My WebLink
|
Help
|
About
|
Sign Out
Browse
Search
AgdaPkt 2020-12-21 Amended Joint SA PFA
RedwoodCity
>
City Clerk
>
Agenda Packets
>
2020-2029
>
2020
>
AgdaPkt 2020-12-21 Amended Joint SA PFA
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
1/5/2021 12:51:59 PM
Creation date
12/18/2020 5:45:35 PM
Metadata
Fields
Template:
CC Index
CC Index - Document Type
Agenda Packet
Meeting Type
Joint
Agency Type
City Council and Successor Agency and Public Financing Authority
Date
12/21/2020
Jump to thumbnail
< previous set
next set >
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
1000
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
Show annotations
View images
View plain text
6.1). - Page 20 of 33 <br />Conclusions <br />Grand Jury survey results and in-depth interviews determined that some local government <br />agencies have Cybersecurity strategies in place. For them, this report is asking those IT <br />departments to re -challenge the sufficiency of their employee training, the regular (full) testing <br />of their defense strategies and the adequacy/age of their Cybersecurity strategy including <br />consideration of cloud hosting. For the rest, this is a good time to complete a review and see <br />what additional measures can be taken to beef up their IT security using the information <br />provided in this report as a guide. The biggest trap is believing that a malware attack, or in the <br />worst case a Ransomware attack, is unlikely to happen to organizations and that the <br />Cybersecurity strategies already in place are sufficient to successfully recover. <br />As learned from the best practices example of the IT manager who thwarted two attacks <br />successfully, a comprehensive Cybersecurity plan includes user prevention steps, spam and <br />malware software, back-ups and full recovery testing. These suggestions as well as those from <br />the professional literature on Cybersecurity include the following list of best practices: <br />• Anti-Malware definitions need to be constantly updated to retain their effectiveness. <br />• Software updates need to be kept current. <br />• To identify external emails, message rules can be used to flag external emails and thereby <br />decrease the probability that a user clicks on bad content. <br />• To thwart phishing attempts, footers can be added to incoming emails to warn about <br />opening attachments and clicking on links (see Appendix Q. <br />• Security training, awareness and assessment need to be routine along with testing all <br />employees to recognize, delete and report attempted attacks (See Appendix B). <br />• Establishing a thorough and comprehensive backup process for all Servers using the 3-2- <br />1 rule and establishing a separate backup process for key users' critical folders (e.g., <br />administration, accounting, human resources) to be able to restore/recover from a secure <br />onsite and/or offsite backup. <br />• Snapshots and/or image backups provide the most complete backup and the fastest <br />recovery option. <br />■ Consider cloud -hosting of email and other applications to provide added security, backup <br />& restore capabilities and filtering benefits to close the largest and easiest route for <br />Ransomware to penetrate entity systems. <br />FINDINGS <br />F1. Ransomware is areal and growing threat to public entities including those in San Mateo <br />County. <br />F2. Across the country, local governments and schools represent 12% of all Ransomware <br />attacks. <br />F3. The direct and indirect costs of Ransomware can be significant. <br />F4. Cybersecurity reviews and assessments, and an updated, well -executed Cybersecurity plan, <br />are critical components of IT security strategy. <br />2019-2020 San Mateo County Civil Grand Jury 12 <br />141 <br />
The URL can be used to link to this page
Your browser does not support the video tag.