Comment Submitted by California Correctional Training and Rehabilitation Authority

AnonymousOtherGovernment
Summary: CALCTRA, a state/local government entity, provides feedback on the State and Local Cybersecurity Grant Program (SLCGP). They describe how the funding helped them implement multi-factor authentication and an asset management platform to improve cybersecurity.
3. How have SLT government recipients leveraged new technology and cybersecurity tools to mitigate cybersecurity threats and incidents? CALCTRA has leveraged the SLCGP funding for multi factor authentication and a new asset management platform that will assist in mitigating cybersecurity threats and incidents organization-wide. 4. What SLCGP funded interventions were most effective at mitigating threats and ensuring continuity of SLT government operations? The use of multi factor authentication using funding from SLCGP has been helpful at mitigating potential cybersecurity threats for CALCTRA staff by adding an extra layer of security for all staff when logging into their Microsoft accounts and other work related accounts. The implementation of a new asset management tool will also benefit our organization. By building a centralized, accurate inventory of hardware and software, CALCTRA can apply security updates consistently and respond quickly when vulnerabilities or incidents arise. 5. What barriers, if any, are preventing the entities from utilizing the grant funds? There were no major barriers identified when utilizing the grant funds because of the consistent communication through regular meetings set up with CalOES. 6. To what extent are SLT grant recipients using the knowledge gained from SLCGP technical assistance and/or products to prevent cybersecurity incidents? The tools that have been implemented with the SLCGP grant funding will help prevent cybersecurity incidents from arising by adding an extra layer of security to staff through the use of multi factor authentication and having an accurate inventory of hardware and software across the organization, mitigating potential security gaps and vulnerabilities that may arise. 7. To what extent do regular ongoing phishing training, awareness campaigns; and role-based cybersecurity training for SLT government employees contribute to a reduction in cybersecurity incidents? Ongoing training for cybersecurity is critical for SLT government employees to ensure that they are aware of the current cybersecurity threats and the ways to avoid and prevent these new threats as they arise. By providing training sessions that spread awareness of phishing and other cybersecurity threats, staff will be able to identify and report the potential scams, avoiding individual account and organization security incidents.

View on Regulations.gov