Advanced Communications and Information Technology - House
Video
Transcript
1 document
Machine transcript
May contain errors. Verify important quotations against the official video.
About transcript accuracy
- Source
- SliQ live captions
- Model
- SliQ live ASR
- Processing date
- October 2, 2026
Unknown speaker
0:08
if you are not present, it will be placed at the bottom of the active agenda after 3 considerations, it will be moved to the deferred list, um, if you want to get it off the deferred list, just let me know prior to the meeting and we will try to get that done as soon as possible. Uh, any amendments, of course, to bills must be made in writing. Make sure to let the staff know that you have that. We can do special orders of business again, just let me know prior to the meeting. Um, last but not least, when we do get into, um, The actual meetings and uh bills if you do have questions, um,
My general policy is, is if the question line of questioning is, uh, reasonable and germane, uh, don't stop and you, you don't have to stop every time and ask, can I have a follow-up? Can I have a follow-up? Just continue asking your questions, but, uh, please just don't take advantage of that, uh, if it gets too long, I may move you back to the bottom of the, uh, of the list. Um, with that, we will jump into our agenda. So for our very first meeting, of course, we generally work with the broadband and DIS offices and so I've asked them to come give us some updates.
uh, Mr. Howie, uh, if you would, uh, come up, uh, front, um, and introduce yourself and uh give us an update on what is happening with broadband in the state. Uh, Glenn Howie state broadband director, and I should have mentioned, I guess at the intro that we do sit within the Department of Commerce for those that are perhaps new to the committee. Noah Haines, I am an ACC AmeriCorps member doing a year
of service with the Arkansas State Broadband Office. Alright. Thank you, gentlemen. Please proceed. Thank you, Representative Meeks and representatives of the committee for having us, uh, present to you today. It's always a pleasure to present before this committee, uh, especially with some of the statistics that we'll look at shortly in the presentation, uh, so with that again thanks for having us. I look forward to walking through this with you. I think first we'll start broadly with the broadband program overall. very quickly with one slide and then go right into what I'm sure is the topic of the day, are $1
billion beat program in Arkansas. So just for, for the committee to recall, uh, quickly, our office was established in 2019, pre-pandemic, we have 7 full-time staff, all federally funded, so there are no state appropriations, uh, for our office. To date, we've awarded $519 million through three separate rounds of funding CAREs, state and local fiscal recovery funds and Capital projects funds to date. Covering 183 projects across the
state and 130,000 homes and businesses. To date of those projects 167 have been completed, covering 121,000 homes and businesses that now today want, can subscribe to internet broadband access, should they so choose that did not before this program started. I do want to note this was not on the slide, but I felt like it was relevant to mention very quickly, uh, when I was first hired, I came before the joint version of this committee on September 12. Of 2022. And that day, Representative Meeks, you were there. I committed, if you go
back and watch the committed that um we would work and do everything in our power and work every single day to make Arkansas a top 10 state in all things broadband, and I'm happy to report that since that time, uh, we are executing on that commitment. It remains one of Governor Sanders' top priorities, broadband does. If you look back across the last 2 years, the second half of 2023, Arkansas was the number 6 state in the country in the reduction of unserved. d locations at a reduction of 24%. We were number 7 in the country
in the first half of 2024, with a reduction in 23% reduction of unserved locations in the country, first half of 2024, last year, we were the 6th. Right, state in the country with the 6th lowest broadband speed gap between urban and rural residents. So if you look at the difference in the speeds that our urban residents are getting as compared to our rural residents, that gap is only 6.7%. OK. And then lastly, the best number that I can report to you today from 2021 to 2024.
Arkansas was the number one state in the country. We led the nation in increased broadband connectivity at nearly 10%. OK. So I just want to let you know that we are committing uh and executing on our commitments to this committee and to the state of Arkansas. With that, into the bead program. To recall for the committee, the bead program in Arkansas Broadband equity access and deployment program funded through, uh, IDA at the federal level for Arkansas, it's a $1 billion program. We're one of only 19 states in the country to receive an allocation in excess of $1 billion.
The program will cover nearly 84,000 homes and businesses across the state that will be connected through this program and of course, the greatest caveat to this, we have to award a grant covering all 84,000 locations in this program, so we will not be able to not award a grant in this program. Summary of the Beat program to date. Our state is well underway on its speed journey. Um, our office has undertaken significant upfront preparations to run a best in class bead
program. Again with the overall goal of 100% connectivity through be our IPV2, which is really in layman's terms, really it's the grant program plan that we presented to US commerce was approved by NTIA in early October, starting our 52 week beat program window. Um, if you recall we had earlier in the year, we had our mapping challenge process that place. Those results were approved by NTIA in late November, finalizing that 84,000 number of locations eligible for the program.
Across the date, across the state. We actually opened our tranche one or round one bidding for the beat program on January 7th, and it closed on January 21st. We received 814 applications. In this program, which is tremendous, uh, as a quick example, Louisiana in their first tranche received less than half that number even though they had doubled the number of eligible locations. And so our program design has been very effective to date. We had 48 ISPs and
partnerships pre-register to participate in our program of those 43 applied, accounting for those 814 applications. Um, and lastly, should there be any funding left in this program. Remember, we have a $1 billion allocation, at least as of today, um, should we have any funding left? After we make these grant awards for infrastructure, uh, the state will be able to utilize those remaining funds for non-deployment related purposes. I think broadband related projects, but just not infrastructure, OK, so other broadband related projects.
Next slide is a quick sort of breakdown summary of the timeline we're under. So from October 4th of last year, started our 52 week clock, and there are several Components to this, unlike the previous grant programs we have run. At the office. This is not a run one round make Grant awards come to you, get them approved, and go back. This is a multi-phased approach where you see tranche one, a tranche 2, negotiations, they all fit together, OK? So the folks that applied in our most recent tranche one round
that we closed on the 21st. They will all be involved in tranche 2. So it's sort of a mesh together and they're all related. And so ultimately, we'll come back to you likely. Middle of the year with one packet of grant awards for the entire state and do it all at one time for you, OK? The next slide, digging in a little bit further into our tranche one, process that we just ran for applications again, 814 applications received from 43 Internet service providers
and partnerships, 98%. Of all program eligible locations received at least one bid in our first tranche. 96% of all the applications we received were competitive mean that they, they overlapped with each other in at least one census block group, which is the foundational building block of the applications in this program in 82% of all locations in ranche One received a bid or application from at least 2 or more different internet service providers. These are really, really great statistics for a
quick reference point, Colorado and there around, uh, their round one results. 60% of their locations received at least one bid, 98% of ours received at least one bid. So again, the early metrics that we do have compared to a limited sample from states around the country are very, very good. for this program. Quickly, our path forward. We are actively scoring and adjudicating all 814 applications that we received, um, they have all been scored, but now we move into the process
of comparing them against each other, uh, and so forth. So we're doing that actively now. We're going to conduct a tranche 2 or round 2 application period, uh, next month in February. Followed by another round of negotiations for any locations that remain. Remember, we have to make a grant for every location in the state, so we can't leave anyone out. So we'll take care of those through a negotiation process. And again, should there be any funding left, um, as it stands today, prior to any revisions that may come from the administration, um, we can look at
broadband-related projects that are not infrastructure. So with that, I will, uh, answer any questions. OK. Um, thank you, that, that's a very, uh, encouraging. Um, uh, Our report that we've received, um, we do have a, uh, couple of questions, uh, Representative Richardson, we'll go to you first. Thank you, Mr. Chair. I appreciate that. I had great presentation. It's good to see that we're moving forward, uh, I, I noticed you said that, uh, we, we've added about 120,000,
121,000 new homes that have availability now that did not have before. Do we have an adoption rate at this point? How many people are starting to latch on and take advantage. That is a really great question. Um, we do not have currently a read into adoption rates. I think that's something that um our providers should be reporting to us. projects that the state is funded and that's something that we can go back to and, and try to grab from them. That'd be great to hear. Thank you. OK. Representative Mayberry.
Thank you. I was trying to actually pull it up on my phone, so when you go to the map that you have out there, and you have the red dots and the gray dots and blue dots and all these other things. I have a subdivision that I've been trying for a very long time to help get them internet service because it's, it's been pretty much satellite that they can get. They have lots of trees, but they're surrounded by lots of good services, um. So
Many of them, and, and I was telling all of them, please, please go, go take tests and, and do it 3 times and all that. So looking at the map, most of them are gray, which to me says that they, according to you all, have adequate service, although many of these families would disagree. But there are some red dots in that neighborhood. So I'm trying to clarify if there are homes in that neighborhood that have some red dots. Does that mean that that whole
neighborhood could eventually get fiber because of those homes that have the red dots. Does any of that make sense from my very simple red dot blue dot. It makes perfect sense. So the context for the committee would be, um, we have released, uh, what is the most detailed state broadband map in our history. We released that earlier this year. Every location in the state, um, has a sort of color coded dot associated with it. Um, there's multiple colors at the end of the day, if it's a red dot or a blue dot location, that means it's eligible. It's one of the 84,000 locations that are
eligible for this particular program and the gray dots would indicate that, um, the services That are reported by the ISPs being provided there, have met the threshold for the for this federal program and so would not be eligible to be constructed to with this program. So what I would say for that is every location that's red or blue, um, will be subject to a grant award through this office. Now, there is no, um, An internet service provider, right? Can use the beat funding through the program to connect
to the red and blue locations. That's what we're doing right now and and going through that process, there is nothing stopping the internet service provider, you know, we would encourage internet service providers to use their own capital, uh, to easily grab locations that are near where they built to, uh, with program funds. And so if, if the business case is there, hopefully, for those folks that, that may be gray, right on the map, um, we would highly encourage whoever is awarded a grant for those red and blue dots. You know, using their own capital, seek out those homes next door or across the street that may have not been eligible
for the program specifically because they I mean, it's a house right next door, and if they've already brought the fiber there and had that paid for, I would think that it would, would help. I was just very disappointed because I know a lot of those families, they just still are, uh, I mean, from what they tell me, they, it's just, yeah, and they shouldn't be a gray dot. I understand, yeah, it's, you know, it. Very complex program that the state was on the hook to execute on behalf of the federal government, and they've said,
look, here's the, the 100 by 20 sort of speed demarcation line, um, the B program has a fiber preference, um, as it sits today. There's a fiber preference for the program. It's fundamentally not a fiber program. It is a 100 by 20 speed threshold program. And so that's the caveat there. I think what I would, you know, for that particular neighborhood. So, hopefully with encouragement, whoever those grant awards for the eligible locations, we'll see that there's a business case to pick up folks on their own dime right next door. That makes
sense to me. This is also the next iteration, right? This is round 4 for Arkansas. Um, this is, this, I would think will not be the last wave of programs that, that come, there's always a new neighborhood, right? There's always a home built 2 miles off the road that aren't accounted for today. Um, and so through private investment by our providers who have done a great job, by the way. It's not just grant programs getting this done, private on behalf of the, the providers have worked on this as well, and they're doing a great job. Um, but this is just the next wave
and next iteration, um, and we'll see what comes next for folks. But I understand, I understand the disappointment. Thank you, is, is in these cases, is there an appeals process where a homeowner can go and appeal what's been assigned to them. Yeah, so we ran through the, the challenge process was, was that process and so the map is currently locked for this particular program, um, so we're kind of the 84,000 or the 84,000. OK, alright. Alright. Any other questions? OK, uh, saying no, I'll wrap up with one quick question, um,
that looking the, the timeline out, what is the uh anticipated completion for getting broadband out to these, uh, 84,000 residents, so we, um, in the scoring process that the providers go through and in this beed process for Arkansas, they're awarded points to construct and complete their projects in less than 2 years, um, you know, according to the federal statute, they'll have 4 years to complete their projects should they need it, um, but we highly encourage them to go 2 years or less. I make that known. every week when we talk to them on our weekly calls with the providers. And so, um, if we, if
you project out and you say that once we make all the awards, we package it up, go get NTIA approval, come back to the legislature, get approval from you guys. Um, and then execute sub-grant agreements and all the shovels in the ground at that point, you know, we hope the shovels in the ground on these projects by the end of the year, uh, which would then hopefully with a two-year, you know, you look into 27 is where we would like to go, um, but probably technically they'd have till 29. OK. All right. All right. Do you have one more, OK.
Thank you, Mr. Chair. I, I asked you before the committee meeting, but maybe there's another member that would, would like to, to know the answer to this. Um, there's some federal funding that we're not really clear on if things are going to be funded. Do you have thoughts on, does this interfere with our broadband rollout and any of the funding that might be supplied due to what took place yesterday. Yeah, great question. I think it is, it is our understanding that uh the B program and our other broadband programs that are not impacted by what, what has occurred in Washington, uh, the last, the
last couple of days, um, even if hypothetically if there was some sort of pause that took place, right? Uh, we are all systems go in our office, um, and we are not stopping our work. We continue our work and we have communicated that to the Internet service providers as well. OK. All right, so no. All right. um, thank you, gentlemen, for, uh, for being here. All right, um. Next up, uh, we have the Department of Information
And uh while they're getting settled in, uh, Representative, um, and it, since you came in, uh, since this is our first meeting, we went around the room, let everybody introduce themselves. Would you like to have that opportunity real quick or? OK. So if you will hit your button, we'll let you introduce yourself to, uh, everyone here. I apologize for my tardiness. I am state Representative Denise Sen and I represent District 80 here in Little Rock and Parts of Pulaski County. Thank you. Thank you. All right, um, if y'all would please introduce yourselves again to the committee and then you uh may
proceed. Fred Grigg, chief Enterprise architect with the division of Information Systems. Uh, Jay Harton, acting director and chief operating officer of DIS, uh, Gary Vance, uh, chief cyber officer for the state as part of a transformation and shared services and uh with DI. Heather Sacco, Chief Administrator of the Arkansas Data Office, which is part of TS TSS DIS.
Thank you. We really appreciate this opportunity and it's great to hear everybody's background, um, you know, everybody has some form of IT or some interest in communications, um, so next slide. Uh Well, there we go. So, uh, we prepared this agenda. It's, we're gonna touch on 4, primary bullet points where, uh, we're gonna talk about some initiatives that we've had that we've completed that we're
moving forward with, um, and then Gary will talk about cybersecurity and, uh, where we're at on that from a state perspective. And then, um, Heather will talk about AR data and some of the things that they're doing and then I'll wrap it up with the future initiatives that we've pulled out of Arkansas Ford, um, which is one of the original initiatives that we'll, I'll briefly go over to any other super technical question. uh, next slide, please.
All right, so, um, back, I look back and, uh, Jonathan Askins, the former director, uh, gave a presentation back in 2022 in September, um, and so one of the main things that we were focused on during that, um, time was our data center modernization, uh, we had gotten some CARES Act money to build out this program to strengthen, um, what we called at that time was the Arkansas private cloud, so you think about AWS or Microsoft Azure.
cloud computing from Google. We built our own internal, um, cloud within, uh, the state data center to host not only DIS systems but systems for customers that they wanted us to host for them, um, so we completed that, um, program and stood it all up, um, we built half of it at state Data Center West and then we have a disaster recovery site we partnered with Department of Public Safety and their new Um, troop headquarters in
Lowell, Arkansas. And so that is our disaster recovery site, so we have a lot of equipment at SDC West and then we have enough equipment to run production out of the what we call SDC North. Um, so one of the big bullet points was to increase our disaster recovery at the time we were paying. A third party to be able to do disaster recovery and that just wasn't um sustainable for this the size of the systems that we were growing, so we built that
into the CARES Act money and data center modernization, um, we have renamed it to Shared Technology Services and Fred's team primarily runs that today, um, we have connect we do even with it, with the private cloud we have connectivity with us so that we can um in case of a disaster or something, we can move things between the. data center and into the um public or Microsoft. Um, the next big thing that
we've been working on and this is a year and a half going, um, is a big network upgrade, so, um, the K-12 network we redid in 2015. And procured all new hardware during that time, so, um, over the two years we rolled all that out and so now that hardware is becoming a little bit longer, um, and getting to its end of life, so we're currently rolling out all new firewalls. And switches to the schools for their K-12 network connectivity.
And then as soon as that is completed, we'll start doing it with the state agencies. We kind of stagger those, um, two different networks so that we can from a resource for the cash flow. Um And part of that upgrade is for the K-12 we're moving them from 1 megabit per second per student to. Um, so we're also, um, actually it just got put up on Friday.
The state network connectivity contract we do um IFBs for those and so that just dropped, so we'll be getting new pricing for which we always see, you know, the or not the longer, but every 3 years, it, it drastically reduces the cost that we, um. Or build from the Internet providers. And um. Then offered to the state agencies. Um, one of the big things, um, we have, um, we do.
Help desk um or trouble ticketing system, um, not necessarily for all the departments, but we do it for, uh, quite a few and so the current system that we're on is end of life and we're fixing to move to the what we consider our next generation of that, which is ServiceNow. Um, probably 45 of the states, other states that are out there are already using service, the sweet spot, it does a lot, um, where people will be able to actually open tickets and be
able to track their ticket from open all the way down to close. Um, so that they know where they are in the pro and one of the big things about that is, um, you'll, we'll talk a little bit in the, uh, future initiatives. The plan is to roll that out statewide, um, for all the executive branch departments, so that, um, we all have one common system that we're working from, and we can, uh, from like connectivity perspective or
whatever we can train, um, and I kind of briefly already touched on cloud computing, but Um, we do have presence with all three of the major cloud providers, um, AWS, Microsoft Azure, and Google Cloud, DIS owns those presents, um, within those cloud, um, providers so that we can provide. Uh, guidance on the correct cybersecurity stance that needs to be applied. Um, we from a DIS perspective, we're not necessarily just moving
everything into the cloud. If you just take what you have on premise and move it into the cloud, it usually costs more, um, which is another reason why we stood up the shared technology services piece, we bring it into there, we kind of right size it, uh, modernize it there and then move it into the to the cloud provider and having to pay on a monthly basis. Um, so we have a cloud right strategy, um, or whenever systems are up for modernization, um, currently we're working with DFNA on a
couple of the modernization of their systems and those are moving directly into the cloud. Um, and then of course, the last big bullet point is Arkansas Ford. We started back in March working with McKenzie Consulting to gather a bunch of data and everything, and I know, I guess it was in December the progress report from that was published, um, and so from that report, you know, basically McKenzie was saying, we really need to look at the executive branch as like
an enterprise like Walmart would look at their, um, IT department. And not every independent department executive branch department just having their own IT and doing their own things. We need to look at it from the clues on our uh current
initiatives and some things that we've completed. Oh sorry. Representative Meeks in the committee, um, I'm excited to talk to you today about cyber because in the almost 4 years I've been here, this is the first opportunity that I've had. To speak to this group about cyber. And so the first thing I would like you all to know that from a focus and a commitment for me in my office, it's, it's really pretty simple. Uh, my focus is
to ensure that we are protecting Arkansas State resources and Arkansas Citizen data. Uh, and that is my focus and uh. Uh, that's where I, I, I put my primary focus in the, the initiatives that I want to go over with you today are some of the things that we put into place to to help us achieve success in those areas. Uh, so, so the first item is the cyber center of excellence. Um, what we realized, uh, early
on is that, you know, from a state perspective, we have a. We have a fairly diverse group of cyber talent within the state, you know, some good, some may, you know, maybe could use a little bit of Uh, improvement or an opportunity to gain cyber skills, um. We also know that it's very difficult for us to compete on with the private sector for cyber training and cyber skills. So we, we stood up and created what we're calling the cyber center of excellence, um.
And we, we are using, I'm using relationships from my private sector career with tier one, what I call tier one providers we're talking AWS we're talking Paullo, Cisco, Microsoft. Ah, you know, we're leveraging these companies to come into the state and help us train our people. Right And so this is, this has been highly successful. We're seeing great participation or entering into our 2nd full year, uh, of,
of training there, um, and we want to cover basic cybersecurity all the way to advanced. Skills and, and be able to train that within the state. Um, these, these, uh, training cyber training and certifications. are extremely expensive to acquire and so we're trying to bring that at a, at a low cost, no cost opportunity for our cyber folks within the state. That that's our mission there with the cyber center.
The 2nd, the 2 key initiative that we've done is we've created. For now it's, it's on boarded at the executive branch level, but we now have. A cyber security awareness training program. That we can track at the uh department level. Uh, we're able to, uh, apply required basic cybersecurity awareness training, uh, with a heavy emphasis on fishing, uh, you know, we, we deal with, with, with quite a bit of fishing, um, you know,
emails within the state and so we're, we're trying to raise that awareness with with our employees and our departments to be more aware, to be more cyber aware, uh, in, in the area of fishing, but and just uh you know good cyber hygiene in general, uh, it, you know, cyber is. It's It's all of our responsibilities, not just a single responsibility, so we've had, we've had good success there. We're also introducing
more advanced elective type cyber courses and classes that individuals can go out into the portal and they can enroll, uh, and take that training on their own, uh, but uh we are putting a requirement on what we call the basic annual cyber awareness training. That helps us with our audits through, uh, our regulatory audits where we have a requirement to show training and so we're now now able to To attest to that, uh, in an audit environment.
Uh, Representative Meeks, you know, Act 504. I know that you're well aware and very familiar with that 504. It's, it's simply what we've done there. Is that we have, we have created and now have completed cybersecurity policies, uh, for all the executive branch, um, as well as the technology resources clause that was in the act as well, um, those policies are now created, um, and, and we have an
annual process now to where we will review and update those policies annually, um, and we'll do those through a portal that is managed out of my office. Um Next is the virtual chief information security officer. So our goal there was to reach into the departments and create a virtual member of my office in the department. That gives us an opportunity to bring a level of consistency and continuity when, when it comes
to policy and standard, uh, and, and really create a uh a more broad cybersecurity platform that we can bring in, you know, we can bring it to the departments, um, and you know the key there we're trying to bring that cyber standard up and we're trying to do that in an enterprise level, not just at a department level, the visas. So are Um There are a virtual member of the state cyber office and so it
gives us a path into their departments to talk about cybersecurity in. Lastly is the the advanced import protection we've, we, we have advanced and, and, and really matured our cyber endpoint protection. Um, you know, the user end points are our most vulnerable. Uh, attack surface that we have in the state. This is where you know, uh,
threat actors usually enter uh through uh compromising credentials or uh identity threats or uh business email compromises which we, we've seen all of those within the state. So the idea there is to bring a a much more mature and higher level, uh, set of advanced services on our endpoints. That will give us the opportunity to detect those events ahead of time so that we can.
Uh, we can, uh, detect and prevent those from proliferating, um. And we've also added a uh a 24 by 7 by 365 monitoring to where now we have eyes on 24 hours on, on, you know, what's going on with our devices within the state. Uh, this, this again strengthens our, our cyber maturity, uh, it, it, it strengthens our capability to detect threats, and if we can detect them, we can prevent them or we can stop
them. And so, um, that's what's that's what's going on. Uh, within the advanced endpoint protection, and that's, that's, I think that's all I've got to cover with you today. OK. Thank you for the opportunity to share with you a little bit about the Arkansas Data Office and the work that's happening there, um, the Arkansas Data Office is part of
DIS. We are legislatively tasked with breaking down information silos across state government for informed decision making, but also to improve how we're delivering services to our Kansans. And I've identified a couple of key initiatives that I'd like to share with you. You today. Uh, the first being the implementation of an integrated data systems approach to our data strategy. And there are a couple of key pieces of legislation that have supported and facilitated the
implementation of, uh, this initiative, the first being the Act 936 of 2019, which tasked our office with establishing the statewide longitudinal data system, um, also known as the SLDS and SLDS is traditionally known as a P20W system, so that is taking. educational data from pre-K to K-12 to post-secondary, as well
as workforce data, including employment and wage data as well as workforce program participation and linking those different data across disparate data systems so that we as a state can assess the employment and wage outcomes of individuals and populations who have participated in education and training program. that have been administered by the state of Arkansas. Um, the next piece of legislation is Act 634 of 2023,
which cast our office with establishing a statewide data hub. So where the SLDS allows us to link records across different systems and look back over time, the Arkansas Data hub allows us to have that up to real-time transactional operational ability to exchange data across systems and applications. And so the data have really is a large toolbox with a lot of different tools in it, and I
won't go into all the details today, but notably we have an enterprise data cataloging capacity now as well as data quality assessment tools and, um, most significantly, the data hub really just functions as a systems integrator for the state of Arkansas. Uh, the next initiative that I'd like to talk about is digital service delivery. So now that the state has made the investments in the data infrastructure that allows us to
link and connect records across different data systems, we can really leverage that capability to improve how we're delivering services to our Kansans. And through the work of the, um, governor's workforce cabinet under the direction of Chief Workforce Officer Mike Rogers, and as part of Arkansas's new workforce strategy. We have been working to develop two citizen facing platforms that are leveraging this data system behind the scenes.
Um, the first is called launch, uh, launch is effectively a large, uh, workforce system, but this part of launch that we're about to hopefully deploy, um, we're in piloting phase right now, but we have launch for job seekers and launch for employers. And this platform is a Ss-based talent marketplace, and on one side of that market, you have the job seekers, Arkansans and individuals who are looking
for career and job opportunities or training and educational opportunities, and that piece of the platform really functions like a Netflix would. So the more an individual engages with the platform, the more um effective the opportunities that are put in front of the user are going to be. And so on the other side of that marketplace for the employers launched for employers. Employers can come in and I post jobs and identify the skill sets
that they're looking for, and this piece of the platform really functions like a Match.com. And so it's matching the needs of the employers with the skills that have been identified by the individuals that are in the talent pool. So that what makes this system really unique is that the underlying data that is powering the algorithms on the back end is Arkansas data. We're using Arkansas Employment and wage data to identify successful um
employment and, and, um, transitions where individuals in Arkansas with these skills have seen successes in this market. And so we're able to use that information to power the algorithm that's making the matches for both the job seekers and that's not just for matches with, um, job seekers and employers, but we're also able to make matches on educational and training opportunities based on the programs that we have here in the state.
Um, the next piece of launch that I'd like to talk about is Civviform. Civviforms is a pla a separate platform that is integrated with launch and is part of the overall launch ecosystem and Civviform is a service discovery and intake tool. So while individuals who may be looking for employment and educational opportunities on the site, they might also be interested in what public benefit services could potentially also be available to help remove
some barriers to employment. So Civvi Forum is a placing uh public benefits programs out there and serving as a referral mechanism. And what's interesting about Civic Forum and unique is that as as users are inputting their information into the, um, The intake tool, it's capturing that and reusing it and repopulating it. So our, our Kansans aren't having to reenter the same information over and
over again as they are introduced to different services that they may be eligible for. OK, the, the next key initiative that I'd like to hit on is the artificial intelligence Center of Excellence, um, in September of last year, Governor Sanders established the AI Center of Excellence, um, as a subcommittee of the data and transparency panel. The COE is chaired by Chief Data Officer
Robert McGoo, and they have been charged with, um, outlining a comprehensive approach to secure ethical. and effective AI deployment in Arkansas. The COE is composed of about 20 members and, um, it includes individuals from the public and private sector academia as well as we have 4 legislators serving on the panel as well. An initial report was uh delivered to the governor's office at the end of the year, and we do anticipate that that
should be published sometime in the near future. And the, the goals of the, the COE at this point in time are really to focus on protecting Arkansans and their data, improving government services and preparing Arkansas for the AI economy, and that's just initial guidelines and guardrails at the um, um, start of this, this, uh, twelve-month engagement, but there will be a comprehensive report, um, delivered to the governor's office at the end of
September this year, which will include recommendations for policies, governance. works and initial findings from pilot projects around AI. And that's all I have to share today. Thank you. All right, back to, uh, kind of future initiatives, um, which are pretty much have all been based off of Arkansas Ford, um, Gary and I actually a couple of months ago, had a meeting with
Representative Richardson, um, and it's kind of funny having been a director of IT where he's at, he basically outlined these exact 3, future initiatives that the Arkansas Forward Project. Um, brought to light, so IT governance. So right now, um, again, Each department kind of acts as their own IT shop. They're not, I don't wanna say they're not unified, right? So we're not all, uh, we don't have a statewide IT strategy.
Um, they all have to put together and send in their IT plans on the biennial, but, um, we're not, we don't have one common strategy, um, what the Arkansas forward um project brought to light was there's 100 currently there's about 1018 what we would consider IT projects that are ongoing, um, but. A lot of them are very, um, while they may not cost a whole lot, they may have a low value of what do they really bring to
the table. Um, there was, I think, 8 to 10 that were identified that would be, um, you know, IT projects that would, you know, really bring the benefit and, um, with the cost that they are. So, um, from that, we're talking about doing an IT governance model and team to basically start reviewing all projects that come. Um, that are IT related or have some IT component, um, so that we can look at the cost, we can look and see what the benefit is
and everything, uh, to that point. Um, the next biggest thing, uh, which this really should be number one is a central cybersecurity office while, um, Gary is the chief information security officer for the state and we had the state, um. Security office within DIS. There's really no, um, while he created the VCO team. There's no ability to really enforce these policies with them, um, we do have the Act 504
where we have the minimum standards, but there's greater policies that we want to roll out and, um, put before them and right now it's kind of an optional thing, so we don't. We want Gary to be able to roll these policies out and then report on them and, you know, give us or give status of, you know, who's complying, who's not, and then, you know, that way we can work with them to make sure that they're in compliance and then again the
central IT service delivery, um, our first pilot is gonna be around the service now, so a centralized incident, uh, management system request and change management system. Um, and that will be one of the first things that will, uh, roll out to all the departments, um, And then we'll through the governance model we'll identify more and more, um, products that could be centralized from a, uh, perspective. I know. Because right now DISC is anything over $100,000 from an
IT perspective, um, I know for a fact that right now there's like 5 or 6 different grant management programs, you know, let's get everybody together. Let's look and see, you know. Probably one grant management system meets 98% of everybody's needs and maybe that 2%, is it a nice to have or is it, uh, we really need to have this type of thing, so, um, it's really about our future initiatives or about bringing everybody together and, you know, making sure that we're spending money wisely and not
just because this department needs it, this department needs it, and we're having duplicative efforts. So, um, that's everything and. We're open for questions, um, first off, I want to, um, thank you all for the, for the work that y'all do. Y'all, uh, do the magic behind the scenes that makes the technology work and a lot of times, um, Uh, y'all don't get the recognition. I don't think that y'all deserve, um, I've, I've had the privilege. I, I did, uh,
you know, legislation for the broadband manager's office. I did the data and transparency, I did the cybersecurity, uh, but without y'all's efforts, it's just words on a paper and you guys have grabbed that and, uh, have taken it, uh, beyond what my expectations were. So I, I appreciate all the work that y'all have done and understandably, the work is not done, and I appreciate it. I know Representative Richardson is working kind of picking that baton up and continuing to carry it in, in the future. And, uh, I actually have legislation coming on the AI piece that you've
talked about that will, um, require essentially what that AI panel is already doing, so you all are already ahead of the ball in that regard. So again, thank you for, for all the, uh, work and effort that, uh, that you have done, uh, on the cybersecurity piece, I do want to remind the committee. Um, that, um, every year, any cybersecurity incidents are reported now through legislative audit, so we do have that information available. Well, we didn't have that in the past. If there is a major cybersecurity
breach within the state, then, um, myself, um, our Senate, uh, chair, the ALC chairs, the pro tem, the speaker, and the governor are alerted that that cyber breach has occurred. We have had one of those alerts in the past 2 years. Um, if those alerts do. occur, the, the joint committee that we have with the Senate is authorized to go into a private executive session so that way we can hear the details of those events, learn from them, um, without letting the bad guys know where our vulnerabilities
are at. Uh, we haven't had to use that yet, but just make the committee aware that we do have that authority should that become, uh, necessary. Um, I see, uh, Representative Richardson did have a question if his colleague will allow. And so we will go to that, uh, representative. Uh, thank you, Mr. Chair. Uh, yeah, it seems, uh, not everyone's, uh, up for me asking questions, but, uh, I, I really appreciate you guys being here today and, uh, and, and providing the information that you have and it's great to see the initiatives that are taking shape and some of the things that are getting accomplished. I
did have uh a couple of really small kind of questions and you, you, you kind of touched on it, but I wanted to make sure I, um, I understood completely what it is. So your server, the ServiceNow rollout is complete to all of the executive. But we have now we're just now starting that just starting that process and that's gonna have an inclusive change management system. What is the current process for change management handled in. So currently each department
handles their own change management, uh, from a DIS perspective, any changes from our perspective internally DIS every morning at 8:15 has a change management call, um, just for DIS staff and to go over changes that we'll be making that day or in the future, um, and then every Tuesday and Thursday at 2 p.m. we have a change management, uh, call with all of our customers or the other departments of anything that might impact them. OK, so that, but they handle
their own change management change management, interesting, um, the, the other one I guess is. Might be more for Gary and I, I think we've already. touched on this, but I'd like it to be said in the committee. Are we doing a cyber review of new projects that the state is taking on. We, we use the visa, so um. Representatives in each department, uh. To assist in that. Effort, uh.
But I, I think it's worth commenting that it You know, for us to deliver a comprehensive cybersecurity program for the state. We have to do that through common standards and policies and frameworks. And as, as Jay mentioned, uh, In, in our, in our current structure, it, it's, it's difficult to establish, uh, enterprise standards in a in a decentralized environment, um. And
We're we're trying to bridge that gap with the VSOs. But that that is a voluntary. Uh, really effort that, that I reached into the. Uh, you know, into the departments through the CIOs and made an appeal that, you know, could we, could you support this effort and, you know, uh, with the understanding that we're, you know, we're trying to mature, you know, we're, we're trying to increase our ability to defend against threats across
all the state. Not just at the department level, which is how I view. Uh, the cyber, you know, initiatives that we're doing today, I mean, we should be able to benefit at an enterprise level across all departments, not, you know, not just at a single departmental level. Let me add just a little bit, and that's really why we wanna have that IT governance is there's no official review from a cyber perspective. It's all voluntary like Gary said. Right. There is no official, you know,
sign off by Gary or anybody like that that says, yes, this has been through. Thank you for that. OK. Um, and, and just to give the, the committee, um, for those who that might be new, um, can you tell us how many attacks farther against state systems on a daily basis. So that, so that everybody understands the, the scale that we're talking about here. So the way I, I, the way I look at attacks and the way I look at cyber threat data.
Is, uh, you know, I don't, I don't talk in terms of incidents because there's millions of those 10s of thousands of those. What what I focus on are are the threat data that that means something to us, you know, as a state, right? And so attack vectors, uh, there, there are many, right? There are many, uh, different levels of tack vectors, but, uh, for, for the state there, there are meaningful threats that we want to You know Pay particular attention to so
you know I, I can tell you on a weekly basis that, that we are, we, we are actively working anywhere from 20 to 50 threats a week. Of a variety of types, identity threats, um, attempted ransomware, uh, events. Um, malware events where threat actors can come in and, and establish what we call command and control, they will take over
your device and they will use your device to talk outbound to uh a nonmilitia site, uh, they can do that to hide themselves or they can do that to begin an intel, uh, gathering process within the state and. Usually ransomware, uh, threat actors will land in our environment, and they will live there for months. Uh, as they gather their intel and then when they feel like they're ready to, to implement, you know, their, um,
Their encryption and take over the environment they will. But, um, it, it, you know, Representative Meeks at a weekly level, you can do the math, but. We're actively working 10 to 50 events of, of what I call not incidents but events a week. So, so as you can see, this is a legitimate ongoing concern that we need to face and, um, we got to get it right every time. So again, I appreciate. Um, do, do any of the agencies do, um, rat
uh red hat events or, uh, you know, attacks to try to look for vulnerabilities beforehand. Uh, sadly, no. But It, it, it's high on my list of establishing again enterprise level, uh, penetration testing and threat and risk assessment process that will allow us to understand our gaps at a state level, uh, and to introduce red teaming and blue teaming events, uh, that, that help our cyber
professionals, our cyber folks, uh, become, uh, you know, more educated and more in tune to understanding, you know, the threat landscape. All right, thank you. Uh, Representative Mayberry. Thank you. We have a meeting at 1:30, so I don't want to keep people here real long. I know legislators, we got to get out of here, but I did want to maybe talk with you a little bit more outside of here, if we can connect in, in some way, and you sparked my interest when you started talking about Civviform. And so I went to the website to
see what, what's on there because I, I actually started this conversation back in 2015 or so, um, there, it's very hard to find the services that are available for people with disabilities. And there's not a good place to go and we had many conversations. I was told that's too expensive, a of a system to do, blah blah blah. I had to drop it. But it sounds like you might have that formula, um, when I look at the site, it, it, it indicates childcare, education, food, general healthcare, housing and
training, but I don't necessarily see that there's like, uh, an aging area or developmental disabilities, and I don't know if that's been part of discussion. It's definitely been part of the from a discovery perspective, so we've piloted the, the platform today with WOA funded workforce programs. So we have things like employment services, adult education, we're bringing WIC in next, so we'll have that support as well. We've been in ongoing conversations with the leadership at DHS on bringing
some of their programs in. So there's, we've captured a large number of programs and, um, we're just getting them in the queue to start taking advantage of the platform. I love to be a part of that conversation or whatever, because, I mean, you talk to families who have children with disabilities and they don't know about the services and they go, well, I didn't know that. No one's ever told me, and I, and I don't even know where to go and all these forms you have to fill out, and if you're telling me, you might be able to fill it out one time and, uh, it just, it, it would make life a whole lot's
the goal. I would love to connect with you and talk about it more. One thing I do want to point out is that this was developed using philanthropic. services from the Google Foundation. So it didn't even touch the state of Arkansas's budget. And so we've had this entire platform developed for us and then they, they're turning the keys over, it's ours, we own it, we maintain it. It's hosted in the state's data center, so we're very excited about the possibilities Actually kind of along those terms, my, my long-term vision for the data and transparency,
and hopefully that's been passed down through the generations as at some point, I'd like to create a single citizen portal where a citizen can go to Arkansas.gov. They log in and everything is right there, taxes, driver's license, you know, your voter ID, uh, all these services, everything's all in that one location so citizens don't have to go to 30 different websites to uh to look this stuff up, you know, if I, if I change, if I move the simple case, if I move right now and I
go to the driver's license bureau and I update my address there. Nobody else in state government has it. Wouldn't it be nice if there was one portal I could go and do that and everybody had it. And so I, I, I think they've caught that vision. They're moving in that direction just like everything else that, that, that's uh Easier said than done. So, uh, so any last-minute questions from committee. Alright. Seeing done, thank you all again, I appreciate the work that you're doing and look forward to continue uh working with y'all as we go into the future, uh, committee members saying no further business
before the committee. We are adjourned.
Agenda
ORGANIZATIONAL MEETING
A. Call to Order
B. Presentation by Arkansas State Broadband Office - Glen Howie, State Broadband Director, Arkansas State Broadband Office
C. Presentation by Arkansas Division of Information Systems, - Jay Harton, Acting Director/Chief Operating Officer, Division of Information Systems
D. Other Business
E. Adjournment
Documents
| Title | Type | Pages | Source |
|---|---|---|---|
| Agenda — ADVANCED COMMUNICATIONS AND INFORMATION TECHNOLOGY - HOUSE, Jan 29, 2025 | Agenda | 1 | Official source ↗ |