Loading...
4.10 SR 11-06-2023�, Elk s �- River Request for Action To Item Number Ma Tor and CinT Council 4.10 Agenda Section Meeting Date Prepared by Consent A enda NovembeY 6, 2023 oe Stremcha, Assistant Cit�r Admitustrator Item Description Reviewed by IT Risk Assessment Proposal Cal Pormer, Ci r Administrator Reviewed by Action Requested Approve, byT motion, the CityT of Elk River (80%) and Elk River Municipal Utilities (20%) cost share parmership for an IT Risk Assessment. Background/Discussion The cityr and ERMU have made numeYous improvements over the past seven years to our IT infYastructure. This risk assessment `vill identifyT syTstem vulnerabilities and provide staff with a road map to prioritize anyT future infrastructure improvements. During the JulyT 27 budget workshop, the Council consensus was to move this project from 2024 to 2023 expenditures using anticipated 2023 General Fund budget surplus funds. Financial Impact $24,800 fYom the anticipated 2023 General Fund budget surplus. Mission/Policy/Goal Responsible for everyT dollar — good ste�vards Attachments ■ IT Risk Assessment Proposal The Elk River Vision A 2a�elcolning co�nlnunity 2a�ith T evolutiona� y and spizzted T esou� cefulness, exceptional se�vice, and coln�nunity engagelnent that encou�ages and ins�iz•es pTo�pe�zty. PowEREo ar �I'1 ���� Update�l• January 2023 SECURE° L3 Assessment with Roadmap Prepared For City of Elk River Prepared for: Seth Calvin Director of Information'fechnology City of Elk River Prepared By: Jennifer Thompson j thompson�frsecure. com (651)505-4473 Date: 09 / 18 / 2023 City of Elk River L3 Assessment with Roadmap 09 / 18 / 2023 Seth Calvin, Director of Information'fechnology City of Elk River 13065 Orono Parkway Elk River MN 55330 Thank you for your time and consideration of this proposal. At FRSecure, we are called to a mission of fixing the broken security industry. Our focus resides in helping our peers and clients master the fundamentals of information security through establishing a common language, providing low or no cost training and resources and by building the very best security professionals in the industry. Our objectivity in guiding you rests in our product agnostic stance and the core values shared by each and every member of our team. Whether or not we formally engage, please count on us to be a resource and help us keep you informed as we make our training and expertise available to the community. Our passion for information security as our sole focus is the driving force to our current and future success. We hope our proposal today adds to our already positive relationship, where our mission is put to wark meeting your information security objectives. Respectfully yours, Evan Francen FRSecure Founder & CEO CONFIDENTIAL INFORNIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Righ ia' Re�erve3. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap �� S E� lJ I� E�R Security Experts on a �s��n The information security industry is broken. We are on a mission to fix it. By staying true to our mission, our commitment to product agnostic services and living our core values, we've developed a community of like-minded individuals, clients and partners. All we do is information security. � � R�G IQNAL C]FFICES � � SC3C2 AUC71T SUCCESS CISSP STUDENTS ,� � PaDCASTS � �MPLQYEE� C�IENTS Securi�y Risk fi�sse�sment • Virtual CIS� Remediativn Planning & Suppart PCI D5S Readines� HIPAA Campliance S�]C Z Readines5 iVI�T & CMIWIC Compliance � � ' � ,- _ Network Penetration Test�ng � Web Applic�t�an Penetration Testing p 1Nireless 119etwork Penetrati�r� Testing Physical Penetratic�n Testing �lulnerak�ility Testing Svcial Er��ine�ring Digital Forensics . I��cicf��nt �c,�,;C�,�,���;F, Additional Information Available On FRSecure.Com • Team Certifications • Team Profiles • Industry Expertise • r'ree'1'ools • Blogs & Security Advice • CISSP Mentor Program Details CONPIDEN'I'IAL INFOI21bIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Righ ia' Re�erve.i Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Statement Of Work The information contained within this document is a proposal and formal statement of wark, if accepted by City of Elk River by execution of this document. Engagement Overview Purpose and Objective Proposed Solution fiming A comprehensive assessment of the organization's Information Security Risk Assessment 6-8 weeks information security posture • Administrative Controls • Physical Controls • 1'echnical Controls • Internal and Ea�ternal Vulnerability Scan • S2Score & Reporting Detemiine the Who, What and When for addressing Roadmap 1-2 weeks identified risks. CONFIDENTIAL INFORMATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Righ ia' Re�erved Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Information Security Risk Assessment FRSecure's information security risk assessment is meant to find the measurable baseline for your security posture and prioritize remediation efforts far the most impactful items. A security assessment is always the first step to building a functioning, measurable security strategy. � SECURITYSTUDIOT Ezecutive Summary Report [� Flh�i�M1liv�lreportinre�rvi�.iirivelerrlercM1�i��iliatlaysuutwnerctl+e�rgan�iza��ion's�intorinatinnscuir�ity6�ogra.m axcn,ls antl w�n¢r� i� is AclEcicn�, Management S�mmgry Repar� L� TM1is�oporlprovitlesamorei�u-deplM1look�iiiloe�dipM1asesollM1eassossme��I,M1�i�jM1ligM1tiii�streny�tM1snntl ��eahnesses Il�at affect I lie uve�all 525CORE_ Full Report u Written�vilM1inform,lipn5e�urilyprqipsS�io�al5inmintl.ih�isreporl.breaksdowniTedela�ilsPfthe9�gd��ilaf�ip�is �ss��:�.,�m�� ��.aua�ng�oois, mg�c, aaa rAamgs. Aetlon Plan [_] 7hls repar� inclutles recommendallons Ihal can be used as a geide ladevelop detailed ae�ian plans rhat address Ihe Idenlllied risks. Week 1 Week 2-3 • • ��T�� NIST Cybersecurity Framework �.,:� u oe�cee 0.pr"1,292� } AGr].>0}p �i. �� � ,zozo } Week 3-6 Documentation � Observation Interview Technical Testing 27�01 ,,�;s S25�ORE Cp �O O� Q ,a`� \ \ � Y ` ��\ - z� 300 499 � � ... � +, ... .. ��:; b60 ]T9 �BO 850 Week 6-g IndefinideEy 1Norkbook & S��n� Info peli+very Suppor� Scheduling Gathering 1-2 Haurs i Hour 1-2 Days 1 Haur As Needed Detailed information available in the Approach and Process section at the end of the proposal. CONFIDEN'I`IAL INFOI2IYIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Righ ia' Re�ervee. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Security Program Roadmap Building a functioning, successful security strategy lies in planning and preparation. Once risk is measured and recommendations are identified, the neat step is to determine how to address the identified risks, determine who will own the execution of those decisions and when to act. The security program roadmap is designed to facilitate and document each step. Inte�n�l Risls� Id'entified � []�rtsau�ree `- - CONFIDENTIAL INFORMATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. * � 1�N'h�en pl�� Securi#+� Rc►adrt�a p � Copyright 2022 FRSecure LLC, All Righ ia' Re�erve�i- Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Engagement Scope Details Engagement Scope Security Risk Assessment and Roadmap - L3 - Number of users - Approximately 285 - Number of physical locations - Elk River, MN Onsite - Number of internal IP addresses - Approximately 600 Laptops/Warkstations/Servers/Netwark Devices No Agent Scanning - Number of active ea�ternal IP addresses - 7 Engagement Planning Engagement Kickoii Date Security Risk Assessment and Roadmap - L3 2-3 months from SOW signature The success of this engagement will be assured by your Key Account Manager in partnership with our Information Security Experts and Project Management'1'eam. We encourage you to include the entire team in relevant communications, but please consider your Key Account Manager as your go-to far anything you need. Every engagement begins with formal initiation procedures. 1. Introductions to respective teams and their roles in the engagement 2. Establishment of communication preferences 3. Confirmation of scope and service levels expectation 4. Confirmation of timing and constraints 5. Engagement completion expectations and due date for deliverables Support Team Name Title Contact Jennifer Thompson Senior Account Executive jthompson@frsecure.com Darin Meyer Manager of Client Success dmeyer�a,frsecure.com Charles Killmer Senior Security Analyst & Solution Architect ckillmer�frsecure.com Executive Leadership Team John Harmon President jharmon�frsecure.com Vanae Yearson Chief Financial Otticer vpearson�trsecure.com Oscar Mixilcs Chief'1'echnology Officer ominks�frsecure.com Drew Boeke Chief Revenue Officer dboeke@frsecure.com CONFIDENTIAL INFORMATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Righ ia' Re�erved. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Engagement Investment Name Price QTY Terms Subtotal Risk Assessment Options RiskAssessment and Roadmap - L3 $31,000.00 1 $31,000.00 Total (USD) $31,000.00 This Proposal Expires In 60 Days Client Acceptance City of Elk River Signature of Authorized Agent Billing EmailAddress Contact Information Date FRSecure LLC Attn: Vanae Yearson 6550 YorkAve S #500 Edina, MN 55435 Phone 612-230-0427 Email: vpearson�frsecure.com CONFIDEN'I`IAL INFOI2IYIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Righ ia' Re�erve�i.. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Assumptions FRSecure will provide all of the materials required far the completion of this engagement. FRSecure will rely upon experience, testing, observation, and interviews with City of Elk River employees to assess the completeness and effectiveness of City of Elk River's information security program. FRSecure will follow all guidance provided by the previously referenced standards far the completion of the work. The FRSecure information security analyst will review a variety of information including, but not necessarily limited to prior warking papers, reviews and current City of Elk River diagrams, policies, processes, and procedures. Assessments that have been conducted follow the standards as noted in the National Institute of Standards in Technology Cybersecurity Framewark (NIST CSF), ISO/IEC 27002:2013 international standard, Center for Internet Security (CIS) Controls, & NIST Special Publication 800-53 (NIST SP 800-53). Change Management Process Changes can be made to the scope of this engagement and Statement of Wark. Any changes requested by either party must be in writing and signed by both parties indicating acceptance. Engagement Related Expenses All engagement related expenses will be billed to the client following FRSecure Client Project Travel And Expense Policy. Invoicing Details Invoicing will fall under one of the following three terms. 1. For one-time project agreements (i.e. assessments), a down payment invoice of 50% will be sent upon acceptance of this proposal and statement of wark. The balance is due upon engagement completion of all deliverables to City of Elk River. 2. Far multi-year ar multi-project agreements, a down payment invoice of 50% will be sent at the beginning of the year in each year ar term in which the project is pertormed. The balance is due upon engagement completion of all deliverables to City of Elk River. 3. Monthly or quarterly recurring consulting agreements, or projects with an amortized payment schedule, will be invoiced quarterly starting on the 1 st day of the first month services begin. • City of Elk River may cancel this engagement at any time pursuant to Section 2.D of the Master Services Agreement between City of Elk River and FRSecure. Cancellation or rescheduling of an engagement by City of Elk River may result in additional fees. • Meetings cancelled by City of Elk River less than 5 business days prior to a FRSecure resource commitment of four or more hours, will result in a reschedule fee of $1,000 for tnne and expenses lost. Note: Przces shown do not include sales tax, if applicable. Please note, tailure by City of Elk River to respond to repeated attempts at communications by FRSecure within 90 days of initial communication of project initiation will result in project engagement closeout and City of Elk River will be invoiced far full remaining balance due as described in this statement of wark. CONFIDEN'I`IAL INFOI2IYIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Righ ia' Re�erve�i. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Practice Lead Senior Consultant BRAD NIGH 6550 YorkAve S#500, Edina, MN 55435 linkedin. com/in/bradnigh bnigh�frsecure.com (952)467-8849 �� - � � �� /` , � � 9 j- 1 � i���/,, .� PROFILE Brad is a passionate information security expert with 20+ years of overall IT experience, including 10+ years of IT management and leadership experience warking in 24/7 environments that required top tier technical skills, and efficient project management. In addition, Brad has several years of experience warking in highly regulated industries that are required to comply with PCI-DSS, HIPAA, HITECH, Sarbanes-Oxley, OCC, and various state regulatory requirements. At FRSecure Brad leads the Professional Services practice, serving businesses of all sizes and in all industries by cooperatively solving the complex issues surrounding information security. Brad's goals are ensuring consistent methodology, nnproving our existing programs, and innovating and continual development of new offerings. EDUCATIONAL & COMMUNITY SERVICE ENGAGEMENTS • CISSP Mentorship Program • FRSecure Workshop Series • ISC2 Safe & Secure Online Volunteer • Wayzata Public Schools COMPASS Mentar (Cybersecurity) CERTIFICATIONS • Certified Information Security Manager (CISIV� • Certified Information Systems Security Professional (CISSP) • Certified Security Studio Analyst (CSSA) • MCSA: Windows Server 2012 • 1'1'1L v.3 Foundations • Certitied Incident Handler (ECIHv2) • CMIVIC CertiYied Registered Practioner (CMMGRP) CONFIDENTIAL INFORNIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap va.Y�� �AYV��;�;5r�iui� Based on the conversations between FRSecure and City of Elk River to date, we believe we are an excellent fit for your engagement. Here are some additional reasons we believe you should select FRSecure: • FRSecure's Methodology — FRSecure has developed a proprietary approach to assessing information security risks. It's more than a checklist of questions and recorded answers. Our approach gives you a full picture of your risks - prioritized and rated - with recommended solutions, so you know which security investments will have the greatest impact. • FRSecure's Project Leader — All of our project leaders have more than 15 years of information security experience as a leader in, and consultant for hundreds of companies ranging from the Fortune 100 to SMBs. BIO's for our project leaders are available upon request. • Full Transparency — FRSecure strongly believes in empowering our customers. The more knowledge transfer that occurs during our engagement, the more value our customers recognize. FRSecure fully discloses the methods, tools, and configurations used to perform analysis wark for our customers in the hope that they can easily adopt our processes for their future benefit. • Product Agnostic — FRSecure does not represent any third-party products or services; on purpose. Our projects and recommendations stand on their own, with no ulterior motive to sell you things you don't really need. Our Information Security Principles are fundamental to our everyday work and help us to stay focused on our mission to "Fix the Broken Industry". All our Principles are able to stand by themselves, but they are also solidly interrelated. 1. A business is in business to make money Information security must align with business objectives. 2. Information Security is a business issue Information security is NOT anlT issue. 3. Information Security is fun That's right, we said "FUN"I 4. People are the biggest risk Not technology. 5. "Compliant" and "secure" are different We shouldn't confuse the two. 6. There is no common sense in Information Security If there were, we would have better information security. 7. "Secure" is relative One of many reasons for ongoing measurements and comparisons. 8. lnformation Security should drive business Identify and focus on information security benefits. Information security shouldn't just be a cost-center. 9. Information Security is not one size fits all No two businesses are exactly alike. 10. There is no "easy button" So stop looking for one. Client references available upon request CONFIDENTIAL INFORNIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Information Security Risk Assessment With S20rgOO And S2ScoreOO The S2ScoreOO, available through the SecurityStudioOO software platform is the most objective and comprehensive measurement of information security risk available in the market. It was designed by engineers at FRSecure, who average more than 15 years of information security experience, with these specific objectives in mind: • Serve as the foundational risk score and measurement. • Based on risk. The most effective way to manage information security is based on risk, not on specific controls that may ar may not fit for your organization. • Easy to understand. Easy to understand and effective are not mutually exclusive. In fact, they usually go hand in hand. The most effective information security programs are typically simple and effective. Complexity is often the enemy to good security. • Comprehensive. Information security is not an IT issue; it is a business issue. • Objective. Scaring is as objective as is possible given what we know about threats, vulnerabilities, exploits and risk in general. Each assessed control is given a risk metric based on professional opinions, best practices, and real-life data. • Clear and free from technical jargon. Terms like "NextGen", "Internet of Things" (IoT), "Advanced Persistent Threats" (APT), eta are all avoided as much as possible. • Industry accepted and credible. The assessment leverages and references current security framewarks and standards such as ISO/IEC 27001:2013 and the NIST Cybersecurity Framewark (CSF). This is very good news for organizations that have built their information security programs per one or more of these framewarks and helps to lend to the credibility of the assessment. • One-stop. The type of assessment that can be used to measure the ei�ectiveness of the security program, provide high-quality next steps (or recommendations), demonstrate regulatory compliance (HIPAA, GLBA, and others), and allow for etfective cyber insurance underwriting * *NOTE: The S2ScoreOO is approved for cyber insurance underwriting submission through Node International and Lloyd's of London. Check with your governing authority to ensure an "update" assessment is compliant before conducting this type of assessment. * Updates must be performed within 12 months upon receipt of deliverables from the previous S20rg * Major infrastructure changes, mergers/acquisitions or other fundamental changes to the environment will require a re-scoping of the project. The S20rgU Assessment is built to be the definitive and best information security risk assessment methodology available with reporting designed to be easy to manage and actionable. Each phase, control category, control subcategory, and the overall S20rgOO assessment is calculated based upon 1. The size of the organization 2. The industry in which the organization operates 3. Historical threat and incident data obtained from a variety of source. Scope The intended scope far the S20rgOO is the entire organization. Information security is a very broad topic so to ensure a comprehensive assessment, that is still easy to understand, the S20rgOO assessment is segmented into four (4) phases. In-Person Assessment Remote Assessment Assessor does an on-premise walkthrough of the facility. Assessor requests a look at key areas of the facility from staff over video Review includes a facility walkthrough and the Assessor is able to conference. validate controls such as: Review includes what client provides the assessor a view of. * facility visitor process. Recommended for clients that have had an independent security review within * clear desk/clear screen practices. the last 12 months. * doors to sensitive areas are locked. No travel costs. * other exceptions from policy. Client covers assessar travel costs. CONFIDENTIAL INFORMATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap The four phases of a S20rgOO assessment are: • Phase 1: Administrative Controls — The "people" part of security, including risk management, security governance, policies, standards, training and employee awareness. • Phase 2: Physical Controls — Physical controls are an essential and often overlooked part of your security strategy. How much does your anti-virus protection mean to you if someone steals your server? • Phase 3: Technical Controls (Internal) — We ai�ectionately call this "the gooey center". Most organizations do a pretty good job at securing the technical perimeter (firewalls, intrusion detection, etc.), but sometime neglect the controls that are essential for an effective defense-in-depth strategy. • Phase 4: Technical Controls (External) — This category covers how effective your organization is at securing the perimeter of your netwark. The S20rgTM process and simple and efficient. We understand that our clients have other wark to do, so the process needs to be focused and time- sensitive. Each phase of the S20rgOO assessment is slightly different in the manner that information is gathered and assessed. Phase 1— Administrative Security Controls Assessment Administrative Controls form the framewark far managing an etfective security program and they are sometimes referred to as the "human" part of information security. Administrative Controls inform people on how organizational leadership expects day-to-day operations to be conducted and they provide guidance on what actions or activities warkforce members are expected to perform. Common Administrative Controls include policies, awareness training, guidelines, standards, and procedures. Administrative Controls are derived ti�om the NIST Cybersecurity Framewark (CSF), ISO/IEC 27001:2013, NIST SP 800-53, and the CIS Critical Security Controls for reference, comparison, gap analysis, and risk rating. Where there are applicable gaps, the following metrics are applied using the S20rgOO proprietary algorithm: • Information Security Maturity ("ISM") - a measure of control quality and maturity, • Likelihood of an adverse event or realized threat, and the potential lmpact suffered by the organization; resulting in a Risk Rating. CONFIDENTIAL INFORMATION .. Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Phase 1— Administrative Security Controls is further segmented into the following 10 control categories which contain a total of 45 subcategories: •� 7.1 Mobile device policy 7.2 Teleworking 7.3 Documented operating procedures 7.4 Change management 7S Controls against malware 7.6 Information backup 7.7 Event logging 7.8 Installation of software on operational systems 7.9 Management of technicaV vulnerabiVities 7.10 Information systems zudit controls 7.11 Network security 7.12 Information transfer policies and procedures 7.13 Information security requirements analysis and specification 7.14 System acceptance testing 7.15 Third party security risk management 8.1 Incident managemerrt roles and responsibilities 8.2 Incident respanse procedures 9.1 Planning information security continuity 9.2 Reco�ery pBac� details . . . � Identpfication of applicable legislation and contractual 10.1 requirements 10.2 Privaey and protection of personally identifia6le information 10.3 Independent review of information security 10.4 Compliance with security policies and standards 10.5 Protections against financial fraud The Administrative Controls are assessed through: Documentation review Interviews with the FRSecure Analyst Observations made by the FRSecure Analyst CONFIDENTIAL INFORNIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Phase 2— Physical Security Controls Assessment Physical Controls are the security controls that can often be touched and provide physical security to protect your information assets. Common physical controls include doors, locks, camera surveillance, and alarm systems. Phase 2 of the S20rgOO assessment is a review of these, and other, physical security controls and associated risks. Focus far the Phase 2 of the assessment will be on where critical information resources are physically located. ., �� Phase 2 takes the following into consideration to generate a definitive risk score: . . .. 1.1 Crime Index . . � 2.1 Natural Disasters . . 3.1 Planning and preparedness 3.2 Perirneter controls 3.3 Entry controls 3.4 Public spaces 3.5 Office spaces 3.s Restricted areas 3.� Delivery and loading areas . . � � � . . 4.1 Equipment siting 4.z 5upporting utilities 4.3 Cabling security 4.4 Maintenance 4s Housekeeping 4.� Clear desk/screen The Physical Controls are assessed through: 1. Documentation review 2. Interviews with the FRSecure Analyst 3. Observations made by the FRSecure Analyst CONFIDEN'I`IAL INFOI2IYIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Phase 3— Internal Technical Controls Assessment Internal '1'echnical Controls are the controls that are technical in nature and used within your organization's technical domain (inside the gateways ar firewalls). Internal technical controls include things such as firewalls, intrusion prevention systems, anti-virus software, and mobile device management (MDM). Phase 3 reviews these controls using a combination of interviews with staff and use of tools to perform: • Vulnerability scanning on the internal netwark(s), • Tests for password policies, system permissions, required auditing and system settings that are common in all netwarks. • Tests for user auditing settings, such as their password complexity and logging access tailures and logons that are common in all netwarks. • 1'ests against known good configurations Phase 3 of the S20rgOO assessment consists of the following control sections: ►r FRSecure discloses the tools, methods, and contigurations employed during testing to enable your personnel to conduct future testing on a regular basis. The Internal'1'echnical Controls are assessed through: 1. Documentation review 2. Interviews with the FRSecure Analyst 3. Observations made by the FRSecure Analyst 4. 1'ools run by FRSecure or your personnel CONFIDENTIAL INFORMATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Phase 4— External Technical Controls Assessment Ea� ternal technical controls are technical in nature and are used to protect outside access to your organization's technical domain (outside the gateways ar firewalls). Eaternal technical controls consist of search engine indexes, social media, DNS, port scanning, and vulnerability scanning. The primary objective of the Eaternal'1'echnical Controls Assessment and testing exercise is to identify significant vulnerabilities that pose a risk of unauthorized information disclosure, alteration, and/or destruction through publicly accessible* information resources. *Publicly accessible is defined as those resources which are purposefully or accidentally made available through the Internet. Phase 4 of the S20rgOO assessment consists of the following control sections: The Ea�ternal Technical Controls are assessed through: 1. Documentation review 2. Interviews with the FRSecure Analyst 3. 1'00l and manual testing conducted by the FRSecure Analyst CONFIDENTIAL INFORNIATION r. Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap Assessment Deliverables City of Elk River will be provided with the following deliverables as part of this engagement: S2Score� One of the most important end results from the S20rgOO assessment engagement is your S2ScoreOO . You will be provided with your overall S2ScoreOO as well as a S2ScoreOO for each Phase, control category, and individual control sub-category. This is important for your organization as you identify your most significant risks and prioritize remediation. The S2ScoreOO can be used to communicate your "risk score" to interested parties and is a definitive risk calculation. The ❑�erall 5�5CQf�E �ar risk r�tingj is G78.77. The S2ScoreOO is represented on a scale of 300 — 850. • 300 — 500 is generally considered to be `�ery Poor" • 501 — 599 is generally considered to be � • 600 — 659 is generally considered to be �ur" • 660 — 779 is generally considered to be "Good" • A score equal to or higher than 780 is generally considered to be Most organizations should be striving to attain and maintain a score of 660 ar higher. CONFIDENTIAL INFORNIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap S20rgOO Executive Summary Report The S20rgOO Executive Summary report is written in plain English with comparisons to other organizations; with a snnilar profile. It provides the necessary information to quickly understand where your organization's information security program excels and where it is deficient. The snapshot views allow solid decision-malculg now (tactically) and into the future (strategically). S�SC�RE 5cal� ��S��RE A�rera�� �l�crr�s� In�du�tries Industry: All Indus#ries The avera�ge 5�5CC}RE Gs 76fi.05 �cross all industries. Aceording to aur calculsti4ns, there is rc�ughlyr 11.41 more risk in th� Fassa Uni�rersity ir�formation seeurity progr�m than other pragrams in si�ilar �rgani�atians. �2��C3RE ph�se-by-pha,se Camp�rison There are f4ur ph�ases in a Full 525C[�€�E :. An "accept�b@e" le�el of s�ecurity is C6C1. 70�.�1� � _�__=='�39�.8�"__=--------------�_______ ___—__ ___. 5[I0.[!0 �OU.Ua �� Adniinistrative Physic�l Controf� Internal Tec:hnira� External T�echni�al Contrnls �nntrols �nn#rols CONFIDENTIAL INFORMATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrv¢d. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap S20rg� Information Security Assessment Full Report The S20rgOO Full Report is written with information security professionals in mind. All the details involved with what was assessed, how it was assessed (including tools and logic), findings, and recommendations are provided. The S20rgOO Full Report is also supported with numerous other documents, technical testing results, and raw data. All supporting information is referenced and provided. How to Use This Report There are four primary purposes for this report: 1. 1'o understand how mature your organization's information security program is. 2. fo understand where your organization's information security risks are. 3. To build a plan of action on how you should address your most significant unacceptable risks. 4. To demonstrate compliance with industry regulations (HIPAA, GLBA, and others) and customers/business partner requirements In order to gain the most benefit from the contents of this report, it is recommended that you read the report in its entirety and develop a plan of action. Information security is a lifecycle discipline that requires a long-term commihnent. In order to get the most benefit ti�om this report, create an action plan for your organization. CONFIDENTIAL INFORMATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrvad. Document ID: FRSQ 5515 City of Elk River L3 Assessment with Roadmap S20rg� Roadmap The primary purpose of the Security Program Roadmap is to empower you to be able to choose which tasks you want to take on and which tasks you want to assign to ea� ternal resources, and provide a strategic Roadmap for completion of all tasks. All actions are measurable and easily communicated. �nternal Risks frl e�nt i�ed � vC15� � MSP � �Ctwtsaurce Y l J 5�uri#y Rla �d�pl Improvement comes through putting the recommendations from the assessment into practice by: 1. Making risk-based decisions about what to do with each recommendation. 2. Assigning responsibility for actions that must be taken. 3. Determiiung the priority for such actions and assigning deadlines/timelines. Activities far the Roadmap are driven ti�om the S20rgOO assessment. The FRSecure Analyst creates the initial roadmap (or plan) for your information security program over the next 12, 24, and 36 months The Security Program Roadmap tackles the planning of "what", "who", and "when" far information security improvement: What are we going to do with each of the findings and recommendations from the S20rgOO ? There are four viable options for decision- making: Accept — the risk "as-is" and take no corrective actions but continue to monitor the risk • Mitigate — the risk and do what the recommendation says (or similar) • 1 ransfer — the risk and/or defer it far insurance (or similar) • Avoid — the risk and stop doing the actions that led to the risk in the first place Who is going to do the actions and carry out the decisions that were made? Decisions such as"Mitigate" and "Avoid" made in the previous step will require somebody to do something. Some of the tasks and/or projects can be done internally with your own resources and some of the tasks and/or projects will require outside assistance. Those tasks and/or projects that require outside assistance can be assigned to the vCISO (Step 4) and some of the tasks and/or projects can be assigned to another party. When will the actions need to be taken to achieve your goals? It's best to assign the tasks and/or projects to a timeline based on quarters to accommodate day-to-day operational challenges along the way. The information ti�om S20rgOO and the Roadmap can be easily communicated to stakeholders (Board of Directors, executive management, exasnixiers/regulators, customers, etc.) includes: • What our current S2ScoreOO is. • What our S2ScoreOO goal is. • What tasks and/or projects are necessary to meet objectives. CONFIDENTIAL INFORNIATION Tltis document may contain information that is privileged, confidential or otherwise protected from disclosure. Dissemination, dis[ribution or copying of this document or the information herein is prohibi[ed without prior permission of FRSecure. Copyright 2022 FRSecure LLC, All Ri@iu`� ResPrvad. Document ID: FRSQ 5515