RES NO 06-02-2026 CITY OF VAN BUREN,ARKANSAS
RESOLUTION NOUL 1 26
BE IT ENACTED BY THE CITY COUNCIL, FOR THE CITY OF VAN BUREN,
ARKANSAS,A RESOLUTION TO BE ENTITLED:
A RESOLUTION ADOPTING THE REVISED PERSONNEL
HANDBOOK GOVERNING CITY EMPLOYEES FOR THE CITY
OF VAN BUREN, ARKANSAS, AND REPEALING THE
EXISTING PERSONNEL HANDBOOK; AND FOR OTHER
PURPOSES.
WHEREAS, it is necessary to update and revise the existing Personnel Handbook for the City of Van
Buren to conform to changes in law and policy;and
WHEREAS, a copy of the revised change to Chapter 7 MISCELLANEOUS INFORMATION, adding
a new section 7.8 City of Van Buren Cybersecurity Policy and Incident Response
Protocol in the Personnel Handbook is attached hereto as "Exhibit A" and all employees
shall receive a copy of the revised personnel handbook page.
NOW, THEREFORE, BE IT RESOLVED BY THE CITY COUNCIL OF THE CITY OF
VAN BUREN,ARKANSAS,THAT:
SECTION 1: Section 7.8 City of Van Buren Cybersecurity Policy and Incident Response Protocol
under Chapter 7 MISCELLANOUS INFORMATION of the existing Personnel
Handbook will be added to describe the expectations of each city employee regarding
cybersecurity and how to respond to a possible cybersecurity incident.
SECTION 2: The revised Personnel Handbook for the City of Van Buren,Arkansas, section 7.8 City of
Van Buren Cybersecurity Policy and Incident Response Protocol is attached hereto as
"Exhibit A" and is hereby adopted and the existing Personnel Handbook dated February
24,2026,is hereby repealed.
IN WITNESS WHERE F, the Cit o Van Buren, Arkansas, by its City Council, did pass,
approve, and adopt, by a vote of for and,6against,the foregoing Resolution at its regular meeting
held on the 221 day of June 2026.
O\�G\erk Treds�
Joseph P. IUrst
City of Van Buren Mayor
c
ATT �ryCounty,P� APPROVED AS FO
Shawnna Reyno ds Jacob Howell
City Clerk/Treas rer City Attorney
City of Van Buren
Cybersecurity Policy and Incident Checklist
Effective June 1 , 2026
PURPOSE
This policy establishes the minimum cybersecurity requirements for the City of Van Buren based on the standards
created by the Arkansas Cyber Response Board (ACRE) pursuant to ACT 846 of 2023. It also incorporates
recommendations by the Arkansas Legislative Audit(ALA) Information Services Best Practices(2025). These
standards are designed to enhance the security posture of the City of Van Buren's systems and data while
complementing existing internal controls.
The City of Van Buren desires to exceed all recommendations from Arkansas Legislative Audit(ALA)and Criminal
Justice Information Services (CJIS) by following as closely as possible the standards set forth in Computer Information
Systems (CIS)guidelines which,for the most part, meet all required criteria, in excess.
This policy applies to all employees, contractors, and third-party service providers who access any City of Van Buren
systems, networks or data. It covers authentication, data protection,training, access control, patch management and
governance practices. The Cybersecurity Policy and Artificial Intelligence Policy are meant to work hand in hand to
provide the City of Van Buren with as much protection as possible at any given time.
The City of Van Buren will comply with the following cybersecurity standards and best practices based on the ACRB
minimum standards.
Multifactor Authentication (MFA)
All employees with access to vital systems and services shall use multifactor authentication (MFA)This includes:
• Access to web-based platforms such as financial services (Example: online banking, investment portals),
cloud-based applications and web-mail services (Example: Gmail.com, Outlook.com).
• Accounts with elevated privileges, including administrative, cloud service, and vendor system accounts (both
on-premises and cloud-based).
• Accounts used to manage application user security.
• Service accounts are exempt from MFA requirements.
Offline Data Backups
The City of Van Buren will maintain offline backups of critical systems and data. These backups will be tested
biannually(March—September)to ensure integrity and recoverability.
K&S computing and the City Clerk-Treasurer's office will maintain a backup schedule,test logs, restoration
verification reports to include date, system tested, outcome,and responsible personnel.
Cybersecurity Awareness Training
All employees will complete monthly cybersecurity awareness training provided by Huntress. The training will include
topics such as phishing prevention, password hygiene, secure data handling, and incident reporting procedures.
K&S Computing and the City Clerk-Treasurer's office will maintain a training roster with employee names, completion
dates and training modules covered.
A monthly report will be provided to all Department Heads with the following expectation in regards to departmental
performance.
• Any employee who has not completed monthly cybersecurity training will be expected to complete such
training within five (5) business days of notification.
• Any employee who has been compromised in the testing scenarios will be expected to provide a statement of
explanation to be included with the monthly reports that will be available to Arkansas Legislative Audit upon
request. A"compromised learner" refers to those employees that have initiated the highest-risk action
available in the phishing scenario, either by clicking on a link or if available,entering information into a landing
page. Other disciplinary actions may apply if there is a pattern of system compromising actions.
Password Management Standards
The City of Van Buren will set a standard for creating, protecting and changing passwords such that they are strong,
secure and protected. Passwords should not be based on a user's personal information or that of his or her friends,
family members, or pets. Personal information includes logon ID, name, birthday, address, phone number, social
security number or any combination thereof.
• Minimum password length of 8 characters
• Passwords changed every 90 days.
• Passwords shall not be stored in plaintext.
• Enforce password complexity requirements (combination of upper-and tower-case letters, numbers and
special characters)
• Prevent reuse of the last 24 passwords or phrases.
• Lock user accounts after five unsuccessful login attempts.
• Default passwords for new users shall require a forced reset upon first login.
Patch Management Standards
The City of Van Buren will maintain a patch management process that includes
• Applying critical updates and patches within 14 days of release
• Applying all other updates and patches within 30 days
• Obtaining patches, upgrades and vendor release only from trusted sources.
• Conducting periodic audits to identify and remediate systems and appliances missing updates.
Compliance Review
The Cybersecurity Policy will be reviewed annually and updated as necessary to reflect changes in technology,
emerging threats, and regulatory requirements. Non-compliance may result in disciplinary action and could affect
participation in the Arkansas Self-Funded Cyber Response Program. Additionally, it may trigger legal or regulatory
consequences.
ARKANSAS SELF-FUNDED
CYBER RESPONSE PROGRAM
Arkansas Act 846 of 2023, A.C.A. 5 19-5-1159, created the mandatory Arkansas Self-Funded
Cyber Response Program. Arkansas municipalities are required to participate in the
program, which provides coverage.
for damages/losses caused by a cyberattack committed against a participating
government entity. The Arkansas Cyber Response Board (ACRB)will determine coverage
for actual losses to an amount not to exceed $100,000. There is a$1,000 deductible.
The following pages contain information about the ACRB, as well as the initial, required
steps to take in the event of a cyberattack and minimum required cybersecurity
standards.
As required by Act 846, the ACRB developed an initial set of minimum
cybersecurity standards for >covered entities. Details of these standards will be
emailed directly to mayors, city managers and IT.
directors.
Additional benefits are available for member cities and towns that participate in the
Arkansas Municipal League's Municipal Property Program.
>To learn more about the Arkansas Self-Funded Cyber Response Program, please
contact Jeff Melton at jmelton@arml.org.
CYBER RESPONSE CONTACT
JEFF MELTON I DIRECTOR, INFORMATION TECHNOLOGY I ARKANSAS MUNICIPAL LEAGUE
CELL: 501.353.4048 1 OFFICE: 501.978.6106 1 EMAIL: IMELTON@ARML.ORG
POLICY LIMIT CLAIMS
The policy limit is $100,000 per All claims must be called in to the
occurrence for entities that comply Arkansas Division of Emergency
with published standards and Management State Watch office at:
*$50,000 for entities that do not 501-683-6705 or 501-683-6709 or
comply for claims reported on or after aswo(�)adem.arkansas.gov.
July 1, 2024. A $1,000 per occurrence
deductible will apply. No coverage is provided for
compensatory damages, punitive
*The Arkansas Cyber Response Board will damages, exemplary damages, ransom
determine on a claim by claim basis demands or any interest or penalty
whether or not the reduced limit will apply to amounts that accrue on a claim.
the affected Participating Governmental
Entity.
CYBER RESPONSE CONTACT
JEFF MELTON I DIRECTOR, INFORMATION TECHNOLOGY I ARKANSAS MUNICIPAL LEAGUE
CELL: 501.353.4048 1 OFFICE: 501.978.6106 1 EMAIL: JMELTON@ARML.ORG
ACRB MINIMUM CYBERSECURITY STANDARDS
The Arkansas Cyber Response Board (ACRB), established under Act 846 of 2023, has established minimum
cybersecurity standards for entities in the Arkansas Self-Funded Cyber Response Program. As the cyber-
security landscape evolves, the ACRB's standards will adapt to address new challenges and threats.
Effective July 1, 2025, all participating entities must comply with these standards. It's important to note that
these standards,while not exhaustive, are not intended to replace existing security policies and procedures.
Organizations should continue to rely on their internally developed controls to ensure comprehensive
security, while these standards provide additional safeguards.
I.Enforce multifactor authentication(MFA)across all employees with access to vital systems and
services,including:
• Access to web-based platforms includes services provided byfinancial institutions,such as online banking
and investment management,and third-party applications like cloud-based software solutions. This category
also encompasses webmail services, such as Gmail and Outlook.com,or any otherweb-based platform
that allows users to perform various transactions, including initiating financial transfers, authorizing payments,
updating account information, and submitting confidential data.
• Multi-factor authentication (MFA)is required for all accounts with elevated access rights, including
administrative,cloud service, and vendor system accounts(on-premises and cloud).This requirement also
applies to accounts used to manage application user security.Service accounts are exempt from this
requirement.
2. Maintain and test offline data backups (at least once yearly)for critical systems and data storage.
3. Implement a cybersecurity awareness training program for all employees.
4. Adhere to the ACRB password standard:
• Minimum of 8 characters (Strongly recommend 12 characters).
• Changed every90 days(Passwords with at least 12 characters changed every 185 days).
• Not stored in plain text.
• Enforce password complexity.
• Prevent the reuse of at least the last 24 passwords/phrases.
• The user account is locked after five unsuccessful attempts.
• Default passwords for new users must require a forced reset.
5.Adhere to theACRB patch management standard:
• Ensure critical updates and patches to systems and hardware are applied within 14 days.
• Ensure all other updates and patches to systems and hardware not designated as essential are applied
within 30 days.
• Patches, system upgrades, or othervendor releases must be obtained from trusted sources.
• Periodic auditing and remediation of systems and appliances missing updates.
Exceptions to Cybersecurity Standards
The ACRB may grant exceptions to these standards on a case-by-case basis, subject to thorough review
and justification provided by the participating entities. Such exceptions must be based on compelling
reasons such as technological limitations, resource constraints, or specific operational requirements.
All exceptions granted shall be documented and periodically reassessed for compliance with evolving
cybersecurity best practices and regulatory mandates.
CYBER INCIDENT CHECKLIST
Upon detection, please follow the required steps outlined below to report all cyber incidents and events.
Prompt reporting serves to reduce costs and extent of loss.
REQUIRED STEPS
Immediately Notify:
i>Jeff Melton, Arkansas Municipal League
jmeltonCarmt.org or 501-353-4048
Within 48 Hours of Incident,Notify.
-'ADEM Watch Office
aswwpadem.arkansas.gov
501-683- 6705 or 501-683-6709
Within 5 Business Days of Incident, Notify:
;>Arkansas Legislative Audit
https://incident.arklegaudit.gov/
Incidents thatare notreported to the cyberresponse contactandADEM within 48 hours of detection may result
in increased mitigation cost to the participating governmental entity.
Additionally:
>Cooperation, assistance, submission, execution, consent, etc., with the cyber response contact is
mandatory.
Failure to submit requested information to the cyber response contact may result in increased
mitigation cost to the participating governmental entity.
>Claim checks must be cashed within 90 days.
RECOMMENDED STEPS
Notify Internet Crime Complaint Center(IC3)
https://www.ic3.gov/
Notify Cybersecurity Infrastructure SecurityAgency
Helen "Gayle" Combs
helen.combs@mait.cisa.dhs.gov
479-866-8691
GOOD (MINIMUM) PROTECTION RECOMMENDATIONS
• Incident Response Plan and Disaster Recovery Plan —Arkansas Act 260 of 2021
• Develop formal policies and specify controls to ensure compliance.
• Quarterly Security Awareness Training
• Business class email: .gov(required by Act 929 of 2025)
• Managed Detection and Response(MDR): Leverage Al and SOC
• Least Privilege Access Model
• Multi-Factor Authentication (MFA)for all web-based applications
• Patch Management:workstations, servers, network devices.
• Remote Access Policy:RDP and VPN connections with the addition of MFA
• Backup Policy: offline backup with Ransomware prevention
• Firewall: network and host-based firewalls
BETTER PROTECTION RECOMMENDATIONS
• Annual Incidence Response Plan and Disaster Recovery Plan —walk through
• Address vetting and oversight of external solutions and providers
• Establish a secure baseline configuration — implement CIS controls
• EmailTagging: alert end user email is from external sender
• Email content and delivery:filter all inbound messages for malicious content(Domain-
Based Message Authentication, Routing and Conformance (DMARC))
• Web Browser Filtering
• Monthly email phishing campaigns/tests
BEST PROTECTION RECOMMENDATIONS
• Protective DNS(Malicious Domain Blocking and Reporting: MS-ISAC-
littps://mdbr.cisecurity.org/)
• Centralized Log Monitor: Security Information and Event Monitoring(SIEM)
• Network Segmentation and Segregation: control access and/or traffic flow within network
environment
• Implement Zero Trust Model
• Multi-Factor Authentication MFAfor all administrative tasks
• Vulnerability Scanning and Threat Hunting
• Develop Vendor Contracts
City of Van Buren Cybersecurity Incident Response Protocol
Purpose
The purpose of the City of Van Buren Incident Response Protocol is to clearly define the steps that
the City of Van Buren and its employees will take in response to any and all cybersecurity incidents.
Report of Cybersecurity Incident
All cybersecurity incidents will be reported to the below, in addition to one's Department Head.
City Clerk-Treasurer
Mayor
IT Support(K&S Computing)
A cybersecurity incident includes, but is not limited to, suspected malware or ransomware, a lost
or stolen device, unauthorized account access, a successful phishing attack, or any unexpected
system behavior that may indicate compromise.
Immediate Response and Containment
When an incident is suspected,the employee will take the following steps:
• Stop using the affected device immediately. Do not shut it down unless instructed, as doing
so may destroy evidence needed to determine the scope of the incident.
• Disconnect the affected device from the network by unplugging the network cable and
disabling Wi-Fi. Leave the device powered on.
• Contact IT, City Clerk-Treasurer or Mayor's office immediately so the nature and scope of
the incident can be assessed.
Once an incident is reported, IT will lead the technical response and direct containment efforts. IT,
in coordination with the City Clerk-Treasurer,will determine whether the incident is isolated to a
single device or has the potential to affect other systems, and will set the appropriate scope of
response. Containment actions will be scaled to the scope of the incident. In most cases,this
means isolating one or more affected devices while the rest of the city continues normal
operations. In a more serious incident, containment may extend to a single department, a group of
systems, or a shared resource such as a server or network segment.
To allow IT to act quickly,employees and Department Heads are expected to follow IT's
containment instructions for the duration of an active incident. If IT determines that the incident
affects broad systems or poses a risk to city-wide infrastructure, a larger containment effort may
be directed.The City Clerk-Treasurer and Mayor's office retain final authority over city operations
and will issue clear notice to staff identifying which departments or systems are affected,what
actions employees must take, and when normal work may resume.
Roles and Responsibilities
Department Heads are responsible for educating their employees on this protocol and ensuring
affected devices are isolated and reported promptly. Each department should maintain a
reasonable means of continuing essential business functions in the event that systems in their
area are taken offline.
The City Clerk-Treasurer is responsible for maintaining all documentation and forensic evidence
related to an incident. Every employee involved must document what occurred and how,to the
best of their knowledge. Interviews may be conducted to gather relevant information.The City
Clerk-Treasurer will initiate the external reporting process by contactingthe appropriate agencies
as noted below.
Jeff Melton ARML jmelton@arml.org
501-353-4048
Mike Kimberling K&S Computing mike kscomputing.biz
help@kscomputing.biz
479-459-4131
Help@kscomputing.biz must be notified of every incident,
regardless of which other contact methods are also used.
ADEM Watch Office aswo@adem.arkansas.gov
501-683-6705 or 501-683-6709
Arkansas Legislative Audit https://incident.arklegaudit.govv
Internet Crime Center https://www.ic3.gov
Cybersecurity Agency Helen Combs helen.combs(-)mail.cisa.dhs.gov
Employee Acknowledgement of Cybersecurity Policy and
Incident Response Protocol
I acknowledge that I have received, read and understand the City of Van Buren's Cybersecurity
Policy. I understand that it is my responsibility to comply with it to protect the security and integrity
of the City of Van Buren's information systems and data.
I further acknowledge that failure to comply with this policy may result in disciplinary action, up to
and including termination of employment and legal action if deemed necessary.
Employee Name (Printed):
Employee Signature:
Date: Employee Number: