Item - 2021.GL27.29

Tracking Status

  • City Council adopted this item on December 15, 16 and 17, 2021 with amendments.
  • This item was considered by the General Government and Licensing Committee on November 30, 2021 and adopted without amendment. It will be considered by City Council on December 15, 16 and 17, 2021.

GL27.29 - Status of Audit Recommendations and Key Cybersecurity Risks

Decision Type:
ACTION
Status:
Amended
Wards:
All

City Council Decision

City Council on December 15, 16 and 17, 2021, adopted the following:

 

1. City Council direct that Confidential Attachments 1 and 2 to the report (November 19, 2021) from the Chief Information Security Officer remain confidential in their entirety, as they involve the security of property belonging to the City of Toronto.

 

2. City Council request the Chief Information and Security Officer to report to the March 22, 2022 meeting of the General Government and Licensing Committee on the matters identified in the confidential attachment to motion 1 by Councillor Stephen Holyday.

 

Confidential Attachments 1 and 2 to the report (November 19, 2021) from the Chief Information Security Officer and the confidential attachment to motion 1 by Councillor Stephen Holyday remain confidential in their entirety, in accordance with the provisions of the City of Toronto Act, 2006, as they involve the security of property belonging to the City of Toronto.

Confidential Attachment - Involves the security of property belonging to the City of Toronto

Background Information (Committee)

(November 19, 2021) Report from the Chief Information Security Officer on Status of Audit Recommendations and Key Cybersecurity Risks
https://www.toronto.ca/legdocs/mmis/2021/gl/bgrd/backgroundfile-173540.pdf
Confidential Attachment 1
Confidential Attachment 2

Background Information (City Council)

Confidential Attachment to motion 1 by Councillor Stephen Holyday

Motions (City Council)

1 - Motion to Amend Item (Additional) moved by Councillor Stephen Holyday (Carried)

That City Council request the Chief Information and Security Officer to report to the March 22, 2022 meeting of the General Government and Licensing Committee on the matters identified in the confidential attachment to this motion.


Motion to Adopt Item as Amended (Carried)

GL27.29 - Status of Audit Recommendations and Key Cybersecurity Risks

Decision Type:
ACTION
Status:
Adopted
Wards:
All

Confidential Attachment - Involves the security of property belonging to the City of Toronto

Committee Recommendations

The General Government and Licensing Committee recommends that:

 

1. City Council direct that Confidential Attachments 1 and 2 to the report (November 19, 2021) from the Chief Information Security Officer remain confidential in their entirety, as they involve the security of property belonging to the City of Toronto.

Origin

(November 19, 2021) Report from the Chief Information Security Officer

Summary

City Council requested the Chief Information Security Officer to report to the General Government and Licensing Committee on a biannual basis regarding the City-wide cyber security program. This is the first such report and includes two confidential attachments:

 

- Attachment 1 - Describes the City's Cyber health as seen from three lenses: cyber resilience, cyber maturity, and cyber awareness.
 

- Attachment 2 - Provides an overview of audit remediation status.
 

Further, these attachments provide details on:

 

a.  Overall cyber health of the organization, the progress made in the past six month and the benefits/efficiencies achieved as a result of the Cyber program implementation, including embedding "cybersecurity by design" principles to support the City's modernization efforts;

 

b.  The status of all outstanding audit recommendations that have not been implemented to date, including any increase to the City's cybersecurity risk profile

 

c.  Additional supports required to address cybersecurity risks in an expedited manner.

 

Subsequent reports to the  General Government and Licensing Committee will include updates on the following:

 

Projects, initiatives, procurement, and operations where cybersecurity requirements or directives were not included in the process
 

The attachments also include highlights of the progress the Office of the Chief Information Security Officer (OC) has made, in collaboration with Technology Services Division and the City's critical infrastructure Divisions, in embedding cyber security risk management practices in their projects, initiatives, procurement, and operations.

Background Information

(November 19, 2021) Report from the Chief Information Security Officer on Status of Audit Recommendations and Key Cybersecurity Risks
https://www.toronto.ca/legdocs/mmis/2021/gl/bgrd/backgroundfile-173540.pdf
Confidential Attachment 1
Confidential Attachment 2

Motions

Motion to Adopt Item moved by Councillor Stephen Holyday (Carried)
Source: Toronto City Clerk at www.toronto.ca/council