are ever evolving; which best practices the County will choose to implement will be based on County-specific evaluations. The Board of Sup...
R3
By July 1, 2024, Orange County Law Enforcement agencies should work with social media companies to ensure law enforcement has timely access to drug-related criminal activity information on their platforms. (F1, F2, F3) Response: This recommendation has been implemented. The Probation Department, through Orange County Law Enforcement Agencies partnership, can currently request a search warrant for such information in the process of a criminal investigation. In 2022, Chairman Wagner, in partnershi...
Response: Implemented
Score: 0
currently underway as part of the countywide cyber security assessments. Review of access controls determines the individuals with access to data and systems and whether there is still a need to have access to said data and systems. The County is expected to have all departments complete these cyber security assessments by June 8, 2018.
R.4.
OCIT should establish a countywide cybersecurity working group by 12/31/2017. Participation should be mandatory for County of Orange agencies that report to the CEO and highly recommended for other county government entities. This recommendation has been...
F4
California law limits prosecution of fentanyl deaths as homicides. Fentanyl death related cases are selectively referred for federal filing consideration. The Orange County District Attorney has cross-designated one of its own senior deputy district attorneys to prosecute such cases under federal narcotics laws. Response: Agrees with the finding. The County agrees with the finding that "California law limits prosecution of fentanyl deaths as homicides" and defers to the District Attorney's respo...
Response: Disagree Partially
Score: 0
measures are ever evolving; which best practices the County will choose to implement will be based on County-specific evaluations. The Board of Supervisors has authorized a dedicated team to lead county security planning, deployment and recovery. The County adheres to best practice both in the commercial and government space and continues to evaluate changes to our protocols as new measures are available.
F.5.
County financial records do not separate out cybersecurity as a line item, making it hard to determine what resources are being allocated in the area and therefore what additional fund...
R4
By January 1, 2024, the Orange County Sheriff's Department, Probation Department, and Orange County Health Care Agency should collaborate to evaluate the effectiveness of existing in-custody and post-custody sobriety treatment programs and determine where improvements can be incorporated. (F2, F7, F8) Response: The recommendation has already been implemented. In 2019 the County underwent a comprehensive assessment of the Criminal Justice System which resulted in the creation of the Integrated Se...
Response: Implemented
Score: 0
group for cyber security.
R.5.
OCIT should develop a formal five-year cybersecurity strategic plan as a separate part of the IT Strategic Plan in the next county strategic plan. This recommendation has been implemented. OCIT does have a formalized Response: road map for Cyber Security to take the County to a point of maturity where the County is implementing National Institute of Standards and Technology (NIST) Cyber Security and Risk Management Frameworks (RMF) and other appropriate measures.
R.6.
OCIT should finalize a mandatory county incident response plan with procedures for individua...
F5
California law does not provide for uniform admonishment of drug dealers of their potential criminal liability for drug-related deaths. Proposed legislation requiring judicial admonishments has been rejected multiple times by the California Legislature. Response: Agrees with the finding.
Response: Disagree Partially
Score: 0
is meant to cover cyber security management, maintenance, assessment, incident response, and new initiatives.
F.6.
Cooperation among county agencies is currently limited due to organizational and cultural issues including the visibility of available centralized OCIT cybersecurity support, the inward focus of county agencies and the fact that the influence of the BOS to compel collaboration is largely limited to county agencies with appointed heads that report to the county CEO and, to a lesser degree, the county agencies with elected heads. <b>Respondent disagrees with this finding.</b> The ...
F6
Under current California law, fentanyl related felonies are not subject to additional penalty for weight enhancements as are other dangerous drugs such as cocaine and heroin. Response: Agrees with the finding.
Response: Disagree Partially
Score: 0
this culture as it is made up of representatives from all County departments, including elected and appointed departments. Additionally, both elected and non-elected department heads sit on the IT Executive Council - a Board of Supervisors-approved IT governance body. OCIT Enterprise Security has seen an increased interest over the past 18 months in sharing information and improved collaboration in the areas of mitigating risks of cyber threats and responding to cyber security incidents. Departmental leadership understands the County is stronger when all departments collaborate to reduce the r...
F7
Orange County will benefit by establishing a chartered multi-agency Task Force to address the fentanyl crisis in Orange County. Response: Agrees with finding. The County has either already established or currently participate on multi-agency task forces to address fentanyl. Each of these taskforces are designed to address the fentanyl crisis from all angles- public health, public safety, and mental health. The County currently participates in two such community groups, one that is Opioid focused...
Response: Disagree Partially
Score: 0
F.8.
IT employees across county government are largely untrained and uncertified in cybersecurity, especially at the agency level. Staffing for cybersecurity is challenging due to outdated county cybersecurity job classifications and salary levels, as well as lengthy county hiring processes, particularly for those agencies requiring extensive background checks. Disagrees partially with this finding. Some departments do provide security Response: specific training such as the County's Health Care Agency. OCIT Enterprise Security is addressing this issue, by increasing the IT security training ...
F8
As long as there is a demand, producers will find ways to supply drugs. Orange County cannot law enforce its way out of the fentanyl crisis. Education, prevention, and treatment are critical to reducing demand. Response: Agrees with the finding. Addressing the fentanyl crisis requires policy makers to address both the supply and demand for the drug. Education, prevention, and treatment are critical, as well as legal mechanisms to hold producers and sellers accountable. On March 3, 2022, Supervis...
Response: Agree
Score: +1
specific training such as the County's Health Care Agency. OCIT Enterprise Security is addressing this issue, by increasing the IT security training budget from $30,000 to $50,000 annually. With respect to non-IT employees, the County implemented mandatory online Cyber Security Awareness Training (CSAT) in January of 2017. Since implementation, over 90% of County employees have competed the online CSAT. The CISO agrees with the finding that it is challenging to hire cyber security professionals for the reasons stated in this finding. RECOMMENDATIONS AND RESPONSES:
R.1.
The county should revi...