Information Security Office

The Information Security Office (ISO) is responsible for evaluating and responding to cyber risks to the City’s technical estate.

The ISO was created in 2013, consists of four people and is building the technical foundations necessary to perform enterprise security monitoring and response. The ISO works in a “Shared Services” model, evaluating and addressing  risks and vulnerabilities within the City. This model creates a center of excellence within ISO and results in significant operational efficiencies and cost savings over department driven responses.

ISOs Key Objectives:

  • Develop and enforce an information security strategy, framework, polies and procedures that align City of Chicago business need, legislative and regulatory requirements and industry best practices
  • Assist City of Chicago IT projects and functional areas with the development of efficient processes that are required to meet requirements as defined by the Information Security Office and/or regulatory standards
  • Develop and support a NIST 800-30 and NIST 800-53 risk management framework to be used in information security solutions and asset prioritization
  • Develop a security awareness program to ensure that City of Chicago users understand their responsibility in protecting City of Chicago assets and information
  • Ensure that information security controls assist privacy efforts
  • Provide information security consulting and support to City of Chicago agencies in the area of compliance review, requirements definition, security risk assessment/measurement, security architecture and operational processes
  • Monitor and measure information security vulnerabilities and incidents and provide timely response to ensure confidentiality, integrity, availability and accountability of City of Chicago and its third-parties
  • Communicate the occurrence of significant security incidents, news, Information Security Office decisions and actions with City of Chicago

Confidentiality and Acceptable Use Policy

Information Security Policy

 Department Main Office

Innovation and Technology

 I Want To