Morrison shares update on county IT infrastructure with supervisors

Montgomery County’s IT infrastructure is almost all caught up to date.
At the regular Montgomery County Board of Supervisors meeting, County IT director shared an update on the status of multiple IT projects conducted for the county.
“The network equipment upgrade is complete, the server equipment upgrade is also complete. We’re still tweaking a few things on the replication set at the Montgomery County Law Enforcement Center to make sure that the replication is ongoing and that we have all of the bugs worked out of it,” Morrison said.
With the new server upgrade, Morrison suggested the county consider upgrading the off-site backup systems.
“The current off-site back up is a Cloud back-up being used on the old environment that is not working the same way that it was before. We are looking at different solutions to replace that and make sure we have a good Cloud back-up. We live in tornado country, and you never know. We have the back-up replications set at the LEC, but in the event of a disaster, I believe we need an off-site back up for our information,” Morrison advised. “I’m looking at a couple of different companies that provide that service, and I’m waiting to get some quotes back for that.”
Morrison added she was also looking into getting a software management solution or remote management & monitoring software.
“Having that would allow us to do software deployment more quickly and more easily and would allow us to do patching and updates. We would also be able to store all that information in one place. Some entities also provide a help desk and remote access option,” Morrison explained. “We currently have one of each with two different companies, so that might be something we end up combining. I’m setting up calls for more information to provide to the supervisors at a later date.”
Morrison also advised the supervisors that multi-factor authentication for log-ins and email has been something on her radar since she started in the IT position.
“I’ll be pursuing getting that software in the months to come. It’s something that our cyber security insurance company wants to see in place. I’ve received some pushback from different departments, so I’m trying to find a solution that will let them have that authentication but will also possibly be a single sign-on solution. That would be ideal especially for our sheriff’s deputies, so they’re not having to constantly sign in and do a separate authentication so they can access their computers as quickly as possible,” Morrison stated.
Morrison had also been looking at the Crowd Strike program for the county’s IT endpoint protection. The program was being offered statewide.
“The State of Iowa is offering the program through the Iowa Office of the Chief Information Officer at no cost. This would take the place of the Webroot software we’re currently using now. The Montgomery County Auditor’s Office already has it, because the Iowa Secretary of State’s Office requires that all of the election computers have the software on there,” commented Morrison. “Through this offer, it’s something we can now deploy county-wide at no cost to us. It’s basically an anit-virus program.”
Morrison also said she would soon be implementing the KnowBe4 security awareness program.
“Every year we do a security awareness training for all the staff. KnowBe4 also provides an anti-phishing campaign. It will send out phishing emails and staff are encouraged to mark them as such if they recognize them as phish. We then get reports back that give us a score on how well we’re doing,” said Morrison.
Morris added KnowBe4 also offered a variety of other security trainings, and she had assigned one other type of security threat training.
“Only 11 county employees had yet to complete the training, and six remained to complete on the county’s annual security training through KnowBe4,” stated Morrison. Once we have them all completed, we can show that as proof we’re following protocols for our cyber security insurance.”
Supervisor Donna Robinson asked if the main upgrades had been performed with American Rescue Plan Act funding. Morrison confirmed much of the upgrades had been.
“The network equipment upgrades and the server upgrades, all that hardware, came out of the ARPA funding,” Morrison said.
Robinson said the county was given a report of an IT audit with red flags that were cited in the report. Morrison received the report when she was first hired as IT director. She advised the supervisors progress was being made.
“We’re ticking off those red flag items little by little. The multi-factor authentication and password security is probably something I’ll be hitting a lot harder in the coming months, but overall, we’re making progress,” said Morrison.
No further action was taken. by the supervisors.
