HomeMy WebLinkAbout2006-02-17-10:00AM-WORKSHOPBRAZOS COUNTY
BRYAN, TEXAS
NOTICE OF MEETING
BRAZOS COUNTY COMISSIONERS COURT
WORKSHOP SESSION
THE COMMISSIONERS COURT WILL MEET IN A WORKSHOP SESSION ON
FRIDAY 17 FEBRUARY 2006 AT 10:00 A.M. IN SUITE 115 OF THE BRAZOS
COUNTY COURTHOUSE, 300 EAST 26TH STREET, BRYAN, TEXAS.
1. Call to Order
2. Review of Brazos County's computer security policies and procedures.
3. Convene into Executive Session, if necessary, pursuant to §551.076 of the Texas
Government Code to discuss computer security devices.
4. Consider and review of possible action(s) on the Executive Session to be placed
on a regular session agenda of the Commissioners Court.
5. Adjourn
The Brazos County Courthouse is wheelchair accessible. Handicap parking spaces are available. Any request for sign
interpretive services must be made two business days before the meeting, To make arrangements, call (979) 361-4102.
Office of the County Judge . 300 East 2e St. . Suite 114
Bryan, Texas 77803 . Fax: (979) 361-4503
`71t..,. X39
COMMISSIONERS' COURT
WORKSHOP SESSION
FEBRUARY 17, 2006
The Commissioners' Court of Brazos County, Texas met in a
Workshop Session in the Commissioners' Courtroom in the
Courthouse in Bryan, Brazos County, Texas, beginning at 10:00
a.m. on Friday, January 17 2006, with the following members of
the Court present:
Randy Sims, County Judge, Presiding;
Lloyd Wassermann, Commissioner of Precinct 1;
Duane Peters, Commissioner of Precinct 2;
Kenny Mallard, Commissioner of Precinct 3, Absent;
Carey Cauley, Jr., Commissioner of Precinct 4, Absent;
Karen McQueen, County Clerk.
Attached is a list of the citizens and officials in
attendance.
The Commissioner's Court met to review the County's
computer security policies and procedures. Eric Caldwell,
Director of the Information Technology Department discussed
both internal and external risks and reviewed current policies
adopted by Brazos County. He said there was a need to
address disaster recovery, and conduct pre-employment
background checks for new IT employees at least.
The following individuals spoke:
Carlos Guitron, Director of Building Maintenance
Vol '71 Page 940
Commissioners Court meeting February 3, 2005
2
a) Said that he would like to see background checks on
his crew too because they have access to all of the offices.
He has established a practice of doing this but does not have
a written policy yet.
Karen McQueen, County Clerk
a) Asked if elected officials would have a chance to
review the proposed policies before adopted by the Court. Mr.
Caldwell said that it is on the agenda for Tuesday, but that
the County Judge would like to wait to have time to review
them.
Buddy Winn, Tax Assessor-Collector
a) Expressed concern that the Court would be adopting
policies that might bind elected officials. He doesn't feel
that the court can do that.
J. D. Langley, Judge 85th District Court
a) asked that the Commissioners Court be sensitive to
questions or input of the elected officials.
Duane Peters, Commissioner, Precinct 2
a) He feels the Commissioners Court must adopt policies
to protect the county. The Court will try to write policies
that work for the majority. If an elected official chooses
not to follow the policies established, then that official
will be liable if something negative happens.
Vol
-7-7
Page.
afI
Commissioners Court meeting February 3, 2005 3
A complete transcript of the meeting is attached and made
a part of this document.
wa..y. `^w-..
+..?k -
Vol ~ 7 Page a 4 a-
The foregoing minutes of the Commissioners Court Workshop
held February 17, 2006, have been examined and approved in
open Court this the '1-4- day of 20 U(o , in Bryan,
Brazos County, Texas.
Duane Peters
Commissioner,
Precinct No. 2
C rey Ca ley, Jr.
Comm issi ner,
Precinct 4
Attest:
Karen McQueen
County Clerk
Lloyd Wassermann
Commissioner,
Precinct No. 1
Kenny Malla
Commissioner,
Precinct No. 3
Vol -7-7 Page 24.3
r
BRAZOS COUNTY COMMISSIONERS COURT
MEETING ON - F7 200(o AT- AM
Name
Organ ization/Dep ment
A, r
8s oLusl~ce S~v%: eAw Xlye-ti
n r
1.
r
n
r
~-keE
o)o6LA+~-o 6-Z
so
1~•,
IIl
Con0e~ 04&-o-~
%✓l C C-c~~fMl~
BRAZOS COUNTY COMMISSIONERS COURT
IT Workshop
February 17, 2006
In Attendance: Rod Anderson, Gary Arnold, Eric Caldwell, Wayne Dicky, Candy Gallego,
Carlos Guitron, Pat Howard, Bill Jeanes, J.D. Langley, Debbie Lockledge, Karen McQueen,
Ekpe Okorafor, Duane Peters, Kristy Roe, Randy Sims, Kay Tracy, Lloyd Wassermann, Buddy
Winn, Ruth McLeod, Katie Conner
Sims: I will call Commissioners Court into session for a workshop session on Friday, the
17th, February 2006 at 10:00 a.m., Suite 115, of Brazos County Courthouse. I will call
this meeting to order and Eric, if you would like to step up and start your
presentation, please do.
Caldwell: Well, thank you. This workshop was titled `Computer Security Policies and
Procedures' or it was a called workshop to discuss certain policies and procedures. I
think a more generic term would be more appropriate. What I think we need to be
talking about is information resources security policies. Computers have this
connotation of a specific piece of equipment that sits on your desktop or you might
carry around in a satchel around with you. What I would really want to discuss with
you today is policies that cover not just that hardware but informational resources in
general. That is the network itself, software running on that network, and the
information, particularly, on that network and of course also the computers and other
associated hardware. I think what I'll do is run over some terms and kind of get some
terminology out of the way, real quick and start with `Information Resources
Security':
Information Resources Security in a nutshell can be defined as a goal. It's a goal that
Brazos County should be striving toward. It would be a goal to maximize the
confidentiality, the integrity and the availability of information. That's pretty broad
but I think that you'll see as we go along that broad definition is really going to be
required to give us the latitude to adopt policies that are going to cover all facets of
information security. Another way of saying that is; Information Resources Security
should be a goal to protect information resources through the use of technology,
processes, and training. So what do we mean by protecting? We protect Information
Resources by controlling the risks related to their ownership and their use.
That brings us to another term, `Risk'. What is risk? Risk can be broadly defined as
uncertain conditions or event that were they to occur would have a negative or even
possibly a positive effect on the Information Resources itself, the owner of that
resource, user, or some other party. So Information Resources Security Policies then
are one tool that can be used to control risks associated with the ownership and use of
Information Resources and move Brazos County closer to the goal of protecting those
resources with technology, processes, and training.
VIM-77 PAGE _)A6
1 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Let's briefly cover different types of the myriads risk that Brazos County must be
concerned with when we are thinking about our Information Resources. These risks
can broadly be categorized into two different groups: internal risks and external risks.
• Internal risks would include flaws in software and hardware; operating systems
have to be patched periodically because of these security flaws that are discovered
and then have to be released. Another source of an internal risk might be
employees. Confidential information can be accidentally disseminated by
employees, for example, or by flaws in software. That confidential information
can also be disseminated intentionally in the case of a malicious or disgruntled
employee, for example. Another type of internal risk might be the accidental or
intentional destruction of critical data. Another internal risk would be the theft of
intellectual property, inappropriate access to secure systems, or general abuse of
those resources.
• External risks: sources of external risks can include natural disasters which we
must take into consideration.
o Hackers: everybody has heard the term hackers; I'm not going to try to
define that.
o Malicious or negligent vendors and then purchasers of used equipment.
Brazos County owns equipment that has critical or confidential
information on it and if it is turned out to the highest bidder at auction and
that information still resides on that equipment, that is another external risk
that we should be concerned about.
o I mentioned hackers a moment ago; there are a number of different things
that hackers attempt. They can get into your system or attempt to get into
your system to deny your system services to your end users. Clog up your
system; it's called `Denial of service attacks'. They can get into your
system to try to commit ID theft, try to obtain personal information.
Typically it's financial information that they will turn around and use for
their own benefit.
o Other external risks would include viruses, you've all heard of viruses;
worms, spyware, Trojans, robots and the resultant zombies. Those are all
classified or categorized generally under the term `Malware'.
o Then there are also external risks related to email. Hackers and other will
use various techniques to commit what is known as `email address
harvesting'. They will go out and commit these techniques to try to obtain
numerous emails that they then can turn around and use in a spamming
effort. Disseminate span email to all these recipients. A lot of times they
will actually sell those email addresses to another party who will, in turn,
use those to Spam the email recipients. Email can also be use to disperse
this `Malware". Email is often the primary vehicle for disseminating
viruses, worms, and Trojans.
o Then there are Web related external risks that would include, again,
identity theft; sites that will trick an unsuspecting user into giving their
personal identity information. One common way of obtain that personal
identity information over a Web site is a technique known as `phishing'.
It's a method whereby the perpetrator will try to mimic something like City
VOL PAGE a-Zq&
2 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Bank's website and therefore they will try to trick the City Bank customers
into believing that they are conversing with City Bank itself. Through that
technique they will obtain the personal information.
o Then there are other types of external risk; I'm not going to go on. One
would be social engineering; a situation where an attacker would come up
to an employee who might be privy about information about how to get
into your system and through social engineering win over their confidence
and in a conversation be able to obtain the information they need to get
into your system.
All of these different risks naturally have consequences. If they didn't have
consequences, we wouldn't be concerned about them. What we are really
concerned about is the consequences of these risks, should they occur. Again,
those consequences would include: customer information leaks, we have health
information over at the health department, physician records, and there are
regulations that prevent dissemination of that sort of information. Health
Insurance Portability and Accountability Act (HIPAA). For publicly traded
companies there are similar regulations; Sarbanes-Oxley. So, were these sorts of
risks to occur and customer information leaks to occur then clearly Brazos
County, at least in some manner, has violated the regulations. There are also costs
associated with cleaning up in the event that there is a customer information spill.
How do you go back and how do you recover from that? It can be a long and
costly process to recover those records or rebuild that information; and certainly
to rebuild the public confidence in Brazos County as a whole.
There can be leaks of other confidential information, not just customer
information. Brazos County systems support the Narcotics Task Force. So I'm
sure you can appreciate what kind of information crosses our system that should
be secured with respect to their activities.
We also support the Joint Terrorism Task Force. Again, confidential information
that can impact homeland security that we have to be concerned about.
Other consequences would include business disruption and down time. Can we
afford for `denial of service attacks' that brings us down and keeps us down for a
week? Again the cost associated with that disruption and the restoration of that
service.
All of these risks to some degree or another also pose as a consequence the
exposure of department heads, elected officials and employees to civil, criminal,
and attitudinal sanctions and penalties.
I think that we can appreciate that it is important than Brazos County do what we
can do understand and mitigate all these different threats.
To date we have taken some steps in that direction. We do have some policies that
are already in place. In your three-ring binder, I have included those policies; they
vaL 77 PAGE a 4-7
3 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
are sandwiched between some blue papers. If you glance through these, you will see
that there are currently three policies that attempt to address these risks and Brazos
County's efforts to recognize and mitigate those risks. They are:
• "The Policies for the Use and Security of the Brazos County Computer Systems."
I often refer to those as the "acceptable use policies". New hires that come on
board are given these policies by the Personnel Department and they are asked to
sign an acknowledgement page indicating that they have received these. These
policies do address some concerns such as appropriate use of county equipment
and appropriate use of home-based equipment for county business. It does touch
on usernames and passwords to some degree. It does discuss a little bit about
authorization and prohibition against accessing certain systems. So it's a good
start.
• There's another policy called, "The Internet Policy". It too has an
acknowledgement page that new hires are expected to sign when give these
policies by the personnel department. It addresses acceptable and unacceptable
use of the Internet. Again, a good start.
• And then finally, one of the most recently adopted policies is, "The Policy For
The Use and Security of the Brazos County Computer Systems Access Codes for
Systems Administration and Servers." It's a long title and I typically shorten that
and refer to that as our "Access List Policy." This policy was adopted in 2004
and addresses how we handle the passwords to our primary servers and more
critical equipment and infrastructure. It provides for a procedure to escrow those
passwords in a safe location so that they can be accessible in the event of a
disaster or in the event of turnover of employment in the IT department. Again, a
good start.
These policies, at least in two of the three cases, go to the trouble of trying to define
some terms that may or not be used consistently through these three policies. Also, a
good start at trying to make these definitions based.
One of the primary problems though with our current status, with these current
policies, is that they don't address all of the concerns that Brazos County could be
faced with. They also address several risks that logically can be separated out into
different policies so that they are a lot easier to manage. And then again, finally, they
will define some terms separately, individually, or in the case of the Internet Policy,
they don't define any terms at all.
Let me stop right here and read a couple of quotes that I found recently on
Information Resources and Security. I am going to paraphrase this from the ISO
17799 Gold Standard of Computer Security Policies.
• Information security is achieved by implementing a suitable set of controls which
should include: policies, practices, procedures, organizational structures, and
software functions. These controls need to be established to insure that the
specific security objectives of, in our case Brazos County, are met.
vot-W PACE a 4 W
4 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
That's a lot. Information Security, then, requires a suitable set of controls which
includes policies; we've got a good start on policies. But it also goes on to state that
it's achieved by implementing practices, procedures, organizational structures, and
software functions. Five more facets that we have yet to address. From the latest
issue of Secure Computing Magazine I read the following quote.
• A consistent and continuous process of monitoring, reviewing and reporting is
crucial in determining the efficacy of existing security processes. Ongoing
audited operations are crucial to insuring business and IT alignment, managing
desktop cost and reducing operational and security threats to business operations.
I choose this particular quote because it emphasizes a consistent and continuous
process of monitoring, reviewing, and reporting on these policies and future
procedures and practices that I hope Brazos County will adopt.
Before we dive into the draft policies, let me just share with you a few final thoughts
and then we will get into the grudge work of going through these policies one by one.
What I am presenting to you today, again, is draft policies to supplant the three that
we currently have that are in the back of your binder. They are what I believe to be a
good start at a framework of policies that we can expand on in the future and that
will drive the formation of the procedures and practices that we need to have in place
so that we can audit ourselves and bring in external auditors to verify our own
adherence to those policies. So, we can adopt these policies as they are or we can
modify these policies before we adopt them. In any case I think we will all agree that
these policies, while they are also a good start, should be a living document that can
be modified from time to time and should be reviewed periodically so that they will
be modified to meet changing business processes and practices, changes in
technology and so forth and so on. But we must go further and we must adopt written
procedures that will be used to enforce these policies. It will be those procedures,
used to enforce these policies, that are, in turn, directly auditable by ourselves or by
external auditors. So we must also be prepared to commit to a practice of internal and
external auditing of these policies. It's not sufficient to adopt the policies and then
rest on our laurels with the false assumption that we've done everything necessary to
secure ourselves and our information resources. I liken that to what I've heard
termed before as the `corporate veil'. A small, family-owned business might
incorporate themselves, but if their board of directors consists of the husband and
wife and they don't have board meetings and they don't keep minutes, it's certainly
possible that they will find themselves in court and they may say that they are
incorporated but they have behaved much more like a sole-proprietorship. As so,
they are not allowed to hide behind this corporate veil. Yes, they incorporated and
they have their documents in order but they didn't act on those documents
appropriately. So it's not enough for us to adopt these policies, and it's not enough
for us to adopt procedures that will be used to enforce these policies, we have to
practice those procedures and we have to audit ourselves and we have to bring in
external auditors on a routine and continuous basis to verify our adherence to these
policies. Only then can we know that we have done what is necessary to at least try
to assure ourselves and our customers, citizens of Brazos County that we've done
what we can to mitigate risks to our information resources.
5 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
When I was putting together all these thoughts to deliver to you this morning, it
dawned on me that, again, while these policies that I'm suggesting to you are a good
start, they still don't address a number of issues that we'll have to be addressed
sooner rather than later. Disaster recovery is a good one. There's really little, if
anything, in these policies that discuss disaster recovery. What happens in the event
that our data center is taken away? That's a major disaster and Brazos County can't
just cease to function, we've got to recover from that. But these policies don't really
address that. Short of let's say, keeping your system logs, keeping your system's
documentation up to date, and assuming that you have backup copies, which can be
addressed in the backup policy and you have backup copies of the systems
documentation; that systems documentation would be a good start at recovering from
that disaster. But these policies do not really address all the necessary steps that have
to be taken to try to mitigate such a risk and to direct how we would recover from
such a disaster.
It also occurred to me that these policies don't address pre-employment background
checks. You may remember that that was a topic that was kicked around about six
and a half to seven months ago. That given the source of information that flows
across Brazos Counties network - again, Narcotics Task Force, The Joint Terrorism
Task Force, information that might impact homeland security - the idea of instituting
a policy and a practice of conducting pre-employment background checks for
individuals that would have access to certainly the critical infrastructure, Brazos
County Information Resources, is probably a good idea. But it didn't make it into
these policies, at least not yet.
So, it's my expectation that these policies will require revisions, most certainly
initially. It's also my expectation that if we do our homework correctly, these policies
will be reviewed periodically and continuously and updated over and over and over
again on an as needed basis. So finally, I think that Brazos County has in front of it
now, draft policies that will take us to the next step. These are really just the
framework necessary to incorporate those additions and those revisions that are
necessary to get us toward out goal of understanding and mitigating the risks that we
face with respect to our information resources.
With that then, I will stop. If you have any questions, I will certainly take those. Then
the next step is try to go through some of these policies and kind of highlight for you
what these policies...
Sims: Before you get away, let me ask a couple of questions: Number one; you're
saying that we need to have background checks of everybody that comes to work
for the county? Is that what I'm understanding?
Caldwell: No sir.
Sims: Or has access to our computer.
kia 77 pArE 250
6 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Caldwell: No sir. What I said was that about seven months ago, you may remember, we kind
of kicked around this idea that new IT employees, at least, might be appropriate
candidates for these pre-employment background checks.
Sims: Ok.
Caldwell: Because of the access that they have to the critical infrastructure of information
resources for Brazos County. Given their access to that, it may be a good idea for
Commissioners Court to consider instituting a policy that states that anybody
that's going to be hired in the IT Department will automatically be subject to a
pre-employment background check.
Sims: Ok. Why would you limit it to just the IT Department?
Caldwell: To prevent biting off more than I can chew, I guess is the best way to put it. You
have to start somewhere.
Sims: Ok, I'll accept that. Ok, I was just kind of curious; you were talking about internal
and external auditing and reviewing and reporting. How often would that take
place? Do you have any idea? Say the outside auditing.
Caldwell: Well the auditing process can take different forms and so I guess I'm giving you
the long answer. The short answer is, annually.
Sims: Ok.
Caldwell: Ok, but you really have to qualify that with a much longer answer in that outside
auditing can take different forms. Roughly a year ago, Brazos County undertook a
security audit that really tested the perimeter of our network. Now the perimeter
of our network would roughly equate to Brazos County's internal network and
where it meets the external Internet at large. So what that external audit did was,
sitting outside of Brazos County's network, sitting out there on the Internet at
large, it just kind of scanned the perimeter of our network to see if it could find
holes and faults. That's one form of an external audit. That's relatively simple to
do. Another kind of audit would be an audit to determine whether or not Brazos
County employees are susceptible to social engineering. If one of the risks that we
are trying to mitigate, let's say, is the dissemination of non-public confidential
immunization records of the health department... well, how far does Brazos
County want to go to verify that we have mitigated that risk? We might decide
that it's really important enough that we would bring in somebody to exercise an
attempt at social engineering.
Sims: Try to break it down.
Caldwell: Somebody would walk in there and try to schmooze somebody, win their
confidence, and see if they couldn't get a hold of some information or some
ability to access that information. That's a different kind of external audit; they
vo[ 77 PAGE a61
7 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
actually come inside but they are an external party, somebody that comes in under
cover. So, again, the short answer is annually. I think that that's a good place to
start to say we will certainly review these policies annually; we will certainly
review the external perimeter of our network annually. And then it's just a matter
of deciding what kind of risks can we mitigate with additional types of external
audits, how critical is it that we do so, what is the cost and therefore how
frequently should we be conducting those. I'm not prepared today to even tell
you...
Sims: How many departments would we have that social engineering would be a
concern do you think? And the Health Department would be one of them
certainly.
Caldwell: Again, I like to answer in long answers and short answers. If you prefer the short
answer, the short answer is all of them. The long answer is; it depends on the kind
of information that that department has access to, the vulnerability of that
information, and then the criticality of that information. A department may have
access to a lot of data but if that data is known to be much more secure and
therefore not nearly as vulnerable then the criticality of that data is not as big as a
consideration. These are just generic terms but let's just take; I was about to say
let's take a specific example but I don't know if that is appropriate.
Sims: Well I can see the Health Department and I can see HR because that's information
that has to do with employees and I could see that that could be very critical.
Caldwell: In the table of contents, you will find a policy called "Customer Information
Security Policy", it begins on page 31 and actually if you will skip the
`Introduction' and `Purpose' of that policy and flip over to page 32, you will see
there is a section called `Audience'. You will find in these policies that I have
tried to use consistent headers to make things a little easier to follow. In the
`Audience' section of every policy, I try to indicate who's going to be effected.
Who would have to adhere to this most closely and who would be impacted by an
audit for example. But you will see there the following departments and
information they handle are specifically noted in this particular policy: the
Auditor's Office because they have financial institution information, banking
numbers and routing numbers. They have personnel information and direct
deposit information, they even have vendor records that might need to be secured.
One of the things that we are going to wind up doing after we have adopted these
policies is to take this framework and in developing the procedures necessary to
enforce these policies start identifying these systems and rating them on the
criticality of that information and rating them on the vulnerability of that
information. But you will see there that I have gone on to the Health Department
because of their Health and Immunization Records and Human Resources
Department because of their personnel records and some of their health and direct
deposit records that they have access to. Certainly the Information Technology for
everything that might be critical that would apply to the Information Technology
Department. Then I go on to, certainly, the Prosecutors, the Judiciary and their
~G 7 PAGE 252
8 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
courts which would have access to civil and criminal records, some of which
might be confidential that shouldn't be leaked out. Purchasing, again, because of
the vendor records that they have access to and the Treasure's Office because of
their Financial Institution, direct deposit, and vendor records. The Voter
Registration because of the voter registration records that might be needed to be
kept confidential. So once again, this is what I believe is a good start and we may
find that I've overlooked a lot of good information that needs to be addressed in
these policies. I'll be the first to admit, I know I have.
McLeod: Juvenile.
Caldwell: Well, right. Now this is customer information, this relates to citizens of Brazos
County at large. Voter registration records, health and immunization records,
vendor records and it does address Brazos County employee information because
of the direct deposit and financial institution information. And yes, as a matter of
fact, I think I noted to myself last night that juvenile was something I didn't type
up and include in here. What this particular policy doesn't even attempt to try and
address though would be confidential information, again, like that that might be
circulated by the Joint Terrorism Task Force, say through email. That's not
customer related, per se, but that is confidential information. Now who all has
access to that? Well, I don't know that I can answer that. I think what we need to
do is in developing procedures for enforcing these policies is bear in mind that
that is one of the things that we have to undertake up front. We have to identify all
this different critical information, where it resides, who has access to it, how
critical is it, and how vulnerable is it?
Sims: Well, I'm just kind of curious because there are some things that certainly, let's
face it, we don't want an open records request for every little thing that the public
wants to know.
Caldwell: Right. Right.
Sims: That they could pull up off of a web site or even, heaven forbid, break into our
system. But that is not confidential. I don't think that we would have a problem,
would we, to make that available to them. It sure would keep our phones from
ringing quite so much.
Caldwell: Well, remember too, one of the things that we have to be concerned about is not
just confidential customer information or even critical non-customer information
like that that might be circulated about these task forces; it would be even non-
critical and even potentially public record information. Let's take Road and
Bridge's records that they may have out there: how critical is that information?
Well, let's back up a little bit. I mean is that public information? Yeah, probably.
Is it confidential? No, probably not. How critical is it? Well, if everything that
they had was destroyed; accidentally or maliciously, whatever it might be, does
that constitute a disruption in our business continuity? Sure it does. What kind of
effect is that going to have on Brazos County's ongoing ability to service its
VOLT 7 PAGE X53
9 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
citizens? It'll have some. So we've got to take that into consideration too. But no,
Road and Bridges records aren't confidential and they're not real critical, but the
loss of those records might have an impact on our operation.
Sims: That I can see. That I can see.
Caldwell: So, yeah, we have to take that into consideration as well.
Sims: Are you ready for any questions as far as you've gone yet? From the audience
here?
Caldwell: I will take any questions.
Sims: Yes sir, Carlos.
Carlos: Well, this is just regarding background search. Some time ago I talked to
(inaudible), Mr. Anderson, and Bill Jeanes about my concerns with hiring
custodial workers that have access to all of these offices and let alone his office
where the servers are at. A&M has this policy where there are three criteria that
require background search; if they have a master key, if they are working around
money, or have access to computer servers. It's not on the application but I
mention to the employees when I go to hire them that if they are offered the job,
we will do a background search. Now, that's selective as to what comes back to
me. I told Mr. Bill Jeanes that he's just gonna be pushing a mop and broom, I
don't need to know that he's had DWIs because he's not gonna be driving for me.
I sent a memo to Mr. Bill Jeanes that if it was a new employee, here's his
application and any information that comes back on him that he may not get the
job. We are currently doing that but it's not a policy.
Jeanes: We've established a practice and we're writing the policy to match the practice
McLeod: Anytime you do a practice, you have created a policy.
Sims: It becomes a policy.
McLeod: Whether it's written or not.
Caldwell: That's something I've been doing in my department just because of the access
that they have and so far I haven't had any hits so there hasn't been any situation.
McLeod: One of the things that we probably need to look at is the job descriptions. The job
descriptions of critical people, your people, need to include a statement of
background check. As well as Carlos's.
Conner: We also have to develop a way to pay for it.
McLeod: Right.
VOL-77 PAGE O
10 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Conner: Sorry, but we're hiring people like crazy and I'm paying for my own background
check.
Sims: You're right. You're right.
Carlos: Well, I can tell you, it was a dollar.
Conner: It's twenty dollars for a state rate.
Jeanes: For the background check it runs around twenty, start around twenty dollars.
Conner: That's for a statewide search.
Jeanes: Yes. That's your criminal records and that type thing. The one we get from the
state which is a dollar is very limited in scope. That's basically just your sex
offenders and that type.
Carlos: When I talked to A&M, they were in the process of expanding that because of that
problem.
Sims: Any other questions? Yes sir, Bud.
Winn: Eric, did you write that policy with the knowledge that the Commissioner's Court
can't adopt policies that would bind the elected officials like myself, or Judge
Langley, or the Sheriff? I mean they can't adopt a policy that will require me to
do any certain thing as an elected official. Each elected official has the
prerogative of doing what they want to, and where they keep their other records in
our office. Each elected official. And it's us, as elected officials to decide whether
or not to release those records to the media, the Commissioner's Court, or
whatever.
Caldwell: I did. And I don't know that there is anything in these policies, per se, that would
obligate any elected official to do anything different.
Winn: I hadn't looked at them, that's just a question.
McQueen: Will we get a chance to look at those before they are adopted?
Caldwell: Yeah. Yeah. I'm sorry; before...?
McQueen: Before they are adopted.
Sims: We are not adopting them today.
Caldwell: Yeah.
VOL77 PAGE 25S
11 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
McQueen: But doesn't he want them on the agenda next week?
Caldwell: I did.
Sims: Well, I think they need to review it and let them take a look at some things; come
up with some questions because they haven't seen it yet. Let them come up with
some questions that we may need to address before we get ready to adopt it.
Maybe we can adopt it in a couple of weeks as opposed to next week and let them
have time to look at it.
Caldwell: Ok. I didn't know how this process was going to unfold so I thought I'd put it on
there and it's easy to remove.
Winn: The Commissioner's Court can adopt policies that would affect their Road and
Bridge Department, Maintenance Department or any other non-elected body.
Conner: HR.
Winn: Health Department, all those departments but when you get into the elected
official, District Judge, County Court at Law, District Attorney, Tax Collector,
Sheriff, JP, Constable, Treasury, then you're looking at a whole different ball
game.
Sims: At least until budget time Buddy.
Caldwell: I had referred earlier to the perimeter of Brazos County's network, if you want to
think of it as a circle, that's fine, it contains all the information resources for
Brazos County and then anything outside of that is Internet. As so, while
conceptually, it's easy to see this circle and think of everything inside of it as
Brazos County and at the edge of circle is this perimeter; it's not always that cut
and dry and not always that black and white. So with respect to these policies that
have might have some bearing on, let's say, voter registration records or even
Health Department records, those records reside on equipment in the data center
that's being managed by Information Technology which is a department under the
management of the Commissioner's Court. And so, don't even go there.
Conner: Don't do it and I can see server request.
Sims: You don't want anybody being able to tap into your voter registration records
either.
Winn: Exactly. Of course, now we're in the Secretary of State's computer, not the
county's computer but we're using county equipment. But still, that's county
equipment that is assigned to me as an elected official and I have total say so over
it as long as it's in my office. You can't tell me how to use it once it's assigned
and budgeted to my department. Just like you can't tell the Sheriff how to use his
car.
VOL 77 PAGE d5L
12 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Sims: That's why I've always said I've got 26 entrepreneurs in this courthouse.
Winn: But now you can take my computer away from me or you can take the Sheriff's
car away from him and reassign it somewhere else.
Sims: Right. Right.
Winn: But you're going to have to answer for it to the voters because that Sheriff is
going to tell the voters, "Hey, the Commissioner's Court took my automobile
away so I can't patrol your neighborhood." I'm going to tell the voters, "They
took my voter registration computer away so I can't enter your names and
information and precincts fast enough to get the job done."
Sims: But you won't take responsibility that if we don't have this security within your
office, that somebody erased all of these and you can't put that on us.
Winn: True.
Sims: Ok.
Winn: But see, I've got a responsibility just like the Sheriff does of putting a deputy in
that and car driving it to make sure that that deputy is not a drunk and not going to
get out there and run over somebody or act crazy. It's my responsibility as the
Voter Registrar to put a clerk on there that I deem competent enough to run the
system without...
Sims: And honest enough, I got you.
Winn: But you're gonna have people that get in there that are going to get sticky fingers,
but you take that chance.
Sims: Well, that's what we're trying to eliminate. That's what we're trying to do,
eliminate some of that.
Roe: It might not be deliberate though. It may be something inadvertent but could
cause...
Sims: Yeah, but like Buddy says, if it doesn't stick to their fingers and it's not
deliberate, we would have to fix it. That's all there is to it.
Winn: And every elected official in the state of Texas takes that chance, or in the nation
of that matter. You're going to have people that are going to get in and manipulate
the system. That's human nature for people who do things like that. You just have
to have enough security and controls in place to try to catch them before they get
too far along.
VOL -)7 PAGE Z7
13 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Sims: I think that if the come in and intentionally manipulate the system; I think that
should be a capital crime, punishable by capital punishment. It sets everybody
back; it just kills an organization to be honest with you.
Winn: Not only that but it ruins your confidence in your fellow...
Sims: And it ruins your confidence of the public.
Winn: Yeah.
Sims: Let's face it. Yes sir, Bill.
Jeanes: I think that once the majority of the elected look at these things in detail and they
come back with their questions, I think that they are going to see that these
procedures are going to add to their security and it's not going to interfere with
anything they are doing. They are still going to be the responsible parties. County
wide, I think that they are going to see that it's a benefit to everybody in the
county. All the elected officials...
Sims: And I'm sure that by the time they read them, they will come with some other
ideas on what needs to go in these policies. No doubt about that.
Langley: One of the things that I've always had to deal with in the Justice System Steering
Committee is whenever we are dealing with an integrated system like we have
here and we are dealing with all of the elected officials like we have to do; there is
always a danger that any one of the elected officials can jump ship and not use the
system at all. So I've always been walking on eggshells trying to keep everybody
on board ship to try to make this system work. But at any point along the way,
any elected official...
Sims: And wondering if we have any authority whatsoever to be able to do it.
Langley: ...that's right. It's one of the dilemmas of county government. The
Commissioner's Court has the purse strings but the end responsibility rests with
each one of these elected officials. So it's very difficult sometimes to keep
everybody on board. We almost lost all of the JPs out of this integrated system a
couple of times because they didn't like the system. Luckily we were able to hold
everybody together, so far. But it's one of these things that the court really needs
to be sensitive to when you get to the point of listening to what the concerns of
the elected officials might be.
Sims: Absolutely. Absolutely
Conner: I do agree but if you don't put anything out there, that's what you get, nothing.
Winn: That's what I was trying to say that the Judge put a little bit better than I did, but it
kind of reminds me of Gene Cricket in McLennan County when he asked his
VOL'77 PAGE 25'
14 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Commissioner's Court for additional bookkeeping personnel. They wouldn't give
it to him at budget time so he just quit paying them money. And wouldn't give
them no money. Well, they sued him to get the money and went to court.
Sims: Wasn't pretty was it? For either side.
Winn: No, it wasn't pretty. And they wound up giving him more personnel and he gave
them the money. But it was embarrassing to the public for them to have to go
through all that. And this is what I've always tried to eliminate here in this county
where you get elected officials fighting with other elected officials and it's like
hanging your dirty laundry out on the fence so that everybody that drives by can
see it.
Sims: We will continue to go that direction.
McLeod: But Buddy, if the elected officials would agree that the policies are good for them
and sign off on it, do you not think that they would follow the policy?
Sims: Do I think they would? I think...
McLeod: I was asking Buddy.
Winn: Until they got mad.
McLeod: Ok.
Winn: Or disgusted or whatever. I mean they are subject to changing their mind later on
down the road. That's just individual nature.
Langley: Definitely a dynamic process.
McLeod: Then we might was well quit working on the personnel policy
Sims: No, we're not going to quit working on it.
Peters: I know what you are saying but it would seem to me like that Commissioner's
Court needs to set up policies and if the elected official decides that they are not
going to follow them, the policies are there, they are the ones that are going to be
liable if something happens. The policies are there, it's up to the elected officials
to decide not to or to follow those policies. If they choose not to and something
comes, I think the elected official is going to be the one responsible, because the
Commissioner's Court is trying to protect the county. That's what I think the
objective of this thing is, is to try to protect the county. And that's all we can do is
set the policies there and then it's up to each one of those elected officials to
choose whether they are going to follow those or they are going to go on their
own and do whatever they want to do on their own. If they do that, to me there is
more liability for that elected official by running their own road than there would
VU 77 PAG a57
15 of 23 Brazos County Commissioners Court ITPolicies and Procedures Workshop.
be to kind of-in working through this process we need to involve all of those
elected official and see if we can come up with something that's acceptable to
most. I know how it is when you get a whole group of people, we may never
come up with; if we decide we're going to do a hundred percent, everybody's got
to agree, we'll never come up with it.
Sims: That's not going to happen.
Peters: That's right.
Winn: Well, it would be like yall setting the office hours from 8 to 5, I mean I could
open my office at 9 and closed at 4 and as long as I satisfied the public that would
be all right. But if the public demanded that I abide by yalls 8 to 5 policy with no
closure at noon, then I would have to answer every four years to the people as to
why I was running my office hours contrary to yours.
Sims: And that's exactly what I'm saying here; if we don't have a policy in place then
they can look at us and say, "Why didn't you have a policy in place." We got it in
place, but Buddy chose to do something else and something happened over there
and everything cratered because of it. Or it was tapped into and this type of thing
then you need to talk to Mr. Bud, don't talk to us.
Peters: That's right.
Sims: And that's the way it ought to be. That's the way county government is set up.
Winn: And county government is; people don't understand the function of county
governments, some county officials in the state don't understand the function of
county government.
Sims: And for sure, state officials don't. They don't understand county government.
Winn: No.
Roe: I think the primary concern is just not necessarily whether elected officials are
kind of going off on their own but I think the concern would be that because each
elected office is unique to it's self and has different responsibilities, is just that
these elected official have the opportunity to look at the structure being laid out
there and have some input to adjust a little bit to conform to their specific needs
and problems so they can participate in the structure comfortably. While it may
not fit everyone the same, that's the big concern. Absolutely the structure is great
and the policy is great. One of my big questions was, I know Eric mentioned it,
now the policies that are there you're having new employees sign off on them; my
question is: can't we drag the old employees in and make them sign off on them
too?
Sims: I don't know why not.
VOL 77 PAGE-;?k _0
16 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
McLeod: We can.
Roe: That's something that you want to make sure that they are all very aware of it and
not having to keep reminding them.
McLeod: When we actually created these policies they were all sent out and we got a
signature page back from the current employees at that time.
Caldwell: You are referring to the employee manual, right?
McLeod: No, I'm referring to these computer policies.
Caldwell: The current ones?
McLeod: The current ones.
Caldwell: Oh, ok.
Langley: What is the discussion about putting time limits on access codes and people
having to come back in and get their access codes again when they did that?
Roe: Yeah. The structure itself is great; the idea that when security is great it's a
concern for everyone, every office is concerned. It's just that I think the elected
officials need to have a little input as far as how they are going to make it fit
comfortably in their office. And I think that is the only concern that you've got.
Winn: I think each elected official could set up their own policy within the policy to
govern some of that.
Langley: One good way to deal with this dilemma that the court and even the elected
officials frequently faces is when you are writing the policies, if it's so bad that
the elected official is threatening to jump ship, when you adopt the policies you
can write in the policy an exception dealing with that issue that would make that
official comfortable with the policy. That's just what I'm kind of asking you to
watch for.
Sims: Well, one of the things that we certainly would watch for is if three, or four, or
five of the elected officials say, "Hey, we can't adhere to this." And that would
certainly be one that we would need to take a look at and see if it needs to be
completely taken out or we can give exceptions to.
Caldwell: There is already a good example of that. The acceptable use policy in these drafts
comprises much of the current computer use policy. It also includes some
additional elements. Also the current computer use policy, some of it has logically
been broken out into email policies and elsewhere. But it's already been pointed
out, for example, that in the acceptable use policy there are provisions in there
VOL-] 7 PAGE 201
17 of 23 Brazos County Commissioners Court ]T Policies and Procedures Workshop.
that if you are not a Brazos County employee you are not supposed to be using
Brazos County equipment. Well, it's already come to our attention that Karen
McQueen will have non-Brazos County employees using Brazos County
equipment at election time. So that is certainly one of those provisions of these
policies that I expect immediately.
Conner: Do you want to adopt it and then revise it?
Caldwell: Well, that's kind of how I saw this unfold.
Caldwell: We adopt these drafts and...
Sims: ...we find exceptions then.
Caldwell: Once these are adopted, the Commissioner's Court has then confirmed that they
recognize that in the absence of these policies Brazos County is at a greater risk
than with them. Then we circulate these among the other elected officials and see
if we can't arrive at some common denominator.
Langley: The way that we adopt local rules in the court is that we tentatively adopt, publish
for 30 days, have an opportunity for comments and then make a final policy. And
that gives everybody the opportunity to say, "Whoa. Hey, this is wrong here. This
needs to be addressed before you make this a final policy and that works pretty
well.
Caldwell: Another anticipated modification to these policies is getting back to these
passwords. There is a provision in these drafts that says the password will be
changed every 60 days. I left there in there, more or less, as an example of some
of the things that are recognized problems with these policies.
Sims: It's standard in the industry probably, isn't it?
Caldwell: It may be standard in the industry but I can tell you where that will lead. It will
lead to post-it notes on monitors and that's a big security issue.
Sims: For everyone to see.
Caldwell: That's a bigger security risk than letting people keep their password indefinitely.
Sims: Yeah. You're right, you're right.
Caldwell: Some middle ground may be appropriate. A password can't be used for more than
two years, one year; I don't know what it might be. But again, really what I was
trying to do here is trying to frame policies that will get us much closer to where I
think Brazos County needs to be.
VOL 77 PAGE a4r,2,
18 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Sims: I think a copy of this needs to go all department heads and elected officials
immediately. Give them two weeks.
Langley: I prefer that it be sent electronically.
Sims: All right. That's fine. That all can be done. And give them two weeks in which to
look this over. Let's have another workshop before we finally get it posted on the
agenda. Ok? Does that sound logical to you? I mean is there any reason to have it
faster than that?
Caldwell: We've never had it to date so obviously no need to rush it...
Sims: Ok. I would like for them to have time to look them over and I urge yall too to
look it over. Come back to Eric with any changes that you see and he can make
note of those for us. And then we'll look it over and it'll take probably about three
weeks to get through with that and then we'll put it on the agenda with any
exceptions that we want to make to it. I like the idea; I guarantee General Motors
has one like this.
Caldwell: Well let's take... ...again, I don't know what the sensitivity of the voter
registration records might be. Is there anything in those voter registration records
that's particularly sensitive that should be leaked out?
McLeod: Social Security numbers.
Caldwell: So that is a good example. So somebody hacks our systems and they get these
Social Security numbers. Now there's been a breach and this non-public,
confidential information is out. If Brazos County has these policies in place, it
ain't enough. Not having these policies in place to try to address that sort of a risk
is definitely a no-no. But if you adopt these policies, you are only half way there.
You have to adopt the practice of implementing those procedures necessary to
enforce your policies and then you have to audit yourselves. And only then do
you have the protection that you need to defend yourselves in that sort of a
scenario. So you don't have anything right now. We have three policies and they
are entirely inadequate because they don't even address, say, physical facility
access. There's no policy in place that says that our data center even has to be
kept locked. Where does it say anywhere in writing that our data center over there
with all of the critical infrastructure for Brazos County even has to have a lock on
the door. It's just not written down. Now I'm sure it's implied, you would think
that everybody knows it's supposed to be locked but is that sufficient? If
somebody walks in there and snatches out a cable and we go down for five days
and that loss of business continuity causes other ramifications and you wind up
getting sued for it and we discover that there is not even a policy that says the
door has to be locked. And we discover that some child just toddled in there
because it wasn't locked. Because we didn't verify for ourselves by a periodic
random checks that, yes, this door is indeed locked. You don't have the protection
of being able to show these audit reports that, yes, every six month or, yes, every
VOL 77PAGE a~3
19 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
year at least, we went in there and randomly checked these doors to verify that
they are indeed locked and therefore we are complying with these policies. If you
had those reports and it was discovered that the door was left unlocked and that's
how the person got into the data center and pulled that plug, you can at least say,
"Well, listen, it happened to be unlocked that day, but we did have these policies
in place and we did have the procedures in place necessary to enforce these
policies and we did audit ourselves on a routine basis. So therefore we feel like
we have done everything we can to mitigate that kind of a risk."
Gallego: Would part of the practice be to make sure you educated employees on what it is
that is not allowed.
Caldwell: That is actually a separate policy in here. It's called a security training policy
Winn: I believe if you have within each office, passwords and security of your computer
system; like the voter registration cards will have telephone numbers and Social
Security numbers and birthdates that are confidential information, but we've got a
written record in the file that everybody knows it's confidential so you can't come
in and go in and check Judge Sim's voter registration card and get his Social
Security number or birth date. And even if you are going to send him a birthday
card, you are not eligible to go in and do that. But that's within security and I
think as long as you maintain fairly adequate security according to what the
election code sets out and the Judge might can correct me here but you have
fulfilled your duties. But now if you are haphazard and you've got it back there in
the back where anybody can go in to the hall and check any voter record that they
might see fit to check, then you are going to be liable.
Caldwell: See if somebody accuses you of being haphazard, how do you defend yourself.
And I'm saying that having adopted procedures and enforcing physical access
security policy, it's still not enough. You still have to have records,
documentation, that you have audited yourself to verify that you are indeed
practicing those procedures. At least show an attempt to adhere to your own
policy to physically secure those records.
Langley: I think it would be harder to prove that you was negligent than it would be to
prove that you was not negligent.
Sims: J.D. how many times have you heard me say this, "Big Chief notebook table and a
number 2 lead pencil, we'll be done with this." We could debate this all day long,
let's get all this information out to all the elected officials and department heads,
ok?
Caldwell: All right.
Sims: And make sure they see it and ask for anything that they would like to see
changed or any questions. You're going to be full of phone calls and emails and
VOL-7 ~ PAGE a & 4
20 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
everything else asking for clarification and so forth. But I think this is the only to
do it, let's get it done. How fast can you get it technology sent out?
Caldwell: Why don't I do this...
Sims: Give me a time frame that you would like to work with. It doesn't make any
difference to us.
Caldwell: Well, we can get it on our intranet and I can get word out to department heads
quickly that they are out there on the intranet and invite them to take a look at
them.
Sims: All right.
Langley: Is there a way, Eric, to send it as a Word document to where the department heads
can make changes on the documents and return them to you?
Caldwell: Sure.
Langley: You know like what their proposed changes might be.
Caldwell: Well, I can put links out there rather than emailing them and further clogging our
mail server; I can put it on our intranet as a Word document and people can click
on them and open up that word document.
Langley: There's a way in Word that you can make changes, don't make a final alteration,
and then you accept the change or reject it.
Caldwell: Right.
Sims: Or he recommends. That's good.
Caldwell: What I was about to say though is, again, one of the flaws of these policies is that
the policies themselves don't discuss these security ramifications with the
dissemination of these policies.
Speaker: What?
Sims: That's double talk there.
Speaker: (overtalking) the policy, you give them a way in, is that what you're saying?
Caldwell: Again, remember, the primary purpose of these policies is to address security
risks; exposure. And we don't want to give away the flaws in our current security.
In the back of your three ring binders, sandwiched between pink is a management
control agreement regarding DPSs FBI CHS system. Our law enforcement and
our prosecutors have access to this Texas Law Enforcement Telecommunications
V01 / ZPAGF. 21(IJr
21 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
System. In a nutshell it's a system that they use let's say, if you get pulled over
and they radio in your driver's license number, your car plates; dispatch will use
this TLETS system to query to see if you had any outstanding warrants. Because
there are these TLETS terminals here in the Brazos County Courthouse and
elsewhere and because those systems allow people to query and get into this
database of information, they have to have policies in place that say, "All right,
Linda Sowders in the Sheriffs Department, you are our terminal agent. You are
going to be responsible to verify that these TLET terminals in Brazos County's
Courthouse are not abused and that they are accessed only by those people that
have access to them. And she has to verify that that access is controlled according
to the FBI CJIS security policies. Well, what are the FBI CJIS security policies?
You go out on the internet and you do a search for the FBI CJIS security policies,
what are you going to find? You are going to find the opinion that those CJIS
policies should not be published on the internet simply because they deal with the
sensitivity of information. So I can put these draft policies on our intranet and I
will send out an email to elected officials and department heads and I will have to
simply ask them that these are not disseminated. Is it critical that these do not get
out into the public? Maybe not, but why chance it? Ok?
Sims: All right. Let's get it done so maybe within three weeks we can have this on the
agenda and we'll put together a meeting after we get enough response from the
elected officials and the department heads that we feel comfortable having
another meeting so that we can make some changes or exceptions or whatever.
That's kind of like what I heard this morning; there is a company over in Iraq that
has the responsibility of some of our ports here in the United States. Ports. It's a
company over there that's running our security. Judge, you had another question?
Langley: The only other question I had was in the development of these policies, how much
has Aporia...
Caldwell: Aporia Solutions.
Langley: ...participated in this? We are going to continue to use them I expect.
Caldwell: Well, perhaps we will continue to use them. By their own admission it's wise to
divide; certainly like the external auditing, it's wise to divide that responsibility or
share the wealth so to speak. You don't want the one single security firm
responsible for your entire security. Because that would equate to me doing all of
our auditing, period. Internal and external auditing. You don't want to rely on me
to do all that auditing. Not because you don't trust me but because...
Sims: Same mistakes crop up.
Caldwell: You shouldn't trust me to be thorough; you shouldn't trust me to be honest. You
want to have other people, you want other outside, independent eyes looking to
verify.
VOL-~ PAGE _~(~4
22 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.
Conner: (inaudible)
Caldwell: Now, I had hired Aporia to start us down this road and they provided me with a
template policies. Frankly, it was a little bit disappointing. It really wasn't what I
was wanting. What I got was what looked like kind of a smattering of
hodgepodge of different things selected off the intemet and weren't in the same
form or anything. So this has consumed every waking hour that I've had now for
too long already and I've had to put this more in the current format by myself.
Langley: I know. I've been trying to get a set of the local rules for the last eight years.
Caldwell: Aporia or somebody like Aporia would be a logical candidate to take a look at
these policies after they have been adopted, make additional recommended
changes to these policies but also to help develop procedures for the enforcement
of these policies. That's where I see a lot of value coming from somebody like
Aporia, an outside security firm.
Sims: Well I would think that elected officials, let's just take elected officials not
department heads, would appreciate what you have done, number one; number
two, would take this and say, "Hey, I can use 90% or I will comply with 90% of
these. Maybe this 10% is what I need to have negotiated with the Commissioner's
Court. If I were another elected official out there and I was the county clerk and
that was my main job, I don't want to mess around with putting a policy together
for my department. This would suffice just fine. Let's see what we get back from
everybody. Let's try and get that done within the next couple of weeks if we can
and then we can move on. Thank you for coming.
End of tape.
VOL27PAGF a&~A
23 of 23 Brazos County Commissioners Court IT Policies and Procedures Workshop.