Item - 2022.GL29.16
Tracking Status
- City Council adopted this item on April 6 and 7, 2022 without amendments and without debate.
- This item was considered by General Government and Licensing Committee on March 22, 2022 and was adopted with amendments. It will be considered by City Council on April 6 and 7, 2022.
GL29.16 - Status of Audit Recommendations and Key Cybersecurity Risks
- Decision Type:
- ACTION
- Status:
- Adopted on Consent
- Wards:
- All
City Council Decision
City Council on April 6 and 7, 2022 adopted the following:
1. City Council direct that Confidential Attachments 1, 2 and 3 to the report (March 8, 2022) from the Chief Information Security Officer remain confidential in their entirety, as they involve the security of property belonging to the City of Toronto.
2. City Council direct the Board of any City Agency or Corporation that has not yet submitted a submission under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, to take immediate action submit their submission to the Chief Information Security Officer.
3. City Council direct the Board of any City Agency or Corporation that has not yet submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, to take immediate action submit their remediation plan to the Chief Information Security Officer.
4. City Council direct the Chief Information Security Officer to report to the April 29, 2022 meeting of the General Government and Licensing Committee on any City Agency or Corporation that has not yet submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer.
5. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation that has not submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, are available at the April 29, 2022 meeting of General Government and Licensing Committee to answer questions of staff on this item.
6. City Council direct the Chief Information Security Officer to report, on an exception basis, the details of any City Agency or Corporation that is not adhering to their 30, 60 or 90 day remediation plans, to the April 29, 2022, June 7, 2022 and July 4, 2022 General Government and Licensing Committee meeting.
Confidential Attachment 1, 2 and 3 to the report (March 8, 2022) from the Chief Information Security Officer, remain confidential in their entirety in accordance with the City of Toronto Act, 2006, as they involve the security of property belonging to the City of Toronto.
Confidential Attachment - The attachments to this report involve the security of property belonging to the City of Toronto.
Background Information (Committee)
https://www.toronto.ca/legdocs/mmis/2022/gl/bgrd/backgroundfile-222639.pdf
Confidential Attachment 1
Confidential Attachment 2
Confidential Attachment 3
GL29.16 - Status of Audit Recommendations and Key Cybersecurity Risks
- Decision Type:
- ACTION
- Status:
- Amended
- Wards:
- All
Confidential Attachment - The attachments to this report involve the security of property belonging to the City of Toronto.
Committee Recommendations
The General Government and Licensing Committee recommends that:
1. City Council direct that Confidential Attachments 1, 2 and 3 to the report (March 8, 2022) from the Chief Information Security Officer remain confidential in their entirety, as they involve the security of property belonging to the City of Toronto.
2. City Council direct the Board of any City Agency or Corporation that has not yet submitted a submission under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, to take immediate action submit their submission to the Chief Information Security Officer.
3. City Council direct the Board of any City Agency or Corporation that has not yet submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, to take immediate action submit their remediation plan to the Chief Information Security Officer.
4. City Council direct the Chief Information Security Officer to report to the April 29, 2022 meeting of General Government and Licensing Committee on any City Agency or Corporation that has not yet submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer.
5. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation that has not submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, are available at the April 29, 2022 meeting of General Government and Licensing Committee to answer questions of staff on this item.
6. City Council direct the Chief Information Security Officer to report, on an exception basis, the details any City Agency or Corporation that is not adhering to their 30, 60 or 90 day remediation plans, to the April 29, 2022, June 7, 2022 and July 4, 2022 General Government and Licensing Committee meeting.
Decision Advice and Other Information
The General Government and Licensing Committee directed the City Manager to ensure that the heads of any City Agency or Corporation that has not yet submitted a submission under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, are available at the April 6 and 7, 2022 meeting of City Council to answer questions of staff on this item.
Origin
Summary
The purpose of this report is to present the biannual report to the General Government and Licensing Committee on the City-wide cyber security program, including an update on the cyber security confirmation program underway with City divisions, agencies and corporations, and to report back on the City's response to the Log4j cybersecurity threat.
This report contains three confidential attachments from the Office of the Chief Information Security Officer:
Attachment 1 The City's Cyber Health describes the City's cyber health as seen from three lenses: cyber resilience, cyber maturity, and cyber awareness.
Further, these attachments provide details on:
a. Overall cyber health of the organization, the progress made in the past six month and the benefits/efficiencies achieved as a result of the Cyber program implementation, including embedding "cybersecurity by design" principles to support the City's modernization efforts;
b. The status of all outstanding audit recommendations that have not been implemented to date, including any increase to the City's cybersecurity risk profile
c. Additional supports required to address cybersecurity risks in an expedited manner.
Subsequent reports to the General Government and Licensing Committee will include updates on the following:
- Projects, initiatives, procurement, and operations where cybersecurity requirements or directives were not included in the process
The attachments also include highlights of the progress the Office of the Chief Information Security Officer has made, in collaboration with Technology Services Division and the City's critical infrastructure Divisions, in embedding cyber security risk management practices in their projects, initiatives, procurement, and operations.
Attachment 2 Status of the Confirmation Program describes the status of the confirmation program in the first quarter of 2022, including rates of compliance, remediation plans and strategies to reduce risk and ensure corporate compliance.
Attachment 3 LOG4J Update describes the situation, sequence of action, incident response and reporting steps taken and the current status of the "Log4j" threat to the City, its agencies, boards and commissions.
Background Information
https://www.toronto.ca/legdocs/mmis/2022/gl/bgrd/backgroundfile-222639.pdf
Confidential Attachment 1
Confidential Attachment 2
Confidential Attachment 3
Motions
That:
1. City Council direct the Board of any City Agency or Corporation that has not yet submitted a submission under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, to take immediate action submit their submission to the Chief Information Security Officer.
2. General Government and Licensing Committee direct the City Manager to ensure that the heads of any City Agency or Corporation that has not yet submitted a submission under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, are available at the April 6 and 7, 2022 meeting of City Council to answer questions of staff on this item.
3. City Council direct the Board of any City Agency or Corporation that has not yet submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, to take immediate action submit their remediation plan to the Chief Information Security Officer.
4. City Council direct the Chief Information Security Officer to report to the April 29, 2022 meeting of General Government and Licensing Committee on any City Agency or Corporation that has not yet submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer.
5. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation that has not submitted a remediation plan under the Confirmation Program described in Confidential Attachment 2 to the report (March 8, 2022) from the Chief Information Security Officer, are available at the April 29, 2022 meeting of General Government and Licensing Committee to answer questions of staff on this item.
6. City Council direct the Chief Information Security Officer to report, on an exception basis, the details any City Agency or Corporation that is not adhering to their 30, 60 or 90 day remediation plans, to the April 29, 2022, June 7, 2022 and July 4, 2022 General Government and Licensing Committee meeting.