Loading...
RES NO 06-02-2026 CITY OF VAN BUREN,ARKANSAS RESOLUTION NOUL 1 26 BE IT ENACTED BY THE CITY COUNCIL, FOR THE CITY OF VAN BUREN, ARKANSAS,A RESOLUTION TO BE ENTITLED: A RESOLUTION ADOPTING THE REVISED PERSONNEL HANDBOOK GOVERNING CITY EMPLOYEES FOR THE CITY OF VAN BUREN, ARKANSAS, AND REPEALING THE EXISTING PERSONNEL HANDBOOK; AND FOR OTHER PURPOSES. WHEREAS, it is necessary to update and revise the existing Personnel Handbook for the City of Van Buren to conform to changes in law and policy;and WHEREAS, a copy of the revised change to Chapter 7 MISCELLANEOUS INFORMATION, adding a new section 7.8 City of Van Buren Cybersecurity Policy and Incident Response Protocol in the Personnel Handbook is attached hereto as "Exhibit A" and all employees shall receive a copy of the revised personnel handbook page. NOW, THEREFORE, BE IT RESOLVED BY THE CITY COUNCIL OF THE CITY OF VAN BUREN,ARKANSAS,THAT: SECTION 1: Section 7.8 City of Van Buren Cybersecurity Policy and Incident Response Protocol under Chapter 7 MISCELLANOUS INFORMATION of the existing Personnel Handbook will be added to describe the expectations of each city employee regarding cybersecurity and how to respond to a possible cybersecurity incident. SECTION 2: The revised Personnel Handbook for the City of Van Buren,Arkansas, section 7.8 City of Van Buren Cybersecurity Policy and Incident Response Protocol is attached hereto as "Exhibit A" and is hereby adopted and the existing Personnel Handbook dated February 24,2026,is hereby repealed. IN WITNESS WHERE F, the Cit o Van Buren, Arkansas, by its City Council, did pass, approve, and adopt, by a vote of for and,6against,the foregoing Resolution at its regular meeting held on the 221 day of June 2026. O\�G\erk Treds� Joseph P. IUrst City of Van Buren Mayor c ATT �ryCounty,P� APPROVED AS FO Shawnna Reyno ds Jacob Howell City Clerk/Treas rer City Attorney City of Van Buren Cybersecurity Policy and Incident Checklist Effective June 1 , 2026 PURPOSE This policy establishes the minimum cybersecurity requirements for the City of Van Buren based on the standards created by the Arkansas Cyber Response Board (ACRE) pursuant to ACT 846 of 2023. It also incorporates recommendations by the Arkansas Legislative Audit(ALA) Information Services Best Practices(2025). These standards are designed to enhance the security posture of the City of Van Buren's systems and data while complementing existing internal controls. The City of Van Buren desires to exceed all recommendations from Arkansas Legislative Audit(ALA)and Criminal Justice Information Services (CJIS) by following as closely as possible the standards set forth in Computer Information Systems (CIS)guidelines which,for the most part, meet all required criteria, in excess. This policy applies to all employees, contractors, and third-party service providers who access any City of Van Buren systems, networks or data. It covers authentication, data protection,training, access control, patch management and governance practices. The Cybersecurity Policy and Artificial Intelligence Policy are meant to work hand in hand to provide the City of Van Buren with as much protection as possible at any given time. The City of Van Buren will comply with the following cybersecurity standards and best practices based on the ACRB minimum standards. Multifactor Authentication (MFA) All employees with access to vital systems and services shall use multifactor authentication (MFA)This includes: • Access to web-based platforms such as financial services (Example: online banking, investment portals), cloud-based applications and web-mail services (Example: Gmail.com, Outlook.com). • Accounts with elevated privileges, including administrative, cloud service, and vendor system accounts (both on-premises and cloud-based). • Accounts used to manage application user security. • Service accounts are exempt from MFA requirements. Offline Data Backups The City of Van Buren will maintain offline backups of critical systems and data. These backups will be tested biannually(March—September)to ensure integrity and recoverability. K&S computing and the City Clerk-Treasurer's office will maintain a backup schedule,test logs, restoration verification reports to include date, system tested, outcome,and responsible personnel. Cybersecurity Awareness Training All employees will complete monthly cybersecurity awareness training provided by Huntress. The training will include topics such as phishing prevention, password hygiene, secure data handling, and incident reporting procedures. K&S Computing and the City Clerk-Treasurer's office will maintain a training roster with employee names, completion dates and training modules covered. A monthly report will be provided to all Department Heads with the following expectation in regards to departmental performance. • Any employee who has not completed monthly cybersecurity training will be expected to complete such training within five (5) business days of notification. • Any employee who has been compromised in the testing scenarios will be expected to provide a statement of explanation to be included with the monthly reports that will be available to Arkansas Legislative Audit upon request. A"compromised learner" refers to those employees that have initiated the highest-risk action available in the phishing scenario, either by clicking on a link or if available,entering information into a landing page. Other disciplinary actions may apply if there is a pattern of system compromising actions. Password Management Standards The City of Van Buren will set a standard for creating, protecting and changing passwords such that they are strong, secure and protected. Passwords should not be based on a user's personal information or that of his or her friends, family members, or pets. Personal information includes logon ID, name, birthday, address, phone number, social security number or any combination thereof. • Minimum password length of 8 characters • Passwords changed every 90 days. • Passwords shall not be stored in plaintext. • Enforce password complexity requirements (combination of upper-and tower-case letters, numbers and special characters) • Prevent reuse of the last 24 passwords or phrases. • Lock user accounts after five unsuccessful login attempts. • Default passwords for new users shall require a forced reset upon first login. Patch Management Standards The City of Van Buren will maintain a patch management process that includes • Applying critical updates and patches within 14 days of release • Applying all other updates and patches within 30 days • Obtaining patches, upgrades and vendor release only from trusted sources. • Conducting periodic audits to identify and remediate systems and appliances missing updates. Compliance Review The Cybersecurity Policy will be reviewed annually and updated as necessary to reflect changes in technology, emerging threats, and regulatory requirements. Non-compliance may result in disciplinary action and could affect participation in the Arkansas Self-Funded Cyber Response Program. Additionally, it may trigger legal or regulatory consequences. ARKANSAS SELF-FUNDED CYBER RESPONSE PROGRAM Arkansas Act 846 of 2023, A.C.A. 5 19-5-1159, created the mandatory Arkansas Self-Funded Cyber Response Program. Arkansas municipalities are required to participate in the program, which provides coverage. for damages/losses caused by a cyberattack committed against a participating government entity. The Arkansas Cyber Response Board (ACRB)will determine coverage for actual losses to an amount not to exceed $100,000. There is a$1,000 deductible. The following pages contain information about the ACRB, as well as the initial, required steps to take in the event of a cyberattack and minimum required cybersecurity standards. As required by Act 846, the ACRB developed an initial set of minimum cybersecurity standards for >covered entities. Details of these standards will be emailed directly to mayors, city managers and IT. directors. Additional benefits are available for member cities and towns that participate in the Arkansas Municipal League's Municipal Property Program. >To learn more about the Arkansas Self-Funded Cyber Response Program, please contact Jeff Melton at jmelton@arml.org. CYBER RESPONSE CONTACT JEFF MELTON I DIRECTOR, INFORMATION TECHNOLOGY I ARKANSAS MUNICIPAL LEAGUE CELL: 501.353.4048 1 OFFICE: 501.978.6106 1 EMAIL: IMELTON@ARML.ORG POLICY LIMIT CLAIMS The policy limit is $100,000 per All claims must be called in to the occurrence for entities that comply Arkansas Division of Emergency with published standards and Management State Watch office at: *$50,000 for entities that do not 501-683-6705 or 501-683-6709 or comply for claims reported on or after aswo(�)adem.arkansas.gov. July 1, 2024. A $1,000 per occurrence deductible will apply. No coverage is provided for compensatory damages, punitive *The Arkansas Cyber Response Board will damages, exemplary damages, ransom determine on a claim by claim basis demands or any interest or penalty whether or not the reduced limit will apply to amounts that accrue on a claim. the affected Participating Governmental Entity. CYBER RESPONSE CONTACT JEFF MELTON I DIRECTOR, INFORMATION TECHNOLOGY I ARKANSAS MUNICIPAL LEAGUE CELL: 501.353.4048 1 OFFICE: 501.978.6106 1 EMAIL: JMELTON@ARML.ORG ACRB MINIMUM CYBERSECURITY STANDARDS The Arkansas Cyber Response Board (ACRB), established under Act 846 of 2023, has established minimum cybersecurity standards for entities in the Arkansas Self-Funded Cyber Response Program. As the cyber- security landscape evolves, the ACRB's standards will adapt to address new challenges and threats. Effective July 1, 2025, all participating entities must comply with these standards. It's important to note that these standards,while not exhaustive, are not intended to replace existing security policies and procedures. Organizations should continue to rely on their internally developed controls to ensure comprehensive security, while these standards provide additional safeguards. I.Enforce multifactor authentication(MFA)across all employees with access to vital systems and services,including: • Access to web-based platforms includes services provided byfinancial institutions,such as online banking and investment management,and third-party applications like cloud-based software solutions. This category also encompasses webmail services, such as Gmail and Outlook.com,or any otherweb-based platform that allows users to perform various transactions, including initiating financial transfers, authorizing payments, updating account information, and submitting confidential data. • Multi-factor authentication (MFA)is required for all accounts with elevated access rights, including administrative,cloud service, and vendor system accounts(on-premises and cloud).This requirement also applies to accounts used to manage application user security.Service accounts are exempt from this requirement. 2. Maintain and test offline data backups (at least once yearly)for critical systems and data storage. 3. Implement a cybersecurity awareness training program for all employees. 4. Adhere to the ACRB password standard: • Minimum of 8 characters (Strongly recommend 12 characters). • Changed every90 days(Passwords with at least 12 characters changed every 185 days). • Not stored in plain text. • Enforce password complexity. • Prevent the reuse of at least the last 24 passwords/phrases. • The user account is locked after five unsuccessful attempts. • Default passwords for new users must require a forced reset. 5.Adhere to theACRB patch management standard: • Ensure critical updates and patches to systems and hardware are applied within 14 days. • Ensure all other updates and patches to systems and hardware not designated as essential are applied within 30 days. • Patches, system upgrades, or othervendor releases must be obtained from trusted sources. • Periodic auditing and remediation of systems and appliances missing updates. Exceptions to Cybersecurity Standards The ACRB may grant exceptions to these standards on a case-by-case basis, subject to thorough review and justification provided by the participating entities. Such exceptions must be based on compelling reasons such as technological limitations, resource constraints, or specific operational requirements. All exceptions granted shall be documented and periodically reassessed for compliance with evolving cybersecurity best practices and regulatory mandates. CYBER INCIDENT CHECKLIST Upon detection, please follow the required steps outlined below to report all cyber incidents and events. Prompt reporting serves to reduce costs and extent of loss. REQUIRED STEPS Immediately Notify: i>Jeff Melton, Arkansas Municipal League jmeltonCarmt.org or 501-353-4048 Within 48 Hours of Incident,Notify. -'ADEM Watch Office aswwpadem.arkansas.gov 501-683- 6705 or 501-683-6709 Within 5 Business Days of Incident, Notify: ;>Arkansas Legislative Audit https://incident.arklegaudit.gov/ Incidents thatare notreported to the cyberresponse contactandADEM within 48 hours of detection may result in increased mitigation cost to the participating governmental entity. Additionally: >Cooperation, assistance, submission, execution, consent, etc., with the cyber response contact is mandatory. Failure to submit requested information to the cyber response contact may result in increased mitigation cost to the participating governmental entity. >Claim checks must be cashed within 90 days. RECOMMENDED STEPS Notify Internet Crime Complaint Center(IC3) https://www.ic3.gov/ Notify Cybersecurity Infrastructure SecurityAgency Helen "Gayle" Combs helen.combs@mait.cisa.dhs.gov 479-866-8691 GOOD (MINIMUM) PROTECTION RECOMMENDATIONS • Incident Response Plan and Disaster Recovery Plan —Arkansas Act 260 of 2021 • Develop formal policies and specify controls to ensure compliance. • Quarterly Security Awareness Training • Business class email: .gov(required by Act 929 of 2025) • Managed Detection and Response(MDR): Leverage Al and SOC • Least Privilege Access Model • Multi-Factor Authentication (MFA)for all web-based applications • Patch Management:workstations, servers, network devices. • Remote Access Policy:RDP and VPN connections with the addition of MFA • Backup Policy: offline backup with Ransomware prevention • Firewall: network and host-based firewalls BETTER PROTECTION RECOMMENDATIONS • Annual Incidence Response Plan and Disaster Recovery Plan —walk through • Address vetting and oversight of external solutions and providers • Establish a secure baseline configuration — implement CIS controls • EmailTagging: alert end user email is from external sender • Email content and delivery:filter all inbound messages for malicious content(Domain- Based Message Authentication, Routing and Conformance (DMARC)) • Web Browser Filtering • Monthly email phishing campaigns/tests BEST PROTECTION RECOMMENDATIONS • Protective DNS(Malicious Domain Blocking and Reporting: MS-ISAC- littps://mdbr.cisecurity.org/) • Centralized Log Monitor: Security Information and Event Monitoring(SIEM) • Network Segmentation and Segregation: control access and/or traffic flow within network environment • Implement Zero Trust Model • Multi-Factor Authentication MFAfor all administrative tasks • Vulnerability Scanning and Threat Hunting • Develop Vendor Contracts City of Van Buren Cybersecurity Incident Response Protocol Purpose The purpose of the City of Van Buren Incident Response Protocol is to clearly define the steps that the City of Van Buren and its employees will take in response to any and all cybersecurity incidents. Report of Cybersecurity Incident All cybersecurity incidents will be reported to the below, in addition to one's Department Head. City Clerk-Treasurer Mayor IT Support(K&S Computing) A cybersecurity incident includes, but is not limited to, suspected malware or ransomware, a lost or stolen device, unauthorized account access, a successful phishing attack, or any unexpected system behavior that may indicate compromise. Immediate Response and Containment When an incident is suspected,the employee will take the following steps: • Stop using the affected device immediately. Do not shut it down unless instructed, as doing so may destroy evidence needed to determine the scope of the incident. • Disconnect the affected device from the network by unplugging the network cable and disabling Wi-Fi. Leave the device powered on. • Contact IT, City Clerk-Treasurer or Mayor's office immediately so the nature and scope of the incident can be assessed. Once an incident is reported, IT will lead the technical response and direct containment efforts. IT, in coordination with the City Clerk-Treasurer,will determine whether the incident is isolated to a single device or has the potential to affect other systems, and will set the appropriate scope of response. Containment actions will be scaled to the scope of the incident. In most cases,this means isolating one or more affected devices while the rest of the city continues normal operations. In a more serious incident, containment may extend to a single department, a group of systems, or a shared resource such as a server or network segment. To allow IT to act quickly,employees and Department Heads are expected to follow IT's containment instructions for the duration of an active incident. If IT determines that the incident affects broad systems or poses a risk to city-wide infrastructure, a larger containment effort may be directed.The City Clerk-Treasurer and Mayor's office retain final authority over city operations and will issue clear notice to staff identifying which departments or systems are affected,what actions employees must take, and when normal work may resume. Roles and Responsibilities Department Heads are responsible for educating their employees on this protocol and ensuring affected devices are isolated and reported promptly. Each department should maintain a reasonable means of continuing essential business functions in the event that systems in their area are taken offline. The City Clerk-Treasurer is responsible for maintaining all documentation and forensic evidence related to an incident. Every employee involved must document what occurred and how,to the best of their knowledge. Interviews may be conducted to gather relevant information.The City Clerk-Treasurer will initiate the external reporting process by contactingthe appropriate agencies as noted below. Jeff Melton ARML jmelton@arml.org 501-353-4048 Mike Kimberling K&S Computing mike kscomputing.biz help@kscomputing.biz 479-459-4131 Help@kscomputing.biz must be notified of every incident, regardless of which other contact methods are also used. ADEM Watch Office aswo@adem.arkansas.gov 501-683-6705 or 501-683-6709 Arkansas Legislative Audit https://incident.arklegaudit.govv Internet Crime Center https://www.ic3.gov Cybersecurity Agency Helen Combs helen.combs(-)mail.cisa.dhs.gov Employee Acknowledgement of Cybersecurity Policy and Incident Response Protocol I acknowledge that I have received, read and understand the City of Van Buren's Cybersecurity Policy. I understand that it is my responsibility to comply with it to protect the security and integrity of the City of Van Buren's information systems and data. I further acknowledge that failure to comply with this policy may result in disciplinary action, up to and including termination of employment and legal action if deemed necessary. Employee Name (Printed): Employee Signature: Date: Employee Number: