Score: +77
(84/53/7)
Santa Barbara County Grand Jury
• 2019-2020
Cyber-attacks Threaten Santa Barbara County
Published: October 01, 2019
10 pages
⚠️ Aviso de traducción: Este contenido ha sido traducido automáticamente. El texto original en inglés es la versión oficial. La traducción puede contener errores.
⚠️ Este contenido ha sido traducido automáticamente. El texto original en inglés es la versión oficial. La traducción puede contener errores.
Findings and Recommendations 8 findings
F1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
Related Recommendations (1)
R1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Related Recommendations (1)
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Related Recommendations (1)
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Related Recommendations (1)
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Related Recommendations (4)
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
R5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
R5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Related Recommendations (2)
R6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Related Recommendations (1)
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Related Recommendations (1)
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Conclusions 9
-
CL1Some public entities within Santa Barbara County do not have a written cyber security plan.
-
CL2Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
-
CL3Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
-
CL4If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
-
CL5Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance. 2019-20 Santa Barbara County Grand Jury Page 8 CYBER-ATTACKS THREATEN SANTA BARBARA COUNTY
-
CL6A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
-
CL7Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
-
CL8Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
-
CL9The 2019-20 Santa Barbara County Grand Jury determined that cyber-attacks and related threats are an ongoing reality and that all public entities within Santa Barbara County need to take prompt and aggressive steps to prevent significant disruption from these attacks. When cyber-attacks are successful, the costs to respond and recover can be in the millions of dollars. While some local public entities are taking steps to protect themselves from these risks, many are not adequately prepared. FINDINGS AND RECOMMENDATIONS Finding 1 Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible. Recommendation 1 That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security. Finding 2 Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data. Recommendation 2 That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks. Finding 3 Some public entities within Santa Barbara County do not have a written cyber security plan. Recommendation 3 That each public entity within Santa Barbara County establish a written cyber security plan. 15 Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012 2019-20 Santa Barbara County Grand Jury Page 7 CYBER-ATTACKS THREATEN SANTA BARBARA COUNTY Finding 4 Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication. Recommendation 4 That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats. Finding 5 Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software. Recommendation 5a That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. Recommendation 5b That each public entity within Santa Barbara County install and update all operating software regularly. Recommendation 5c That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness. Recommendation 5d That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness. Finding 6 If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it. Recommendation 6a That each public entity within Santa Barbara County create and implement a full backup and recovery plan. Recommendation 6b That each public entity within Santa Barbara County regularly update and test their backup and recovery plan. Finding 7 Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance. 2019-20 Santa Barbara County Grand Jury Page 8 CYBER-ATTACKS THREATEN SANTA BARBARA COUNTY Recommendation 7 That each public entity within Santa Barbara County secure adequate cyber insurance. Finding 8 A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium. Recommendation 8 That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance. REQUEST FOR RESPONSE Pursuant to California Penal Code Sections 933 and 933.05, the Santa Barbara County Grand Jury requests each entity or individual named below to respond to the enumerated findings and recommendations with the specified statutory time limit: Responses to Findings shall be either: Agree Disagree wholly Disagree partially with an explanation Responses to Recommendations shall be one of the following: Has been implemented, with brief summary of implementation actions taken Will be implemented, with an implementation schedule Requires further analysis, with analysis completion date of no more than six months after the issuance of the report Will not be implemented, with an explanation of why Santa Barbara County Board of Supervisors – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 City of Buellton – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 2019-20 Santa Barbara County Grand Jury Page 9 CYBER-ATTACKS THREATEN SANTA BARBARA COUNTY City of Carpinteria – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 City of Goleta – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 City of Guadalupe – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 City of Lompoc – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 City of Santa Barbara – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 City of Santa Maria – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 City of Solvang – 90 Days Findings 1, 2, 3, 4, 5, 6, 7, and 8 Recommendation 1, 2, 3, 4, 5a, 5b, 5c, 5d, 6a, 6b, 7, 8 2019-20 Santa Barbara County Grand Jury Page 10
Observations 1
-
OB1The responses to the Grand Jury’s survey showed most entities were deficient in one or more critical areas. Many of those surveyed reported that they had no cyber security plan, had never performed a security audit and carried no cyber insurance. Clearly, many public entities within Santa Barbara County are not fully prepared to withstand a cyber- attack. Important Concepts and Best Practices: As a result of its investigation, the Grand Jury found the following important concepts and best practices should be implemented as soon as possible to lower an organization’s risks from cyber threats and damage: Identify someone to be in charge. Organizations should appoint a designated individual with the proper expertise who is granted authority to be accountable and responsible for all cyber security, including managed service providers.14 Identify the nature of the organization’s data and the electronic systems employed and understand the security risks. Organizations should understand what type of data they maintain and use in the execution of their mission and the electronic systems employed that do, or could, allow access to the data. How is the data handled and protected to prevent unauthorized use? Who has access to that data and under what circumstances? What are risks related to unauthorized access or, in the worst case, destruction of the organization’s data? Establish a written cyber security plan. A cyber security plan adds a layer of protection to an organization’s important resources. Protecting important data and related systems is important, not only for the organization, but also its customers. Cybercrime is escalating and having a strong defense and recovery plan helps protect the organization’s reputation. A well written plan should not only detail the preventative steps the organization needs to take to prevent an attack, but also provide a recovery plan in case the data is attacked, corrupted or otherwise compromised. Protect data from internal and external threats. Data can be attacked or compromised from many sources, whether intentional or by accident. Protecting an organization’s data and systems from an external threat and intentional attack is not enough—they also must be protected from unauthorized internal access, accidental corruption or destruction. An organization’s plan needs to identify and 14 Edward Gately, “ESET: MSPs Not Proactive Enough with Cybersecurity”, ChannelFutures.com, February 7, 2020 https://www.channelfutures.com/channel-research/eset-msps-not-proactive-enough-with-cybersecurity. (Last visited 02/10/2020) 2019-20 Santa Barbara County Grand Jury Page 5 CYBER-ATTACKS THREATEN SANTA BARBARA COUNTY address all possible threats and should require periodic changing of all passwords and making sure sensitive systems are contained in a secure environment with controlled access. Have strong firewalls, appropriate authorization and access controls, and effective antivirus software. Strong firewalls prevent unauthorized outside access to an organization’s systems and data. If an attacker cannot get into the system, it is harder for them to disrupt operations or damage or steal data. Having an appropriate authorization and access control system helps, among other things, assure that employees and authorized contractors can access only the systems and data they require to properly execute their duties and helps prevent unauthorized activities, theft, corruption or destruction of data. Antivirus software helps prevent software viruses, worms, “Trojan Horses,” spyware or malware from being downloaded to an organization’s electronic systems, as well as increasing protection from phishing attacks. Install and update software regularly. Using the correct software and keeping it updated frequently is a strong step to help prevent attacks. Software providers are continually updating and improving their products to not only make it more effective but to address flaws that are discovered that could be used to attack an organization’s systems or data. Old and out-of-date software is much more vulnerable than current software. Software should not only be updated on internal equipment but also on all portable devices that have access to the organization’s systems. Maintain cyber security awareness and training for all employees. A system is only as strong as the people who are using it. While there are many ways to attack a system electronically, one of the easiest ways to get access to a system is to trick someone to open the door for you. This “social engineering” is cheap, effective and quicker than trying to break into a system through other means. Employees and contractors with access to the system should be made aware of the dangers of social engineering and phishing scams, and be trained how to prevent access through these means. This awareness and training should focus not only on electronic devices provided by the organization but also personal and portable electronic devices that have access to the organization’s system via Wi-Fi, email or the internet. Create a recovery plan. While planning and prevention is a vital component to strong cyber security, the reality is that things can go wrong, attackers can succeed, and things break. Therefore, it is very important that an organization have a detailed and documented recovery plan. This plan, among other things, should include periodic backups, and safe offsite storage of backup data and system software. Regularly update and test the plan. Just like practice fire drills are an important component of assuring the safety of employees, practicing the steps of an organization’s cyber security plan, especially the recovery components of the plan, is vitally important. Practice runs not only help to confirm if the plan works and what improvements could be made, they also prepare the organization for a fast response in the case of an actual attack. 2019-20 Santa Barbara County Grand Jury Page 6 CYBER-ATTACKS THREATEN SANTA BARBARA COUNTY Consider working with other organizations to improve cyber security practices cost effectively. Working as a consortium provides an approach allowing even those with smaller budgets to participate and contribute to a successful security program.15
Agency Responses 9
Government agencies' official responses to this report's findings and recommendations. Click on a response to see the structured breakdown.
▶
Board of Supervisors
May 27, 2020
•
5 pages
• 16 responses
•
Score: +9
(+12, 1, -3)
View Details ▾
16 responses to findings and recommendations
F1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
Response: Agree
Score: +1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible. The Board of Supervisors agrees with the finding.
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Response: Agree
Score: +1
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data. The Board of Supervisors agrees with the finding.
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Response: Agree
Score: +1
Some public entities within Santa Barbara County do not have a written cyber security plan. The Board of Supervisors agrees with the finding.
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County establish a written cyber security plan. The recommendation has not yet been implemented, but will be implemented in the future for the County of Santa Barbara. The County does not have jurisdiction over other public agencies in the County on this matter. The County is in the process of implementing this recommendation. Beginning in December of 2019, the County secured 3rd party consulting firm Insight Security (formally PCMG) to conduct a fullscale IT Security Audit that as a promised deliverable will produce documented cyber security plans ...
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Response: Agree
Score: +1
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication. The Board of Supervisors agrees with the finding.
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats. The recommendation has not yet been implemented, but will be implemented in the future for the County of Santa Barbara. The County does not have jurisdiction over other public agencies in the County on this matter. Beginning in December of 2019, the County secured 3rd party consulting firm Insight Security (formally PCMG) to conduct a full-scale IT Security Audit that as a promised deliverable will produce documented cyber security plans and scorecards speci...
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software. The Board of Supervisors agrees with the finding.
Recommendation 5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. The County has implemented this recommendation for the County of Santa Barbara. The County does not have jurisdiction over other public agencies in the County on this matter. Attachment A Page 3 of 5
Recommendation ...
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Will Not Implement
Score: -1
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. The County has implemented this recommendation for the County of Santa Barbara. The County does not have jurisdiction over other public agencies in the County on this matter. Attachment A Page 3 of 5
Recommendation 5b
That each public entity within Santa Barbara County install and update all operating software regularly. The recommendation will not be implemented because it is not warranted or is not reasonable. The County agrees that it is critical to inst...
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
Response: Will Not Implement
Score: -1
That each public entity within Santa Barbara County install and update all operating software regularly. The recommendation will not be implemented because it is not warranted or is not reasonable. The County agrees that it is critical to install and update all operating software regularly. However, in certain use cases there are State regulated systems and/or hardware compatibility issues that limit the County's ability to upgrade to the most current versions of operating software. The County maintains a complete inventory of all operating systems and applications and, where legacy issues exi...
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it. The Board of Supervisors agrees with the finding.
Recommendation 6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan. The County has implemented this recommendation for the County of Santa Barbara. The County does not have jurisdiction over other public agencies in the County on this matter. The County maintains offsite backup ...
R6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County create and implement a full backup and recovery plan. The County has implemented this recommendation for the County of Santa Barbara. The County does not have jurisdiction over other public agencies in the County on this matter. The County maintains offsite backup and recovery capabilities. Two (2) data centers backup data from each other and are geographically separated. These locations are separated by (60) miles and are serviced by two independent electrical utility providers (PG&E in the north and SCE in the south). Attachment A Page 4 of...
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan. The recommendation has not yet been implemented, but will be implemented in the future for the County of Santa Barbara. The County does not have jurisdiction over other public agencies in the County on this matter. Beginning in December of 2019, the County secured 3rd party consulting firm Insight Security (formally PCMG) to conduct a full-scale IT Security Audit that as a promised deliverable will produce documented go-forward best practices for a more modernized data center/disaster ...
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Response: Disagree
Score: -1
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance. The Board of Supervisors disagrees with the finding as it pertains to the County. The County maintains cyber insurance at generally acceptable risk levels of coverage. The Board of Supervisors cannot comment on the adequacy of cyber insurance for independent cities, districts and other municipalities within the County that are not under the jurisdiction of the Board.
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County secure adequate cyber insurance. The County has already implemented this recommendation for the County of Santa Barbara. The County maintains cyber insurance at generally acceptable risk levels of coverage. The Board of Supervisors cannot comment on the adequacy of cyber insurance for independent cities, districts and other municipalities within the County that are not under the jurisdiction of the Board.
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Response: Agree
Score: +1
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium. The Board of Supervisors agrees with the finding.
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance. The recommendation has not yet been implemented, but will be implemented in the future for the County of Santa Barbara. Beginning in December of 2019, the County secured 3rd party consulting firm Insight Security (formally PCMG) to conduct a full-scale IT Security Audit that as a promised deliverable will produce documented go-forward strategy to develop a unifi...
▶
Buellton City Council
June 08, 2020
•
6 pages
• 20 responses
•
Score: +13
(+13, 7, 0)
View Details ▾
20 responses to findings and recommendations
F1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
Response: Agree
Score: +1
AGREE
Recommendation 1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
R1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
Response: Implemented
Score: 0
HAS BEEN IMPLEMENTED - Various aspects of Information Technology and Data Management have been overseen by different City Department Heads. However, given the overarching nature of cyber security, the individual to be accountable and responsible for the oversight of cyber security is the City Manager. 107 W. Highway 246 • P.O. Box 1819 • Buellton, CA 93427 • t: 805.688.5177 • f:805.686.0086 • www.cityofbuellton.com
Page 2
Finding 2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they mainta...
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Response: Disagree Partially
Score: 0
DISAGREE PARTIALLY WITH AN EXPLANATION - the City of Buellton can only agree with this statement as it pertains to its own understanding of its systems and the risks and other issues associated with them. The City of Buellton has no knowledge of other public entities within Santa Barbara County with regard to this issue.
Recommendation 2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
Response: Will Implement
Score: +1
WILL BE IMPLEMENTED - The City of Buellton will be issuing a Request for Proposals (RFP) for a consultant to perform comprehensive Information Technology management for the City, to include cyber security. This consultant will, as a part of their initial task upon beginning work for the City, conduct the full inventory of data, electronic, and communication systems for the purpose of identifying and minimizing security risks within these systems.
Finding 3
Some public entities within Santa Barbara County do not have a written cyber security plan.
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Response: Agree
Score: +1
AGREE
Recommendation 3
That each public entity within Santa Barbara County establish a written cyber security plan.
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
Response: Will Implement
Score: +1
WILL BE IMPLEMENTED - The City of Buellton will be issuing a Request for Proposals (RFP) for a consultant to perform comprehensive Information Technology management for the City, to include cyber security. This consultant will, upon completion of the inventory identified in Recommendation 2, establish a written cyber security plan. Once this plan has been approved, the consultant will oversee the implementation of this plan on an on-going basis.
Page 3
Finding 4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency ...
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Response: Agree
Score: +1
AGREE <b>Recommendation 4</b> That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Requires Analysis
Score: 0
REQUIRES FURTHER ANALYSIS - While the City of Buellton has taken steps to protect its data from threats (both internal and external), there is still a question as to whether those steps are adequate in light of modern cyber security threats. Completion of this analysis will occur upon the engagement of an Information Technology consultant, as discussed in responses to previous recommendations, with corrective measures (if necessary) undertaken upon identification.
Finding 5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, st...
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
AGREE
Recommendation 5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Implemented
Score: 0
HAS BEEN IMPLEMENTED - The City of Buellton has installed antivirus software on all of its computers and servers to avoid, detect, and eliminate malware and other threats to its systems. This software is regularly updated. <b>Recommendation 5b</b> That each public entity within Santa Barbara County install and update all operating software regularly.
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
Response: Will Implement
Scheduled: Fiscal Year 2020/21
Score: +1
WILL BE IMPLEMENTED - The City of Buellton has ensured that the operating systems of all of its computers and servers are regularly updated with all recommended security updates and patches. However, in
Page 4 January of 2020, a number of the computers operated by the City were running the Windows 7 operating system, which ceased to be supported with such security updates by Microsoft. Critical devices, such as servers and desktop/laptop devices which are used to access finance applications and other sensitive data, were upgraded to Windows 10. Some less critical devices have not yet been upg...
R5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
Response: Will Implement
Score: +1
WILL BE IMPLEMENTED - The City of Buellton will be issuing a Request for Proposals (RFP) for a consultant to perform comprehensive Information Technology management for the City, to include cyber security. This consultant will be responsible for establishing a training regimen for employees, and will conduct periodic testing of security practices and protocols to ensure that cyber security awareness continues to be a priority.
Recommendation 5d
That each public entity within Santa Barbara County periodically ensure electronic systemrelated contractors have been trained for cyber security awa...
R5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
Response: Will Implement
Score: +1
WILL BE IMPLEMENTED - The City of Buellton will be issuing a Request for Proposals (RFP) for a consultant to perform comprehensive Information Technology management for the City, to include cyber security. Responses to the RFP will be asked to include documentation of certification and additional training (to include continuing education) in cyber security awareness, technologies, and best practices.
Finding 6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups...
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
AGREE
Recommendation 6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
Page 5
R6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
Response: Implemented
Score: 0
HAS BEEN IMPLEMENTED - The City of Buellton has developed a full backup and recovery plan, which has been used for recovery of data lost in the past.
Recommendation 6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
Response: Will Implement
Score: +1
WILL BE IMPLEMENTED - The City of Buellton will be issuing a Request for Proposals (RFP) for a consultant to perform comprehensive Information Technology management for the City, to include cyber security. This consultant will be responsible for evaluating the effectiveness of the City's existing backup and recovery plan, making changes to that plan where appropriate, and conducting periodic testing of the plan to ensure its adequacy.
Finding 7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Response: Agree
Score: +1
AGREE
Recommendation 7
That each public entity within Santa Barbara County secure adequate cyber insurance.
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
Response: Requires Analysis
Score: 0
REQUIRES FURTHER ANALYSIS - The City of Buellton will be issuing an RFP for a consultant to perform comprehensive Information Technology management for the City, to include cyber security. As part of a cyber security planning effort, this consultant will be tasked with analyzing the City's need for cyber insurance, and recommending to the City Manager an adequate amount of insurance, as well as a list of providers of such insurance.
Finding 8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Response: Agree
Score: +1
AGREE <b>Recommendation 8</b> That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Page 6
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Response: Requires Analysis
Score: 0
REQUIRES FURTHER ANALYSIS - The City of Buellton expects to be able to allocate adequate funding for cyber security considerations within its Information Technology management program. However, the participation in such a working group with other agencies may, nevertheless, be beneficial. Moving forward, the City will investigate the benefits of participating with other jurisdictions or agencies in such a working group to enhance cyber security within the County. The City of Buellton hopes that you have found these responses both sufficient and useful. Should additional information be required...
▶
Carpinteria City Council
June 08, 2020
•
4 pages
• 14 responses
•
Score: +8
(+9, 4, -1)
View Details ▾
14 responses to findings and recommendations
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Response: Disagree Partially
Score: 0
Most public entities within Santa Barbara Gounty have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and cosb associated with the destruction of systems or loss of data.
The City disagrees partially with the finding. The City can only speak to its own situation
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County complete a full inventory of their data electronic and communication systems and determine the related security risks. This recommendation will be implemented in fiscal year 2O2O-21. The City will undertake this work as a part of an amendment contract for lT services.
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Response: Agree
Score: +1
Some public entities within Santa Barbara Gounty do not have a written cyber security plan. The City agrees with the finding
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
Response: Will Implement
Score: +1
That each public entity within Santa Barbara Gounty establish a written cyber security plan. The recommendation will be implemented through the City's agreement for lT services in the 2020-21fiscal year.
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Response: Agree
Score: +1
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication. The City agrees with the finding.
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara Gounty take substantial steps to protect data from internal and external attacks or threats. The recommendation will be implemented. The City already has cyber-security systems and procedures in place but in the 2020-21 fiscal year will undertake work to, in part, make substantial improvement to its cyber-security systems and procedures.
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
Gyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software. The City agrees with the finding
Recommendation 5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. 2
The City has implemented this recommendation. Anti-virus software is deployed and current in the network. The City also maintains subscription-based security scanning at the network perimeter in the firewall.
Recommendation 5b
T...
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. 2
The City has implemented this recommendation. Anti-virus software is deployed and current in the network. The City also maintains subscription-based security scanning at the network perimeter in the firewall.
Recommendation 5b
That each public entity within Santa Barbara Gounty install and update all operating software regularly. The recommendation has been implemented. The City of Carpinteria installs system updates on a regular basis.
Recommendation 5...
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
Response: Implemented
Score: 0
That each public entity within Santa Barbara Gounty install and update all operating software regularly. The recommendation has been implemented. The City of Carpinteria installs system updates on a regular basis.
Recommendation 5c
That each public entity within Santa Barbara Gounty periodically train employees and then test their cyber security awareness. The City has implemented this recommendation for the City. The City of Carpinteria utilizes cyber security awareness protocols and training tools.
Recommendation 5d
That each public entity within Santa Barbara County periodically ensure ...
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
lf data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it. The City agrees with the finding.
Recommendation 6a
That each public entity within Santa Barbara Gounty create and implement a full backup and recovery plan. The City has implemented this recommendation. The City of Carpinteria has implemented onsite and offsite backup systems.
Recommendation 6b
That each public entity within Santa Barbara Gounty regularly update and test their ba...
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Response: Disagree
Score: -1
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance. The City disagrees with the finding as it pertains to the City.
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County secure adequate cyber insurance. This recommendation has been implemented. The City has adequate cyber insurance through the California Joint Powers lnsurance Authority's Cyber Liability Program.
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Response: Agree
Score: +1
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium. The City agrees with the finding
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance. The recommendation will be implemented for the City. As a part of the work previously described for the 2020-21fiscal year, the City will explore joining a cybersecurity working group; however, the City feels that it can currently allocate adequate resources for the cyber security measures described in this report. Once again, thank you for the opportunity to re...
▶
Goleta City Council
May 26, 2020
•
19 pages
• 20 responses
•
Score: +12
(+12, 7, 0)
View Details ▾
20 responses to findings and recommendations
F1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
Response: Agree
Score: +1
Agree. <b>
R1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
Response: Implemented
Score: 0
Has been implemented. The City Administrator has been designated the
primary individual to be accountable and responsible to oversee cyber security.
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Response: Agree
Score: +1
Agree. •
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks. • Response: Has been implemented. City of Guadalupe stores City data on shared drives stored on in-house servers. Files and folders are organized and secured to limit access to only appropriate and approved City staff. Email is controlled through an in-house Microsoft Exchange Email Server using standard security practices based on Microsoft guidelines for government entities. All email is scanned for malware and spam before...
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Response: Agree
Score: +1
Agree. •
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
Response: Will Implement
Score: +1
Will be implemented. The City's Information Technology (IT) service provider has been directed to help the City develop a written cyber security plan over the next 90 days.
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Response: Agree
Score: +1
Agree. <b>
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Implemented
Score: 0
Has been implemented. A hardened firewall, updated regularly, is in place to • Administration Department: Tel (805) 356.3891 Fax (805) 343.5512 918 Obispo Street P.O. Box 908, Guadalupe CA 93434
protect all City IT infrastructure from external attacks. To help remedy internal attacks, all City staff are limited to access only the data needed to perform their job functions. Auditing in place on servers allows for tracking of suspicious behavior. Enterprise-grade anti-virus is installed to protect data from any malicious activity. The City will receive a cybersecurity scan of its network to ide...
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
Agree. .
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Will Implement
Score: +1
Will be implemented. The City is already in the process of upgrading all servers. The City's plan is to complete upgrades of all old workstations and laptops throughout the coming year fiscal year 20-21. The City's accounting system is in the process of being upgraded and should be completed within one year. All systems owned by the City receive weekly security updates to the current operating systems, as well as line of business applications where appropriate.
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
Response: Will Implement
Score: +1
Will be implemented. The City is already in the process of upgrading all servers. The City's plan is to complete upgrades of all old workstations and laptops throughout the coming year fiscal year 20-21. The City's accounting system is in the process of being upgraded and should be completed within one year. All systems owned by the City receive weekly security updates to the current operating systems, as well as line of business applications where appropriate.
R5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
Response: Will Implement
Score: +1
Will be implemented pending available funds for service. The City will be developing a cyber-security awareness training plan for its employees within the next 6 months. Testing cyber-security awareness for the City's employees is best completed using services purchased from a 3rd party. The City currently has no funds available for this purpose. The City will seek attempt to obtain funding for this purpose by applying Administration Department: Tel (805) 356.3891 Fax (805) 343.5512 918 Obispo Street P.O. Box 908, Guadalupe CA 93434
for grants and/or trying to increase revenue. The City will ...
R5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
Response: Implemented
Score: 0
Has been implemented.
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
Agree.
R6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
Response: Implemented
Score: 0
Has been implemented. Enterprise-grade backup and disaster recovery software is installed on all servers. All City data is stored on the servers. The City's IT service provider continually updates the recovery plan as changes take place. However, the City is evaluating the alternative of having offsite cloud backups.
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
Response: Implemented
Score: 0
Has been implemented. The City's IT service provider tests the integrity of
backups, as well as the recovery process, every 3 months. The back and recovery plan is updated as changes are made.
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Response: Agree
Score: +1
Agree. • <b>
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
Response: Unknown
Score: 0
Agree. • <b>
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Response: Agree
Score: +1
Agree. • <b>
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Response: Implemented
Score: 0
Has been implemented. The City is already actively addressing cyber risks and concerns; however, the City is willing to participate in such a cyber security working group and share costs provided that the City has available funds for such purposes. Sincerely, Ariston D. Julian Mayor Gina Rubalcaba, Mayor pro tem Tony Ramirez, Council member Eugene Costa Jr., Council member Liliana Cardenas, Council member Administration Department: Tel (805) 356.3891 Fax (805) 343.5512 918 Obispo Street P.O. Box 908, Guadalupe CA 93434
<b>RESOLUTION NO. 2020-39</b> A RESOLUTION OF THE CITY COUNCIL OF THE CITY...
▶
Goleta City Council
April 22, 2020
•
4 pages
• 20 responses
•
Score: +6
(+7, 12, -1)
View Details ▾
20 responses to findings and recommendations
F1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
Response: Agree
Score: +1
The City of Goleta agrees with this finding. Recommendation 1: That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
R1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta contracts IT services out to Synergy Computing, Inc. (Synergy). Synergy has a staff person designated to be accountable and responsible for overseeing cyber security for the City. Finding 2: Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Response: Disagree
Score: -1
The City of Goleta disagrees wholly with this finding
Recommendation 2: That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
Response: Implemented
Score: 0
Has been implemented/will be implemented. The City of Goleta has an existing inventory of its data and is in the process of completing an update of the inventory of data, electronic and communication systems. The City has yet to complete a full analysis of all the security risks. Both tasks will be completed within the next 6 months. Finding 3: Some public entities within Santa Barbara County do not have a written cyber security plan.
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Response: Agree
Score: +1
The City of Goleta agrees with this finding. Recommendation 3: That each public entity within Santa Barbara County establish a written cyber security plan.
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
Response: Implemented
Score: 0
Has been implemented. The City of Goleta has drafted a written cyber security plan. Finding 4: Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Response: Agree
Score: +1
The City of Goleta agrees with this finding. Recommendation 4: That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta has implemented industry standard hardware and software protection measures to protect data from internal and external attacks or threats. Sharing additional information on the specific methodology of these protection measures in this response could put the City at risk. Finding 5: Cyber-attackers use several methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
The City of Goleta agrees with this finding. Recommendation 5a: That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta
has implemented industry standard antivirus software to detect malware and other threats. The City has taken a layered security approach, has installed software on all City-owned devices and the software is updated regularly. Sharing additional information on the methodology of these protection measures in this response could put the City at risk. Recommendation 5b: That each public entity within Santa Barbara County install and update all operating software regularly.
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta installs and updates all operating software regularly. The City's operation system patches are applied weekly. Recommendation 5c: That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
R5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta's IT Consultant has conducted cyber security awareness training. As part of the City's cyber security plan, any staff or consultant that uses or touches any city data or systems, must complete cyber security awareness training. Recommendation 5d: That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
R5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta has contacted all contractors of electronic systems to ensure they have been trained for cyber security awareness. Finding 6: If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
The City of Goleta agrees with this finding, Recommendation 6a: That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
R6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
Response: Implemented
Score: 0
Has been implemented. The City has implemented several backup servers for all its data both onsite and offsite City Hall, and in the event any of this data is lost or compromised a recovery plan is in place to restore this data using the several back-up servers. Recommendation 6b: That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta has implemented regularly updating and testing the City's backup servers for integrity. Finding 7: Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Response: Agree
Score: +1
The City of Goleta agrees with this finding. Recommendation 7: That each public entity within Santa Barbara County secure adequate cyber insurance.
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta has adequate cyber insurance through the California Joint Powers Insurance Authority's Cyber Liability Program. Finding 8: A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Response: Agree
Score: +1
The City of Goleta agrees with this finding. Recommendation 8: That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Response: Implemented
Score: 0
Has been implemented. The City of Goleta can allocate adequate funds for its cyber security and already participates in a cyber security working group through the Municipal Information Systems Association of California (MISAC) to learn and establish best practices and expertise. The City of Goleta shares the Grand Jury's concern regarding Cyber-Attacks threatening Santa Barbara County public entities. City staff have already been working on these issues and will continue to cooperatively and proactively address many of the findings and recommendations of the Grand Jury's report. This concludes...
▶
Lompoc City Council
June 18, 2020
•
5 pages
• 13 responses
•
Score: +8
(+8, 4, 0)
View Details ▾
13 responses to findings and recommendations
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
Response: Will Implement
Score: +1
r 2: Agree - Will be implemented.
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
Response: Will Implement
Score: +1
r 3: Agree - Will be implemented.
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Implemented
Score: 0
r 4: Agree - Has been implemented.
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Recommendation 5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. Answer 5a: Agree - Has been implemented. Current endpoint protection software contains up-to-date antivirus.
Recommendation 5b
That each public entity within Santa Barbara County install and update all operating software regularly. Answer 5b: Agree - Will be parti...
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Implemented
Score: 0
r 5a: Agree - Has been implemented.
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
Response: Unknown
Score: 0
r 5b: Agree - Will be partially implemented.
R5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
Response: Implemented
Score: 0
r 5c: Agree - Has been implemented and requires further analysis.
R5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
Response: Will Implement
Score: +1
r 5d: Agree - Will be implemented.
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Page 4 of 5
Recommendation 6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan. Answer 6a: Agree - Will be implemented. Lompoc utilizes backups for all data related to production environment. Data recovery plan is being established.
Recommendation 6b
That each public entity within Santa Barbara County regularly update and te...
R6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
Response: Will Implement
Score: +1
r 6a: Agree - Will be implemented.
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
Response: Will Implement
Score: +1
r 6b: Agree - Will be implemented.
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
Response: Will Implement
Score: +1
r 7: Agree - Will be implemented.
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Response: Requires Analysis
Score: 0
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance. Answer 8: Agree - Requires further analysis.
Page 5 of 5 Sincerely, Jenelle Osborne, Mayor City of Lompoc
▶
Santa Barbara County Jail Industries Commission
June 17, 2020
•
5 pages
• 11 responses
•
Score: +2
(+3, 7, -1)
View Details ▾
11 responses to findings and recommendations
R1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security. City of Santa Barbara Response Agree: this recommendation has been implemented. Since 2014, the City's Infrastructure Supervisor has been the primary individual responsible to oversee cyber security.
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
Response: Implemented
Score: 0
That each public entity within Santa Barbara County establish a written cyber security plan. City of Santa Barbara Response Disagree Wholly (that this finding applies to the City of Santa Barbara): this recommendation has been implemented. The City has in place, written Standard Operating Procedures for handling cyber security incidents.
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats. City of Santa Barbara Response Disagree Wholly (that this finding applies to the City of Santa Barbara): this recommendation has been implemented. The City has maintained a robust cybersecurity program for many years through the use of industry-standard firewall(s), and monitoring of the firewall by staff and third parties, staff training on cyber threats, and third-party penetration testing to identify and mitigate potential weaknesses.
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Recommendation 5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. City of Santa Barbara Response Agree: this recommendation has been implemented. The City has installed and maintained industry-standard anti-virus/malware software for approximately twenty-five (25) years. Updates and patches are installed regularly.
Cyber-Attacks ...
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. City of Santa Barbara Response Agree: this recommendation has been implemented. The City has installed and maintained industry-standard anti-virus/malware software for approximately twenty-five (25) years. Updates and patches are installed regularly.
Cyber-Attacks Threaten Santa Barbara County June 17, 2020 Page 3 <b>Recommendation 5b</b> That each public entity within Santa Barbara County install and update all operating software regularly. City of Santa Ba...
R5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness. City of Santa Barbara Response Agree: this recommendation has been implemented. The City has fully followed this recommendation since 2018 with the implementation of a cybersecurity training program for City staff. Beyond formal training, the City also tests employee knowledge of common cybersecurity threats, such as email phishing schemes and sends the results of these tests to employees to further reinforce best practices.
Recommendation 5d
That each public entity ...
R5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness. City of Santa Barbara Response Agree: This recommendation will be implemented by having vendors certify that they have completed a cyber security awareness program with relevant contractors as part of the vendor account renewal process.
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it. <b>Recommendation 6a</b> That each public entity within Santa Barbara County create and implement a full backup and recovery plan. City of Santa Barbara Response Agree: this recommendation has been implemented. The City has followed this recommendation for many years through the use and maintenance of a robust, redundant backup system.
Cyber-Attacks Threaten Santa Barbara County June...
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan. City of Santa Barbara Response Agree: this recommendation has been implemented. The City routinely evaluates and updates its backup and recovery systems. Moreover, the City employs a multi-layer backup system that essentially provides "back up of backups."
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Response: Disagree
Score: -1
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance. <b>Recommendation 7</b> That each public entity within Santa Barbara County secure adequate cyber insurance. City of Santa Barbara Response Disagree Wholly (that this finding applies to the City of Santa Barbara): this recommendation has been implemented. The City has maintained cyber insurance since 2010.
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance. City of Santa Barbara Response Disagree Wholly (that this finding applies to the City of Santa Barbara): this recommendation has been implemented. The City allocates funding for cybersecurity infrastructure, monitoring, testing, and employee training in its annual budget. Moreover, the City is a member of the Multi-State Information Sharing and Analysis Center (...
▶
Santa Maria City Council
June 16, 2020
•
4 pages
• 20 responses
•
Score: +12
(+12, 7, 0)
View Details ▾
20 responses to findings and recommendations
F1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
Response: Agree
Score: +1
Agree.
R1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
Response: Implemented
Score: 0
Has been implemented by the City of Santa Maria as of September 2019. The senior systems analyst for Public Safety systems is designated the point of contact for information security.
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Response: Disagree Partially
Score: 0
Disagree partially. It may be that some public entities have an inadequate understanding of their systems and data but the City is unable to say with certainty that most public entities have an inadequate understanding.
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
Response: Will Implement
Score: +1
Will be implemented by the City of Santa Maria by September 1, 2020. This has been partially implemented already.
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Response: Agree
Score: +1
Agree.
R3
That each public entity within Santa Barbara County establish a written cyber security plan. Wany Zhao and Gregory White, “A collaborative information sharing framework for community cyber security,” published in Homeland Security (HST), 2012 IEEE Conference on Technologies for Homeland Security (HST), November 13-15, 2012
Response: Will Implement
Score: +1
Will be implemented by the City of Santa Maria by September 1, 2020.
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Response: Agree
Score: +1
Agree.
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Implemented
Score: 0
Has been implemented by the City of Santa Maria.
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
Agree.
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Implemented
Score: 0
Has been implemented by the City of Santa Maria.
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
Response: Will Implement
Score: +1
Will be implemented by the City of Santa Maria. Most workstations have been updated and servers are scheduled to be updated with the infrastructure upgrade project currently in progress.
R5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness.
Response: Implemented
Score: 0
Has been implemented by the City of Santa Maria.
R5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors have been trained for cyber security awareness.
Response: Requires Analysis
Scheduled: within 6 months
Score: 0
Requires further analysis. This activity will be completed within 6 months.
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
Agree.
R6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
Response: Will Implement
Score: +1
Will be implemented by the City of Santa Maria. The written plan to support the current practice will be adopted in calendar year 2020.
R6b
That each public entity within Santa Barbara County regularly update and test their backup and recovery plan.
Response: Will Implement
Scheduled: within 90 days
Score: +1
Will be implemented by the City of Santa Maria within 90 days. Ŷ
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Response: Agree
Score: +1
Agree.
R7
That each public entity within Santa Barbara County secure adequate cyber insurance.
Response: Unknown
Score: 0
Agree.
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Response: Agree
Score: +1
Agree.
R8
That each public entity within Santa Barbara County that is unable to allocate adequate funds for cyber security develop a cybersecurity working group to establish best practices and share costs for education, expertise, and insurance.
Response: Requires Analysis
Score: 0
Requires further analysis to be completed in calendar year 2020. <b>ALICE M. PATINO</b> Mayor
▶
Solvang City Council
June 08, 2020
•
4 pages
• 13 responses
•
Score: +7
(+8, 4, -1)
View Details ▾
13 responses to findings and recommendations
F1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible.
Response: Agree
Score: +1
Ensuring critical cyber security tasks and activities are properly executed on a timely basis requires a designated individual to be accountable and responsible. The City agrees with the finding.
R1
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security.
Response: Implemented
Scheduled: fiscal year 2019-20
Score: 0
That each public entity within Santa Barbara County designate an individual to be accountable and responsible to oversee cyber security. This recommendation has been implemented. The City transitioned Information Technology services to an Information Technology management firm in fiscal year 2019-20. The City Manager is ultimately responsible for oversight of cyber security in partnership with the specialized firm of experts. The CEO of the company is responsible for communication, strategic management, and addressing of any immediate needs or concerns. The Information Technology firm provides...
F2
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data.
Response: Disagree Partially
Score: 0
Most public entities within Santa Barbara County have an inadequate understanding of what communication and electronic systems they use and what data they maintain, and do not fully understand the risks, security issues and costs associated with the destruction of systems or loss of data. The City disagrees partially with the finding. The City can only speak to its own situation.
R2
That each public entity within Santa Barbara County complete a full inventory of their data, electronic and communication systems and determine the related security risks.
Response: Will Implement
Scheduled: fiscal year 2020-21
Score: +1
That each public entity within Santa Barbara County complete a full inventory of their data electronic and communication systems and determine the related security risks. This recommendation will be implemented in fiscal year 2020-21. The City is undertaking this work as a part of the new contract for IT services.
F3
Some public entities within Santa Barbara County do not have a written cyber security plan.
Response: Agree
Score: +1
Some public entities within Santa Barbara County do not have a written cyber security plan. The City agrees with the finding.
F4
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication.
Response: Agree
Score: +1
Nationally, cyber-attacks on governmental organizations have been successful for many years and are occurring with more frequency and sophistication. The City agrees with the finding.
R4
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats.
Response: Will Implement
Score: +1
That each public entity within Santa Barbara County take substantial steps to protect data from internal and external attacks or threats. The recommendation will be implemented. The City already has cyber-security systems and procedures in place but in the 2020-21 fiscal year will undertake work to, in part, make substantial improvement to its cyber-security systems and procedures.
F5
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software.
Response: Agree
Score: +1
Cyber-attackers use a number of methods to install malicious software on systems including access through backdoors, staff or employee carelessness, and known bugs in software. The City agrees with the finding.
Recommendation 5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. The City has implemented this recommendation. The City has current industry standard Antivirus software and firewall.
Recommendation 5b
That each public entity within Santa Barbara County install and update all operating software ...
R5a
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County install and maintain current antivirus software to detect malware and other threats. The City has implemented this recommendation. The City has current industry standard Antivirus software and firewall.
Recommendation 5b
That each public entity within Santa Barbara County install and update all operating software regularly. The recommendation has been implemented. The City installs system updates on a regular basis.
Recommendation 5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber...
R5b
That each public entity within Santa Barbara County install and update all operating software regularly.
Response: Implemented
Score: 0
That each public entity within Santa Barbara County install and update all operating software regularly. The recommendation has been implemented. The City installs system updates on a regular basis.
Recommendation 5c
That each public entity within Santa Barbara County periodically train employees and then test their cyber security awareness. The City is implementing this recommendation. The City will utilize cyber security awareness protocols and training tools.
Recommendation 5d
That each public entity within Santa Barbara County periodically ensure electronic system-related contractors h...
F6
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it.
Response: Agree
Score: +1
If data is lost or compromised for any reason, including cyber-attack, mechanical failure or error, the most cost effective and expedient way to recover is to have current data backups and a plan to reinstall it. The City agrees with the finding.
Recommendation 6a
That each public entity within Santa Barbara County create and implement a full backup and recovery plan.
The City has implemented this recommendation. The City has implemented onsite and offsite backup systems.
Recommendation 6b
That each public entity within Santa Barbara County regularly update and test their backup and recov...
F7
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance.
Response: Disagree
Score: -1
Some public entities within Santa Barbara County do not have any, or adequate, cyber insurance. The City disagrees with the finding as it pertains to the City.
F8
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium.
Response: Agree
Score: +1
A cost-effective method to address cyber risks and concerns is to form an information sharing and learning consortium. The City agrees with the finding.