HomeMy WebLinkAbout2006-03-28-10:00AM-WORKSHOPBRAZOS COUNTY
BRYAN, TEXAS
NOTICE OF MEETING
b E1,i~ 2t; A tr 12
CLLR!{
~ 4.7[:XAS
21 ~111
BRAZOS COUNTY COMMISSIONERS COURT
WORKSHOP SESSION
THE COMMISSIONERS COURT OF BRAZOS COUNTY WILL MEET IN
WORKSHOP SESSION ON TUESDAY, MARCH 28, 2006 AT 10:00 A.M. IN THE
COMMISSIONERS COURTROOM IN THE BRAZOS COUNTY COURTHOUSE,
BRYAN, TEXAS.
1. Call to Order.
2. Review of Brazos County's computer and security policies and procedures.
3. Adjourn.
The Brazos County Courthouse is wheelchair accessible. Handicap parking spaces are available. Any request
for sign into titive services m6t be made two business days before the meeting. To make armagements,call
(979)361-4"2
VOL 7.9 PAGE
- Brazos.:0Q*jy70qur1hoU" 300: East 2d St 9 BOOM, Bryan, Texas 77803 • ; Fax: (979) 823-8993
COMMISSIONERS' COURT
WORKSHOP SESSION
MARCH 28, 2006
The Commissioners' Court of Brazos County, Texas met in a
Workshop Session in the Commissioners' Courtroom in the
Courthouse in Bryan, Brazos County, Texas, beginning at 10:00
a.m. on Tuesday, March 28, 2006, with the following members of
the Court present:
Randy Sims, County Judge, Presiding;
Lloyd Wassermann, Commissioner of Precinct 1;
Duane Peters, Commissioner of Precinct 2;
Kenny Mallard, Commissioner of Precinct 3;
Carey Cauley, Jr., Commissioner of Precinct 4;
Karen McQueen, County Clerk.
Attached is a list of the citizens and officials in
attendance.
Attached is a transcript of the meeting.
Vol 11.9 Page c)- 13
I of 27
BRAZOS COUNTY COMMISSIONERS COURT
Computer Security Policies Workshop
March 28th, 2006
Sims: Ladies and gentlemen, thank you for coming to the Commissioner's Court
Workshop Session. We will meet in workshop session on Tuesday March
28`11 2006 at 10:00 a.m. in the Commissioner's Court Room in the Brazos
County Courthouse. First item on the agenda is: Call to Order and the next
item on the agenda is: Review of Brazos County's computer and security and
procedures. Are you ready Mr. Eric?
Caldwell: I am.
Sims: Please proceed.
Caldwell: Ok. Thank you. With your indulgence, I am not going to strap on my jacket.
I'm told it's just me but I'm hot so I'm going to stand up here with out it.
Well I have given each of you and outline of the things I'd like to try to cover
today. So I would just like to spend five or ten minutes on the first six bullets
and then the real work is going to be in bullet number seven down as we go
over the draft policy processing detail. First of all as you recall on the 17th of
February we had our first workshop on these draft polices. It was not as well
attended as perhaps it should have been, never the less what I did in that
workshop was to go over what I believe was the most pertinent rational for
adopting an Information Security Plan as a whole beginning with the
Information Security Policies. And I did what I thought was a pretty good job
of justifying that really without any reference to any statutory authority or
mandate to do so and without any direct references to industry best practices.
But what I did was, for those that were present; I built a case for adopting an
Information Security Program and adherence to that program on an on-going,
long term basis. The transcript and the recording of that meeting is available
for anybody who wants it. Feel free to ask me. At that meeting, it was
decided that the best way to proceed was to circulate those draft polices and
obtain feedback from other department heads and elected officials and so to
that end, those were circulated and I have gotten feedback from a handful of
people and will go over those responses again in more detail in just a little
while. Given the responses that I received to those policies, I think it's
probably important that I stop and explain the purpose of the policies, the
supporting standards, and the next steps that we have to go through in order
to achieve these goals. So with that, let me just define polices for you. The
International Organization on Standardization defines Policies as follows:
Vol 7 9 Page
2 of 27
"The objective of an Information Security Policy is to provide management
direction and support for information security." The State of Texas,
Department of Information Resources writes, "The Polices are management
instructions indicating a course of action, guiding principals, or appropriate
procedures that is expedient, prudent, or advantageous. Polices are high level
statements that provide guidance to workers who must make present and
future decisions. It is also correct to say that Polices are generalized
requirements that must be written down and communicated to certain groups
of people inside and in some cases outside the organization. Although
Information Security Policies vary considerably by organization, they
typically include general statements of goals, objectives, beliefs, ethics,
controls, and work responsibilities."
So policies then are a high level statement of managements' beliefs and goals
and in this case beliefs that the information that resides on our systems is a
business asset that really needs to be protected and we need to try to achieve
maximum confidentiality, availability, and integrity of that data.
Sims: Tell me what page you're reading off of.
Caldwell: Well this is just my notes. I'm just trying to lay some groundwork.
Sims: Oh, ok. This is verbiage only.
Caldwell: I'm just trying to lay some groundwork for you in large part to try to address
some of the concerns that were given to me as feedback. Remember what I
had circulated was just these higher level statements of executive
management belief that they needed to undertake this program to protect their
assets; in this case, information. It won't be until we get to the next step
which is to further refine the standards and procedures that we have to follow
in order to adhere to these polices that some of the comments that I received
are really going to be pertinent. So again, standards are the mandatory
activities, actions, rules, or regulations designed to provide policies with the
support structure and specific direction they require to be meaningful and
effective. So in a nutshell, you start from the higher level policy statement
and then you start working your way down and refining those practices that
you must follow in order to adhere to your own policies. A good example
might be that if information custodians in policy are responsible for
providing a safe and secure processing environment which information can
be maintained with integrity. A supporting standard then; which is more
refined and much more direct, might read that the custodian of information
processing systems must use X brand of anti-virus software to insure that the
system is free from destructive software elements. And then you can go
further to define procedures and those procedures might state that every new
PC that is rolled out into service must have this software loaded and it must
Vol 7F Page a 15
3 of 27
be configured with these particular parameters. So you can see as we go
along that we have to get more and more refined.
So again, one of the things that I did not try to address in that previous
workshop was that any authority or any mandate to do this. What I did was I
tried to deliver to those present rational for adopting this program on the
merits of the program alone. So given some of the remarks I received, I went
and started trying to research ...in fact, is there any mandate or any statutory
authority to undertake this program. As it turns out it doesn't appear there is.
Now while Chapter 2054 of the Goverment Code also known as
Information Management Resources Act creates The Department of
Information Resources and it declares that information and the resources
possessed by agencies of state government are strategic assets belonging to
the residents of Texas and must be managed as valuable as state resources.
There is not similar, chapter in the Local Government Code. So there's no
statutory mandate that we undertake this. And so we kind of fall back to
adopting such a program based on its merits only.
Well, in such a case you might wonder where we begin. Well fortunately, as
I've pointed out to you on several occasions because of the draft policies and
because of the security audit that we undertook early last year and for other
reasons; there is an international standard on information security. It is the
ISO17799. Now ISO is the International Organization for Standardization
and together with International Electrotechnical Commission formed a
specialized system for worldwide standardization. National bodies that are
members of the ISO and IEC "participate in the development of international
standards through technical committees established by the respective
organization that deal with particular fields of technical activity." ISO and
IEC technical committees collaborate and fills a mutual interest other
international organizations governmental and non-governmental liaison
with ISO and IEC also take part of the work. So the International Standard
17799 was initially prepared by the British Standards Institute as British
Standards 7799 and was later adopted under a special fast-track procedure by
the Joint Technical Committee ISO, IEC Joint Technical Committee won
permission to (inaudible) parallel was approved by national bodies of ISO
and IEC. So what does all that mean? Well again, in a nutshell, at an
international level, bodies have participated in developing this standard for
securing information as business assets and trying to achieve this goal of
maximizing the confidentiality of the data, the integrity of that data and the
availability of that data to those who are authorized to use it and need to get
to it. So again, going back to this ISO17799 standard let me read for you their
definition of, rather my paraphrase, interpretation of their definition of
information security.
Vol -78 Page a hP
4 of 27
`Information security is the protection of data from a wide range of threats
that could lead to accidental or (inaudible) disclosure of confidential
information, unauthorized modifications, or destruction sensitive or mission
critical data or the unavailable of data, possessing systems and other
information resources. The purpose of information security is to insure
business continuity, minimize business damage, and maximize return on
investments, efforts, and business opportunities and promote information
sharing. Information security then is the preservation and maximization of
confidentiality, integrity, and availability.'
So kind of looking forward then, let me just briefly kind of cover what the
next steps of this bigger program is going to be assuming that we can get
policies adopted. Once we get these security policies adopted, shouldn't the
next steps that we have to undertake is identification of data owners.
Identifying who owns the data is going to be a necessary prerequisite before
we can start classifying this data and determining how much risk we face in
maintaining this data on our system without security pieces in place. How
mission critical that data is and, again, how confidential that information
needs to be. Is it nonpublic customer information such as health records or is
road and bridge work history records? So given the kind of data, we're going
to have to classify it into a number of different categories like business
criticality, confidentiality, and things of that sort. So to do that, we are going
to have to identify various roles and responsibilities. Who's the data owner,
who's the data custodian, who are the various intermediates between the two
extremes and what roles do they play, what are their responsibilities? Again,
we are going to have to work on classifying the data as I mentioned
previously, we are going to have to develop the procedures that we must
follow in order to adhere to these polices. It will be those procedures that we
are following to adhere to these polices that are then auditable. We can audit
ourselves to verify that we are following these procedures, again, to adhere to
our own polices.
We also have to develop a training program. It is important and I pointed out
in the last workshop that part of these policies includes a security training
policy. It's important that everybody understand how critical their role is in
insuring the security of this data; all the way down to the clerks who are
doing data entry at terminals, day in and day out.
Finally, we are going to have to commit ourselves to auditing. The practice of
auditing ourselves not only in house but also having external auditors come
in to audit our adherence to our procedures. Our following of these
procedures in order to adhere to the policies.
With that then, let me stop and point out that in everybody's package there is
a little three page piece that has... should be the only piece that has a
Vol 7 9 Page a 17
5 of 27
statement with it. Probably at the very front of your binder. At the risk of
further aggravating the people's reservations about the lengths of these
policies, I have ...in thinking about the responses that I got to those drafts, it
was clear to me that I kind of put the cart before the horse. I started looking
at all the minutiae and I was building these more detailed, supportive policies
before I had put together the master policy. So this master policy then, you
will see, summarizes again what I would hope you and the other elected
officials as executive management would recognize as appropriate policy to
adopt. I'm hopeful that we can all agree that this document right here
summarizes at the highest level your understanding the importance of
adopting this security program.
With that then, I am down to bullet point number seven and prepared to start
going over the initial drafts in more detail. I brought my laptop and an
overhead projector. I've got enough printed copies.
Mallard: Where is bullet point number seven?
Female: The front page.
Caldwell: Did you not get this sheet here?
Cauley: No we don't have that.
Caldwell: I'm so sorry. First of all let me apologize to those in the audience if your
copies are black and white, I had just enough time last time to crank out copy
number six in color and it was time to move on and get these other knocked
out. The modification to the original draft is there, although it is in black and
white, they are the portions that are underlined. Ok. Now this is where the
fun begins; plowing through this. I don't know of any better way to this other
than to try to go through it one by one. It will be somewhat time consuming
and I'm certainly open for suggestions. We can try setting up the overhead if
yall feel like yall will be able to see it up here better. It would be easier for
me to kind of click through it where it will carry me through these changes. I
can just jump from the next change to the next change to the next change.
Mallard: That's good.
Caldwell: Fair enough.
Sims: Rod, I think the biggest problem is to determine who owns these records.
We've already been through that several times here in the last six months.
Anderson: I think that it will be helpful to define that not just for this purpose but for
other public information.
Vol ~ t- Page a le
6 of 27
Sims: Absolutely. Absolutely.
Boyett: Is there a question as to who owns the data?
Conner: Yes.
Sims: Yes.
Boyett: My last count, there was 26 elected officers in Brazos County. And I think
everybody else is an agency that provides some service to those 26 agencies.
Is that correct?
Sims: That's correct.
Boyett: Service is the key word, I'd sure like to see it emphasized.
Sims: We've got 26 independent entrepreneurs that work for the citizens of Brazos
County.
Boyett: Amen. Right.
Caldwell: Ok, you're going to find that on all of these polices I have gone back and I
have added references to the IS017799 standard. So in each individual policy
that will be the first modification that I introduced form that original draft on
February 17`h. Now for those of you in the audience it may be easiest to
follow along if you watch down here in this lower left hand corner of the
screen on the page that I'm on. I believe that corresponds to the page name in
the lower right hand corner of the hard copy.
Mallard: So all of these things are going to be essential to this IS017799 section so
and so but what is that?
Caldwell: The ISO17799, again, it is the International Standard Code of Practice for
Information Security Management.
Mallard: If we're all to adhere to it, shouldn't that be said or are we just supposed to
know what that is or does it matter?
Wassermann:
Or is it defined already?
Mallard: I don't know what it is.
Caldwell: I guess I'm not following your point.
Vol -79 Page C~ 11
7 of 27
Mallard: Well I mean we're pledging allegiance to the IS017799 and I don't know
what it is.
Caldwell: I guess I'm not following you Commissioner. This international standard sets
a benchmark so that if you want your information systems resources
protected as business assets and you want to do what is reasonably within
your power to protect those, this standard code of practice is a goal to shoot
for. Maybe it would help for you to actually see the standard yourself.
Cauley: That's what they're saying, we don't what it is.
Mallard: I don't know what it is. Maybe it's something that we can not as a county can
utilize. I'm not doubting you, but I just don't know what it is.
Caldwell: I really don't know how more to describe it to you. Again, it's a standard...
Peters: Is it a guideline? Is that what it is?
Caldwell: It's a guideline. Again, it's a just a code of practice that governs ten different
areas of information resources security management. For example, it states
that facilities security is going to be one component of it.
Peters: Who set it up?
Caldwell: It was the International Organization on Standardization, which, again, is a
body that is participated in by technical committees from nations all over the
world. Maybe Bill can explain it better.
Jeanes: It's kind of a gold standard apparently, because there are a lot of underwriters
now with insurance when they start talking about data in the computers and
storage of it and where it's at. It's kind of a standard that's being asked in
some of the questionnaires, "Do you comply with..." Now that doesn't
explain what it is but it tells me that an underwriter is looking at it and that's
kind of a gold standard of..
Mallard: Well, it's just like on item here. `Personal Security' is security in the job
definition and resourcing. The objective; to reduce risk of human error, theft,
fraud, and misuse of facilities. So it's fairly good words but I don't know if
there are some specifics in here but what concerns me is there is some
specifics that somehow are contrary to what county government does or has
to do. I don't know that there are, that's just my concern. I don't see it.
Because I assume my SO with insurance service offices that they did but this
is the International Security Operations. That's the other thing that confused
me as far as the ISO definition. But I don't know; these appear to be very
Vol V 8 Page a a 0
8 of 27
general on the first blush, just looking at these, so I don't know that that is
something that would cause us pain on down the road to want to adhere to
that. You said it is international standard; are government and private
enterprise all wanting to utilize these standards?
Caldwell: Yes. These standards are recognized by national governments worldwide as
opposed to, let's say a consortium of private industry players may get
together and they may set up a specification. I'd have to get out of the IT
world to give you a good clear example but there are soft ware vendors for
example that will get together who may be competitors in the open market
but they recognize that if they can standardize on a particular
communications protocol so that their software can talk back and forth, then
their market share is a little more secure. Because their market share can
continue purchasing their software knowing that their software will talk with
IBM's software and Microsoft's software. So this consortium will get
together and they'll develop this communications standards but it is not
adopted at the international level and is not recognized by governments. For
example, the federal government would never require that their contractors
adhere to this consortium private standard whereas these international
standards carry much more weight and the federal government will often
require that their contractors meet these international standards. I don't know
if that's helping or not. Let me try it this way. There's nothing about these
policies that requires that we even reference the ISO17799...again, you may
remember that I said in my opening remarks that the previous presentation I
delivered the idea of adopting the security program on it's merits alone,
really without any material reference to these international standards. And
again, the State of Texas has their government code, Chapter 2054, which
requires that they adopt this kind of program. The county does not. So I
simply said, "Listen, we can adopt these polices and the program as a whole
based solely on the merit of doing so, and we'd never have to try to align it
with any international standard or any standard for any reason." However,
this is a way of demonstrating that this set of polices is consistent with this
international recognized code of practice for securing your information
resources.
Sims: So basically what you're using this international standard for is credibility?
Caldwell: That's certainly one way of putting it. I keep searching for a...
Boyett: I see a parallel situation here, perhaps a metaphor, i.e. the United States
dealing with the United Nations, we don't always agree with what the United
Nations puts forth. Fortunately, we have a complete veto in the Security
Council of the United Nations and we can slam the door on them. By
reference in a legal document that the Commissioner's Court would be asked
Vol $ Page aa!
9 of 27
to sign and approve; by reference you're adopting that standard. Am I correct
or not?
Anderson: No I don't; I think what Eric is saying is we're going to develop these county
polices and procedures and here is how it does actually comply with the ISO
but we're not actually adopting the ISO, we're adopting county procedures
and he's just referencing in here, I believe, that `the policy is consistent
with.' So we're not actually going out and adopting the ISO...
Sims: In total.
Anderson: Exactly. We're just saying this is the policy and it does comply with the ISO
provision, whatever it may be. Is that right?
Caldwell: That's correct. Now at the risk of clouding things further, I will tell you that
as a long term goal, we really should be shooting for complete compliance
with that international standard. Because that would be a badge of honor that
we could wear on our sleeve demonstrating that the executive management
understands the importance of information residing on it's system, the
importance of securing that information and treating that as a business asset.
And we've gone to the trouble of adopting the policies, practices, and
auditing practices to verify that we are indeed in adherence with those
international standards.
Sims: But that could be set up with or without the international standards.
Caldwell: Again, we can adopt these polices without any reference what so ever simply
on their merit along. You're absolutely right. You may remember that we had
hired Aporia Solutions to do a scan of our network periphery and do an initial
security audit on Brazos County. When I was looking for this security outfit,
I told them that what I would for them to do is grade us on how compliant we
are with this international standard. That's a big mouthful to try to chew all at
once and I understand that this is going to be a long process but if we can at
least set out sites on achieving this goal of compliance with this international
standard and work toward it, we can move forward for a long time before we
get there. But at least we're making progress and if we get there, I won't say
that we're done but there's not much more that you can do to secure out
systems. Now to that end, they did point out in a report that there are a
number of areas where we fall far short of adherence to this international
standard. One of which, again, as I pointed out in the February 17`h meeting, I
don't even try to address in here because it's another large undertaking and
that is business continuity plan. Disaster recovery plan. These policies don't
even touch on that. But that's another big undertaking that we're going to
have to work on. That is what happens in the event that our data center goes
south on us? A tornado comes in, picks it up, and moves it elsewhere. What
Vol '78' Page o2aa
10 of 27
do we do? We've got to work on that. Again, I don't want to bite off more
than I can chew so this is big enough as it is. We get this in place and we can
continue working toward those other goals. So, again, we need not reference
in here at all. You can see that I've worded so that it simply says, "consistent
with". I'm not saying that we are adopting it as our policy. All I'm saying is
that we recognize the merit of adopting this sort of a security program on it's
on. And if we can align it with this international recognized standard code of
practice, all the better.
Well, I'm not going to accept any of these changes yet, we can just bump
through here. This is on page five and let me just jump head first in here.
`Ownership of Electronic Files and Documents', again, as I stated in the
opening remarks, identification of data ownership is going to be a big part of
resolving some of the concerns that have been voiced after circulation of
those initial draft policies. Again, I think that the way that we attack that is to
first define roles and responsibilities; try to identify data ownership but more
than that we've got to identify roles and responsibilities. What is this data
owner responsible for? What role do they play? What about their supporting
staff? What role does the supporting staff play? What roles does Information
Technology as the simple custodian to insure that the systems are up and
running and do data restores from time to time if necessary? What role do we
play? I'll tell you that at first blush, you might take something like TSG as
an example. So here we have this integrated justice system and you might
think of it as the various modules in that system. The criminal case
management system might be thought of as belonging to the District Clerk,
Mark Hamlin and the civil case management system might be thought of as
belonging to Karen McQueen, the County Clerk. But if you actually look at
who all has update privileges in all of these various modules, it is no longer a
clear delineation just down these module lines. So it's going to be difficult.
There's no question about it, it's going to be a major undertaking and it's
important that everybody... all the data owners... understand the reason for
undertaking this project.
Mallard: So you're saying that since its electronic then it won't be owned by the
individuals who are producing it?
Caldwell: I'm not saying anything of the sort. All I'm saying is, I don't know yet. I
don't know how it's all going to fall out. So we have no ruling.... Let's take
the publicly available Justice Web, our criminal records search web site. Who
owns that data? I don't know. I couldn't begin to tell you. Now I will tell you
that I believe it is IT's responsibility to help sort all the stuff out. Hence
you'll find later in these policies that I have included a set of roles and
responsibilities, fairly generalized so you can start to appreciate how many
different roles we have and what their various responsibilities might be. But
again, how the data ownership issue falls out in the end, I don't know. I think
Vol 7 Page ;a3
I1 of 27
we've got opinions from the attorney general and the Office of Court
Administration that makes it pretty clear that if it is email that is produced by
one of the judiciary or his or her staff, that sort of information belongs to that
judge. But again, when you are talking about a record or records in the
Criminal Case Management Module of our TSG system and who owns that?
Who starts that process? Well you have sheriff deputies out in the field that
are responsible for the arrest and that information goes into the jail module
but some of the information... one of the reason of getting this integrated
system is to prevent duplicate data entry. So if you have a deputy out in the
field who does initial arrest and then they book him into the jail and that
some portion of that information ultimately winds up in this court record and
that Mark Hamlin and his staff have to work, have to scan images for, and
that ultimately the court co-coordinators have to incorporate into their court
docket and then the judges and their staff have to work on the sentencing and
whatever it might be; suddenly you've got a number of elected officials that
all have their hands on this one little set of records and the ownership of that
information is, at least in my mind, is suddenly obscure.
Mallard: What was it when it was a paper...?
Caldwell: In the ideal... somebody out here in the audience will tell me no, it's quite
clear cut and here's where we go with it all.
Boyett: No, you're absolutely right, it is not clear cut. The Open Records Act, Public
information is there until it becomes, "...a judicial record." The Office of
Court Administration and Supreme Court is not even sure what Rule 12 says
and I've been to three different classes by three different representatives from
the Supreme Court and they were not consistent. A judicial record is a record
produced by a judge in the course of his action. But within that record,
there's going to be some demographics, there's going to be some information
on the arrest, there's going to be a lot of stuff that comes from other agencies
just as you say. It is not a clear cut situation. A document produced by a
judge in the course of the thing may very well be a judicial record and have
Rule 12 shielding but the data leading up to it that are in other files may very
well be public information. It's not going to be clear.
Caldwell: Let me make one more remark along these same lines. I certainly hope that
this in the end this doesn't reduce down into a reverse of our course; I'm not
saying this very well. At some point in Brazos County's history, various
elected officials were on disparate systems and to try to resolve some of the
problems associated with the, there was a move toward this integrated system
known as TSG. For all of it's faults, one of the biggest merits of going with
TSG was this integration. I certainly hope that in trying to go through this
process of identifying ownership that we don't wind up getting crossways
with one another and splitting out again. Because what you're going to wind
Vol 7 Page as ~
12 of 27
up with is a system much like pre-TSG in which everybody is in their own
little silo of data. I can tell you that the State of Texas is trying to resolve
some of those very sorts of problems by bringing information resources
management tasks across a number of agencies around the state and
consolidating them into just a handful of data centers around the state. So
they've already recognized that they've got some major problems because of
this disintegration.
Mallard: Well, I would think that if you wanted the judges' records... whatever that is,
the Rule 12 you're saying ...those are set aside. Now there may be some
information in there that was produced by somebody else that is not, they
would have to go to that other party and get that information. I mean all
that's in that record should just be kept secret or whatever. Closed.
Boyett: Well I think that IT is the location to identify the fact that a given document
may be well produced by a judicial officer to make it a Rule 12 item. But
everything else has got to be in that great databank. What Eric says is
absolutely correct, the sharing of information between the courts, the district
and the county clerks, the prosecutors offices, the JP offices, and everything
else. The Sheriff has a gone a long way to eliminate duplication and
misidentification of people because of how people spell names three or four
different ways, they use initials, they have different addresses and everything
else. We have made an effort to try and consolidate those things in a
significant way because the data base that we have now, while it is not
perfect, is certainly better than it was four years ago.
Mallard: Well, can't they just do that? Say you can't get this from the judges' records
because it has other stuff in it but some of the information that came in came
from the sheriff's office and you can get that so you will have to go to the
sheriff s office or the clerks' office to get to their information because it's
public information. Wouldn't that be an easier way to go about it? You may
have to go to three different places instead of just the one record.
Caldwell: I think a better way of stating that is that once we have completed this
process and we've gotten this first step document, it should be pretty clear
cut. There shouldn't be any of this guesswork anymore. You simply go to
your document showing who owns what and what kind of request might
come in for information and whether or not it even should or shouldn't be
released and if it's eligible for release, who you have to go to get it approval
to do that. Better yet, to whom do you direct that request for the release of
that information. So again, I think the bigger point is that by executive
management recognizing the need for classifying this data ownership, once
that has been recognized and has been... these policies making that
Vol 7 9' Page a? J6
13 of 27
recognition very clear have been adopted. Then we can go to the next step
and we can start doing this data ownership identification.
Mallard: Well, obviously it starts at law enforcement and works up to the clerk's
office and then ends up in the judges office, is there ever a time that from the
judges office it works it's way back down to the sheriff's office or the clerk's
office.
Sims: Sure it does.
Boyett: Sure, I'll give you a good example. An officer brings and affidavit for
probable cause to a judge. Based on that affidavit of probable cause, the
judge issues a warrant. At that point, it is not public information at all. Once
the warrant is served, the person arrested, and the warrant returned, the
affidavit is public information and can be made available in the court's
office. It can be made available in any agency that has access to it. But there
are steps that go through there that are clearly delineated and, of course, we
go through that all the time. It's just a matter of when that information can be
released. But while the character of that is confidential and is a judicial
record as well as a law enforcement record, it changes to a public upon
service of the warrant and upon the return coming back to the court. We're
probably going to have to get a lot tighter about getting a return back to the
court and getting that information identified to IT if it's in the computer
somewhere. But that's an example of how the character will change.
Mann: If you're talking about data ownership, a big question has to be decided.
When you say ownership, are you insinuating that the owner of that data is
accountable for the integrity of that data? If that's the case then the
ownership is transferred once it goes into the database and anyone else had
the option of amending that data then it no longer can be owned by the
person who originated that data. In which case, I would think that it would
become county owned data at that point. Which means that the IT department
would be the group who was accountable for the integrity of that data?
Sims: Yeah, but then that data becomes not true and factual once it's changed.
Mann: That's a possibility, that's not necessarily the case. It's just like a property
room. Once a deputy puts property in that evidence or property room, he's no
longer accountable for what happens to that evidence. It's the person who has
clear custody of that evidence at that point in time. Same thing with out data.
Once it goes into the database, if it can be altered by the district clerk, county
clerk, the judge's, then we are not accountable for what happens to that data
at that point. Now the people who are in control of the access to that ...what
can be done with that data once it goes into the system ...those are the only
Vol -7g Page as ~
14 of 27
ones that can be held accountable for the integrity of that data and that would
be the IT department. So it becomes county owned data at that point.
Sims: Is there a way to determine if somebody does go in there and change the
data? Can you pinpoint and say, "Katy, you went in and you changed some
information on the data."
Caldwell: Yes and no. Audit trails are one way of doing that; however, audit trails are
not typically turned on in TSG simply because of the massive amount of
audit trail information that is captured. By TSGs own admission it is way to
voluminous to really turn on and leave on. The only time you'd ever do that
is if you already suspect somebody of monkeying they system and you want
to try to catch them
Sims: You want to try to catch them.
Caldwell: Let me make a couple of remarks if you don't mind concerning IT's data
ownership. It was unfortunate that I didn't make it much more clear in our
February 17`h meeting that ...and it was unfortunate too my use of Brazos
County Commissioner's Court fairly liberally throughout here which by itself
suggest that I was trying to gamer more data ownership for myself and
Commissioner's Court than I ever intended. You find further down in the
document that IT is really going to be playing a role of data custodian. No
data ownership at all. Our role is to make sure that it's available for the other
data owners and users, doing restorations from tape back up, making sure the
systems are up and running and then the integrity of that data residing on the
systems is really going to be everybody's responsibility; which is why I
stated earlier in my opening remarks that we need a security training program
in place. We need everybody in the county to be aware of what role they play
and why is it important that when they calls from strangers about the systems
and who your boss it...why should they be wary of potential social
engineering attempts and that sort of thing. IT does have a responsibility for
integrity which is one of the bigger reason for my push to get this sort of
programs in place because once we give somebody access in the sheriff's
module, without auditing trails, we have no way of verifying that people are
doing what they are supposed to be doing. Such as accessing only the data
that they are supposed to be accessing, not maliciously modifying that data
when they're not supposed to. So our best hope of assisting and maintaining
the integrity and the confidentiality of that data in conjunction with our
efforts to keep the system up and available is to try to get executive
management to and recognize the importance of these sorts of policies and
practices and then help to insure that everybody is following the practices.
Mann: I understand what you are saying but if data goes on to your server and you
have the keys to allow other people to go in there from other departments and
Vol ~ 9- Page 9a7
15 of 27
alter that for good reasons or whatever, then it becomes county owned data at
that point in time. Because the initiator of that data no longer has control of
what happens to that data. Without having control of the integrity of that data
they don't own it, because it's just going to be something different at some
point in time.
Caldwell: I'm certainly not trying to shirk responsibility and so if in the end it's clear
that IT is playing more of a data ownership role in those scenarios... and one
of the responsibilities of that data ownership is the protection and
confidentiality ...we'll do it. I would try to point out too that we have kind of
confined our discussion here to ownership of justice information but
remember, we have got human resources data, we've got financial data,
we've got health records, and we've got Road and Bridge as a good example.
Also remember that after identifying data owners the next step is to classify
that data in terms of mission criticality and confidentiality. That brings us
back to some remarks that I made back in February and that is to take Road
and Bridges as an example; Road and Bridge has information that may or
may not be public. Maybe we should or should not be trying to keep that
stuff confidential and not be leaked out. I'm going to assume for a minute
that it's not confidential; if the public needs it, we can get it to them.
Sims: I think that's a poor use of departments. I don't think that anything with Road
and Bridge is confidential. Now health department I could see.
Caldwell: But it may be mission critical though.
Cauley: Maybe I'm on the wrong track but I think the IT department should be the
custodian of the information that the county has. I also think that the IT
Department should be responsible for the integrity of what is put into these
records. But we are talking about ownership and what have you, to me I think
that sometimes we may have to do that on an individual basis. There are
some things that we know automatically but I don't think we can't make this
a broad policy and say this is this or this because circumstances can
sometimes determine what is and what isn't.
Mallard: Who's going to be the gatekeeper?
Cauley: Well, I don't know.
Mallard: I appreciate you volunteering.
Mann: Right. And that's the way it's going to have to be. The wording is if such and
such exists then this...
Vol $ Page aa9
16 of 27
Cauley: I hate to say it like this but it appears to me that with a lot of this stuff there is
going to be a lot of if, ands, and buts. So a lot of time we're still going to
have to get some clarification relative to whether this information needs to be
public or private or whatever the situation might be.
Mann: There are a lot of things that are thrown on the server that may not
necessarily need to be there and will take away the argument that IT might
have some role in custodianship of it. Memorandums and things like that. If
they are on the server when then IT certainly has access to it but some kind
of problem employee could go in there and tamper with that so we may have
to revisit what actually goes on the server and can potential put IT in a
custodian situation. I don't know if Eric's desire is to get through this
workshop ...a hundred a something pages ...and come up with a policy by the
end of it but I don't think that's going to happen. Is there not an IT committee
standing right now? I know we had one when we...
Sims: Did you just volunteer?
Mann: No sir I did not.
Caldwell: You actually kind of touched on something that I was saying that might kind
of wrap this up. There is a justice steering committee and that pre-dates me
but it's my understanding that the primary purpose of that was to guide the
effort to move to TSG. Now I was thinking that it's probably appropriate,
certainly for the process of identifying data ownership and maybe even go
through the minutia of developing the procedures to support these policies to
put together just such a committee. Either change the role of that or broaden
the role of that existing committee or put together a completely different
committee but I think that you are on the right track. Because this is well
beyond...
Mann: You can't handle this in a workshop, it's too big a project and I think if you
charge it to a committee one of the first things you're going to have to do is
identify these contentious issues or concepts and get those resolved through
reporting back to the elected officials and department heads and then hammer
out a policy proposal to present in a workshop where the court knows that
everyone has input on it and this is presented for them to rule on.
Cauley: Let this committee make recommendations to the Commissioner's Court for
adoption of what they have gone through would be proper and in order.
Boyett: That steering committee was made up from representative from each of the
departments as well as elected officials and it was utilized on into the
software group program to discuss and recommend additional changes and
stuff as they were allocated and whether it was thought that we should
Vol IS Page 62 02 9
17 of 27
expend county funds and make a recommendation to the Commissioner's
Court to go on. The committee still exists; Judge Langley is the chair of it. I
don't think we've met in the last six months, as such, but I think you're really
on the right track there. The issues can be identified. What is going to kind of
flower it a little bit is going to be some of these issues are not set in stone,
they are going to be transitional. They'll go from a status A to a status B to a
status C and frankly the data ownership will probably transition as well. I
think the committee is probably a real good solution and I would urge you to
consider that. We may want to re-look at who's on it. It sort of evolved in
many cases where an elected official was on that committee and substituted
somebody from their department over time to do it. It's probably certainly
time to re-look at the membership of it and this is a worthy project for it.
Sims: It may be time to freshen that committee up too.
Mann: I would suggest that you would want to make sure that ever elected official
has the opportunity to have representation on that committee, just for some of
the things that Buddy Winn has pointed out on page 11. He addresses some
very valid points that I think every elected official might have those same
concerns. It may be a fairly large committee but I think elected officials at
least need to have the opportunity to have their office represented.
Mallard: And whoever ends up being the gatekeepers on person in charge of it then
they're going to want to limit access to other people that have the opportunity
to change information because they're the ones that accountable for it.
Whoever you do, somebody's got to be in control unless you can make the
information not alterable... where you can't delete it.
Boyett: That would total defeat the interoperability that we have among the
departments and agencies that feed data into the database. At some point you
have to give up some rigid control in order for it to be able to be utilized by
more than one agency or department.
Mallard: I know with the system we had in the insurance office that was a
concern ...who did it. But every time that record was touched, it recorded
who it was or at least what machine and somebody had to have a password to
get into that machine so it wasn't perfect. It didn't actually identify the face
but it identified the computer and the person that had the password or you
could be on any computer with a password. You could put a note in there
about what you did. Now if you were going to bad things, you probably
weren't going to put the right kind of note in there but, in general, just told
everybody, "We accessed this and we did X." And it logged in who did it.
Boyett: As Eric points out that while the software group overall program has the
ability to do it, it is such a colossal data stream that I don't think we have
Vol ? $ Page 900.
18 of 27
enough equipment to hold all of the data. Whatever feed we operate at, I
think would be critical particularly to those agencies that are not here in the
courthouse or in this vicinity that depend upon data transmission over other
lines.
Mann: If the court decides to go the committee route, I would think one of the things
would do would be to look and see what other counties have a security policy
in place.
Sims: Yeah, and who they have on their committee that has put those in place. Yes
Michelle.
Meade: Let me further muddy the water by bringing up the topic of emergency
management and the projects that we work on with all of our surrounding
jurisdictional entities as well as the six additional counties. When we talk
about access of information, that's huge. That is especially problematic for us
during an emergency response because we have a lot of people coming into
the EOC, accessing software programs that are password protected and that
type of thing. So we understand that there are some real challengers in setting
up a policy that would be open enough to allow activity on an ongoing basis
as well.
Sims: Could you have a separate platform that could be used. When I say platform,
say we go into an emergency management or we activate the EOC and we've
got other counties that are working with us and as we talked about this
morning; the Red Cross, The Salvation Army and all this good stuff, could
there not be a platform put in place that it doesn't go any further than that?
You talk to one another by way of this platform but it never spills over into
Brazos County, i.e. our system.
Meade: Well, I guess that is possible...
Sims: You understand what I'm saying Eric?
Caldwell: Who are you asking?
Sims: Either one. I'm just saying; can that be put together?
Caldwell: Yes that's certainly one possibility. Another possibility that we've already
discussed would be the solution to a similar situation in which Karen
McQueen has equipment that elections workers use at election time. That's
county owned equipment but these people are apparently not county
employees and that's now kind of a cloudy issue ...in any case, let's assume
for a minute that they are not county employees but they are using this
county owned equipment; which in these drafts is not prohibited. As I've
Vol -79 Page ~
19 of 27
pointed out, there will always be exceptions to these policies. I think what's
more important than trying to refine the policies so that it takes all of these
exceptions into consideration, you simply adopt the polices and then if there
are exceptions that are known and are understood and are required, we
simply write that up as a known accepted exception and that becomes a
permanent part of all future audits. So your audit comes through and says,
"Well now here are your policies but here is where you are deviating from
your own polices. You've got non-county employees working on this
election equipment." And you pull out this written exception and you say,
"Well yeah, I understand but remember as an addendum to these policies
we've got this known exception where at election time these election workers
are not going to be county employees but they will be using this equipment.
And that's ok, because that equipment is never networked into our network."
Mallard: Or it has a password where it can't get beyond a certain section.
Caldwell: Similarly, given the duty of the software and equipment that emergency
management maintains, typically in a non-emergency situation it's not used
by anybody other than county employees. But that it's understood that in the
event of a major disaster and our EOC has to stand up, that equipment will be
used by a non county employee. That's just a written exception. That way
you don't have to try to refine these polices to try to take into account all the
minute exceptions. Remember the policies are just the higher level statement.
Granted, having said that, some of these policies in here are closer to
standards than policies. There's a lot of procedural information that's in these
polices. Email is a good example. We go to great trouble to explain that your
password can't be your pet's name; it can't be your home address. That's
more procedural in nature than it is just a higher level statement of
managements' appreciation that email is something that needs to be secured
and to that end, email passwords or password management is an important
part of this security program.
Mann: I think what Michelle has alluded is this is an important project and needs to
be done, this is a very complex project and there are just a lot of things that
we may not have thought about at this point in time that could be effecting
different levels.
Sims: Well, hopefully, we don't get into trouble before we get them amended
where we know where we're going and maybe some type of firewall set up
where they can't get into critical information that they don't need and we
don't need to be divulging.
Mallard: So Eric, does that give you some direction or what do we need to do. I guess
we have need to have a committee to look at this or...?
Vol 7 Page 930Z
20 of 27
Caldwell: Well, I'm really kind of looking to you. Now if you want me to recommend a
course for going forward, certainly the creation or the refimnent of the
existing judicial steering committee and revision of their expectations
including responsibilities is certainly a good step. My only question is
whether or not we should try to adopt the policies and then give those
adopted polices to this committee to pour through and make any
recommended changes before they go on to the onerous task of data
ownership identification and procedure development and that sort of thing. In
other words, do yall want to give them an adopted set of policies and say,
"Here's what we've adopted, pour through these and come back with a
recommended changes." Or do you want to give them these drafts and say,
"We still haven't made up our minds and this is still all up in the air.", or
whatever it might be. One of my concerns is that things will start to stall out.
Again, one of the purposes of the policy is just to make it clear that executive
management appreciates the need for this sort of program. You adopt that
policy and that policy... certainly that master document that states that the
data is going to be classified and data ownership is going to be delineated.
That master policy gives somebody like a committee the authority to go
forward and institute this next step of data classification, data ownership
identification.
Cauley: I would like to say that I think that we should reinstitute, rejuvenate, or
whatever the committee and give them this draft. Because a lot of times, once
you so something it's very difficult to change it. Let them do this and let the
Commissioner's Court put a time limit on this rather than just having people
just dragging their feet and, "When is gonna be?" "Well they didn't set a
time." Set a time limit. Forty-five days, within forty-five days or thirty days
or twenty days or whatever that this committee would have met however
many times they need to meet and come back with a recommendation to the
Commissioner's Court as to what needs to be done relative to this draft. We
all know that it's important. Our risk manager said that this is some of things
that we are being asked. Our department head is saying, "Hey, this is
something that we need to do." So it's urgent. Recent events have shown that
we need to have something more than what we have in place so my
suggestion would be to reinstitute and recharge the committee, give them this
draft information, and set some time lines and constraints and dates ...not
constraints, dates ...on them to come back with something positive.
Sims: How many is on the committee right now George, do you know?
Boyett: Oh, it's a couple of dozen, at least. I mean we've had to meet in the 85`h
district court room because we couldn't all meet in here. To me, it's quite a
large committee with multiple people from some of the offices.
Sims: Who are the most vocal? Did we have a core group that might be...?
Vol ~ t Page a33
21 of 27
Boyett: We did have a core group and Judge Langley notified us by email about the
meeting times and then interacted with IT.
Anderson: But I don't think that committee had representatives from all the
departments. I think it was the criminal justice are the ones that dealt with it.
I'm not sure that you got in to personnel.
Boyett: Yeah, he did.
Anderson: Risk management, auditors...
Boyett: The auditors were there.
Meade: They were against.
Anderson: Road and Bridge. It may take a new committee...
Sims: That's what I'm asking for, Carey, we may have to reconstitute. Put another
one in place.
Peters: Let me ask a question Eric. This is a privacy or protection policy, are there
things that need to be implemented... let's take ownership out of the question
right now because it's going to take a while to work through that thing, but
are there things in here that really need to be implemented to protect
ourselves?
End of CD 1
CD 2 begins mid-sentence.
Caldwell: You have to have someone a capability and can actually get out there and get
it done, bridge these two networks. So, in summary, the risk of that
happening is probably small enough that if we get all of our ducks in order on
this wireless online legal library and want to bring in the media for a big
event and go ahead and go public with before we get these policies in place,
we're probably ok. But in the long run these polices need to be in place and
that information needs to be disseminated to the end users and then the end
users need to be trained on the purposes of these policies to prevent this from
happening in the future. But again, the long answer... that was the short
answer ...I think we can do it all at once. I liken that to one of the biggest
problems that I see that we have with TSG; in a nutshell, the majority of
problems that we have with TSG stems from the fact that the underlying
database was not modeled all at once. This is an artifact from the old practice
Vol 78 Page 1),34
22 of 27
of having these various departments function more or less independently with
little silos of data so that the jail module was kind of built around this
business process of booking inmates into the jail. And they modeled that data
for that system. Well, some point later they decided, "Well, let's go to the
next step and let's build the sheriff's package and we'll try to stitch the two
together. And so we'll design the sheriff s package, more or less, in isolation
over here ...we'll model that data." Then they stitched the two things
together and we came up with this Frankenstein known as TSG. What I don't
want to happen is that we try to adopt one policy and then adopt another
policy because if you're read these at all, you'll notice that these policies
reference one another quite a bit. And so, it's really going to be difficult to
try to adopt a single policy without adopting the entire program. Not just the
policies but the procedures and the standards and the auditing the, the whole
kit and caboodle. I know that's a big chunk to bite off but I think that's the
best way to go about doing it.
Peters: I just want to make a comment on it, I think that is a subject for another
workshop... the TSG system ...but that said, if we were looking at adopting
and we have ownership addressed here currently as Commissioner's Court
owns it and that's not correct and we're trying to pass something ...if we want
to pass the whole documents and then go back and re-work it...how do we
leave it? I mean if we leave in there that ownership belongs to the
Commissioner's Court and that's not correct and we know that right now as
we sit here that that's not correct, is that what we pass? I mean if we
decided...
Caldwell: Well that, of course, is your decisions but I would think it would be easier to
give the committee and adopted policy and say, "Listen, here's the policy..."
Peters: That's what I'm asking though. You say give them an adopted policy, ok...
Caldwell: Say, "Now here's the adopted policy. Now we recognize that data ownership
is something has got to be addressed and because of that, this adopted policy
needs to be tweaked and we would like for this committee to come back and
give us recommendations. And they come back and they say, "Well, here's
what we recommend on defining this policy." But that gives some stability
and that really gives them kind of a launching point rather than this massive
compilation of various thoughts and ideas... some of which are not really
appropriate for the higher level policy itself. They were remarks that were
more appropriate for the standards and procedures. We haven't gotten to
them yet but specifically I think it was the Health Department off the top of
my head that had some recommendations or had some comments that are
more appropriately directed toward the standards and procedures that have to
be developed as one of the next steps. Remember, these policies are really
meant to be a higher level expression of managements understanding of the
Vol 7 Page 625
23 of 27
need to adopt a better information Security Program as a whole. We have to
refine this and we have to get down to the standards and procedures.
Mallard: My only concern is that if we adopt this as it is today, knowing that it's going
to be changed then how do we try to enforce it if we know that it's...
Caldwell: Well, again, enforcement can't happen until you've gotten the procedures in
place and it really can't happen until after we have developed the security
training program and carried people through it. Some sort of training to
explain to them what is the purpose of these massive policies. To date we
have had a total of nine pages of what could possibly be construed as
information security related polices for Brazos County. Nine pages. Which is
not nearly sufficient. So the end users have to be trained on the purposes of
these policies, the ramifications, they have to be explained, we have to
explain their roles and their responsibilities. So you really can't hope to
enforce these until after all of that is done. Again, we have to develop the
standards and procedures and guidelines before we can expect people to start
following the procedures. And you really can't do that until you adopt the
policy. I know it seems like a catch 22 but it's just industry standard practice
to start with policies that give direction to people like IT that have to go
forward and start construction of the standards, procedures, and guidelines in
the security program.
Mallard: That's hard for me to want to do.
Mann: We are talking about elected officials. There are some concepts here that are
going to have to be worked out in the committee if you go that route. I don't
know where the county is on their policy revision is that they are doing but I
know in the sheriffs office we have a policy that deals with conduct so we
have some protection there in terms of inappropriate use of these systems.
Just to go ahead and pass something just to make sure that we have
something there is a mistake, I think.
Caldwell: That's fair enough and I'm not really adamant about it. That it may not be the
way, really, is fine. I am concerned that it might stall out but if that's the
route you want to go that's fine.
Mallard: We just have to keep pushing it to make sure it doesn't get stalled out.
Caldwell: I would ask though, and maybe it's not appropriate but if another committee
is going to be formed or if this current committee is going to be restructured,
I'd like for you to consider directing this committee to approach other topic
beyond these policies. If you're going to restructure... number one; rename.
Because Justice Steering Committee was really conveys that it's concerned
with Justice Information Systems. Remember, these policies cover
Vol 7 8 Page
24 of 27
everything. Justice is a big part of it but so are financials and health records.
So if you create a new one, give it a new name. If you restructure it, rename
the existing one.
Mallard: It should just be the computer policy.
Caldwell: Well, actually, what I was going to ask is that you consider creating just and
Information Technology Steering Committee and give them a little bit
broader responsibilities than just working on these policies. For example: IT
is currently... has been... executing expunctions of records out of TSG. Now,
Mark Hamlin and I and others have discussed this in a couple of
meetings ...one of which I think Mr. Anderson attended. It is my hope that
the responsibility for actually executing the expunction of these records can
be returned to the various departments that create and maintain these records.
Which immediately opens up this issue of dead ownership; I mean who's
responsible for it. In this case, I think it's pretty clear cut because records
have to be deleted out of specific modules in TSG and so I think it's very
clear which department is going to be responsible for that.
Boyett: What Eric is saying can be simplified to say that if some record is going to be
expunged, which mean total obliterated an action has to take place in a court.
One of ten courts. Surprise, surprise. All five of the JP courts have
expunction privileges under different levels. But that means it's got to come
from the court. There is no reason why it shouldn't be done by the court other
than the fact that the software groups program doesn't allow it at this point.
But what he's saying makes a lot of sense (overtalking).
Sims: Is there a policy on expunction now?
Caldwell: Just a real quick point of clarification. The TSG does allow that to happen. In
fact we have already had two meetings and that was one of the many topics
we explored. First of all is it important that it be consolidated under one
person for concurrency sake? Is it important, for example, that the sheriff's
module record be deleted before the district clerk's module record be deleted.
Because if they're done out of order maybe one of them gets orphaned out
there and gets hung up in the system and fouls the system up. We've
explored that. The point of all this is that I think we're ready to move forward
and hand off this responsibility back to the other departments. But when I
took over the directorship out there, I inherited this responsibility for
executing these expunctions and one of my staff members has been doing
that for some time. But it came to light that it was important that we look at
handing that back over to the owning departments when my staff member
went home and had a baby. She was off FMLA and these things started
stacking up and the next thing you know we were getting calls, "Why is this
happening." But in any case, if this committee were charged with looking at
Vol 7 9 Page o2 3 7
25 of 27
that sort of thing as well, that would help me...certainly if they are in
agreement with me to champion my cause in giving that responsibility back
to the owner departments.
Sims: Big problem with some of that, and I'm going to speak from personal
experience and Rod knows this too; somebody's got to be responsible for
open records request and we can't have every department out there handling
their own request from the news media.
Caldwell: Right. Well now this expunction is not mandated but it really doesn't have
anything to do with...
Mallard: Those are records that are mandated but the department as to deal with their
own records.
Caldwell: In other words, currently that responsibility resides over at IT. There is no
statutory mandate. There's no software requirement. There's no business
practice requirement other than the fact that...
Sims: Yeah, but you weren't speaking just about expunction, you were speaking
about the whole record system within a department.
Caldwell: No. No. No. I'm talking about ...in this particular case, it is my hope that you
may give this committee the charge to look at my idea of handing this
expunction responsibility back to the owner departments. Just the expunction
responsibility. Ok?
Sims: Ok, what...
Caldwell: And then remember too...
Sims: I've been through this once. That was scary.
Caldwell: And remember too, one of the things that we have not...one of the things that
these policies have not even tried to address is things like the business
continuity planning. As you well know, if we are going to start replicating
systems at remote sites in the event that our primary servers go down, we can
switch over to that remote site without skipping a beat. That's going to cost
money and that's going to require planning. And so a committee such as we
are discussing might be...
Sims: I'll get with Judge Langley, ok? And I will find out who is on the original
committee and we may sit down with a core group of maybe ten and say,
"Hey, who needs to be on this one? Who needs to remain on the criminal
justice side of this?" And we'll get some names within the next week.
Vol "7 Sr Page a38
26 of 27
Gallego: Judge, I probably have a list but it's not an original list.
Sims: Yeah, but if you don't mind, let's give Judge Langley an opportunity to get
through this next election. Ok, because April the 11`h, he's got one. Ok? But I
will talk to him before then.
Caldwell: I will be happy to let somebody else take a look at these policies for a while.
Sims: Ok. Does that sound good?
Caldwell: Yes.
Sims: All right. We'll get it...
Mallard: But I would say that I would rather we go and we start a new committee.
Sims: Well I think you're right. We make pick and choose some of those off the old
committee...
Mallard: Oh, I hope there are some.
Sims: ...because they have some background.
Mallard: Yes.
Sims: Ok. Yes sir.
Boyett: My whole purpose in coming here today was to make the next comment. I
want you to understand that I say it knowing that people that work for Brazos
County. We've got bright, intelligent, dedicated employees. Now understand
this, it is my personal opinion and that of several others who have read the
draft and everything that we haven't got a snowballs chance in hell of
educating our general employees of a document of this size. It must, must be
reduced to a synopsis document or one that we could teach readily to
everybody and at some point down the road perhaps teach supervisors a little
bit more detail and I think we're probably going to be at the department head
level or maybe the manager level to be able to teach and feel confident that
everybody can inherit it. I support the effort to develop a security policy. We
absolutely have to have it but we have to recognize that we can't stuff this
down every employee that we've got.
Sims: Well said. Yes, you're right. And there's going to have to be an ongoing
training session. As you loose people within each department, they are going
Vol -79 Page 0-2,39
27 of 27
to have to be hand carried down the road by your supervisor. Whomever is
the "expert" out there.
Caldwell: Right.
Sims: Ok. All right. Anything else? I will adjourn this workshop. Thank yall for
coming. Eric that was well done. Thanks George, I'm going to be getting in
touch with you too because I know...
End of tape.
Page a IJD
Vol V'
The foregoing minutes of the Commissioners Court Workshop
held March 28, 2006, have been examined and approved in open
Court this the day of J-uyia~ , 20Q( , in Bryan, Brazos
County, Texas.
Duane Peters
Commissioner,
Precinct No. 2
-1'YA'q , WL,& zj ft C
arey C ley, Jr. 6
Commis toner,
Precinct 4
Attest:
aren McQueen
County Clerk
Vol 7 9 Page a ~ 1
~~,x
Lloy Wassermann
Commissioner,
Precinct No. 1
R -
Malla
Commissioner,
Precinct No. 3
BRAZOSCOUNTY
COMMISSIONERS COURT
~g te DAY OF J,&z
20 06- AT (XM/PM
~4)40~/ ~k7,3 ~
Name Organization
r" Z
4U
0
614
VOL'79PAGE L24a
So
BRAZOSCOUNTY
COMMISSIONERS COURT
9 t' DAY OF
2000 AT lo:ao
Name Organization
1-la4cza,
VOL -7 g PAGE 13