4.4 SR 03-06-2023
Request for Action
To Item Number
Mayor and City Council 4.4
Agenda Section Meeting Date Prepared by
Consent March 6, 2023 Cal Portner, City Administrator
Item Description Reviewed by
Information Security Committee Charter
Update
Reviewed by
Action Requested
Approve, by motion, an update to the Information Security Committee Charter.
Background/Discussion
In 2017, the City of Elk River and Elk River Municipal Utilities jointly established an Information Security
Committee to review and manage the risks to shared IT hardware, software and equipment.
The city and utility have jointly reviewed the committee charter and have made a handful of minor changes,
primarily in regard to membership appointments and appointment timing.
The Utilities Commission approved the updated charter at their February meeting.
Financial Impact
N/A
Mission/Policy/Goal
Elk River Mission
Attachments
Information Security Charter
Redline version of Information Security Charter
The Elk River Vision
A welcoming community with revolutionary and spirited resourcefulness, exceptional
service, and community engagement that encourages and inspires prosperity.
Updated: August 2020
COMMISSION POLICY
Section: Category:
Governance Governance Policies
Policy Reference: Policy Title:
G.2g3 Information Security Committee Charter
PURPOSE:
Information security is managing risks to the confidentiality, integrity, and availability of
information using administrative, physical, and technical controls.
The Information Security Committee exists to help develop and maintain industry appropriate
information security policies and oversight. Because of shared hardware and resources, there
exists an overlap and shared risk for ERMU and the City of Elk River (City) operations.
Although governed autonomously, this shall be an advisory Committee to both the ERMU and
the City.
MEMBERSHIP:
This Committee shall be comprised of equal representation from ERMU and the City. From
ERMU this committee shall include a Commissioner and the General Manager. The General
Manager will appoint three additional members, at least one of whom will be a manager and at
least one will be an information technology employee. From the City this committee shall
include a Councilmember and the City Administrator. The City Administrator will appoint three
additional members, at least one of whom will be a manager and at least one will be an
information technology employee. At no time shall there be a quorum of the Commission or the
Council on the Committee.
The Commission shall appoint ERMU’s Committee member representatives annually following
the Commission election of officers during the March Regular Commission meeting. The
Council shall appoint its member annually. The Committee shall elect a chair annually. The
General Manager and the City Administrator shall serve as the authorized reporting
representatives for their respective governing bodies.
ROLE OF THE COMMITTEE CHAIR:
The primary role of the Committee Chair is to run the Committee meetings and act as committee
secretary. The Committee will adhere to the Current edition of Robert’s Rules of Order Newly
______________________________________________________________________________
Page 1 of 3
ERMU Commission Policy – G.2g3 Information Security Committee Charter
______________________________________________________________________________
Revised for all situations to which they are applicable and are not inconsistent with ERMU’s
bylaws, policies, and any special rules of order that the Commission may adopt; and similarly,
the Committee action shall not be inconsistent with applicable laws and policies which regulate
the City of Elk River. The Committee meetings may be open or closed to employees at the
discretion of the Committee Chair.
AUTHORITY:
Except as established in this Committee Charter, the authority of the Committee is limited to the
purpose of research and recommendation to ERMU and the City.
SPECIFIC DUTIES:
1. Policies and Procedures: Assist ERMU and the City in the development of information
security related policies. Review effectiveness of information security policy
implementations. Identify and recommend how to handle non-compliance. Assist with the
development of information security related procedures, standards, guidelines, and baselines
to the ERMU and the City. At least annually, provide timely reports including
recommendations regarding effectiveness of polices and procedures to ERMU and City
leadership teams.
2. Risk Assessment: Review industry appropriate information security trends to maintain an up-
to-date perspective on related risks and industry’s best practice risk mitigation methods.
Identify significant threats and vulnerabilities. Assess the adequacy and coordination of the
implementation of information security controls. Recommend methodologies and processes
for information security. Evaluate ongoing related legal and regulatory compliance changes.
Review incident information and recommend follow-up actions. At least annually, provide
timely reports including recommendation regarding risks assessment to ERMU and City
leadership teams.
3. Budget Development: Develop data needed for thorough evaluation of proposed information
security initiatives for budget preparation and consideration. Information shall include
options, risk evaluation, resource requirements, implementation timelines, and costs. At least
annually and coordinating with their respective budgeting process schedules, provide timely
reports regarding information security initiatives proposed for consideration to ERMU and
City leadership teams.
4. Education and Awareness: Function as an information security program champion providing
clear direction and unity in ERMU and City leadership teams’ support for approved security
initiatives and policies. Develop and implement plans and programs to maintain information
security awareness. Promote information security education, training, and awareness
throughout ERMU and the City.
SCHEDULE:
At a minimum, the Committee shall meet on an annual basis.
______________________________________________________________________________
Page 2 of 3
ERMU Commission Policy – G.2g3 Information Security Committee Charter
______________________________________________________________________________
TERMINATION:
The Committee shall exist as a joint effort between ERMU and the City until at such time either
the Commission or Council dissolve the joint nature of the Committee.
POLICY HISTORY:
Established August 8, 2017
Revised November 12, 2019
Revised February 14, 2023
______________________________________________________________________________
Page 3 of 3
COMMISSION POLICY
Section: Category:
Governance Governance Policies
Policy Reference: Policy Title:
G.2g3 Information Security Committee Charter
PURPOSE:
Information security is managing risks to the confidentiality, integrity, and availability of
information using administrative, physical, and technical controls.
The Information Security Committee exists to help develop and maintain industry appropriate
information security policies and oversight. Because of shared hardware and resources, there
exists an overlap and shared risk for ERMU and the City of Elk River (City) operations.
Although governed autonomously, this shall be an advisory Committee to both the ERMU and
the City.
MEMBERSHIP:
This Committee shall be comprised of equal representation from ERMU and the City. From
ERMU this committee shall include: a Commissioner, and the General Manager. a field
manager, an administrative manager, and an information technology employee. The General
Manager will appoint three additional members, at least one of whom will be a manager and at
least one will be an information technology employee. From the City this committee shall
include: a Councilmember, and the City Administrator. a field manager, an administrative
manager, and an information technology employee. The City Administrator will appoint three
additional members, at least one of whom will be a manager and at least one will be an
information technology employee. At no time shall there be a quorum of the Commission or the
Council on the Committee.
The Commission shall appoint ERMU’s Committee member representatives annually following
the Commission election of officers during the March Regular Commission meeting. The
Council shall appoint the City’s representatives its member annually in March. The Committee
shall elect a chair annually. The General Manager and the City Administrator shall serve as the
authorized reporting representatives for their respective governing bodies.
ROLE OF THE COMMITTEE CHAIR:
______________________________________________________________________________
Page 1 of 3
ERMU Commission Policy – G.2g3 Information Security Committee Charter
______________________________________________________________________________
The primary role of the Committee Chair is to run the Committee meetings and act as committee
secretary. The Committee will adhere to the Current edition of Robert’s Rules of Order Newly
Revised for all situations to which they are applicable and are not inconsistent with ERMU’s
bylaws, policies, and any special rules of order that the Commission may adopt; and similarly,
the Committee action shall not be inconsistent with applicable laws and policies which regulate
the City of Elk River. The Committee meetings may be open or closed to employees at the
discretion of the Committee Chair.
AUTHORITY:
Except as established in this Committee Charter, the authority of the Committee is limited to the
purpose of research and recommendation to ERMU and the City.
SPECIFIC DUTIES:
1. Policies and Procedures: Assist ERMU and the City in the development of information
security related policies. Review effectiveness of information security policy
implementations. Identify and recommend how to handle non-compliance. Assist with the
development of information security related procedures, standards, guidelines, and baselines
to the ERMU and the City. At least annually, provide timely reports including
recommendations regarding effectiveness of polices and procedures to ERMU and City
leadership teams.
2. Risk Assessment: Review industry appropriate information security trends to maintain an up-
to-date perspective on related risks and industry’s best practice risk mitigation methods.
Identify significant threats and vulnerabilities. Assess the adequacy and coordination of the
implementation of information security controls. Recommend methodologies and processes
for information security. Evaluate ongoing related legal and regulatory compliance changes.
Review incident information and recommend follow-up actions. At least annually, provide
timely reports including recommendation regarding risks assessment to ERMU and City
leadership teams.
3. Budget Development: Develop data needed for thorough evaluation of proposed information
security initiatives for budget preparation and consideration. Information shall include
options, risk evaluation, resource requirements, implementation timelines, and costs. At least
annually and coordinating with their respective budgeting process schedules, provide timely
reports regarding information security initiatives proposed for consideration to ERMU and
City leadership teams.
4. Education and Awareness: Function as an information security program champion providing
clear direction and unity in ERMU and City leadership teams’ support for approved security
initiatives and policies. Develop and implement plans and programs to maintain information
security awareness. Promote information security education, training, and awareness
throughout ERMU and the City.
SCHEDULE:
______________________________________________________________________________
Page 2 of 3
ERMU Commission Policy – G.2g3 Information Security Committee Charter
______________________________________________________________________________
At a minimum, the Committee shall meet on an annual basis.
TERMINATION:
The Committee shall exist as a joint effort between ERMU and the City until at such time either
the Commission or Council dissolve the joint nature of the Committee.
POLICY HISTORY:
Established August 8, 2017
Revised November 12, 2019
Revised February 14, 2023
______________________________________________________________________________
Page 3 of 3