Score: +77 (84/53/7)
Santa Barbara County Grand Jury • 2019-2020

Cyber-attacks Threaten Santa Barbara County

Published: October 01, 2019 10 pages
View Original PDF

Findings and Recommendations 8 findings

F1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
Related Recommendations (1)
R1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Related Recommendations (1)
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Related Recommendations (1)
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Related Recommendations (1)
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Related Recommendations (4)
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
R5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
R5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Related Recommendations (2)
R6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Related Recommendations (1)
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Related Recommendations (1)
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.

Conclusions 9

Observations 1

Agency Responses 9

Government agencies' official responses to this report's findings and recommendations. Click on a response to see the structured breakdown.