116 Information Systems Security
Original Approval Date: July 15, 2009
Revision Effective: June 16, 2026
The Ohio Legislature created new cybersecurity requirements for local governments in Amended Substitute House Bill 96, effective September 30, 2025, which became law as Ohio Revised Code Section 9.64. ORC Section 9.64 has three requirements:
The Tri-County Board of Recovery and Mental Health Services and its employees shall comply with the directives of ORC Section 9.64 or its superseding statutes by:
The Executive Director shall designate an Manager of Information and Cybersecurity Services as the Primary Responder to Cybersecurity Incidents. The Manager of Information and Cybersecurity Services shall review and maintain documentation of Mission-Essential Functions and Key Cyber Terrain, Threat Detection Mechanisms, Vulnerability Remediation Procedures, Incident Response Plans, Disaster Recovery Plans, and mandatory cybersecurity training programs and processes for employees to comply with ORC Section 9.64, as directed by the Executive Director.
Misuse of Tri-County Board computers or violation of this policy may result in disciplinary action up to and including termination.
B. Security:
C. Internet Access:
D. Protecting systems from environmental damage.
Employees shall use ordinary care to ensure Board-owned equipment is not subject to heat, water, or other environmental damage.
E. Disaster Recovery Plan
The Manager of Information and Cybersecurity Services shall develop, review and maintain a Disaster Recovery Plan.
F. Insurance Coverage
The Tri-County Board holds a property insurance policy which covers loss of computer equipment. Loss or damage to equipment owned by employees or guests may not be covered.
Revision Effective: June 16, 2026
The Ohio Legislature created new cybersecurity requirements for local governments in Amended Substitute House Bill 96, effective September 30, 2025, which became law as Ohio Revised Code Section 9.64. ORC Section 9.64 has three requirements:
- Each political subdivision shall implement a basic cybersecurity program.
- Political subdivisions must report cyber incidents to the Ohio Cyber Integration Center and the Auditor of State.
- Political subdivisions must pass an authorizing resolution before paying a ransomware demand.
The Tri-County Board of Recovery and Mental Health Services and its employees shall comply with the directives of ORC Section 9.64 or its superseding statutes by:
- Implementing CIS Controls v.8.1 or later as its set of prioritized cyber defense practices.
- Reporting substantial cyber incidents to the Ohio Cyber Integration Center and the Auditor of State as soon as possible, but within 7 days
- Requiring Board approval of an Authorizing Resolution prior to paying a ransomware demand.
The Executive Director shall designate an Manager of Information and Cybersecurity Services as the Primary Responder to Cybersecurity Incidents. The Manager of Information and Cybersecurity Services shall review and maintain documentation of Mission-Essential Functions and Key Cyber Terrain, Threat Detection Mechanisms, Vulnerability Remediation Procedures, Incident Response Plans, Disaster Recovery Plans, and mandatory cybersecurity training programs and processes for employees to comply with ORC Section 9.64, as directed by the Executive Director.
Misuse of Tri-County Board computers or violation of this policy may result in disciplinary action up to and including termination.
- Malware Protection. If malware is detected or suspected, immediately notify the Manager of Information and Cybersecurity Services or your Supervisor.
- Software: The Board does not permit unauthorized copying or installation of software.
- Data integrity and backups shall meet or exceed the standards of CIT Controls cyber defense practices.
- Retention and disposal of media containing Electronic Protected Health Information shall comply with HIPAA, applicable laws of the State of Ohio, Board policies regarding records retention, and CIS cyber defense practices. Media containing Electronic Protected Health Information (EPHI) is defined as any device or device component that may store, or provide access to, health information related to clients or employees.
B. Security:
- Staff members shall not share individual passwords with others or post passwords in a publicly visible manner. Questions about shared access should be directed to the Manager of Information and Cybersecurity Services or supervisor.
- Staff members should close all applications or lock their workstation when leaving the Board premises at the end of business. To ensure that security updates are installed in a timely manner, workstations should be restarted at the end of each business day. If circumstances require a staff member to not restart at end of business, the staff member should notify the Manager of Information and Cybersecurity Systems so that any security updates may be installed as soon as feasible.
- Applications providing access to Electronic Protected Health Information should be closed before the staff member leaves their individual office.
- Systems shall auto-lock after a maximum of 15 minutes of inactivity per HIPAA guidelines.
- The server shall remain in a secured room and shall be accessed only by authorized personnel.
- HIPAA-acceptable standards shall be met or exceeded in the transmission of EPHI data. Data transferred between the Board and State entities shall comply with protocol requirements for usage on the State provided network. Data transferred between the Board and other contracted entities shall follow Board-developed procedures.
- Fax or e-Fax transmissions of documents containing Protected Health Information shall adhere to State and HIPAA guidelines.
- When an employee is hired, access to the Board’s secure network shall be established by the Manager of Information and Cybersecurity Services. When an employee terminates employment with the Board, the Manager of Information and Cybersecurity Services shall assure that access to and the Board’s secure network has been terminated, and all Board-owned devices in the possession of the employee are secured.
- The Manager of Information and Cybersecurity Services shall manage any outside agency’s or provider’s access to the Board’s secure network for services delineated in the service contract, and termination of access upon termination of the service contract.
- When an individual, agency or provider’s access to relevant State systems is terminated, relevant state agencies shall be notified immediately so that access to secure State systems can be terminated.
- If a device able to connect to the Board’s secure network, or containing EPHI or able to access EPHI, is believed to be lost or stolen, the employee using the device at the time of loss shall immediately inform their supervisor and the Manager of Information and Cybersecurity Services.
C. Internet Access:
- Internet access is available via the connections with established monitoring and security. Board computers that access the Board’s secure network, or that contain EPHI or have access to EPHI shall not access the internet for any purpose by any means not approved by the Manager of Information and Cybersecurity Services.
- Guest access to the internet may be provided for the facilitation of training, virtual meetings, or other purposes related to Board functions. Terms and conditions for accessing guest networks will be published by the Manager of Information and Cybersecurity Services, and may be revoked at any time and for any reason.
- No use of the internet for commercial purposes will be allowed, nor any use which is considered to be offensive or harassing to another person.
- Devices that are not configured to access the Board’s secure network, whether owned by Board, employees, or guests of the Board, which use guest privileges to access the internet, are expected to use up-to-date anti-malware software. The Manager of Information and Cybersecurity Services may deny access to guest internet when they have reasonable concern about the guest device.
- Internet-based software and services may be used for virtual meetings, presentations, and other purposes. Use of such software and services on any device able to connect to the Board’s secure network, or containing EPHI or able to access EPHI, shall be approved prior to use by the Manager of Information and Cybersecurity Services. Such software or services may be used without prior approval by employees or guests with reasonable precautions on devices not able to connect to the Board’s secure network, or not containing EPHI or able to access EPHI.
- Where employees require the use of internet-based applications and services for the efficient conduct of Board business, any account information, including username, password, and account recovery or authentication methods must be shared with the Manager of Information and Cybersecurity Services and maintained in a documented record of internet accounts and services.
- Documents created by, stored on, or shared through internet-based applications and services may be subject to open records laws and records retention requirements. Employees should discuss such requirements with their supervisor prior to use.
D. Protecting systems from environmental damage.
Employees shall use ordinary care to ensure Board-owned equipment is not subject to heat, water, or other environmental damage.
E. Disaster Recovery Plan
The Manager of Information and Cybersecurity Services shall develop, review and maintain a Disaster Recovery Plan.
F. Insurance Coverage
The Tri-County Board holds a property insurance policy which covers loss of computer equipment. Loss or damage to equipment owned by employees or guests may not be covered.