committee on information technology · users of ccsf information systems with access to critical...

41
Committee on Information Technology Regular Meeting November 21, 2019 1 1 Dr. Carlton B. Goodlett Place, City Hall, Room 305 San Francisco, CA 94102

Upload: others

Post on 13-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Committee on Information Technology

Regular Meeting

November 21, 2019

1

1 Dr. Carlton B. Goodlett Place, City Hall, Room 305San Francisco, CA 94102

Page 2: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Agenda• Call to Order by Chair• Roll Call• Approval of Meeting Minutes from October 17, 2019• Chair Update• CIO Update• Digital Services Strategy Update• Policy Update: Citywide Cybersecurity Policy• Policy Update: Cybersecurity Awareness & Training Standard• Public Comment• Adjournment

2

Page 3: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

3. Approval of MinutesAction Item

3

Page 4: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

4. Chair Update

4

Page 5: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

5. CIO Update

5

Page 6: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Department of Technology Town Hall 11.19.19

Providing Kincade Fire Refugees with Internet Access

Partnerships for

St. Mary’s Church Shelter

Services for 200 people

Department of Emergency Management, Special Event Operations

Department of Technology, Division of Public Safety

Monkeybrains – routers, WAPs and service

ATT – phone charger

Page 7: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Department of Technology Town Hall 11.19.19

Department of Technology Monkeybrains

Connecting Kincade Fire Refugees

Build fiberConnection

Pull fiber tothe premises

Connect wirelessaccess points

Connectswitch

Connectrouter

Page 8: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Department of Technology Town Hall 11.19.19

Connecting Kincade Fire Refugees

Page 9: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

bit.ly/dthelps

Department of Technology Town Hall 11.19.19

Connecting Kincade Fire Refugees

Page 10: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

An Overview of ballot-comparison audit for

Ranked-Choice Voting

Election Commission Meeting

November 20th, 2019

Project ShangRLA

Page 11: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

• Implementation of a Risk-Limiting Audit on a Ranked-Choice Voting

• Independent validation of Dominion’s RCV Tabulation

• Open source voting project component piloted and tested

Introducing a few firsts

Open Source Voting System Project

11

Page 12: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

A Risk-Limiting Audit (RLA) offers a statistical guarantee:

“If a full manual tally of the paper ballots would show that the reported election outcome is

wrong, an RLA has a known minimum chance, the RLA limit, of leading to a full manual tally”

– Philip B. Stark

“As with other elections audit, the goal is to identify not only intentional alterations of ballots

and tallies, but also bugs in election machines, such as software errors, scanners with blocked

sensors or scanners skipping some ballots. ” – Wikipedia

What is a Risk-Limiting Audit?

Open Source Voting System Project

12

Page 13: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Open Source Voting System Project

13

Tabulates &Convert to RAIRE

CVR(JSON)

Assertions(Json)

Raire(JSON)

RaireAssertion generator

Assertion visualizer

CVR(json)

Manifest(tab)

RLA Tool

Ballots to audit (CSV)

Manual Vote RecorderTool

Physical ballots

Dominion

MVR(json)

1

2

3

4

6

Audit results

7

Seed

8

Elections Dept

5

ShangRLA flow overview

Page 14: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Open Source Voting System Project

14

Page 15: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Next Step: Taking ShangRLA from Pilot to Product

Open Source Voting System Project

15

Phase I:

• Standardize on languages

• Transition out of Jupyter notebook

• Migrate from files to an RDBMS

• JSON is ill-suited for a system that has a natural entity-relationship model

• Build a test suite above and beyond unit tests

• Document

Phase II:

• Support for Multi-Contest auditing

• Integrate non-VBM Ballot auditing

• Enhance the UI

• ShangRLA is engineered to support various forms of contest beyond RCV

Page 16: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Acknowledgements

Open Source Voting System Project

16

CCSF would like to acknowledge the team effort:

RCV Team: Dr. Michelle Blom: Research Fellow, School of Computing and Information Systems, The University of Melbourne, AustraliaDr. Andrew Conway: CEO, Silicon Econometrics Pty. Ltd., AustraliaPeter Stuckey: Professor, Data Science & AI, Monash University, Melbourne, Australia

Vanessa Teague: Associate Professor, School of Computing and Information Systems, The University of Melbourne, Australia

RLA Team:

Dan King: ViewPoint Technology, San Diego Philip B. Stark:Professor of Statistics, Associate Dean, Division of Mathematical and Physical Sciences , Regional Associate Dean (Interim), College of Chemistry and Division of Mathematical and Physical Sciences, University of Berkeley, CA

Page 17: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

San Francisco Digital Services

Digital Services update

Carrie Bishop

November 2019

Page 18: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Hello COIT! It’s been a while…

Page 19: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

We launched a new website for the City!

Page 20: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

In line with our design principles

1. Represent the diversity of the city

2. Celebrate our unique culture and progressive values

3. Be accessible and inclusive for all people

4. Reflect that the website is easy to use, efficient and reliable

5. Be flexible for the variety of services and content we offer

Page 21: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Done Doing To-doSearch

Service start

pages

Dept

homepages

News

EventsBranding

Homepage

Info pages

Single sign-on

for staff

Transaction

pages

Topics /

navigation

Translation

People info

pages

SEO

Analytics

Public

meetings

Content editor

for staff

Pattern library

Website progress

Emergency

info

Page 22: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

By the new year

● Human translation implemented

● Ability to put forms online

Beyond

● Meetings, minutes and agendas

● Transactions online (digital permitting)

● Supporting more departments to move across

Page 23: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Thank you to the departments we’ve worked with so far!

● OCEIA

● OTI

● DPH

● County Clerk

● DPA

● Fire

● Entertainment Commission

Page 24: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

We will be bringing an accessibility policy to COIT through APRB:

• 5th grade reading level

• Human translation

• Comply with the law and meet international

standards

Page 25: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

We also moved 80 existing city websites to a new hosting provider.

We continue to support these existing websites.

Page 26: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Permitting –transactions online

Page 27: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

We’re helping people get an ADU permit

Page 28: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

And apply online

Page 29: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

And connecting systems at the back end for a seamless customer experience

Case

management

Power BIPredictive

analyticsMeta-data

Digital

Forms

Document

management

Zone

checking

Appt.

booking

Payments

Unique Identifiers

Enterprise AddressSystem

Identity Access Mgmt

Electronic

SignaturesWeb

content

Fee

estimator

Status

trackingNotifications EPR

Page 30: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

To support all of this work we are growing the team.

Page 31: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users
Page 32: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Into FY20/21

Page 33: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

As we mature our services we must be able to support them. This means:

● Technical support (patches, fixes, updates)

● Customer support (public facing)

● Accessibility support (language translation, compliance)

● Content support (timely public information, legislative changes)

Page 34: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Questions?

Page 35: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

7. Citywide Cybersecurity Policy

35

Page 36: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Background

Original Approval: November 17, 2016

Updated: June 19, 2018

2019 Update:

› Role of Department Information Security Officer

› Update to Requirement Timelines

› Emergency Support Function Unified Cyber Command

36

Page 37: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

RequirementsThe COIT Cybersecurity Policy requires all departments to:

1.Appoint a Departmental Information Security Officer (DISO) or Chief Information Security Officer (CISO) depending on Department size.

2.Adopt a cybersecurity framework as a basis to build their cybersecurity program.

3.Support cyber incident response as needed in accordance with Emergency Support Function 18 (ESF-18) Unified Cyber Command.

4.Conduct and update, at least annually, a department cybersecurity risk assessment.

5.Develop and update, at least annually, department cybersecurity requirements to mitigate risk and comply with legal and regulatory cybersecurity requirements.

6.Participate in citywide cybersecurity forum meetings.

37

Page 38: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

8. Cybersecurity Awareness & Training Standard

38

Page 39: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

Background

Original Approval: October 27, 2017

Update:

› Defines role of Human Resources

› Help to improve citywide adoption

39

Page 40: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

RequirementsUsers of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including:

1. All users are required to take annual cybersecurity awareness training in the form of Computer- Based-Training (CBT) or instructor led workshops.

2. All new users are required to take mandatory cybersecurity awareness training in the form of the CBT or instructor led workshops.

3. Awareness reinforcement and additional training may be provided through newsletters, posters, phishing campaigns, screensavers, webcasts, workshops and national cybersecurity related events.

40

Page 41: Committee on Information Technology · Users of CCSF information systems with access to critical systems shall participate in cybersecurity awareness training, including: 1. All users

9. Public Comment

41