Laserfiche WebLink
6.D. - Page 32 of 33 <br />technology architecture is designed with redundancy and failover capabilities such that no single event <br />short of a natural disaster could bring down the entire infrastructure at one time. The different <br />functions/components are generally tested during the normal course of business as functions fail, <br />servers patched, or requested data restored. Nevertheless, the City has planned for such a <br />circumstance, and recovery processes are documented in the City's secure internal systems. <br />All network devices have their configurations backed up nightly in the event of an equipment failure or <br />breach. <br />R1.3. Prevention (turning on email filtering, setting up message rules to warn users, providing <br />employee training on phishing and providing a reporting system to flag suspect content) <br />City response: The recommendation has been partially implemented. Following is a summary of what <br />has been implemented and what is planned. <br />The City utilizes both cloud and an on premise dedicated SPAM prevention appliance and software <br />which all email is first run though before being delivered to recipients. The appliance continuously <br />communicates with the manufacturer's secure site to update its protections to the latest known threats. <br />In addition, the appliance wraps all links within an email with a path which, when clicked, first go <br />through the manufacturer's secure cloud services to confirm as best as possible that the link is <br />legitimate and not a known hacking site. <br />The City prepends the subject of certain emails with [suspect] when an email contains one of many <br />known to be trouble phrases such as "gift cards." Every external email prepends the body of the email <br />with a warning the email is from an external source and to use caution when responding or clicking on <br />any links contained within. <br />The City is currently in the process of implementing employee required cyber security and awareness <br />training and will have it implemented by March 2021. It will include best practices for handling Personal <br />Identifying Information (PID) among other topics requiring vigilance. <br />Additional City security strategies <br />The City carries cyber security insurance in the event of a data breach which provides the City with <br />resources to assist in the cost of recovery, including notifications to those whose personal information <br />was likely breached. <br />As cloud services become more a part of the City's infrastructure, City IT strives to connect cloud <br />services to its internal Active Directory security model, often referred to as "Single Sign On." This allows <br />IT staff to manage access to internal and hosted (cloud) applications from a single secure source. <br />Some high risk data, such as credit card information, is never stored, in any format, on City equipment <br />or premise. Credit card processing is always done through third party providers who must be Payment <br />Card Industry (PCI) compliant. PCI standards and requirements are well documented and only vendors <br />meeting PCI compliance are considered and used by the City. <br />City IT staff is investigating the implementation of multi -factor authentication. This effort has been <br />ramped up given the current pandemic environment in which the majority of the workforce is located <br />outside of a City facility. Whereas in the past security was focused on keeping people out, the pandemic <br />has turned that upside down in which now the strategy is to secure endpoints theoretically located <br />153 <br />