Item - 2022.GL30.12
Tracking Status
- City Council adopted this item on May 11 and 12, 2022 without amendments and without debate.
- This item was considered by General Government and Licensing Committee on April 29, 2022 and was adopted with amendments. It will be considered by City Council on May 11 and 12, 2022.
GL30.12 - Confirmation Program Response Rate - Addressing Cyber Risks
- Decision Type:
- ACTION
- Status:
- Adopted on Consent
- Wards:
- All
City Council Decision
City Council on May 11 and 12, 2022, adopted the following:
1. City Council direct the Chief Information Security Officer to develop a process to periodically report to the General Government and Licensing Committee on instances of non-compliance and associated risk treatments and their associated Risk Treatment Plans (RTPs) for all risk assessments conducted by the Office of the Chief Information Security Officer, starting with critical systems.
2. City Council direct the Chief Information Security Officer to report periodically to the General Government and Licensing Committee the details of any City Agency or Corporation or entity that is deemed part of the Confirmation Program, that deviates from carrying out the objectives of the Confirmation Program.
3. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation or entity that is deemed part of the Confirmation Program that has not submitted a remediation plan or signed risk treatment plans under the Confirmation Program or other risk assessments starting with critical systems, conducted by the Office of the Chief Information Security Officer, are available when required at the General Government and Licensing Committee meetings to answer questions on their item.
4. City Council direct that Confidential Attachment 1 to the report (April 14, 2022) from the Chief Information Security Officer remain confidential in its entirety, as it involves the security of property belonging to the City of Toronto.
Confidential Attachment 1 to the report (April 14, 2022) from the Chief Information Security Officer remains confidential in its entirety in accordance with the provisions of the City of Toronto Act, 2006, as it pertains to the security of property belonging to the City of Toronto.
Confidential Attachment - Involves the security of property belonging to the City of Toronto
Background Information (Committee)
https://www.toronto.ca/legdocs/mmis/2022/gl/bgrd/backgroundfile-224808.pdf
Confidential Attachment 1
GL30.12 - Confirmation Program Response Rate - Addressing Cyber Risks
- Decision Type:
- ACTION
- Status:
- Amended
- Wards:
- All
Confidential Attachment - Involves the security of property belonging to the City of Toronto
Committee Recommendations
The General Government and Licensing Committee recommends that:
1. City Council direct the Chief Information Security Officer to develop a process to periodically report to the General Government and Licensing Committee on instances of non-compliance and associated risk treatments and their associated Risk Treatment Plans (RTPs) for all risk assessments conducted by the Office of the Chief Information Security Officer, starting with critical systems.
2. City Council direct the Chief Information Security Officer to report periodically to the General Government and Licensing Committee the details of any City Agency or Corporation or entity that is deemed part of the Confirmation Program, that deviates from carrying out the objectives of the Confirmation Program.
3. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation or entity that is deemed part of the Confirmation Program that has not submitted a remediation plan or signed risk treatment plans under the Confirmation Program or other risk assessments starting with critical systems, conducted by the Office of the Chief Information Security Officer, are available when required at General Government and Licensing Committee meetings to answer questions on their item.
4. City Council direct that Confidential Attachment 1 to the report (April 14, 2022) from the Chief Information Security Officer remain confidential in its entirety, as it involves the security of property belonging to the City of Toronto.
Origin
Summary
The purpose of this report is to provide an update to the General Government and Licensing Committee on the Confirmation Program to address cyber risks identified in the City's divisions, agencies and corporations.
This report contains one confidential attachment from the Office of the Chief Information Security Officer:
Confidential Attachment 1 - Confirmation Program Response Rate provides a summary of the Confirmation Program, and highlights any City agency or corporation that has not yet submitted a remediation plan under the Confirmation Program.
Background Information
https://www.toronto.ca/legdocs/mmis/2022/gl/bgrd/backgroundfile-224808.pdf
Confidential Attachment 1
Motions
That:
1. City Council direct the Chief Information Security Officer to develop a process to periodically report to the General Government and Licensing Committee on instances of non-compliance and associated risk treatments and their associated Risk Treatment Plans (RTPs) for all risk assessments conducted by the Office of the Chief Information Security Officer, starting with critical systems.
2. City Council direct the Chief Information Security Officer to report periodically to the General Government and Licensing Committee the details of any City Agency or Corporation or entity that is deemed part of the Confirmation Program, that deviates from carrying out the objectives of the Confirmation Program.
3. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation or entity that is deemed part of the Confirmation Program that has not submitted a remediation plan or signed risk treatment plans under the Confirmation Program or other risk assessments starting with critical systems, conducted by the Office of the Chief Information Security Officer, are available when required at General Government and Licensing Committee meetings to answer questions on their item.