LA Council Watch

2026 Budget Recommendation / R54 / Information Technology / Citywide Cybersecurity Governance / Roles and Responsibilities / Citywide Enforcement of Standards including Third Party Systems / Compliance

Council File 26-0600-S76

Pending — the city's cybersecurity governance structure was submitted to the Government Operations Committee for review, but hasn't been voted on yet and is awaiting committee action.

Introduced
2026-06-24
Last changed
2026-07-28
Status
open
Expires
2028-07-27
Committee
Government Operations Committee
Initiated by
Council
References
Information Technology Agency Report: EXE - 105-26

Brief

This budget-related matter, initiated by Council in June 2026, directs the Information Technology Agency to develop and implement a citywide cybersecurity governance structure. It covers the definition of roles and responsibilities across city departments, enforcement of security standards, and compliance oversight for both internal systems and third-party vendors. The file is currently pending in the Government Operations Committee after the ITA submitted its report on July 27, 2026.

Full summary

Council File 26-0600-S76 is a budget recommendation focused on how Los Angeles governs cybersecurity across all city departments, including departments that operate their own IT infrastructure and vendors that access city systems. The Budget and Finance Committee posed a formal question during the 2026-27 budget process, and ITA General Manager Ted Ross responded with a report describing the city's existing governance structure and enforcement mechanisms. The ITA's report outlines a layered governance model. At the top, the Mayor's Executive Directive No. 2 establishes the overarching security framework. The Cyber Intrusion Command Center (CICC), created under that directive, serves as the central coordinating body for risk management and incident response across all city departments. The Information Technology Agency sits at the operational core, managing centralized defenses — firewalls, vulnerability scans, intrusion detection, endpoint protection, and an Integrated Security Operations Center — for Council-controlled departments. The Chief Information Security Officer chairs the CICC and can assume direct command authority during an active cyber incident. Individual departments are responsible for their own employees' network behavior and must annually document mission-critical systems in a Department Emergency and Continuity of Operations Plan. On enforcement, the report distinguishes three tracks. Technically, departments are required to run weekly vulnerability scans, and identified threats must be patched within tiered timelines based on severity. Internally, the city monitors employee use of city systems and can discipline violators up to termination. For vendors and third parties, contracts require security assessments and limit network access to authorized business purposes; violations by non-employees are referred to the City Attorney's office for potential criminal referral. The ITA also runs a mandatory cybersecurity awareness program for all employees, with annual refresher training and signed acknowledgments of security policy compliance, framed explicitly as a liability-prevention measure. The ITA's report was submitted July 27, 2026 and referred to the Government Operations Committee the following day. The file remains pending committee review with no council vote yet taken. It expires July 27, 2028.

Activity (3)

  • 2026-07-28 Information Technology Agency document(s) referred to Government Operations Committee.
  • 2026-07-27 Document submitted by Information Technology Agency, dated July 27, 2026.
  • 2026-07-07 Council document(s) referred to Government Operations Committee.

Documents (2)

View on CFMS →