Loading...
HomeMy WebLinkAbout2006-03-28-10:00AM-WORKSHOPBRAZOS COUNTY BRYAN, TEXAS NOTICE OF MEETING b E1,i~ 2t; A tr 12 CLLR!{ ~ 4.7[:XAS 21 ~111 BRAZOS COUNTY COMMISSIONERS COURT WORKSHOP SESSION THE COMMISSIONERS COURT OF BRAZOS COUNTY WILL MEET IN WORKSHOP SESSION ON TUESDAY, MARCH 28, 2006 AT 10:00 A.M. IN THE COMMISSIONERS COURTROOM IN THE BRAZOS COUNTY COURTHOUSE, BRYAN, TEXAS. 1. Call to Order. 2. Review of Brazos County's computer and security policies and procedures. 3. Adjourn. The Brazos County Courthouse is wheelchair accessible. Handicap parking spaces are available. Any request for sign into titive services m6t be made two business days before the meeting. To make armagements,call (979)361-4"2 VOL 7.9 PAGE - Brazos.:0Q*jy70qur1hoU" 300: East 2d St 9 BOOM, Bryan, Texas 77803 • ; Fax: (979) 823-8993 COMMISSIONERS' COURT WORKSHOP SESSION MARCH 28, 2006 The Commissioners' Court of Brazos County, Texas met in a Workshop Session in the Commissioners' Courtroom in the Courthouse in Bryan, Brazos County, Texas, beginning at 10:00 a.m. on Tuesday, March 28, 2006, with the following members of the Court present: Randy Sims, County Judge, Presiding; Lloyd Wassermann, Commissioner of Precinct 1; Duane Peters, Commissioner of Precinct 2; Kenny Mallard, Commissioner of Precinct 3; Carey Cauley, Jr., Commissioner of Precinct 4; Karen McQueen, County Clerk. Attached is a list of the citizens and officials in attendance. Attached is a transcript of the meeting. Vol 11.9 Page c)- 13 I of 27 BRAZOS COUNTY COMMISSIONERS COURT Computer Security Policies Workshop March 28th, 2006 Sims: Ladies and gentlemen, thank you for coming to the Commissioner's Court Workshop Session. We will meet in workshop session on Tuesday March 28`11 2006 at 10:00 a.m. in the Commissioner's Court Room in the Brazos County Courthouse. First item on the agenda is: Call to Order and the next item on the agenda is: Review of Brazos County's computer and security and procedures. Are you ready Mr. Eric? Caldwell: I am. Sims: Please proceed. Caldwell: Ok. Thank you. With your indulgence, I am not going to strap on my jacket. I'm told it's just me but I'm hot so I'm going to stand up here with out it. Well I have given each of you and outline of the things I'd like to try to cover today. So I would just like to spend five or ten minutes on the first six bullets and then the real work is going to be in bullet number seven down as we go over the draft policy processing detail. First of all as you recall on the 17th of February we had our first workshop on these draft polices. It was not as well attended as perhaps it should have been, never the less what I did in that workshop was to go over what I believe was the most pertinent rational for adopting an Information Security Plan as a whole beginning with the Information Security Policies. And I did what I thought was a pretty good job of justifying that really without any reference to any statutory authority or mandate to do so and without any direct references to industry best practices. But what I did was, for those that were present; I built a case for adopting an Information Security Program and adherence to that program on an on-going, long term basis. The transcript and the recording of that meeting is available for anybody who wants it. Feel free to ask me. At that meeting, it was decided that the best way to proceed was to circulate those draft polices and obtain feedback from other department heads and elected officials and so to that end, those were circulated and I have gotten feedback from a handful of people and will go over those responses again in more detail in just a little while. Given the responses that I received to those policies, I think it's probably important that I stop and explain the purpose of the policies, the supporting standards, and the next steps that we have to go through in order to achieve these goals. So with that, let me just define polices for you. The International Organization on Standardization defines Policies as follows: Vol 7 9 Page 2 of 27 "The objective of an Information Security Policy is to provide management direction and support for information security." The State of Texas, Department of Information Resources writes, "The Polices are management instructions indicating a course of action, guiding principals, or appropriate procedures that is expedient, prudent, or advantageous. Polices are high level statements that provide guidance to workers who must make present and future decisions. It is also correct to say that Polices are generalized requirements that must be written down and communicated to certain groups of people inside and in some cases outside the organization. Although Information Security Policies vary considerably by organization, they typically include general statements of goals, objectives, beliefs, ethics, controls, and work responsibilities." So policies then are a high level statement of managements' beliefs and goals and in this case beliefs that the information that resides on our systems is a business asset that really needs to be protected and we need to try to achieve maximum confidentiality, availability, and integrity of that data. Sims: Tell me what page you're reading off of. Caldwell: Well this is just my notes. I'm just trying to lay some groundwork. Sims: Oh, ok. This is verbiage only. Caldwell: I'm just trying to lay some groundwork for you in large part to try to address some of the concerns that were given to me as feedback. Remember what I had circulated was just these higher level statements of executive management belief that they needed to undertake this program to protect their assets; in this case, information. It won't be until we get to the next step which is to further refine the standards and procedures that we have to follow in order to adhere to these polices that some of the comments that I received are really going to be pertinent. So again, standards are the mandatory activities, actions, rules, or regulations designed to provide policies with the support structure and specific direction they require to be meaningful and effective. So in a nutshell, you start from the higher level policy statement and then you start working your way down and refining those practices that you must follow in order to adhere to your own policies. A good example might be that if information custodians in policy are responsible for providing a safe and secure processing environment which information can be maintained with integrity. A supporting standard then; which is more refined and much more direct, might read that the custodian of information processing systems must use X brand of anti-virus software to insure that the system is free from destructive software elements. And then you can go further to define procedures and those procedures might state that every new PC that is rolled out into service must have this software loaded and it must Vol 7F Page a 15 3 of 27 be configured with these particular parameters. So you can see as we go along that we have to get more and more refined. So again, one of the things that I did not try to address in that previous workshop was that any authority or any mandate to do this. What I did was I tried to deliver to those present rational for adopting this program on the merits of the program alone. So given some of the remarks I received, I went and started trying to research ...in fact, is there any mandate or any statutory authority to undertake this program. As it turns out it doesn't appear there is. Now while Chapter 2054 of the Goverment Code also known as Information Management Resources Act creates The Department of Information Resources and it declares that information and the resources possessed by agencies of state government are strategic assets belonging to the residents of Texas and must be managed as valuable as state resources. There is not similar, chapter in the Local Government Code. So there's no statutory mandate that we undertake this. And so we kind of fall back to adopting such a program based on its merits only. Well, in such a case you might wonder where we begin. Well fortunately, as I've pointed out to you on several occasions because of the draft policies and because of the security audit that we undertook early last year and for other reasons; there is an international standard on information security. It is the ISO17799. Now ISO is the International Organization for Standardization and together with International Electrotechnical Commission formed a specialized system for worldwide standardization. National bodies that are members of the ISO and IEC "participate in the development of international standards through technical committees established by the respective organization that deal with particular fields of technical activity." ISO and IEC technical committees collaborate and fills a mutual interest other international organizations governmental and non-governmental liaison with ISO and IEC also take part of the work. So the International Standard 17799 was initially prepared by the British Standards Institute as British Standards 7799 and was later adopted under a special fast-track procedure by the Joint Technical Committee ISO, IEC Joint Technical Committee won permission to (inaudible) parallel was approved by national bodies of ISO and IEC. So what does all that mean? Well again, in a nutshell, at an international level, bodies have participated in developing this standard for securing information as business assets and trying to achieve this goal of maximizing the confidentiality of the data, the integrity of that data and the availability of that data to those who are authorized to use it and need to get to it. So again, going back to this ISO17799 standard let me read for you their definition of, rather my paraphrase, interpretation of their definition of information security. Vol -78 Page a hP 4 of 27 `Information security is the protection of data from a wide range of threats that could lead to accidental or (inaudible) disclosure of confidential information, unauthorized modifications, or destruction sensitive or mission critical data or the unavailable of data, possessing systems and other information resources. The purpose of information security is to insure business continuity, minimize business damage, and maximize return on investments, efforts, and business opportunities and promote information sharing. Information security then is the preservation and maximization of confidentiality, integrity, and availability.' So kind of looking forward then, let me just briefly kind of cover what the next steps of this bigger program is going to be assuming that we can get policies adopted. Once we get these security policies adopted, shouldn't the next steps that we have to undertake is identification of data owners. Identifying who owns the data is going to be a necessary prerequisite before we can start classifying this data and determining how much risk we face in maintaining this data on our system without security pieces in place. How mission critical that data is and, again, how confidential that information needs to be. Is it nonpublic customer information such as health records or is road and bridge work history records? So given the kind of data, we're going to have to classify it into a number of different categories like business criticality, confidentiality, and things of that sort. So to do that, we are going to have to identify various roles and responsibilities. Who's the data owner, who's the data custodian, who are the various intermediates between the two extremes and what roles do they play, what are their responsibilities? Again, we are going to have to work on classifying the data as I mentioned previously, we are going to have to develop the procedures that we must follow in order to adhere to these polices. It will be those procedures that we are following to adhere to these polices that are then auditable. We can audit ourselves to verify that we are following these procedures, again, to adhere to our own polices. We also have to develop a training program. It is important and I pointed out in the last workshop that part of these policies includes a security training policy. It's important that everybody understand how critical their role is in insuring the security of this data; all the way down to the clerks who are doing data entry at terminals, day in and day out. Finally, we are going to have to commit ourselves to auditing. The practice of auditing ourselves not only in house but also having external auditors come in to audit our adherence to our procedures. Our following of these procedures in order to adhere to the policies. With that then, let me stop and point out that in everybody's package there is a little three page piece that has... should be the only piece that has a Vol 7 9 Page a 17 5 of 27 statement with it. Probably at the very front of your binder. At the risk of further aggravating the people's reservations about the lengths of these policies, I have ...in thinking about the responses that I got to those drafts, it was clear to me that I kind of put the cart before the horse. I started looking at all the minutiae and I was building these more detailed, supportive policies before I had put together the master policy. So this master policy then, you will see, summarizes again what I would hope you and the other elected officials as executive management would recognize as appropriate policy to adopt. I'm hopeful that we can all agree that this document right here summarizes at the highest level your understanding the importance of adopting this security program. With that then, I am down to bullet point number seven and prepared to start going over the initial drafts in more detail. I brought my laptop and an overhead projector. I've got enough printed copies. Mallard: Where is bullet point number seven? Female: The front page. Caldwell: Did you not get this sheet here? Cauley: No we don't have that. Caldwell: I'm so sorry. First of all let me apologize to those in the audience if your copies are black and white, I had just enough time last time to crank out copy number six in color and it was time to move on and get these other knocked out. The modification to the original draft is there, although it is in black and white, they are the portions that are underlined. Ok. Now this is where the fun begins; plowing through this. I don't know of any better way to this other than to try to go through it one by one. It will be somewhat time consuming and I'm certainly open for suggestions. We can try setting up the overhead if yall feel like yall will be able to see it up here better. It would be easier for me to kind of click through it where it will carry me through these changes. I can just jump from the next change to the next change to the next change. Mallard: That's good. Caldwell: Fair enough. Sims: Rod, I think the biggest problem is to determine who owns these records. We've already been through that several times here in the last six months. Anderson: I think that it will be helpful to define that not just for this purpose but for other public information. Vol ~ t- Page a le 6 of 27 Sims: Absolutely. Absolutely. Boyett: Is there a question as to who owns the data? Conner: Yes. Sims: Yes. Boyett: My last count, there was 26 elected officers in Brazos County. And I think everybody else is an agency that provides some service to those 26 agencies. Is that correct? Sims: That's correct. Boyett: Service is the key word, I'd sure like to see it emphasized. Sims: We've got 26 independent entrepreneurs that work for the citizens of Brazos County. Boyett: Amen. Right. Caldwell: Ok, you're going to find that on all of these polices I have gone back and I have added references to the IS017799 standard. So in each individual policy that will be the first modification that I introduced form that original draft on February 17`h. Now for those of you in the audience it may be easiest to follow along if you watch down here in this lower left hand corner of the screen on the page that I'm on. I believe that corresponds to the page name in the lower right hand corner of the hard copy. Mallard: So all of these things are going to be essential to this IS017799 section so and so but what is that? Caldwell: The ISO17799, again, it is the International Standard Code of Practice for Information Security Management. Mallard: If we're all to adhere to it, shouldn't that be said or are we just supposed to know what that is or does it matter? Wassermann: Or is it defined already? Mallard: I don't know what it is. Caldwell: I guess I'm not following your point. Vol -79 Page C~ 11 7 of 27 Mallard: Well I mean we're pledging allegiance to the IS017799 and I don't know what it is. Caldwell: I guess I'm not following you Commissioner. This international standard sets a benchmark so that if you want your information systems resources protected as business assets and you want to do what is reasonably within your power to protect those, this standard code of practice is a goal to shoot for. Maybe it would help for you to actually see the standard yourself. Cauley: That's what they're saying, we don't what it is. Mallard: I don't know what it is. Maybe it's something that we can not as a county can utilize. I'm not doubting you, but I just don't know what it is. Caldwell: I really don't know how more to describe it to you. Again, it's a standard... Peters: Is it a guideline? Is that what it is? Caldwell: It's a guideline. Again, it's a just a code of practice that governs ten different areas of information resources security management. For example, it states that facilities security is going to be one component of it. Peters: Who set it up? Caldwell: It was the International Organization on Standardization, which, again, is a body that is participated in by technical committees from nations all over the world. Maybe Bill can explain it better. Jeanes: It's kind of a gold standard apparently, because there are a lot of underwriters now with insurance when they start talking about data in the computers and storage of it and where it's at. It's kind of a standard that's being asked in some of the questionnaires, "Do you comply with..." Now that doesn't explain what it is but it tells me that an underwriter is looking at it and that's kind of a gold standard of.. Mallard: Well, it's just like on item here. `Personal Security' is security in the job definition and resourcing. The objective; to reduce risk of human error, theft, fraud, and misuse of facilities. So it's fairly good words but I don't know if there are some specifics in here but what concerns me is there is some specifics that somehow are contrary to what county government does or has to do. I don't know that there are, that's just my concern. I don't see it. Because I assume my SO with insurance service offices that they did but this is the International Security Operations. That's the other thing that confused me as far as the ISO definition. But I don't know; these appear to be very Vol V 8 Page a a 0 8 of 27 general on the first blush, just looking at these, so I don't know that that is something that would cause us pain on down the road to want to adhere to that. You said it is international standard; are government and private enterprise all wanting to utilize these standards? Caldwell: Yes. These standards are recognized by national governments worldwide as opposed to, let's say a consortium of private industry players may get together and they may set up a specification. I'd have to get out of the IT world to give you a good clear example but there are soft ware vendors for example that will get together who may be competitors in the open market but they recognize that if they can standardize on a particular communications protocol so that their software can talk back and forth, then their market share is a little more secure. Because their market share can continue purchasing their software knowing that their software will talk with IBM's software and Microsoft's software. So this consortium will get together and they'll develop this communications standards but it is not adopted at the international level and is not recognized by governments. For example, the federal government would never require that their contractors adhere to this consortium private standard whereas these international standards carry much more weight and the federal government will often require that their contractors meet these international standards. I don't know if that's helping or not. Let me try it this way. There's nothing about these policies that requires that we even reference the ISO17799...again, you may remember that I said in my opening remarks that the previous presentation I delivered the idea of adopting the security program on it's merits alone, really without any material reference to these international standards. And again, the State of Texas has their government code, Chapter 2054, which requires that they adopt this kind of program. The county does not. So I simply said, "Listen, we can adopt these polices and the program as a whole based solely on the merit of doing so, and we'd never have to try to align it with any international standard or any standard for any reason." However, this is a way of demonstrating that this set of polices is consistent with this international recognized code of practice for securing your information resources. Sims: So basically what you're using this international standard for is credibility? Caldwell: That's certainly one way of putting it. I keep searching for a... Boyett: I see a parallel situation here, perhaps a metaphor, i.e. the United States dealing with the United Nations, we don't always agree with what the United Nations puts forth. Fortunately, we have a complete veto in the Security Council of the United Nations and we can slam the door on them. By reference in a legal document that the Commissioner's Court would be asked Vol $ Page aa! 9 of 27 to sign and approve; by reference you're adopting that standard. Am I correct or not? Anderson: No I don't; I think what Eric is saying is we're going to develop these county polices and procedures and here is how it does actually comply with the ISO but we're not actually adopting the ISO, we're adopting county procedures and he's just referencing in here, I believe, that `the policy is consistent with.' So we're not actually going out and adopting the ISO... Sims: In total. Anderson: Exactly. We're just saying this is the policy and it does comply with the ISO provision, whatever it may be. Is that right? Caldwell: That's correct. Now at the risk of clouding things further, I will tell you that as a long term goal, we really should be shooting for complete compliance with that international standard. Because that would be a badge of honor that we could wear on our sleeve demonstrating that the executive management understands the importance of information residing on it's system, the importance of securing that information and treating that as a business asset. And we've gone to the trouble of adopting the policies, practices, and auditing practices to verify that we are indeed in adherence with those international standards. Sims: But that could be set up with or without the international standards. Caldwell: Again, we can adopt these polices without any reference what so ever simply on their merit along. You're absolutely right. You may remember that we had hired Aporia Solutions to do a scan of our network periphery and do an initial security audit on Brazos County. When I was looking for this security outfit, I told them that what I would for them to do is grade us on how compliant we are with this international standard. That's a big mouthful to try to chew all at once and I understand that this is going to be a long process but if we can at least set out sites on achieving this goal of compliance with this international standard and work toward it, we can move forward for a long time before we get there. But at least we're making progress and if we get there, I won't say that we're done but there's not much more that you can do to secure out systems. Now to that end, they did point out in a report that there are a number of areas where we fall far short of adherence to this international standard. One of which, again, as I pointed out in the February 17`h meeting, I don't even try to address in here because it's another large undertaking and that is business continuity plan. Disaster recovery plan. These policies don't even touch on that. But that's another big undertaking that we're going to have to work on. That is what happens in the event that our data center goes south on us? A tornado comes in, picks it up, and moves it elsewhere. What Vol '78' Page o2aa 10 of 27 do we do? We've got to work on that. Again, I don't want to bite off more than I can chew so this is big enough as it is. We get this in place and we can continue working toward those other goals. So, again, we need not reference in here at all. You can see that I've worded so that it simply says, "consistent with". I'm not saying that we are adopting it as our policy. All I'm saying is that we recognize the merit of adopting this sort of a security program on it's on. And if we can align it with this international recognized standard code of practice, all the better. Well, I'm not going to accept any of these changes yet, we can just bump through here. This is on page five and let me just jump head first in here. `Ownership of Electronic Files and Documents', again, as I stated in the opening remarks, identification of data ownership is going to be a big part of resolving some of the concerns that have been voiced after circulation of those initial draft policies. Again, I think that the way that we attack that is to first define roles and responsibilities; try to identify data ownership but more than that we've got to identify roles and responsibilities. What is this data owner responsible for? What role do they play? What about their supporting staff? What role does the supporting staff play? What roles does Information Technology as the simple custodian to insure that the systems are up and running and do data restores from time to time if necessary? What role do we play? I'll tell you that at first blush, you might take something like TSG as an example. So here we have this integrated justice system and you might think of it as the various modules in that system. The criminal case management system might be thought of as belonging to the District Clerk, Mark Hamlin and the civil case management system might be thought of as belonging to Karen McQueen, the County Clerk. But if you actually look at who all has update privileges in all of these various modules, it is no longer a clear delineation just down these module lines. So it's going to be difficult. There's no question about it, it's going to be a major undertaking and it's important that everybody... all the data owners... understand the reason for undertaking this project. Mallard: So you're saying that since its electronic then it won't be owned by the individuals who are producing it? Caldwell: I'm not saying anything of the sort. All I'm saying is, I don't know yet. I don't know how it's all going to fall out. So we have no ruling.... Let's take the publicly available Justice Web, our criminal records search web site. Who owns that data? I don't know. I couldn't begin to tell you. Now I will tell you that I believe it is IT's responsibility to help sort all the stuff out. Hence you'll find later in these policies that I have included a set of roles and responsibilities, fairly generalized so you can start to appreciate how many different roles we have and what their various responsibilities might be. But again, how the data ownership issue falls out in the end, I don't know. I think Vol 7 Page ;a3 I1 of 27 we've got opinions from the attorney general and the Office of Court Administration that makes it pretty clear that if it is email that is produced by one of the judiciary or his or her staff, that sort of information belongs to that judge. But again, when you are talking about a record or records in the Criminal Case Management Module of our TSG system and who owns that? Who starts that process? Well you have sheriff deputies out in the field that are responsible for the arrest and that information goes into the jail module but some of the information... one of the reason of getting this integrated system is to prevent duplicate data entry. So if you have a deputy out in the field who does initial arrest and then they book him into the jail and that some portion of that information ultimately winds up in this court record and that Mark Hamlin and his staff have to work, have to scan images for, and that ultimately the court co-coordinators have to incorporate into their court docket and then the judges and their staff have to work on the sentencing and whatever it might be; suddenly you've got a number of elected officials that all have their hands on this one little set of records and the ownership of that information is, at least in my mind, is suddenly obscure. Mallard: What was it when it was a paper...? Caldwell: In the ideal... somebody out here in the audience will tell me no, it's quite clear cut and here's where we go with it all. Boyett: No, you're absolutely right, it is not clear cut. The Open Records Act, Public information is there until it becomes, "...a judicial record." The Office of Court Administration and Supreme Court is not even sure what Rule 12 says and I've been to three different classes by three different representatives from the Supreme Court and they were not consistent. A judicial record is a record produced by a judge in the course of his action. But within that record, there's going to be some demographics, there's going to be some information on the arrest, there's going to be a lot of stuff that comes from other agencies just as you say. It is not a clear cut situation. A document produced by a judge in the course of the thing may very well be a judicial record and have Rule 12 shielding but the data leading up to it that are in other files may very well be public information. It's not going to be clear. Caldwell: Let me make one more remark along these same lines. I certainly hope that this in the end this doesn't reduce down into a reverse of our course; I'm not saying this very well. At some point in Brazos County's history, various elected officials were on disparate systems and to try to resolve some of the problems associated with the, there was a move toward this integrated system known as TSG. For all of it's faults, one of the biggest merits of going with TSG was this integration. I certainly hope that in trying to go through this process of identifying ownership that we don't wind up getting crossways with one another and splitting out again. Because what you're going to wind Vol 7 Page as ~ 12 of 27 up with is a system much like pre-TSG in which everybody is in their own little silo of data. I can tell you that the State of Texas is trying to resolve some of those very sorts of problems by bringing information resources management tasks across a number of agencies around the state and consolidating them into just a handful of data centers around the state. So they've already recognized that they've got some major problems because of this disintegration. Mallard: Well, I would think that if you wanted the judges' records... whatever that is, the Rule 12 you're saying ...those are set aside. Now there may be some information in there that was produced by somebody else that is not, they would have to go to that other party and get that information. I mean all that's in that record should just be kept secret or whatever. Closed. Boyett: Well I think that IT is the location to identify the fact that a given document may be well produced by a judicial officer to make it a Rule 12 item. But everything else has got to be in that great databank. What Eric says is absolutely correct, the sharing of information between the courts, the district and the county clerks, the prosecutors offices, the JP offices, and everything else. The Sheriff has a gone a long way to eliminate duplication and misidentification of people because of how people spell names three or four different ways, they use initials, they have different addresses and everything else. We have made an effort to try and consolidate those things in a significant way because the data base that we have now, while it is not perfect, is certainly better than it was four years ago. Mallard: Well, can't they just do that? Say you can't get this from the judges' records because it has other stuff in it but some of the information that came in came from the sheriff's office and you can get that so you will have to go to the sheriff s office or the clerks' office to get to their information because it's public information. Wouldn't that be an easier way to go about it? You may have to go to three different places instead of just the one record. Caldwell: I think a better way of stating that is that once we have completed this process and we've gotten this first step document, it should be pretty clear cut. There shouldn't be any of this guesswork anymore. You simply go to your document showing who owns what and what kind of request might come in for information and whether or not it even should or shouldn't be released and if it's eligible for release, who you have to go to get it approval to do that. Better yet, to whom do you direct that request for the release of that information. So again, I think the bigger point is that by executive management recognizing the need for classifying this data ownership, once that has been recognized and has been... these policies making that Vol 7 9' Page a? J6 13 of 27 recognition very clear have been adopted. Then we can go to the next step and we can start doing this data ownership identification. Mallard: Well, obviously it starts at law enforcement and works up to the clerk's office and then ends up in the judges office, is there ever a time that from the judges office it works it's way back down to the sheriff's office or the clerk's office. Sims: Sure it does. Boyett: Sure, I'll give you a good example. An officer brings and affidavit for probable cause to a judge. Based on that affidavit of probable cause, the judge issues a warrant. At that point, it is not public information at all. Once the warrant is served, the person arrested, and the warrant returned, the affidavit is public information and can be made available in the court's office. It can be made available in any agency that has access to it. But there are steps that go through there that are clearly delineated and, of course, we go through that all the time. It's just a matter of when that information can be released. But while the character of that is confidential and is a judicial record as well as a law enforcement record, it changes to a public upon service of the warrant and upon the return coming back to the court. We're probably going to have to get a lot tighter about getting a return back to the court and getting that information identified to IT if it's in the computer somewhere. But that's an example of how the character will change. Mann: If you're talking about data ownership, a big question has to be decided. When you say ownership, are you insinuating that the owner of that data is accountable for the integrity of that data? If that's the case then the ownership is transferred once it goes into the database and anyone else had the option of amending that data then it no longer can be owned by the person who originated that data. In which case, I would think that it would become county owned data at that point. Which means that the IT department would be the group who was accountable for the integrity of that data? Sims: Yeah, but then that data becomes not true and factual once it's changed. Mann: That's a possibility, that's not necessarily the case. It's just like a property room. Once a deputy puts property in that evidence or property room, he's no longer accountable for what happens to that evidence. It's the person who has clear custody of that evidence at that point in time. Same thing with out data. Once it goes into the database, if it can be altered by the district clerk, county clerk, the judge's, then we are not accountable for what happens to that data at that point. Now the people who are in control of the access to that ...what can be done with that data once it goes into the system ...those are the only Vol -7g Page as ~ 14 of 27 ones that can be held accountable for the integrity of that data and that would be the IT department. So it becomes county owned data at that point. Sims: Is there a way to determine if somebody does go in there and change the data? Can you pinpoint and say, "Katy, you went in and you changed some information on the data." Caldwell: Yes and no. Audit trails are one way of doing that; however, audit trails are not typically turned on in TSG simply because of the massive amount of audit trail information that is captured. By TSGs own admission it is way to voluminous to really turn on and leave on. The only time you'd ever do that is if you already suspect somebody of monkeying they system and you want to try to catch them Sims: You want to try to catch them. Caldwell: Let me make a couple of remarks if you don't mind concerning IT's data ownership. It was unfortunate that I didn't make it much more clear in our February 17`h meeting that ...and it was unfortunate too my use of Brazos County Commissioner's Court fairly liberally throughout here which by itself suggest that I was trying to gamer more data ownership for myself and Commissioner's Court than I ever intended. You find further down in the document that IT is really going to be playing a role of data custodian. No data ownership at all. Our role is to make sure that it's available for the other data owners and users, doing restorations from tape back up, making sure the systems are up and running and then the integrity of that data residing on the systems is really going to be everybody's responsibility; which is why I stated earlier in my opening remarks that we need a security training program in place. We need everybody in the county to be aware of what role they play and why is it important that when they calls from strangers about the systems and who your boss it...why should they be wary of potential social engineering attempts and that sort of thing. IT does have a responsibility for integrity which is one of the bigger reason for my push to get this sort of programs in place because once we give somebody access in the sheriff's module, without auditing trails, we have no way of verifying that people are doing what they are supposed to be doing. Such as accessing only the data that they are supposed to be accessing, not maliciously modifying that data when they're not supposed to. So our best hope of assisting and maintaining the integrity and the confidentiality of that data in conjunction with our efforts to keep the system up and available is to try to get executive management to and recognize the importance of these sorts of policies and practices and then help to insure that everybody is following the practices. Mann: I understand what you are saying but if data goes on to your server and you have the keys to allow other people to go in there from other departments and Vol ~ 9- Page 9a7 15 of 27 alter that for good reasons or whatever, then it becomes county owned data at that point in time. Because the initiator of that data no longer has control of what happens to that data. Without having control of the integrity of that data they don't own it, because it's just going to be something different at some point in time. Caldwell: I'm certainly not trying to shirk responsibility and so if in the end it's clear that IT is playing more of a data ownership role in those scenarios... and one of the responsibilities of that data ownership is the protection and confidentiality ...we'll do it. I would try to point out too that we have kind of confined our discussion here to ownership of justice information but remember, we have got human resources data, we've got financial data, we've got health records, and we've got Road and Bridge as a good example. Also remember that after identifying data owners the next step is to classify that data in terms of mission criticality and confidentiality. That brings us back to some remarks that I made back in February and that is to take Road and Bridges as an example; Road and Bridge has information that may or may not be public. Maybe we should or should not be trying to keep that stuff confidential and not be leaked out. I'm going to assume for a minute that it's not confidential; if the public needs it, we can get it to them. Sims: I think that's a poor use of departments. I don't think that anything with Road and Bridge is confidential. Now health department I could see. Caldwell: But it may be mission critical though. Cauley: Maybe I'm on the wrong track but I think the IT department should be the custodian of the information that the county has. I also think that the IT Department should be responsible for the integrity of what is put into these records. But we are talking about ownership and what have you, to me I think that sometimes we may have to do that on an individual basis. There are some things that we know automatically but I don't think we can't make this a broad policy and say this is this or this because circumstances can sometimes determine what is and what isn't. Mallard: Who's going to be the gatekeeper? Cauley: Well, I don't know. Mallard: I appreciate you volunteering. Mann: Right. And that's the way it's going to have to be. The wording is if such and such exists then this... Vol $ Page aa9 16 of 27 Cauley: I hate to say it like this but it appears to me that with a lot of this stuff there is going to be a lot of if, ands, and buts. So a lot of time we're still going to have to get some clarification relative to whether this information needs to be public or private or whatever the situation might be. Mann: There are a lot of things that are thrown on the server that may not necessarily need to be there and will take away the argument that IT might have some role in custodianship of it. Memorandums and things like that. If they are on the server when then IT certainly has access to it but some kind of problem employee could go in there and tamper with that so we may have to revisit what actually goes on the server and can potential put IT in a custodian situation. I don't know if Eric's desire is to get through this workshop ...a hundred a something pages ...and come up with a policy by the end of it but I don't think that's going to happen. Is there not an IT committee standing right now? I know we had one when we... Sims: Did you just volunteer? Mann: No sir I did not. Caldwell: You actually kind of touched on something that I was saying that might kind of wrap this up. There is a justice steering committee and that pre-dates me but it's my understanding that the primary purpose of that was to guide the effort to move to TSG. Now I was thinking that it's probably appropriate, certainly for the process of identifying data ownership and maybe even go through the minutia of developing the procedures to support these policies to put together just such a committee. Either change the role of that or broaden the role of that existing committee or put together a completely different committee but I think that you are on the right track. Because this is well beyond... Mann: You can't handle this in a workshop, it's too big a project and I think if you charge it to a committee one of the first things you're going to have to do is identify these contentious issues or concepts and get those resolved through reporting back to the elected officials and department heads and then hammer out a policy proposal to present in a workshop where the court knows that everyone has input on it and this is presented for them to rule on. Cauley: Let this committee make recommendations to the Commissioner's Court for adoption of what they have gone through would be proper and in order. Boyett: That steering committee was made up from representative from each of the departments as well as elected officials and it was utilized on into the software group program to discuss and recommend additional changes and stuff as they were allocated and whether it was thought that we should Vol IS Page 62 02 9 17 of 27 expend county funds and make a recommendation to the Commissioner's Court to go on. The committee still exists; Judge Langley is the chair of it. I don't think we've met in the last six months, as such, but I think you're really on the right track there. The issues can be identified. What is going to kind of flower it a little bit is going to be some of these issues are not set in stone, they are going to be transitional. They'll go from a status A to a status B to a status C and frankly the data ownership will probably transition as well. I think the committee is probably a real good solution and I would urge you to consider that. We may want to re-look at who's on it. It sort of evolved in many cases where an elected official was on that committee and substituted somebody from their department over time to do it. It's probably certainly time to re-look at the membership of it and this is a worthy project for it. Sims: It may be time to freshen that committee up too. Mann: I would suggest that you would want to make sure that ever elected official has the opportunity to have representation on that committee, just for some of the things that Buddy Winn has pointed out on page 11. He addresses some very valid points that I think every elected official might have those same concerns. It may be a fairly large committee but I think elected officials at least need to have the opportunity to have their office represented. Mallard: And whoever ends up being the gatekeepers on person in charge of it then they're going to want to limit access to other people that have the opportunity to change information because they're the ones that accountable for it. Whoever you do, somebody's got to be in control unless you can make the information not alterable... where you can't delete it. Boyett: That would total defeat the interoperability that we have among the departments and agencies that feed data into the database. At some point you have to give up some rigid control in order for it to be able to be utilized by more than one agency or department. Mallard: I know with the system we had in the insurance office that was a concern ...who did it. But every time that record was touched, it recorded who it was or at least what machine and somebody had to have a password to get into that machine so it wasn't perfect. It didn't actually identify the face but it identified the computer and the person that had the password or you could be on any computer with a password. You could put a note in there about what you did. Now if you were going to bad things, you probably weren't going to put the right kind of note in there but, in general, just told everybody, "We accessed this and we did X." And it logged in who did it. Boyett: As Eric points out that while the software group overall program has the ability to do it, it is such a colossal data stream that I don't think we have Vol ? $ Page 900. 18 of 27 enough equipment to hold all of the data. Whatever feed we operate at, I think would be critical particularly to those agencies that are not here in the courthouse or in this vicinity that depend upon data transmission over other lines. Mann: If the court decides to go the committee route, I would think one of the things would do would be to look and see what other counties have a security policy in place. Sims: Yeah, and who they have on their committee that has put those in place. Yes Michelle. Meade: Let me further muddy the water by bringing up the topic of emergency management and the projects that we work on with all of our surrounding jurisdictional entities as well as the six additional counties. When we talk about access of information, that's huge. That is especially problematic for us during an emergency response because we have a lot of people coming into the EOC, accessing software programs that are password protected and that type of thing. So we understand that there are some real challengers in setting up a policy that would be open enough to allow activity on an ongoing basis as well. Sims: Could you have a separate platform that could be used. When I say platform, say we go into an emergency management or we activate the EOC and we've got other counties that are working with us and as we talked about this morning; the Red Cross, The Salvation Army and all this good stuff, could there not be a platform put in place that it doesn't go any further than that? You talk to one another by way of this platform but it never spills over into Brazos County, i.e. our system. Meade: Well, I guess that is possible... Sims: You understand what I'm saying Eric? Caldwell: Who are you asking? Sims: Either one. I'm just saying; can that be put together? Caldwell: Yes that's certainly one possibility. Another possibility that we've already discussed would be the solution to a similar situation in which Karen McQueen has equipment that elections workers use at election time. That's county owned equipment but these people are apparently not county employees and that's now kind of a cloudy issue ...in any case, let's assume for a minute that they are not county employees but they are using this county owned equipment; which in these drafts is not prohibited. As I've Vol -79 Page ~ 19 of 27 pointed out, there will always be exceptions to these policies. I think what's more important than trying to refine the policies so that it takes all of these exceptions into consideration, you simply adopt the polices and then if there are exceptions that are known and are understood and are required, we simply write that up as a known accepted exception and that becomes a permanent part of all future audits. So your audit comes through and says, "Well now here are your policies but here is where you are deviating from your own polices. You've got non-county employees working on this election equipment." And you pull out this written exception and you say, "Well yeah, I understand but remember as an addendum to these policies we've got this known exception where at election time these election workers are not going to be county employees but they will be using this equipment. And that's ok, because that equipment is never networked into our network." Mallard: Or it has a password where it can't get beyond a certain section. Caldwell: Similarly, given the duty of the software and equipment that emergency management maintains, typically in a non-emergency situation it's not used by anybody other than county employees. But that it's understood that in the event of a major disaster and our EOC has to stand up, that equipment will be used by a non county employee. That's just a written exception. That way you don't have to try to refine these polices to try to take into account all the minute exceptions. Remember the policies are just the higher level statement. Granted, having said that, some of these policies in here are closer to standards than policies. There's a lot of procedural information that's in these polices. Email is a good example. We go to great trouble to explain that your password can't be your pet's name; it can't be your home address. That's more procedural in nature than it is just a higher level statement of managements' appreciation that email is something that needs to be secured and to that end, email passwords or password management is an important part of this security program. Mann: I think what Michelle has alluded is this is an important project and needs to be done, this is a very complex project and there are just a lot of things that we may not have thought about at this point in time that could be effecting different levels. Sims: Well, hopefully, we don't get into trouble before we get them amended where we know where we're going and maybe some type of firewall set up where they can't get into critical information that they don't need and we don't need to be divulging. Mallard: So Eric, does that give you some direction or what do we need to do. I guess we have need to have a committee to look at this or...? Vol 7 Page 930Z 20 of 27 Caldwell: Well, I'm really kind of looking to you. Now if you want me to recommend a course for going forward, certainly the creation or the refimnent of the existing judicial steering committee and revision of their expectations including responsibilities is certainly a good step. My only question is whether or not we should try to adopt the policies and then give those adopted polices to this committee to pour through and make any recommended changes before they go on to the onerous task of data ownership identification and procedure development and that sort of thing. In other words, do yall want to give them an adopted set of policies and say, "Here's what we've adopted, pour through these and come back with a recommended changes." Or do you want to give them these drafts and say, "We still haven't made up our minds and this is still all up in the air.", or whatever it might be. One of my concerns is that things will start to stall out. Again, one of the purposes of the policy is just to make it clear that executive management appreciates the need for this sort of program. You adopt that policy and that policy... certainly that master document that states that the data is going to be classified and data ownership is going to be delineated. That master policy gives somebody like a committee the authority to go forward and institute this next step of data classification, data ownership identification. Cauley: I would like to say that I think that we should reinstitute, rejuvenate, or whatever the committee and give them this draft. Because a lot of times, once you so something it's very difficult to change it. Let them do this and let the Commissioner's Court put a time limit on this rather than just having people just dragging their feet and, "When is gonna be?" "Well they didn't set a time." Set a time limit. Forty-five days, within forty-five days or thirty days or twenty days or whatever that this committee would have met however many times they need to meet and come back with a recommendation to the Commissioner's Court as to what needs to be done relative to this draft. We all know that it's important. Our risk manager said that this is some of things that we are being asked. Our department head is saying, "Hey, this is something that we need to do." So it's urgent. Recent events have shown that we need to have something more than what we have in place so my suggestion would be to reinstitute and recharge the committee, give them this draft information, and set some time lines and constraints and dates ...not constraints, dates ...on them to come back with something positive. Sims: How many is on the committee right now George, do you know? Boyett: Oh, it's a couple of dozen, at least. I mean we've had to meet in the 85`h district court room because we couldn't all meet in here. To me, it's quite a large committee with multiple people from some of the offices. Sims: Who are the most vocal? Did we have a core group that might be...? Vol ~ t Page a33 21 of 27 Boyett: We did have a core group and Judge Langley notified us by email about the meeting times and then interacted with IT. Anderson: But I don't think that committee had representatives from all the departments. I think it was the criminal justice are the ones that dealt with it. I'm not sure that you got in to personnel. Boyett: Yeah, he did. Anderson: Risk management, auditors... Boyett: The auditors were there. Meade: They were against. Anderson: Road and Bridge. It may take a new committee... Sims: That's what I'm asking for, Carey, we may have to reconstitute. Put another one in place. Peters: Let me ask a question Eric. This is a privacy or protection policy, are there things that need to be implemented... let's take ownership out of the question right now because it's going to take a while to work through that thing, but are there things in here that really need to be implemented to protect ourselves? End of CD 1 CD 2 begins mid-sentence. Caldwell: You have to have someone a capability and can actually get out there and get it done, bridge these two networks. So, in summary, the risk of that happening is probably small enough that if we get all of our ducks in order on this wireless online legal library and want to bring in the media for a big event and go ahead and go public with before we get these policies in place, we're probably ok. But in the long run these polices need to be in place and that information needs to be disseminated to the end users and then the end users need to be trained on the purposes of these policies to prevent this from happening in the future. But again, the long answer... that was the short answer ...I think we can do it all at once. I liken that to one of the biggest problems that I see that we have with TSG; in a nutshell, the majority of problems that we have with TSG stems from the fact that the underlying database was not modeled all at once. This is an artifact from the old practice Vol 78 Page 1),34 22 of 27 of having these various departments function more or less independently with little silos of data so that the jail module was kind of built around this business process of booking inmates into the jail. And they modeled that data for that system. Well, some point later they decided, "Well, let's go to the next step and let's build the sheriff's package and we'll try to stitch the two together. And so we'll design the sheriff s package, more or less, in isolation over here ...we'll model that data." Then they stitched the two things together and we came up with this Frankenstein known as TSG. What I don't want to happen is that we try to adopt one policy and then adopt another policy because if you're read these at all, you'll notice that these policies reference one another quite a bit. And so, it's really going to be difficult to try to adopt a single policy without adopting the entire program. Not just the policies but the procedures and the standards and the auditing the, the whole kit and caboodle. I know that's a big chunk to bite off but I think that's the best way to go about doing it. Peters: I just want to make a comment on it, I think that is a subject for another workshop... the TSG system ...but that said, if we were looking at adopting and we have ownership addressed here currently as Commissioner's Court owns it and that's not correct and we're trying to pass something ...if we want to pass the whole documents and then go back and re-work it...how do we leave it? I mean if we leave in there that ownership belongs to the Commissioner's Court and that's not correct and we know that right now as we sit here that that's not correct, is that what we pass? I mean if we decided... Caldwell: Well that, of course, is your decisions but I would think it would be easier to give the committee and adopted policy and say, "Listen, here's the policy..." Peters: That's what I'm asking though. You say give them an adopted policy, ok... Caldwell: Say, "Now here's the adopted policy. Now we recognize that data ownership is something has got to be addressed and because of that, this adopted policy needs to be tweaked and we would like for this committee to come back and give us recommendations. And they come back and they say, "Well, here's what we recommend on defining this policy." But that gives some stability and that really gives them kind of a launching point rather than this massive compilation of various thoughts and ideas... some of which are not really appropriate for the higher level policy itself. They were remarks that were more appropriate for the standards and procedures. We haven't gotten to them yet but specifically I think it was the Health Department off the top of my head that had some recommendations or had some comments that are more appropriately directed toward the standards and procedures that have to be developed as one of the next steps. Remember, these policies are really meant to be a higher level expression of managements understanding of the Vol 7 Page 625 23 of 27 need to adopt a better information Security Program as a whole. We have to refine this and we have to get down to the standards and procedures. Mallard: My only concern is that if we adopt this as it is today, knowing that it's going to be changed then how do we try to enforce it if we know that it's... Caldwell: Well, again, enforcement can't happen until you've gotten the procedures in place and it really can't happen until after we have developed the security training program and carried people through it. Some sort of training to explain to them what is the purpose of these massive policies. To date we have had a total of nine pages of what could possibly be construed as information security related polices for Brazos County. Nine pages. Which is not nearly sufficient. So the end users have to be trained on the purposes of these policies, the ramifications, they have to be explained, we have to explain their roles and their responsibilities. So you really can't hope to enforce these until after all of that is done. Again, we have to develop the standards and procedures and guidelines before we can expect people to start following the procedures. And you really can't do that until you adopt the policy. I know it seems like a catch 22 but it's just industry standard practice to start with policies that give direction to people like IT that have to go forward and start construction of the standards, procedures, and guidelines in the security program. Mallard: That's hard for me to want to do. Mann: We are talking about elected officials. There are some concepts here that are going to have to be worked out in the committee if you go that route. I don't know where the county is on their policy revision is that they are doing but I know in the sheriffs office we have a policy that deals with conduct so we have some protection there in terms of inappropriate use of these systems. Just to go ahead and pass something just to make sure that we have something there is a mistake, I think. Caldwell: That's fair enough and I'm not really adamant about it. That it may not be the way, really, is fine. I am concerned that it might stall out but if that's the route you want to go that's fine. Mallard: We just have to keep pushing it to make sure it doesn't get stalled out. Caldwell: I would ask though, and maybe it's not appropriate but if another committee is going to be formed or if this current committee is going to be restructured, I'd like for you to consider directing this committee to approach other topic beyond these policies. If you're going to restructure... number one; rename. Because Justice Steering Committee was really conveys that it's concerned with Justice Information Systems. Remember, these policies cover Vol 7 8 Page 24 of 27 everything. Justice is a big part of it but so are financials and health records. So if you create a new one, give it a new name. If you restructure it, rename the existing one. Mallard: It should just be the computer policy. Caldwell: Well, actually, what I was going to ask is that you consider creating just and Information Technology Steering Committee and give them a little bit broader responsibilities than just working on these policies. For example: IT is currently... has been... executing expunctions of records out of TSG. Now, Mark Hamlin and I and others have discussed this in a couple of meetings ...one of which I think Mr. Anderson attended. It is my hope that the responsibility for actually executing the expunction of these records can be returned to the various departments that create and maintain these records. Which immediately opens up this issue of dead ownership; I mean who's responsible for it. In this case, I think it's pretty clear cut because records have to be deleted out of specific modules in TSG and so I think it's very clear which department is going to be responsible for that. Boyett: What Eric is saying can be simplified to say that if some record is going to be expunged, which mean total obliterated an action has to take place in a court. One of ten courts. Surprise, surprise. All five of the JP courts have expunction privileges under different levels. But that means it's got to come from the court. There is no reason why it shouldn't be done by the court other than the fact that the software groups program doesn't allow it at this point. But what he's saying makes a lot of sense (overtalking). Sims: Is there a policy on expunction now? Caldwell: Just a real quick point of clarification. The TSG does allow that to happen. In fact we have already had two meetings and that was one of the many topics we explored. First of all is it important that it be consolidated under one person for concurrency sake? Is it important, for example, that the sheriff's module record be deleted before the district clerk's module record be deleted. Because if they're done out of order maybe one of them gets orphaned out there and gets hung up in the system and fouls the system up. We've explored that. The point of all this is that I think we're ready to move forward and hand off this responsibility back to the other departments. But when I took over the directorship out there, I inherited this responsibility for executing these expunctions and one of my staff members has been doing that for some time. But it came to light that it was important that we look at handing that back over to the owning departments when my staff member went home and had a baby. She was off FMLA and these things started stacking up and the next thing you know we were getting calls, "Why is this happening." But in any case, if this committee were charged with looking at Vol 7 9 Page o2 3 7 25 of 27 that sort of thing as well, that would help me...certainly if they are in agreement with me to champion my cause in giving that responsibility back to the owner departments. Sims: Big problem with some of that, and I'm going to speak from personal experience and Rod knows this too; somebody's got to be responsible for open records request and we can't have every department out there handling their own request from the news media. Caldwell: Right. Well now this expunction is not mandated but it really doesn't have anything to do with... Mallard: Those are records that are mandated but the department as to deal with their own records. Caldwell: In other words, currently that responsibility resides over at IT. There is no statutory mandate. There's no software requirement. There's no business practice requirement other than the fact that... Sims: Yeah, but you weren't speaking just about expunction, you were speaking about the whole record system within a department. Caldwell: No. No. No. I'm talking about ...in this particular case, it is my hope that you may give this committee the charge to look at my idea of handing this expunction responsibility back to the owner departments. Just the expunction responsibility. Ok? Sims: Ok, what... Caldwell: And then remember too... Sims: I've been through this once. That was scary. Caldwell: And remember too, one of the things that we have not...one of the things that these policies have not even tried to address is things like the business continuity planning. As you well know, if we are going to start replicating systems at remote sites in the event that our primary servers go down, we can switch over to that remote site without skipping a beat. That's going to cost money and that's going to require planning. And so a committee such as we are discussing might be... Sims: I'll get with Judge Langley, ok? And I will find out who is on the original committee and we may sit down with a core group of maybe ten and say, "Hey, who needs to be on this one? Who needs to remain on the criminal justice side of this?" And we'll get some names within the next week. Vol "7 Sr Page a38 26 of 27 Gallego: Judge, I probably have a list but it's not an original list. Sims: Yeah, but if you don't mind, let's give Judge Langley an opportunity to get through this next election. Ok, because April the 11`h, he's got one. Ok? But I will talk to him before then. Caldwell: I will be happy to let somebody else take a look at these policies for a while. Sims: Ok. Does that sound good? Caldwell: Yes. Sims: All right. We'll get it... Mallard: But I would say that I would rather we go and we start a new committee. Sims: Well I think you're right. We make pick and choose some of those off the old committee... Mallard: Oh, I hope there are some. Sims: ...because they have some background. Mallard: Yes. Sims: Ok. Yes sir. Boyett: My whole purpose in coming here today was to make the next comment. I want you to understand that I say it knowing that people that work for Brazos County. We've got bright, intelligent, dedicated employees. Now understand this, it is my personal opinion and that of several others who have read the draft and everything that we haven't got a snowballs chance in hell of educating our general employees of a document of this size. It must, must be reduced to a synopsis document or one that we could teach readily to everybody and at some point down the road perhaps teach supervisors a little bit more detail and I think we're probably going to be at the department head level or maybe the manager level to be able to teach and feel confident that everybody can inherit it. I support the effort to develop a security policy. We absolutely have to have it but we have to recognize that we can't stuff this down every employee that we've got. Sims: Well said. Yes, you're right. And there's going to have to be an ongoing training session. As you loose people within each department, they are going Vol -79 Page 0-2,39 27 of 27 to have to be hand carried down the road by your supervisor. Whomever is the "expert" out there. Caldwell: Right. Sims: Ok. All right. Anything else? I will adjourn this workshop. Thank yall for coming. Eric that was well done. Thanks George, I'm going to be getting in touch with you too because I know... End of tape. Page a IJD Vol V' The foregoing minutes of the Commissioners Court Workshop held March 28, 2006, have been examined and approved in open Court this the day of J-uyia~ , 20Q( , in Bryan, Brazos County, Texas. Duane Peters Commissioner, Precinct No. 2 -1'YA'q , WL,& zj ft C arey C ley, Jr. 6 Commis toner, Precinct 4 Attest: aren McQueen County Clerk Vol 7 9 Page a ~ 1 ~~,x Lloy Wassermann Commissioner, Precinct No. 1 R - Malla Commissioner, Precinct No. 3 BRAZOSCOUNTY COMMISSIONERS COURT ~g te DAY OF J,&z 20 06- AT (XM/PM ~4)40~/ ~k7,3 ~ Name Organization r" Z 4U 0 614 VOL'79PAGE L24a So BRAZOSCOUNTY COMMISSIONERS COURT 9 t' DAY OF 2000 AT lo:ao Name Organization 1-la4cza, VOL -7 g PAGE 13