Item - 2022.AU13.9

Tracking Status

  • City Council adopted this item on July 19, 20, 21 and 22, 2022 without amendments and without debate.
  • This item was considered by Audit Committee on July 11, 2022 and was adopted with amendments. It will be considered by City Council on July 19, 20, 21 and 22, 2022.

AU13.9 - Status Update of the IT Disaster Recovery Plan

Decision Type:
ACTION
Status:
Adopted on Consent
Wards:
All

City Council Decision

City Council on July 19, 20, 21 and 22, 2022, adopted the following:

 

1.  City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Director, Office of Emergency Management and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2023 with a City-wide Risk Governance Model addressing risks related to business continuity, cyber major incident and technology disaster recovery.

 

2.  City Council request the Chief Technology Officer, in co-ordination with the Chief Information Security Officer and the Director, Office of Emergency Management to report to the Audit Committee in the third quarter of 2023 on the status of the Information Technology Disaster Recovery Plan from each City of Toronto division, agency and corporation; the status update should also be reported for City of Toronto's Corporate Technology Services Disaster Recovery Plan, including business continuity and cyber major incident.

 

3. City Council direct that Confidential Attachment 1 to the report (June 24, 2022) from the Chief Technology Officer remain confidential in its entirety, as it involves the security of the property of the City.

 

Confidential Attachment 1 to the report (June 24, 2022) from the Chief Technology Officer remains confidential in its entirety in accordance with the provisions of the City of Toronto Act, 2006, as it involves the security of the property of the City.

Confidential Attachment - The security of property belonging to the City of Toronto.

Background Information (Committee)

(June 24, 2022) Report from the Chief Technology Officer on Status Update of the IT Disaster Recovery Plan
https://www.toronto.ca/legdocs/mmis/2022/au/bgrd/backgroundfile-227993.pdf
Attachment 1 - Distribution list for the Questionnaire
https://www.toronto.ca/legdocs/mmis/2022/au/bgrd/backgroundfile-227994.pdf
Confidential Attachment 1 - Status Update of the IT Disaster Recovery Plan

AU13.9 - Status Update of the IT Disaster Recovery Plan

Decision Type:
ACTION
Status:
Amended
Wards:
All

Confidential Attachment - The security of property belonging to the City of Toronto.

Committee Recommendations

The Audit Committee recommends that:

 

1.  City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Director, Office of Emergency Management and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2023 with a City-wide Risk Governance Model addressing risks related to business continuity, cyber major incident and technology disaster recovery.

 

2.  City Council request the Chief Technology Officer, in co-ordination with the Chief Information Security Officer and the Director, Office of Emergency Management to report to the Audit Committee in the third quarter of 2023 on the status of the Information Technology Disaster Recovery Plan from each City of Toronto division, agency and corporation; the status update should also be reported for City of Toronto's Corporate Technology Services Disaster Recovery Plan, including business continuity and cyber major incident.

 

3. City Council direct that Confidential Attachment 1 to the report (June 24, 2022) from the Chief Technology Officer remain confidential in its entirety, as it involves the security of the property of the City.

Origin

(June 24, 2022) Report from the Chief Technology Officer

Summary

This report provides status update of IT Disaster Recovery Plan pursuant to a City Council decision under AU10.8 - Status of Audit Recommendations for the Technology Services Division at its meeting on November 9, 2021. At this meeting, City Council requested the City Manager to report to the Audit Committee in the second quarter of 2022 with information from each City of Toronto Division, Agency and Corporation on their Information Technology Disaster Recovery Plan should the City's systems, technology, communications, or backups be made unavailable. In that meeting, City Council also requested the Chief Technology Officer to report to the Q2 2022 Audit Committee with an update on the status of City of Toronto's Corporate Technology Services Disaster Recovery Plan, including implementation, testing and a full project plan for any outstanding work.

 

The City creates and manages large volumes of electronic information or data. The impact of data loss or corruption of data from hardware failure, human error, hacking, malware, or a natural disaster could be significant. In such a case, a Technology Disaster Recovery Plan is designed to assist an organization in executing recovery processes in response to a disaster to protect business IT infrastructure and promote recovery.

 

The Technology Services Division (TSD) has collaborated with multiple Divisions, Agencies and Corporations to gather inputs related to the status of their IT Disaster Recovery Plan should the City's systems, technology, communications, or backups be made unavailable.  This information is documented in 'Section 1: City-wide assessment of Information Technology Disaster Recovery Plans' of this report and analysis is provided in Confidential Attachment # 1 - Status Update of the IT Disaster Recovery Plan.  

 

'Section 2 - TSD Disaster Recovery Plan' of this report details the status of the Technology Services Division's Disaster Recovery Plan, including implementation, testing and a full project plan for outstanding work that will highlight the road map for the transition from current state to the future state, based on best practices that have been identified by the project team. The analysis and details of implementation plan are provided in Confidential Attachment # 1.

Background Information

(June 24, 2022) Report from the Chief Technology Officer on Status Update of the IT Disaster Recovery Plan
https://www.toronto.ca/legdocs/mmis/2022/au/bgrd/backgroundfile-227993.pdf
Attachment 1 - Distribution list for the Questionnaire
https://www.toronto.ca/legdocs/mmis/2022/au/bgrd/backgroundfile-227994.pdf
Confidential Attachment 1 - Status Update of the IT Disaster Recovery Plan

Motions

1 - Motion to Amend Item (Additional) moved by Councillor Stephen Holyday (Carried)

That the Audit Committee recommend that:

 

1.  City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Director, Office of Emergency Management and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2023 with a City-wide Risk Governance Model addressing risks related to business continuity, cyber major incident and technology disaster recovery.

 

2.  City Council request the Chief Technology Officer, in co-ordination with the Chief Information Security Officer and the Director, Office of Emergency Management to report to the Audit Committee in the third quarter of 2023 on the status of the Information Technology Disaster Recovery Plan from each City of Toronto division, agency and corporation; the status update should also be reported for City of Toronto's Corporate Technology Services Disaster Recovery Plan, including business continuity and cyber major incident.


Motion to Adopt Item as Amended (Carried)
Source: Toronto City Clerk at www.toronto.ca/council