Item - 2020.AU5.9

Tracking Status

  • City Council adopted this item on June 29 and 30, 2020 without amendments.
  • This item was considered by the Audit Committee on February 10, 2020 and adopted without amendment. It will be considered by City Council on June 29 and 30, 2020.
  • See also AU4.1

AU5.9 - Mechanisms for the Auditor General to Conduct Cyber Security Assessments for City Agencies and Corporations

Decision Type:
ACTION
Status:
Adopted
Wards:
All

City Council Decision

City Council on June 29 and 30, 2020, adopted the following:

 

1. City Council receive the report (January 24, 2020) from the Chief Technology Officer, Information and Technology for information. 

Background Information (Committee)

(January 24, 2020) Report from the Chief Technology Officer - Mechanisms for the Auditor General to Conduct Cyber Security Assessments for City Agencies and Corporations
https://www.toronto.ca/legdocs/mmis/2020/au/bgrd/backgroundfile-145340.pdf
Attachment 1 - Agencies Subject to Auditor General's Authority
https://www.toronto.ca/legdocs/mmis/2020/au/bgrd/backgroundfile-145341.pdf

Motions (City Council)

Motion to Adopt Item (Carried)

AU5.9 - Mechanisms for the Auditor General to Conduct Cyber Security Assessments for City Agencies and Corporations

Decision Type:
ACTION
Status:
Adopted
Wards:
All

Committee Recommendations

The Audit Committee recommends that:

 

1. City Council receive the report (January 24, 2020) from the Chief Technology Officer, Information and Technology Division, for information. 

Origin

(January 24, 2020) Report from the Chief Technology Officer

Summary

This report responds to a request from City Council at its meeting in October 2019 that the City Manager, in consultation with the Auditor General, report on the mechanisms required that would enable the Auditor General to conduct risk assessments or investigate cyber security for City Agencies and Corporations not currently within the Auditor General's purview.  This report therefore outlines the existing mechanisms which may be used by the Auditor General to conduct risk assessments or investigate cyber security for City Agencies and Corporations not currently within the Auditor General's purview.  These Agencies and Corporations are specifically identified as Toronto Hydro Corporation and its subsidiaries, Toronto Police Services, Toronto Public Library and Toronto Board of Health.

 

The Auditor General is currently engaging with these entities to conduct risk or cyber security assessments utilizing these existing mechanisms.  As a result, no new mechanisms are required at this time.

Background Information

(January 24, 2020) Report from the Chief Technology Officer - Mechanisms for the Auditor General to Conduct Cyber Security Assessments for City Agencies and Corporations
https://www.toronto.ca/legdocs/mmis/2020/au/bgrd/backgroundfile-145340.pdf
Attachment 1 - Agencies Subject to Auditor General's Authority
https://www.toronto.ca/legdocs/mmis/2020/au/bgrd/backgroundfile-145341.pdf

Motions

1 - Motion to Adopt Item (Carried)
Source: Toronto City Clerk at www.toronto.ca/council