Item - 2022.GL30.12

Tracking Status

  • City Council adopted this item on May 11 and 12, 2022 without amendments and without debate.
  • This item was considered by General Government and Licensing Committee on April 29, 2022 and was adopted with amendments. It will be considered by City Council on May 11 and 12, 2022.

GL30.12 - Confirmation Program Response Rate - Addressing Cyber Risks

Decision Type:
ACTION
Status:
Adopted on Consent
Wards:
All

City Council Decision

City Council on May 11 and 12, 2022, adopted the following:

 

1. City Council direct the Chief Information Security Officer to develop a process to periodically report to the General Government and Licensing Committee on instances of non-compliance and associated risk treatments and their associated Risk Treatment Plans (RTPs) for all risk assessments conducted by the Office of the Chief Information Security Officer, starting with critical systems.

 

2. City Council direct the Chief Information Security Officer to report periodically to the General Government and Licensing Committee the details of any City Agency or Corporation or entity that is deemed part of the Confirmation Program, that deviates from carrying out the objectives of the Confirmation Program.

 

3. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation or entity that is deemed part of the Confirmation Program that has not submitted a remediation plan or signed risk treatment plans under the Confirmation Program or other risk assessments starting with critical systems, conducted by the Office of the Chief Information Security Officer, are available when required at the General Government and Licensing Committee meetings to answer questions on their item.

 

4. City Council direct that Confidential Attachment 1 to the report (April 14, 2022) from the Chief Information Security Officer remain confidential in its entirety, as it involves the security of property belonging to the City of Toronto.

 

Confidential Attachment 1 to the report (April 14, 2022) from the Chief Information Security Officer remains confidential in its entirety in accordance with the provisions of the City of Toronto Act, 2006, as it pertains to the security of property belonging to the City of Toronto.

Confidential Attachment - Involves the security of property belonging to the City of Toronto

Background Information (Committee)

(April 14, 2022) Report from the Chief Information Security Officer on Confirmation Program Response Rate
https://www.toronto.ca/legdocs/mmis/2022/gl/bgrd/backgroundfile-224808.pdf
Confidential Attachment 1

GL30.12 - Confirmation Program Response Rate - Addressing Cyber Risks

Decision Type:
ACTION
Status:
Amended
Wards:
All

Confidential Attachment - Involves the security of property belonging to the City of Toronto

Committee Recommendations

The General Government and Licensing Committee recommends that:

 

1. City Council direct the Chief Information Security Officer to develop a process to periodically report to the General Government and Licensing Committee on instances of non-compliance and associated risk treatments and their associated Risk Treatment Plans (RTPs) for all risk assessments conducted by the Office of the Chief Information Security Officer, starting with critical systems.

 

2. City Council direct the Chief Information Security Officer to report periodically to the General Government and Licensing Committee the details of any City Agency or Corporation or entity that is deemed part of the Confirmation Program, that deviates from carrying out the objectives of the Confirmation Program.

 

3. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation or entity that is deemed part of the Confirmation Program that has not submitted a remediation plan or signed risk treatment plans under the Confirmation Program or other risk assessments starting with critical systems, conducted by the Office of the Chief Information Security Officer, are available when required at General Government and Licensing Committee meetings to answer questions on their item.

 

4. City Council direct that Confidential Attachment 1 to the report (April 14, 2022) from the Chief Information Security Officer remain confidential in its entirety, as it involves the security of property belonging to the City of Toronto.

Origin

(April 14, 2022) Report from the Chief Information Security Officer

Summary

The purpose of this report is to provide an update to the General Government and Licensing Committee on the Confirmation Program to address cyber risks identified in the City's divisions, agencies and corporations.

 

This report contains one confidential attachment from the Office of the Chief Information Security Officer:

 

Confidential Attachment 1 - Confirmation Program Response Rate provides a summary of the Confirmation Program, and highlights any City agency or corporation that has not yet submitted a remediation plan under the Confirmation Program.

Background Information

(April 14, 2022) Report from the Chief Information Security Officer on Confirmation Program Response Rate
https://www.toronto.ca/legdocs/mmis/2022/gl/bgrd/backgroundfile-224808.pdf
Confidential Attachment 1

Motions

1 - Motion to Amend Item (Additional) moved by Councillor Stephen Holyday (Carried)

That:

 

1. City Council direct the Chief Information Security Officer to develop a process to periodically report to the General Government and Licensing Committee on instances of non-compliance and associated risk treatments and their associated Risk Treatment Plans (RTPs) for all risk assessments conducted by the Office of the Chief Information Security Officer, starting with critical systems.

 

2. City Council direct the Chief Information Security Officer to report periodically to the General Government and Licensing Committee the details of any City Agency or Corporation or entity that is deemed part of the Confirmation Program, that deviates from carrying out the objectives of the Confirmation Program.

 

3. City Council direct the City Manager to ensure that the heads of any City Agency or Corporation or entity that is deemed part of the Confirmation Program that has not submitted a remediation plan or signed risk treatment plans under the Confirmation Program or other risk assessments starting with critical systems, conducted by the Office of the Chief Information Security Officer, are available when required at General Government and Licensing Committee meetings to answer questions on their item.


Motion to Adopt Item as Amended moved by Councillor Paul Ainslie (Carried)
Source: Toronto City Clerk at www.toronto.ca/council