Data-Sharing & Data-Driven Decision-Making Task Force
Video
Transcript
5 documents
Machine transcript
May contain errors. Verify important quotations against the official video.
About transcript accuracy
- Source
- Whisper
- Model
- ggml-large-v3-turbo.bin RTX5060
- Processing date
- October 7, 2026
Representative Stephen Meeks
Unverified
0:00
I get everyone's attention. We're going to go ahead and get started with the meeting this morning, and hopefully we'll have a few more of our colleagues filter in. First thing this morning, I want to thank everyone for being here and for participating. This is the, as of right now, will be the last scheduled meeting of this task force, and so I appreciate everyone's hard work and participation as we've gone forward with this. Senator D'Anglis, do you have any? No, that's fine. Okay. So first thing we need to do is approve the minutes from our last meeting.
If I can get a motion to that effect. All right. Okay. All in favor, say aye. Aye. Any opposed? All right. So we'll consider those adopted. This morning, we're going to basically we've got two main things on the agenda. First off, we're going to hear a presentation from Mr. Norman from a legislative audit, and if you would, sir, go ahead and we'll let you guys get settled in there, and then we're going to discuss our final recommendations from the task force. So when you gentlemen get settled in, if you would, just introduce yourself to the committee,
Speaker 4
1:06
and then you're recognized to proceed. Thank you, Mr. Chairman. My name is Roger Norman. I'm the legislative auditor for Arkansas, and I have with me David Coles, who is one of our information system supervisors. Uh, may I proceed? Yeah. First off, I'd just like to thank this task force at DIS and the other members who have worked so diligently to, to get us where we are today. Um, legislative audit, we're all about data. We deal with it day in and day out. Uh, we've, we've been dealing with data
before databases. Uh, you know, if you don't have good data, you don't have good databases. And so as databases have been used within the various agencies, I feel like that our staff has a lot of input on that. We have to check the accuracy of that. So we have a lot of expertise in databases. I would say that our IIS group, I would put them up against anybody in the state
as far as the knowledge, as far as what the standards need to be and how it needs to work. Data is, as you all well know, what makes the world go round. It keeps changing. We've gone from paper to digital. I know one of the big things that we saw years ago was when checks were going away. Check imaging came about because we used to catch a lot of frauds looking at the back of checks and the banks got to where they did not want to send, like, the images, only the fronts of the checks.
So we worked with the legislature, we worked with the Arkansas Bankers Association, and we have a law in Arkansas, and it's probably going to change too because checks are fixing to go away. But as of now, all public entities, they have to get the front and the backs of the checks because if you don't have the backs of the checks, you don't know where that money went because of the routing numbers and things on the check. So we still use that, but data continues to change. And with AI, with blockchain, with all the technology changes that are coming about,
what we do and how this enterprise database or data hub operates is going to be a continuing dynamic change. There's so much, not only do we have a need for data, but the General Assembly has just as great a need, because that's who we work for, and the citizens of the state of Arkansas. And there needs to be transparency, there needs to be enough data and good, reliable data so that the General Assembly can make good policy decisions.
In 2015, we issued the Enterprise Database Report, and we made some recommendations on that. And I think that if you look at that report, you can see how important we feel like this project is. I think the data hub is a good start. I think if I can make any suggestions this morning, I think that we're at a place where the legislature, the legislative agencies, legislative audit, the bureau, and the judicial branch also, they all need to be involved.
I think we need to have a spirit of cooperation. I think that it starts down at the agency level. and we all need to work together to try to get the best product that we can. So if I have any recommendations, it would be that the legislature stay involved, that the legislative agencies take an active role in the development of this. I know back in the late 90s and early 2000s when ACES was coming about, we worked directly with DF&A and SAP in the development of that.
We had two individuals that literally were located over at DF&A for a year trying to make sure that that system was put in place where it met not only the needs of the executive branch but also the needs of the legislative branch. And so I would suggest that some sort of legislative committee continue to stay involved in this. It's too important to the state of Arkansas and wherever that may be in whatever form or fashion
and that there be more legislative involvement. And I would like to turn it over to
Speaker 6
5:41
David Coles for a few comments. Thank you, Mr. Chair and members of the committee
David Coles
Unverified
5:46
for allowing me to come speak to you today. My name is David Coles. I'm the Information Systems Supervisor at Legislative Audit. Part of my duties at Legislative Audit is data analytics. We've been doing data analytics for over 20 years. We see data files sizes anywhere from two megabytes to over a terabyte worth of data.
We are capable of managing both ends. All of our audits in some way, shape, or form benefit from data analytics. I don't know how we would be able to go back and not use this information. It has made our audits more efficient. We're like any other government agency.
We have to deal with finite resources. We have to make the best of those resources, and we do that by using data analytics. It allows our auditors to focus in on the high-risk transactions, the high-risk areas. Frankly, it makes for a better quality audit. We're always looking to improve. We don't like to rest on our laurels. We think that the audit profession is growing.
Our standards are changing to be more data-centric. There's more guidance when it comes from the AICPA on data analytics. We use data analytics for a lot of special projects that we use. So I'm very familiar with the endeavors that it takes to go and collect data sets from multiple agencies. There's challenges in every form.
You know, it's a monumental task to collect data from four or five different agencies. You still have agencies that push back that don't like to share their data. There's data quality issues. There's data privacy issues. We take data privacy to the nth degree. We believe that when we get that data, it is our responsibility to be good stewards of that data. It's our responsibility to use that data effectively and ethically,
and that's what we endeavor to do every single time we get any kind of information. We use data. We have to destroy data when we're done with it. It has to be disposed of properly. Mr. Norman mentioned the SAP implementation, And, you know, if you were around, you remember that AFGM was basically a state checkbook.
So we went from a state checkbook system to full accrual accounting. This was a monumental task. It was made easier by the efforts of not just one agency, but the entire state. That was both executive, judicial, and legislative. uh we mr norman mentioned that we sent two individuals they were on site for a year before the go live day now there were hiccups there were a lot of things but this this changed
the way we did business in the state of arkansas it was huge and for all intent and purposes it was a success there were there were challenges there were hiccups things that had to be ironed out. But when you go from that type, I mean, you're talking about personnel challenges, technology challenges. There was a whole spectrum of issues that that group of people got together and made it work and made it happen. That wasn't an outside consulting agency. That
that was state of Arkansas employees, people that were down in the weeds, that worked in those areas and those agencies, they put forth a lot of effort. I know at the end of that, when we finally went live, people came back to their prospective agencies. Some of them stayed. Some of them were asked to stay that didn't want to stay. They did it anyway because it was so important for the state.
And dealing with data for such a long time, and we issued that data warehouse report in 2015, we're passionate about this. We realize, you know, I talk to auditors from other states that have data warehouses. They have told me some of the benefits that not only that group of auditors have gotten from it, but the state as a whole. You know, I was reading some state of Michigan correspondence the other day,
and, you know, they did things like they found gaps in immunization for children. You know, children are our future. We have to protect them. And with data analytics, they were able to actually identify areas where more assistance was needed. You know, we're all dealing with these finite resources. Government has to be transparent. If we want to deliver better government services, then a data warehouse is imperative that the state of Arkansas put this initiative,
develop a clear vision of what we want to do and how we want to do it, fund it, get the right resources, whether that be pulling people from other agencies to do that, I think that that's the way we need to go. I'll reiterate Mr. Norman's suggestions. I think it would be a great step forward for the state of Arkansas, just as the ACES implementation was. I'm going to leave it there, and if you have any questions, I'll be glad to do my best to answer those.
Representative Stephen Meeks
Unverified
12:17
Thank you. I do have a question. Okay. I do have a question, but our Senator English has one, so ladies
Senator Jane English
Unverified
12:28
first. Thanks. So actually what you're saying is I was around when we put ACES into effect, and there was a lot of gnashing of teeth and people lying on the floor and crying and talking about how it wasn't going to work. And, you know, the bottom line was the governor said do it. And that's exactly what happened.
And we are probably due for some new changes even today as we look at procurement and transparency and all these kinds of things. But that definitely was a great leap for the state of Arkansas to move us into a better future. So you're right about the transparency. I think it covers multitudes. And we've kind of ended up looking specifically at DIS, but we need to be looking at the broader thing.
There are lots of people who need to be involved in a discussion to see where we need to go. But you're right, we need
Representative Stephen Meeks
Unverified
13:36
to have a vision, have to develop that. So my question that I have is, is one of the things that y'all had mentioned was the need for this to be a government-wide solution that we need to be going towards. And so on a practical level, as we try to maintain the separation of powers between the agencies, my question is, you know, practically the implementation.
So, for example, we have the data and transparency panel that works on the agency levels, kind of like you all mentioned. Do we need to look at, now we've got a judiciary representative that we placed on there. Would it be beneficial for us to maybe add a legislative branch either y'all or the bureau or both to that panel? As we talk at cyber security for my colleagues around the table, You guys are probably the agency that's more at the forefront of that than any other agency within state government.
Do we need to have one cybersecurity officer who is responsible for the whole state, working with all three branches? Or is it better to have a cybersecurity officer, one for y'all, one for executive, one for judiciary? So kind of talk to us in your mind, you know, the practical implementation of everybody working together, but still maintaining those separations that we need to maintain.
Speaker 4
15:06
Well, Mr. Meeks, I appreciate the opportunity to respond to that. We do need to be involved in some form or fashion. Personally, I cannot participate as far as the code provision to be ex officio on a board or commission. Now this is a task force and I think that's something different, but I don't think that would prevent our staff from being involved. We've been involved in a lot of such as the ACES things, and there was specific legislation on that.
But I think that both the bureau and us need to be involved, because the bureau has just as much need for information as we do and they represent y'all also as we do. So yes, I do think that that needs to be involved. As far as the officers and how it needs to work, it's just like a lot of the other laws in the state. The general accounting laws for the state, some of it applies to everyone, constitutional agencies and others, some of it does not.
But I think there needs to be an overall plan for everybody. And I think that's one of the frustrating things that, as far as David runs into, is having uniform standards out there for data and just for policies relating to information systems, that they're either years behind or they're not compliant with it. And as some of you all that are on audit may know, we write people up for time and time again for not using passwords and this and that,
and after a while it just gets sloughed off. But we're seeing the results of some of that now when money is being actually taken from some of these entities, whether it be education or municipalities or higher ed bank accounts. And so I think security is important. You need a security, someone in charge of security. You need someone in charge of making sure that data is, that the databases are designed appropriately and that they're managed in such a way that you're able to share the data.
David Coles
Unverified
17:20
David, you may have something else to add. You know, cybersecurity is a really, it's such a large task. And, you know, we work with our colleagues over at Division of Information Systems, and we have a really good working relationship with Carter and Robert and his team. They, you know, they're very mindful of how massive that is. I think they're mindful to how big the data warehouse and data has to be as well.
Well, I think that we keep an arm's length distance between ourselves. I mean, don't offense, Carter. I love these guys. They do a good job, and I deal with them. But I think we understand the lines that can't be crossed, and we just have a really good working relationship. And I think that in today's day and age, being able to work together, you know,
even in separate agencies and separate branches of government is crucial. And I think we do a good
Speaker 4
18:36
job with that. Being involved in the design of a system I don't think would impair our independence or create any sort of separation of powers issue because at the end of the day, y'all are the ones that set the policies that deal with this data warehouse and how it should
Speaker 7
18:53
function and what your goals of it are. So I think it's a legitimate legislative function.
Speaker 22
19:01
All right, colleagues, are there any questions? Anyone else? And I
Representative Stephen Meeks
Unverified
19:06
think we've got some of our colleagues, too, that are not members of the committee. We've got a lot of empty seats, so if any of you would like to join us and participate, we would definitely
Senator Jane English
Unverified
19:17
welcome that. If you have some thoughts and ideas,
Representative Stephen Meeks
Unverified
19:22
we'll go ahead and hear them. All right, hearing now, gentlemen, thank you. Thank you.
All right, so we're getting ready to vote on recommendations. There's a few on your packet, if you want to go to page five. We're going to start there. I've got a few that we're going to add to it. But before we get to that, because this is our last meeting, I want to open it up to anybody who is visiting us today out to the general public. If you would like to come up and address the committee, just a quick three to five minutes, to give us your thoughts before we vote on these recommendations, we would welcome that.
Is there anyone who would like to take advantage of that
Senator Jane English
Unverified
20:14
before we proceed? So, Don Berry, did you want to talk about
Representative Stephen Meeks
Unverified
20:26
your VA stuff, the UAMS, quickly? If you would, just grab a seat there and introduce yourself to the committee, and then you're
Speaker 39
20:33
welcome to proceed. Don Berry with the Arkansas Veterans Coalition. Thank you, ma'am, and Representative Meeks for the opportunity.
Really quickly, I wanted to talk about some of the things that are also going on within. We have federal entities and obviously state entities working common issues and projects probably best known to us in the veterans community. The VA, the Central Arkansas Veterans Health Care System has a research entity. In fact, Dr. Angie Willisky from Seymour, the Center for Mental Health and Outcomes Research is here with me. The investigators for Seymour are basically dual enrolled.
They basically, they work for the VA as well as for UAMS. So they are actually a bridge element that working a number of different elements. One of the projects that our veterans council was briefed on last week by Seymour investigators is an opioid study initiative, which will pull in data elements from a disparate number of federal and state, as well as private databases to be able to get a better picture on combating opioids.
As an individual is being, is withdrawn from a program over here, but then they start drawing their other opioids from another different program, so it's not transparent, not visible to to the practitioners. And this is an effort that's being made in that regard. So that's an example of how larger data and the ability for state as well as state and federal data sources can play to providing decision makers with a much better picture of the
Speaker 40
22:19
current situation. Is there any other questions for
Representative Stephen Meeks
Unverified
22:24
that? I think that points again to the need for us to create a master citizen file so that way it helps I'll just kind of track that. Any questions, Marilyn? Thank you. Thank you, sir, we appreciate it. Okay, is there anybody else who would like to address the panel before we proceed with our, okay. So with that, we're gonna go ahead and proceed. What I'd like to do is go over the recommendations that are on page five.
Following that, I've got a list of recommendations that I'd also ask for the committee to consider, and then of course if anybody here, anyone else has any recommendations, we'll try to consider those as well. So the first recommendation on page five is that all state agencies accept and work toward a data hub for the state of Arkansas. The task force understands that agencies can be protective about their data, but agencies must realize they are stewards, not owners. The state directs the way the data is used, not the agencies.
So, first off, can I get a motion to adopt that recommendation? Okay, second, any discussion on this recommendation? Okay, I was hearing none, all in favor say aye. Aye. Any opposed? All right, we'll adopt number one. Recommendation number two, that the Arkansas Research Center continue to assist agencies in this effort, any motion? Okay, second? Okay. Motion and a second, any discussion on recommendation number two?
Okay, saying none, all in favor say aye. Aye. Any opposed? Number two is adopted. Number three, we are going to skip and the reason why it says members of the data sharing task force will learn the mechanics of the data and transparency panel after the end of this month, this task force will no longer exist, so there's no reason to adopt that one. Number four, the legislature should consider and pass legislation requiring agencies to negotiate and enter into data sharing agreements.
I get a motion on this one, second, got them all over. Any discussion on number four? Who's the second? Representative Brown, got to make sure our staff can keep up here. Any discussion? Seeing none, all in favor say aye. Aye. Any opposed, okay. number four will be adopted. The next recommendation that I'm going to make to the committee is, and I think Mr. Norman touched on this, one of the challenges I think that we have
within the state is whenever there's a cybersecurity breach, there's no protocol for that reporting up to our level of government. And so obviously we don't want to broadcast all of our cyber security vulnerabilities all over the place. But at some level, we need to have that information so we can make positive policy decisions. I've heard of numerous data breaches that don't make the news, obviously, for security reasons.
But our folks in audit and others need to have that data. So I'm going to make the recommendation that the, my recommendation is that the legislature look at increasing the reporting requirements of cyber security breaches and the proper policy on how to handle those breaches. So when a breach happens, how is it addressed, the reporting, and so forth.
So that's going to be my first recommendation. And okay, okay, I've got a motion and a second to adopt it. Any discussion on that recommendation? Okay, hearing none, all in favor, please say aye. Aye. Opposed? Okay, so that'll be number four. The next recommendation that I'm going to make is, as was discussed as chair of the House Technology Committee, it is my intention to continue these discussions. However, there is not a Senate Technology Committee.
Right now, the committee that we work with is just an overall infrastructure committee. And so I'm going to recommend that to the committee, that we recommend that the Senate create a comparable technology committee that focuses on technology-only issues or technology-related issues. And I don't know if Senator Engel, as a senator, has any other comments you'd like to make on that before we?
Speaker 45
27:13
On that particular one? On that particular one. No, that's fine with me. I have a recommendation.
Representative Stephen Meeks
Unverified
27:21
Let me get to it. Okay. Okay. All right. So the next recommendation is that the Senate will create a technology committee. Thank you,
Representative David Whitaker
Unverified
27:32
Mr. Chair, and thank you for this particular recommendation because one thing I hope we, you know, I've taken from this and I hope everybody else has through this process is just how important all of this is and how much more important it will become very quickly.
And the idea that we don't have, you know, a standing committee in both houses to shepherd this and make sure that the policy continues to move forward is startling. And I'm just thrilled you did this, and thank you. All right. Can
Representative Stephen Meeks
Unverified
28:07
I consider that a motion to adopt that? Yes. Okay. Okay. All
right. Second. Any other discussion on that before we move on that recommendation? All right. Hearing no other discussion, all in favor say aye.
Aye. Any opposed? Okay. So that one will proceed. The last one I have, and this one may require a little more discussion, But all of you at your desk should have this little piece of paper. So the main issue going forward is how do we implement the things that we have talked about? We've had folks from other states that have come in and talked to us about how they've laid out their data and analytics and so forth.
And so this is what I'd like us to consider for our layout here in Arkansas. Again, this is my recommendation, and so I'm definitely open to changes or, you know, whether we want to adopt this or not. But as it stands right now, the Department of Information Systems is a cost recovery agency, which means they get no general revenue. They bill the agencies for the services that they provide. However, doing data analytics, there's no real way to bill that out.
Same thing with cybersecurity. There's no real way to build that out. And so what I would like to do is for us to look at creating a division of data analytics and cybersecurity within DIS. It'll be a general revenue funded part of the agency. I've already asked the director to begin looking at budgets for implementation. The way I'm going to propose that this division be laid out is the chief data officer will be the one over this division. The chief data officer will work and report to the director of DIS.
Under the chief data officer, we'll have the privacy officer. We'll have the cyber security officer and their team. And then on the data analytics, we'll break them into the four pillars that we've talked about. Education workforce, public safety and correction, the healthcare agencies, the financial agencies, and then as part of that, kind of that catch all one would be the public. So they would be the ones that would work with getting data and working with it available to the public. And maybe at some point we break off the private sector one.
But for right now, maybe start with the four pillars. And each one of these pillars, like I said, North Carolina, I think they said they have like maybe three employees per pillar based upon what the need is. Obviously, starting off with the fiscal session, my goal would be to try to get our chief data officer in place. And then when we get the chief data officer in place, then we can work on developing the plans, and get everything lined up.
So when we get to the general session in 21, that will be ready to go and implement the rest of that if that is what the committee so chooses. So with that, does anybody have any questions? Does anyone have any comments? Are you all
Representative David Whitaker
Unverified
31:24
okay with this? I'd like to see variations. Thank you, Mr. Chair. Just curious, is this just a broad roadmap and basically for demonstration purposes today? So the chief data officer would actually promulgate what they think works best?
Speaker 3
31:41
Right, right. Because remember, this is just a task force,
Representative Stephen Meeks
Unverified
31:44
so this would just be our recommendation. What the final picture obviously would be, we would have to draft legislation, and appropriations and all that kind of good stuff. But this is just a broad overview of what our recommendation would be. Thank you.
Representative Austin McCollum
Unverified
32:03
Okay, Representative. Just a clarification. Did you say for this recommendation you'd have the chief data officer reporting to the director of DIS?
Representative Stephen Meeks
Unverified
32:11
Yeah, because this would be a division within DIS. Otherwise, we would have to create a whole separate
standalone agency. And I think that could create, yeah, could create more problems. So I do want there to be a little bit of autonomy there, but it still needs to have, you know, be within an established hierarchy. At least in my thoughts. I mean, y'all may think differently, but. Any other thoughts?
Senator Jane English
Unverified
32:43
Well, I do have. Okay. So as I look at this thing, though, and I'm looking at the cybersecurity officer, so what I have been hearing lately is that the cybersecurity officer, that person in charge, should probably not be at a DIS. It should probably be at another agency because then, as Roger said, what is the plan, what is the strategy for cybersecurity throughout state government,
not specifically just with DIS, but it's almost a conflict of interest because all these different data things, agencies, or people are under DIS rather than having an outside area. So I would almost take that cybersecurity officer out of there and put it as a separate, as we go along in the world, while they're closely connected, in a lot of ways there's a whole lot of difference between cyber security and it's not just data.
Representative Stephen Meeks
Unverified
33:53
Right, just to make, oh, okay. Does that make sense? Yeah, so we're
keeping our, we don't want the cyber security officer to be beholden to the data officer. We want them to be an independent, kind of like an inspector general type position. Okay, so let's scratch the cybersecurity officer off there, and we'll, but at some, so maybe we'll look, let's handle the cybersecurity separately. So we'll pull cybersecurity off, and then we'll explore that one separately.
Does anyone else have any other thoughts on that? Representative Lederman. Thank
Representative Jack Ladyman
Unverified
34:32
you, Mr. Chair. I appreciate you letting me make a comment. But I'd like to add in what the senator just said about that, because I agree with what you say, because the cybersecurity officer, the decisions that they would make could be affected by who they're reporting to. And so I agree they need to be separate but involved and have a direct report to someone else, because it can affect what you might want to do if your report is thinking differently.
Speaker 66
35:04
So I think that's a real good recommendation. Let me ask your thoughts on this, and I'll
Representative Stephen Meeks
Unverified
35:09
throw it out to the whole committee. Should we, well, I'll tell you what, before I run down a rabbit trail, so let's set the cybersecurity one aside. I think everyone's in agreement that we're not going to include the cybersecurity yet. And then let's
come back and talk about what we want to do with the cybersecurity one. Is that good? Okay, Representative
Speaker 72
35:31
Brown, you had. Well, I kind of forgot my question, but I think we just resolved it.
Speaker 74
35:39
And I'll make my suggestion about the cybersecurity officer at the proper time.
Representative Stephen Meeks
Unverified
35:44
Proper time, okay. All right. Does anybody have any other thoughts
or concerns, discussion on the layout of the data? So this is going to be just the Division of Data Analytics. We're going to take the and cybersecurity out because we won't have cybersecurity in the data analytics. So we're going to have the Division of Data Analytics. We'll have the Chief Data Officer, the Privacy Officer, and then the four pillars within that.
Does everyone understand kind of what we're looking at here? Okay. Any other discussion on that piece of the pie? Okay. Can I get a motion to adopt that? Okay. Motion, second. Okay. Any discussion on the motion? Hearing none, all in favor, please say aye. Aye. Any opposed? Okay. All right. So, we'll adopt that recommendation. And so, cybersecurity, did you want to make your recommendation or do you want to jump on the cybersecurity? I'm
Senator Jane English
Unverified
36:44
not sure that that actually was part of our task force.
I mean, maybe it is, but I just think maybe my recommendation would be is that because we don't have a state strategy, we don't have a person overall in charge, we haven't figured any of that. We have a lot of little bits and pieces of things going on, so I'm not sure how we want to attack that here other than, I mean, I mean, that's basically the administration is doing some work,
but I don't think they've gotten anywhere. Right. So what kind of suggestions would you all have about
Speaker 72
37:30
this? Representative Brown, you had a thought? Well, would that be an appropriate role under the auditor's office? Probably not. Because they're just dealing with the money. they're not auditing the data and the tracking the data? Well, if you think about cybersecurity in the bigger picture,
Senator Jane English
Unverified
37:51
I mean, if you think about someplace up here, you've got to have this now, we're talking about across the state, but we're talking about state agencies, we're talking about schools, we're talking about municipalities, we're talking about, which actually doesn't fit really right underneath this, but is a whole different kind of thing, and how do we work with the private sector? I mean, there's just so much out there. It's probably mind-boggling for most all of us. It is for me just to think about how do you organize something like that.
And I think that's a legitimate role for a group to begin to have those discussions, whether it's another task force or whether it's a legislative group or what it is. but somehow we've got to find a way that we're working with the administration because they do their stuff over here, and we don't know what's going on. So it's over here we're planning our own things. But from my standpoint, we need to figure out we need to push the envelope
so that folks are beginning to think about what is the state strategy. You obviously can't tell everything that you're doing, but someplace. And who's going to be responsible? And would
Speaker 74
39:05
it be possible to tie in with all the security work that they're doing out at Kemp Robinson?
Representative Stephen Meeks
Unverified
39:12
Potentially. I think whatever we decide to do as a state, whatever that looks like, that they will work with the cybersecurity alliance that we set up. But we've got to figure out what our picture looks like.
And on the audit question, the auditors, they do a lot of implementing and checking, but they don't set the standards so it would be the job of the cyber security officer to try to set what the standards are for the state and to determine like responses and then once those standards are set then the auditors would be the ones who would help to implement and make sure those standards are in place. So how do we want to make that for a recommendation? Okay so so we
We want to make sure I'm reworking. So our recommendation is that we need to develop a state policy on cybersecurity. So instead of us deciding what the recommendation is, we're just saying somebody, maybe the IT committee, needs to figure out what that looks
Representative David Whitaker
Unverified
40:22
like. Does that make sense to everybody? Yes. Thank you, Mr. Chair. Just throwing out some ideas, if it could be just simply urging, you know, urging the governor to identify an agency or entity that would oversee the administration, the executive branches, implementation of a cybersecurity program.
I mean, there's a dozen things, places it could end up, but I think that really is, in the end, the specifics would be executive prerogative. I mean, you've already got Department of Emergency Management that, you know, has some background with this sort of thing and a broad contact with all agencies and all branches. You have the state police who do certain types of work in cybersecurity, But I think executive priority would be they identify who they think would best do it.
Representative Stephen Meeks
Unverified
41:15
Right. I think we can urge them. Right. Thank you. And that may be something that instead of that person being directly in an agency, it's someone
who reports directly and be part of the governor's office and work out
Senator Jane English
Unverified
41:30
of there. Essentially, they're responsible. You know, I mean, that buck stops right there with them. And so it's
got to be. But hopefully it would be something that we all could work together on that hopefully could happen.
Representative Stephen Meeks
Unverified
41:45
Yeah, because obviously I think everybody agrees this
is something that needs to be addressed. And without a plan on how to address it, it's just going to be something out there that we all agree needs to be addressed, right? So our recommendation is going to be that the executive branch work with the legislative branch to come up with policy on cybersecurity. Right. Would that be a fair way of wording that? Yeah. Okay.
All right. Any other discussion on that? Okay. All right. Hearing none, I guess I'll need a motion. Motion. Okay. I got a motion. A second. Any discussion on the motion? Hearing none, all in favor say aye. Aye.
Any opposed? All right, that is adopted. All right. That's all I have. Do
Senator Jane English
Unverified
42:39
you have any? I just do. I do have this one, and I had planned to do it today, but I got waylaid, is to establish a legislative subcommittee of legislative council to continue this kind of work
to looking to bringing in folks, because it'll be a while before we can get a technology committee set up. That'll be 21 before we can do that. So in the meantime, we could have this opportunity for further discussion in bringing in other folks
Representative Stephen Meeks
Unverified
43:18
to talk to us and make some greater recommendations. So Senator English's recommendation is that ALC
set up a technology subcommittee to allow for the discussions to continue.
Obviously, we could still continue them in the House and the Technology Committee and we'll do so, but there's no instrument in place for the senators to be able to do that. And so this would allow the senators to be able to stay involved in this, at least until we get to the 21 session. We've talked to the chairs of ALC, and both of the chairs are agreeable to this. And so if that's agreeable to the committee, then we'll proceed with that. So first off, I guess we need a motion, a motion to adopt Senator English's recommendation.
Got a motion? Okay. Second. Okay. Any discussion on this motion? Hearing none, all in favor say aye. Any opposed? Okay. That motion is adopted. All right. Anybody else got any recommendations,
Senator Jane English
Unverified
44:18
anything you can think of that we need to want to add
Speaker 86
44:25
here? Speak now or forever hold your peace. That's right.
Representative Stephen Meeks
Unverified
44:29
Don't complain. And all Representative McCollum there, it looks like he's ready to go. All right.
Okay. All right. Hearing none, I don't think there's any other business to come
before the committee. Appreciate all your work. Mr. Gillum will get all this stuff laid out in a nice report for us. He'll get that emailed out and then just everyone, I know it's holiday season, but we need to have that completed by the end of the year. So when that arrives in your mailbox, just read through it real briefly, make sure it all looks good. If you see any issues with it, let either him or one of us know
And I guess the last bit of business that I do need from the committee is for the committee to vote to allow us to approve the final version of the report once Mr. McCollum was able to get that all in place. Okay, you got a motion, second, any discussion, all in favor say aye. Okay, so with that, again, we appreciate everyone's work. We wish everyone a Merry Christmas and a Happy New Year. And I think we've done some good things here to get this moving forward for the state.
Senator Jane English
Unverified
45:42
Any closing comments, Senator? Keep your minds going and be thinking about, and as you're reading and taking in things like what Rogers talked about in legislative audit, we just need to think about this in a much bigger view than what we've had. And we definitely have to have some kind of a vision and a plan. And we do a lot of talking about a lot of
things, but we've got to somehow develop a vision and a plan. Thank you.
Representative Stephen Meeks
Unverified
46:09
Again, thank you to everyone who's participated from the audience.
You guys are a part
of obviously making this possible. This is only the beginning, right? So with that, we are adjourned.
Agenda
Call to Order
Comments by the Co-Chairs: Senator English and Representative Meeks
Consideration to Approve November 6, 2019, Meeting Minutes [EXHIBIT C]
Presentation of Data Transparency
Discussion of Recommendations for the Data-Sharing and Data-Driven Decision-Making Task Force Report [EXHIBIT D]
Other Business
Adjournment
Documents
| Title | Type | Pages | Source |
|---|---|---|---|
| Agenda — DATA SHARING & DATA-DRIVEN DECISION-MAKING TASK FORCE, Dec 19, 2019 | Agenda | 1 | Official source ↗ |
| Draft Minutes | Exhibit | 2 | Official source ↗ |
| Exhibit C Draft Minutes | Exhibit | 2 | Official source ↗ |
| Exhibit D Task Force Report | Exhibit | 14 needs OCR | Official source ↗ |
| Handout 1 Division of Analytics and Cybersecurity | Exhibit | 1 needs OCR | Official source ↗ |
Speakers
Representative Stephen Meeks
Unverified
Speaker 4
Speaker 6
David Coles
Unverified
Senator Jane English
Unverified
Speaker 7
Speaker 22
Speaker 39
Speaker 40
Speaker 45
Representative David Whitaker
Unverified
Speaker 3
Representative Austin McCollum
Unverified
Representative Jack Ladyman
Unverified
Speaker 66
Speaker 72
Speaker 74
Speaker 86