E5. FY 22 Award - SLCGP - Network Intrusion Detection SystemKalispell IT Department
CITY-7F (406) 758-7751 itkkali spell. com
OF 201 Ist Ave. East
Kalispell, Montana, 59901
KALISPELL www.kalispell.com
REPORT TO: Doug Russell, City Manager
FROM: Erika Billiet, Information Technology Director
SUBJECT: State and Local Cybersecurity Grant Program
NIIEETINGDATE: Apri121,2025
BACKGROUND:
The city of Kalispell has been awarded $17,750 for a network intrusion detection system, funded
by the State and Local Cybersecurity Grant Program's (SLCGP) FY 22 award letter. The purpose
of the FY 22 SLCGP is to strengthen cybersecurity practices and resilience of state and local
governments.
Four of the eight included focus areas of the SLCGP grant were open in the FY 22 SLCGP.
Network monitoring and management intrusion detection systems for county and city networks was
one of the four focus areas open.
RECOMMENDATION: It is recommended that the City Council accept the grant award of
$17,750 from the State and Local Cybersecurity Grant Program and authorize the city manager to
sign the necessary documents.
FISCAL EFFECTS: The city of Kalispell is not required to match the FY 22 SLCGP $17,750
award.
ALTERNATIVES: As suggested and approved by City Council.
ATTACHNILENT: SLCGP FY 22 Award Letter with Agreement
's
DE
CD J:Ss rn
A 13
Doug Russell
City of Kalispell
201 1 st Ave E
Kalispell MT 59901
City Manager Doug Russell,
State and Local Cybersecurity Grant Program
FY 2022 Award Letter
Congratulations, on behalf of Montana Disaster and Emergency Services (MT DES), the application for financial
assistance submitted under the Fiscal Year (FY) 2022 State and Local Cybersecunity Grant Program, Network
Intrusion Detection System (IDS), has been approved in the amount of $17,750.00 to provide services to local
entities. City of Kalispell is not required to match this award with any amount of non -Federal funds.
Before City of Kalispell requests and receives any of the Federal funds, acceptance of the award must be
established. By accepting this award, City of Kalispell acknowledges that the terms of the following documents are
incorporated into the terms of this award:
• Agreement Articles (attached to this Award Letter)
• Obligating Document for Award (attached to this Award Letter)
• FY 22 State and Local Cybersecunity Grant Program Notice of Funding Opportunity
Per the Notice of Funding Opportunity (NOFO), all sub -recipients are required to complete the following:
• Complete the Nationwide Cybersecurity Review (NCSR)
• Register and maintain CISA's no cost Cyber Hygiene Services (CyHy)
Please make sure you read, understand, and maintain a copy of these documents in the official file for this award.
In order to establish acceptance of the award and its terms, please complete, sign and return the Obligating
Document for Award to your MT DES Grant Coordinator.
For additional assistance, please contact your MT DES Grant Coordinator.
Sincerely,
Burke S. Honzel
Preparedness Bureau Chief
Montana Disaster and Emergency Services
CC Erika Billiet
Page 1 of 12
Agreement
0/8', 0
CD EE S 'M
0;o'
AGREEMENT ARTICLES
State and Local Cybersecurity Grant Program
SUB -RECIPIENT: City of Kalispell
PROGRAM: State and Local Cybersecurity Grant
STATE GRANT NUMBER: 22SLCGP-KAL-IDS
TABLE OF CONTENTS
Article I
Summary Description of Award
Article 2
SLCGP Performance Goal
Article 3
DHS Standard Terms and Conditions Generally
Article 4
Assurances, Administrative Requirements, Cost Principles, Representations and
Certifications
Article 5
General Acknowledgements and Assurances
Article 6
Acknowledgement of Federal Funding from DHS
Article 7
Activities Conducted Abroad
Article 8
Age Discrimination Act of 1975
Article 9
Americans with Disabilities Act of 1990
Article 10
Best Practices for Collection and Use of Personally Identifiable Information
Article I I
Civil Rights Act of 1964 — Title VI
Article 12
Civil Rights Act of 1968
Article 13
Copyright
Article 14
Debarment and Suspension
Article 15
Drug -Free Workplace Regulations
Article 16
Duplication of Benefits
Article 17
Education Amendments of 1972 (Equal Opportunity in Education Act) — Title IX
Article 18
Energy Policy and Conservation Act
Article 19
False Claims Act and Program Fraud Civil Remedies
Article 20
Federal Debt Status
Article 21
Federal Leadership on Reducing Text Messaging while Driving
Article 22
Fly America Act of 1974
Article 23
Hotel and Motel Fire Safety Act of 1990
Article 24
John S. McCain National Defense Authorization Act of Fiscal Year 2019
Article 25
Limited English Proficiency (Civil Rights Act of 1964, Title VI)
Article 26
Lobbying Prohibitions
Article 27
National Environmental Policy Act
Article 28
Nondiscrimination in Matters Pertaining to Faith -Based Organizations
Article 29
Non -Supplanting Requirement
Article 30
Notice of Funding Opportunity Requirements
Article 31
Patents and Intellectual Property Rights
Article 32
Procurement of Recovered Materials
Article 33
Rehabilitation Act of 1973
Article 34
Reporting of Matters Related to Recipient Integrity and Perfon-nance
Article 35
Reporting Subawards and Executive Compensation
Article 36
Required Use of American Iron, Steel, Manufactured Products, and Construction
Materials
Article 37
SAFECOM
Article 38
Terrorist Financing
Article 39
Trafficking Victims Protection Act of 2000 (TVPA)
Article 40
Universal Identifier and System of Award Management
Article 41
USA PATRIOT Act of 2001
Article 42
Use of DHS Seal, Logo and Flags
Article 43
Whistleblower Protection Act
Article 44
Envirom-nental Planning and Historic Preservation (EHP) Review
Article 45
Applicability of DHS Standard Tenns and Conditions to Tribes
Article 46
Acceptance of Post Award Changes
Article 47
Disposition of Equipment Acquired Under the Federal Award
Article 48
Prior Approval for Modification of Approved Budget
Article 49
Indirect Cost Rate
Article 50
MT DES Specific Acknowledgements and Assurances
Article 51
Accruals
Article 52
Authorized Representative
Article 53
Nationwide Cybersecurity Review
Article 54
Cyber Hygiene Services
Article 1 Summary Description of Award
The purpose of the Fiscal Year 2022 State and Local Cybersecurity Grant Program (SLCGP) is to
assist state, local, and territorial (SLT) governments with managing and reducing systemic cyber
risk. Through funding from the Infrastructure Investment and Jobs Act, also known as the Bipartisan
Infrastructure Law, the SLCGP enables DHS to make targeted cybersecurity investments in SILT
government agencies, thus improving the security of critical infrastructure and improving
the resilience of the services SILT governments provide their community. This SLCGP award
provides funding in the amount of: $2,427,866 for the state of Montana. Of this amount, up to
$121,393 can be retained by the State Administrative Agency (SAA) for management and
administrative expenses. The terms of the approved Investment Justification(s) and Budget Detail
Worksheet(s) submitted by the recipient are incorporated into the terms of this Federal award,
subject to the additional description and limitations stated in this Agreement Article and the
limitations stated in subsequent reviews by FEMA and CISA of the award budget. Post -award
documents uploaded into ND Grants for this award are also incorporated into the terms and
conditions of this award, subject to any limitations stated in subsequent approvals by FEMA and
CISA of changes to the award. Investments not listed in this Agreement Article are not approved for
funding under this award.
Article 2 SLCGP Performance Goal
In addition to the Performance Progress Report (PPR) recipients must demonstrate how the grant -
funded projects address the capability gaps identified in their Cybersecurity Plan or other relevant
documentation or sustains existing capabilities per the CISA-approved Investment Justification. The
capability gap reduction or capability sustainment must be addressed in Performance Narrative.
Article 3 DHS Standard Terms and Conditions Generally
The Fiscal Year (FY) 2022 DHS Standard Terms and Conditions apply to all new federal financial
assistance awards funded in FY 2022. These terms and conditions flow down to subrecipients
unless an award term or condition specifically indicates otherwise. The United States has the right
to seek judicial enforcement of these obligations.
All legislation and digital resources are referenced with no digital links. The FY 2022 DHS Standard
Terms and Conditions will be housed on dhs.gov at www.dhs..qov/publication/fvl 5-dhs-standard-
terms-and-conditions.
Article 4 Assurances, Administrative Requirements, Cost Principles, Representations and
Certifications
1. DHS financial assistance recipients must complete either the Office of Management and
Budget (OMB) Standard Form 424B Assurances - Non -Construction Programs, or OMB
Standard Form 424D Assurances - Construction Programs, as applicable. Certain assurances in
these documents may not be applicable to your program, and the DHS financial assistance office
(DHS FAO) may require applicants to certify additional assurances. Applicants are required to fill
out the assurances as instructed by the awarding agency.
11. DHS financial assistance recipients are required to follow the applicable provisions of the
Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal
Awards located at Title 2, Code of Federal Regulations (C. F. R.) Part 200 and adopted by DHS at
2 C.F.R. Part 3002.
111. By accepting this agreement, recipients, and their executives, as defined in 2 C.F.R. section
170.315, certify that their policies are in accordance with OMB's guidance located at 2 C.F.R.
Part 200, all applicable federal laws, and relevant Executive guidance.
Article 5 General Acknowledgements and Assurances
All recipients, subrecipients, successors, transferees, and assignees must acknowledge and
agree to comply with applicable provisions governing DHS access to records, accounts,
documents, information, facilities, and staff.
1. Recipients must cooperate with any DHS compliance reviews or compliance
investigations conducted by DHS.
11. Recipients must give DHS access to examine and copy records, accounts, and other
documents and sources of information related to the federal financial assistance award and
permit access to facilities or personnel.
111. Recipients must submit timely, complete, and accurate reports to the appropriate DHS
officials and maintain appropriate backup documentation to support the reports.
IV. Recipients must comply with all other special reporting, data collection, and evaluation
requirements, as prescribed by law, or detailed in program guidance.
V. Recipients (as defined in 2 C.F.R. Part 200 and including recipients acting as pass -
through entities) of federal financial assistance from DHS or one of its awarding component
agencies must complete the DHS Civil Rights Evaluation Tool within thirty (30) days of
receipt of the Notice of Award for the first award under which this term applies. Recipients of
multiple awards of DHS financial assistance should only submit one completed tool for their
organization, not per award. After the initial submission, recipients are required to complete
the tool once every two (2) years if they have an active award, not every time an award is
made. Recipients should submit the completed tool, including supporting materials, to
CivilRightsEvaluation@hq.dhs.gov. This tool clarifies the civil rights obligations and related
reporting requirements contained in the DHS Standard Terms and Conditions.
Subrecipients are not required to complete and submit this tool to DHS. The evaluation tool
can be found at https://www.dhs.gov/publication/dhs-civi1-rights-evaluation-tool.
The DHS Office for Civil Rights and Civil Liberties will consider, in its discretion, granting an
extension if the recipient identifies steps and a timeline for completing the tool. Recipients
should request extensions by emailing the request to CivilRightsEvaluation@hq.dhs.gov
prior to expiration of the 30-day deadline.
Article 6 Acknowledgement of Federal Funding from DHS
Recipients must acknowledge their use of federal funding when issuing statements, press releases,
requests for proposal, bid invitations, and other documents describing projects or programs funded in
whole or in part with federal funds.
Article 7 Activities Conducted Abroad
Recipients must ensure that project activities performed outside the United States are
coordinated as necessary with appropriate government authorities and that appropriate
licenses, permits, or approvals are obtained.
Article 8 Age Discrimination Act of 1975
Recipients must comply with the requirements of the Age Discrimination Act of 1975, Pub. L. No. 94-
135 (codified as amended at 42 U.S.C. § 6101 et seq.), which prohibits discrimination on the basis of
age in any program or activity receiving federal financial assistance.
Article 9 Americans with Disabilities Act of 1990
Recipients must comply with the requirements of Titles 1, 11, and III of the Americans with Disabilities
Act, Pub. L. No. 101-336 (1990) (codified as amended at 42 U.S.C. §§ 12101— 12213), which
prohibits recipients from discriminating on the basis of disability in the operation of public entities,
public and private transportation systems, places of public accommodation, and certain testing
entities.
Article 10 Best Practices for Collection and Use of Personally Identifiable
Information
Recipients who collect personally identifiable information (PII) as part of carrying out the scope of
work under a federal award are required to have a publicly available privacy policy that describes
standards on the usage and maintenance of the PII they collect. DHS defines PII as any information
that permits the identity of an individual to be directly or indirectly inferred, including any information
that is linked or linkable to that individual. Recipients may also find the DHS Privacy Impact
Assessments: Privacy Guidance and Privacy Template as useful resources respectively.
Article 11 Civil Rights Act of 1964 — Title VI
Recipients must comply with the requirements of Title VI of the Civil Rights Act of 1964, Pub. L. No.
88-352 (codified as amended at 42 U.S.C. § 2000d et seq.), which provides that no person in the
United States will, on the grounds of race, color, or national origin, be excluded from participation in, be
denied the benefits of, or be subjected to discrimination under any program or activity receiving
federal financial assistance. DHS implementing regulations for the Act are found at 6 C.F.R. Part 21.
Recipients of an award from the Federal Emergency Management Agency (FEMA) must also comply
with FEMA's implementing regulations at 44
C. F. R. Part 7.
Article 12 Civil Rights Act of 1968
Recipients must comply with Title VIII of the Civil Rights Act of 1968, Pub. L. No. 90-284 (codified as
amended at 42 U.S.C. § 3601 et seq.) which prohibits recipients from discriminating in the sale,
rental, financing, and advertising of dwellings, or in the provision of services in connection. therewith,
on the basis of race, color, national origin, religion, disability, familial status, and sex, as
implemented by the U.S. Department of Housing and Urban Development at 24 C.F.R. Part 100.
The prohibition on disability discrimination includes the requirement that new multifamily housing
with four or more dwelling units— i.e., the public and common use areas and individual apartment
units (all units in buildings with elevators and ground -floor units in buildings without elevators) —be
designed and constructed with certain accessible features. (See 24 C.F.R. Part 100, Subpart D.)
Article 13 Copyright
Recipients must affix the applicable copyright notices of 17 U.S.C. §§ 401 or 402 to any work first
produced under federal awards and also include an acknowledgement that the work was produced
under a federal award (including the federal award number and federal awarding agency). As
detailed in 2 C.F.R. § 200.315, a federal awarding agency reserves a royalty -free, nonexclusive, and
irrevocable right to reproduce, publish, or otherwise use the work for federal purposes and to
authorize others to do so.
Article 14 Debarment and Suspension
Recipients must comply with the non -procurement debarment and suspension regulations
implementing Executive Orders (E.O.) 12549 and 12689 set forth at 2 C.F.R. Part 180 as
implemented by DHS at 2 C.F.R. Part 3000. These regulations prohibit recipients from entering into
covered transactions (such as subawards and contracts) with certain parties that are debarred,
suspended, or otherwise excluded from or ineligible for participation in federal assistance programs
or activities.
Article 15 Drug -Free Workplace Regulations
Recipients must comply with drug -free workplace requirements in Subpart B (or Subpart C, if the
recipient is an individual) of 2 C.F.R. Part 3001, which adopts the Government- wide implementation
(2 C.F.R. Part 182) of the Drug -Free Workplace Act of 1988 (41 U.S.C. §§ 8101-8106).
Article 16 Duplication of Benefits
Recipients are prohibited from charging any cost to this federal award that will be included as a cost
or used to meet cost sharing or matching requirements of any other federal award in either the
current or a prior budget period. (See 2 C.F.R. § 200.403(f)). However, recipients may shift costs
that are allowable under two or more federal awards where otherwise permitted by federal statutes,
regulations, or the federal financial assistance award terms and conditions.
Article 17 Education Amendments of 1972 (Equal Opportunity in Education Act) — Title IX
Recipients must comply with the requirements of Title IX of the Education Amendments of 1972,
Pub. L. No. 92-318 (codified as amended at 20 U.S.C. § 1681 et seq.), which provide that no person in
the United States will, on the basis of sex, be excluded from participation in, be denied the benefits of,
or be subjected to discrimination under any educational program or activity receiving federal financial
assistance. DHS implementing regulations are codified at 6 C.F.R. Part 17. Recipients of an award
from the Federal Emergency Management Agency (FEMA) must also comply with FEMA's
implementing regulations at 44 C.F.R. Part 19.
Article 18 Energy Policy and Conservation Act
Recipients must comply with the requirements of the Energy Policy and Conservation Act, Pub. L.
No. 94-163 (1975) (codified as amended at 42 U.S.C. § 6201 et seq.), which contain policies relating to
energy efficiency that are defined in the state energy conservation plan issued in compliance with this
Act.
Article 19 False Claims Act and Program Fraud Civil Remedies
Recipients must comply with the requirements of the False Claims Act, 31 U.S.C. §§ 3729- 3733, which
prohibit the submission of false or fraudulent claims for payment to the Federal Government. (See 31
U.S.C. §§ 3801-3812, which details the administrative remedies for false claims and statements made.)
Article 20 Federal Debt Status
All recipients are required to be non -delinquent in their repayment of any federal debt. Examples of
relevant debt include delinquent payroll and other taxes, audit disallowances, and benefit
overpayments. (See OM B Circular A-1 29.)
Article 21 Federal Leadership on Reducing Text Messaging while Driving
Recipients are encouraged to adopt and enforce policies that ban text messaging while driving
recipient -owned, recipient -rented, or privately owned vehicles when on official government business
or when performing any work for or on behalf of the Federal Government. Recipients are also
encouraged to conduct the initiatives of the type described in Section 3(a) of E.O. 13513.
Article 22 Fly America Act of 1974
Recipients must comply with Preference for U.S. Flag Air Carriers (a list of certified air carriers can be
found at: Certificated Air Carriers List I US Department of Transportation,
https://www.transportation.gov/policy/aviation-policy/certificated- air-carriers-list)for international air
transportation of people and property to the extent that such service is available, in accordance with
the International Air Transportation Fair Competitive Practices Act of 1974, 49 U.S.C. § 40118, and the
interpretative guidelines issued by the Comptroller General of the United States in the March 31,
1981, amendment to Comptroller General Decision B-1 38942.
Article 23 Hotel and Motel Fire Safety Act of 1990
Recipients must ensure that all conference, meeting, convention, or training space funded entirely or in
part by federal award funds complies with the fire prevention and control guidelines of Section 6 of
the Hotel and Motel Fire Safety Act of 1990, 15 U.S.C. § 2225a.
Article 24 John S. McCain National Defense Authorization Act of Fiscal Year 2019
Recipients, subrecipients, and their contractors and subcontractors are subject to the prohibitions
described in section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year
2019, Pub. L. No. 115-232 (2018) and 2 C.F.R. 200.216, 200.327, 200.471, and Appendix 11 to 2
C. F. R. Part 200. The statute — as it applies to DHS recipients, subrecipients, and their contractors
and subcontractors — prohibits obligating or expending federal award funds on certain
telecommunications and video surveillance products and contracting with certain entities for
national security reasons.
Article 25 Limited English Proficiency (Civil Rights Act of 1964, Title VI)
Recipients must comply with Title VI of the Civil Rights Act of 1964 (42 U.S.C. § 2000d et seq.)
prohibition against discrimination on the basis of national origin, which requires that recipients of
federal financial assistance take reasonable steps to provide meaningful access to persons with
limited English proficiency (LEP) to their programs and services. For additional assistance and
information regarding language access obligations, please refer to the DHS Recipient Guidance:
https://www.dhs.gov/guidance-published-help- department -supported- organ izations-provide-
mean i ngful-access-people-I imited and additional resources on http://www.lep.gov.
Article 26 Lobbying Prohibitions
Recipients must comply with 31 U.S.C. § 1352 and 6 C.F.R. Part 9, which provide that none of the
funds provided under a federal award may be expended by the recipient to pay any person to
influence, or attempt to influence an officer or employee of any agency, a Member of Congress, an
officer or employee of Congress, or an employee of a Member of Congress in connection with any
federal action related to a federal award or contract, including any extension, continuation, renewal,
amendment, or modification. Per 6 C.F.R. Part 9, recipients must file a lobbying certification form as
described in Appendix A to 6 C.F.R. Part 9 or available on Grants.gov as the Grants.gov Lobbying
Form and file a lobbying disclosure form as described in Appendix B to 6 C.F.R. Part 9 or available
on Grants.gov as the Disclosure of Lobbying Activities (SF-LLL).
Article 27 National Environmental Policy Act
Recipients must comply with the requirements of the National Environmental Policy Act of 1969, Pub. L.
No. 91-190 (1970) (codified as amended at 42 U.S.C. § 4321 et seq.) (NEPA) and the Council on
Environmental Quality (CEQ) Regulations for Implementing the Procedural Provisions of NEPA,
which require recipients to use all practicable means within their authority, and consistent with other
essential considerations of national policy, to create and maintain conditions under which people
and nature can exist in productive harmony and fulfill the social, economic, and other needs of
present and future generations of Americans.
Article 28 Nondiscrimination in Matters Pertaining to Faith -Based Organizations
It is DHS policy to ensure the equal treatment of faith -based organizations in social service programs
administered or supported by DHS or its component agencies, enabling those organizations to
participate in providing important social services to beneficiaries. Recipients must comply with the
equal treatment policies and requirements contained in 6 C.F.R. Part 19 and other applicable
statues, regulations, and guidance governing the participations of faith- based organizations in individual
DHS programs.
Article 29 Non -Supplanting Requirement
Recipients of federal awards under programs that prohibit supplanting by law must ensure that federal
funds supplement but do not supplant non-federal funds that, in the absence of such federal funds,
would otherwise have been made available for the same purpose.
Article 30 Notice of Funding Opportunity Requirements
All the instructions, guidance, limitations, scope of work, and other conditions set forth in the Notice
of Funding Opportunity (NOFO) for this federal award are incorporated by reference. All recipients
must comply with any such requirements set forth in the NOFO. If a condition of the NOFO is
inconsistent with these terms and conditions and any such terms of the Award, the condition in the
NOFO shall be invalid to the extent of the inconsistency. The remainder of that condition and all other
conditions set forth in the NOFO shall remain in effect.
Article 31 Patents and Intellectual Property Rights
Recipients are subject to the Bayh-Dole Act, 35 U.S.C. § 200 et seq. and applicable regulations
governing inventions and patents, including the regulations issued by the Department of Commerce at
37 C.F.R. Part 401 (Rights to Inventions Made by Nonprofit Organizations and Small Business Firms
under Government Awards, Contracts, and Cooperative Agreements) and the standard patent
rights clause set forth at 37 C.F.R. § 401.14.
Article 32 Procurement of Recovered Materials
States, political subdivisions of states, and their contractors must comply with Section 6002 of the
Solid Waste Disposal Act, Pub. L. No. 89-272 (1965) (codified as amended by the Resource
Conservation and Recovery Act at 42 U.S.C. § 6962) and 2 C.F.R. § 200.323. The requirements of
Section 6002 include procuring only items designated in guidelines of the Environmental Protection
Agency (EPA) at 40 C. F. R. Part 247 that contain the highest percentage of recovered materials
practicable, consistent with maintaining a satisfactory level of competition.
Article 33 Rehabilitation Act of 1973
Recipients must comply with the requirements of Section 504 of the Rehabilitation Act of 1973, Pub. L.
No. 93-112 (codified as amended at 29 U.S.C. § 794), which provides that no otherwise qualified
handicapped individuals in the United States will, solely by reason of the handicap, be excluded from
participation in, be denied the benefits of, or be subjected to discrimination under any program or
activity receiving federal financial assistance.
Article 34 Reporting of Matters Related to Recipient Integrity and Performance
If the total value of any currently active grants, cooperative agreements, and procurement
contracts from all federal awarding agencies exceeds $10,000,000 for any period of time
during the period of performance of the federal award, then the recipient must comply with
the requirements set forth in the government -wide Award Term and Condition for Recipient
Integrity and Performance Matters located at 2 C.F.R. Part 200, Appendix XII, the full text of
which is incorporated by reference.
Article 35 Reporting Subawards and Executive Compensation
For federal awards that equal or exceed $30,000, recipients are required to comply with the
requirements set forth in the government -wide award term on Reporting Subawards and Executive
Compensation set forth at 2 C.F.R. Part 170, Appendix A, the full text of which is incorporated by
reference.
Article 36 Required Use of American Iron, Steel, Manufactured Products, and Construction
Materials
Recipients of an award of Federal financial assistance from a program for infrastructure are hereby
notified that none of the funds provided under this award may be used for a project for infrastructure
unless: (1) all iron and steel used in the project are produced in the United States —this means all
manufacturing processes, from the initial melting stage through the application of coatings, occurred
in the United States; (2) all manufactured products used in the project are produced in the United
States —this means the manufactured product was manufactured in the United States; and the cost
of the components of the manufactured product that are mined, produced, or manufactured in the
United States is greater than 55 percent of the total cost of all components of the manufactured
product, unless another standard for determining the minimum amount of domestic content of the
manufactured product has been established under applicable law or regulation; and (3) all
construction materials are manufactured in the United States —this means that all manufacturing
processes for the construction material occurred in the United States. The Buy America preference
only applies to articles, materials, and supplies that are consumed in, incorporated into, or affixed to
an infrastructure project. As such, it does not apply to tools, equipment, and supplies, such as
temporary scaffolding, brought to the construction site and removed at or before the completion of
the infrastructure project. Nor does a Buy America preference apply to equipment and furnishings,
such as movable chairs, desks, and portable computer equipment, that are used at or within the
finished infrastructure project but are not an integral part of the structure or permanently affixed to
the infrastructure project. Waivers, when necessary, recipients may apply for, and the agency may
grant, a waiver from these requirements. The agency should notify the recipient for information on
the process for requesting a waiver from these requirements. (a) When the Federal agency has
determined that one of the following exceptions applies, the awarding official may waive the
application of the domestic content procurement preference in any case in which the agency
determines that: (1) applying the domestic content procurement preference would be inconsistent
with the public interest; (2) the types of iron, steel, manufactured products, or construction materials
are not produced in the United States in sufficient and reasonably available quantities or of a
satisfactory quality; or (3) the inclusion of iron, steel, manufactured products, or construction
materials produced in the United States will increase the cost of the overall project by more than 25
percent. A request to waive the application of the domestic content procurement preference must be
in writing. The agency will provide instructions on the format, contents, and supporting materials
required for any waiver request. Waiver requests are subject to public comment periods of no less
than 15 days and must be reviewed by the Made in America Office. There may be instances where
an award qualifies, in whole or in part, for an existing waiver described as "Buy America" Preference
in FEMA Financial Assistance Programs for Infrastructure I FEMA.gov. Definitions The definitions
applicable to this term are set forth at 2 C.F.R. § 184.3, the full text of which is incorporated by
reference.
Article 37 SAFECOM
Recipients receiving federal financial assistance awards made under programs that provide emergency
communication equipment and its related activities must comply with the SAFECOM Guidance for
Emergency Communication Grants, including provisions on technical standards that ensure and
enhance interoperable communications. The SAFECOM Guidance is updated annually and can be
found at Funding and Sustainment I CISA.
Article 38 Terrorist Financing
Recipients must comply with E.O. 13224 and applicable statutory prohibitions on transactions with, and the
provisions of resources and support to, individuals and organizations associated with terrorism.
Recipients are legally responsible for ensuring compliance with the E.O. and laws.
Article 39 Trafficking Victims Protection Act of 2000 (TVPA)
Recipients must comply with the requirements of the government -wide financial assistance award
term which implements Trafficking Victims Protection Act of 2000, Pub. L. No. 106-386, § 106
(codified as amended at 22 U.S.C. § 7104). The award term is located at 2 C. F. R. § 175.15, the full
text of which is incorporated by reference.
Article 40 Universal Identifier and System of Award Management
Recipients are required to comply with the requirements set forth in the government -wide financial
assistance award term regarding the System for Award Management and Universal Identifier
Requirements located at 2 C.F.R. Part 25, Appendix A, the full text of which is incorporated reference.
Article 41 USA PATRIOT Act of 2001
Recipients must comply with requirements of Section 817 of the Uniting and Strengthening America by
Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 (USA PATRIOT
Act), which amends 18 U.S.C. §§ 175-175c.
Article 42 Use of DHS Seal, Logo and Flags
Recipients must obtain written permission from DHS prior to using the DHS seals, logos, crests, or
reproductions of flags, or likenesses of DHS agency officials. This includes use of DHS components
(e.g., FEMA, CISA, etc.) seals, logos, crests, or reproductions of flags, or likenesses of component
officials.
Article 43 Whistleblower Protection Act
Recipients must comply with the statutory requirements for whistleblower protections at 10
U.S.0 § 470141 U.S.C. § 4712.
Article 44 Environmental Planning and Historic Preservation (EHP) Review
DHS/FEMA funded activities that may require an Environmental Planning and Historic Preservation
(EHP) review are subject to the FEMA EHP review process. This review does not address all federal,
state, and local requirements. Acceptance of federal funding requires the recipient to comply with all
federal, state and local laws. DHS/FEMA is required to consider the potential impacts to natural and
cultural resources of all projects funded by DHS/FEMA grant funds, through its EHP review process, as
mandated by: the National Environmental Policy Act; National Historic Preservation Act of 1966, as
amended; National Flood Insurance Program regulations; and any other applicable laws and executive
orders. General guidance for FEMA's EHP process is available on the DHS/FEMA Website at:
https://www.fema.gov/grants/guidance-tools/environmental-historic. Specific applicant guidance on
how to submit information for EHP review depends on the individual grant program and applicants
should contact their grant Program Officer to be put into contact with EHP staff responsible for assisting
their specific grant program. The EHP review process must be completed before funds are released to
carry out the proposed project; otherwise, DHS/FEMA may not be able to fund the project due to
noncompliance with EHP laws, executive orders, regulations, and policies. If ground disturbing
activities occur during construction, the applicant will monitor ground disturbance, and if any potential
archaeological resources are discovered the applicant will immediately cease work in that area and
notify the pass -through entity, if applicable, and DHS/FEMA.
Article 45 Applicability of DHS Standard Terms and Conditions to Tribes
The DHS Standard Terms and Conditions are a restatement of general requirements imposed upon
recipients and flow down to sub -recipients as a matter of law, regulation, or executive order. If the
requirement does not apply to Indian tribes or there is a federal law or regulation exempting its
application to Indian tribes, then the acceptance by Tribes of, or acquiescence to, DHS Standard Terms
and Conditions does not change or alter its inapplicability to an Indian tribe. The execution of grant
documents is not intended to change, alter, amend, or impose additional liability or responsibility upon
the Tribe where it does not already exist.
Article 46 Acceptance of Post Award Changes
In the event FEMA determines that an error in the award package has been made, or if an
administrative change must be made to the award package, recipients will be notified of the change
in writing. Once the notification has been made, any subsequent requests for funds will indicate
recipient acceptance of the changes to the award. Please call FEMA Grant Management Operations at
(866) 927-5646 or via e-mail to: ASK-GMD@fema.dhs.gov if you have any questions.
Article 47 Disposition of Equipment Acquired Under the Federal Award
For purposes of original or replacement equipment acquired under this award by a non -state recipient
or non -state sub -recipients, when that equipment is no longer needed for the original project or
program or for other activities currently or previously supported by a federal awarding agency, you
must request instructions from FEMA to make proper disposition of the equipment pursuant to 2
C.F.R. section 200.313. State recipients and state sub -recipients must follow the disposition
requirements in accordance with state laws and procedures.
Article 48 Prior Approval for Modification of Approved Budget
Before making any change to the FEMA approved budget for this award, you must request prior written
approval from FEMA where required by 2 C.F.R. section 200.308. For purposes of non -construction
projects, FEMA is utilizing its discretion to impose an additional restriction under 2 C.F.R. section
200.308(f) regarding the transfer of funds among direct cost categories, programs, functions, or
activities. Therefore, for awards with an approved budget where the federal share is greater than the
simplified acquisition threshold (currently $250,000), you may not transfer funds among direct cost
categories, programs, functions, or activities without prior written approval from FEMA where the
cumulative amount of such transfers exceeds or is expected to exceed ten percent (10%) of the total
budget FEMA last approved. For purposes of awards that support both construction and non -
construction work, FEMA is utilizing its discretion under 2 C.F.R. section 200.308(h)(5) to require
the recipient to obtain prior written approval from FEMA before making any fund or budget transfers
between the two types of work. You must report any deviations from your FEMA approved budget in
the first Federal Financial Report (SF-425) you submit following any budget deviation, regardless of
whether the budget deviation requires prior written approval.
Article 49 Indirect Cost Rate
2 C. F. R. section 200.211 (b)(1 5) requires the terms of the award to include the indirect cost rate for
the federal award. If applicable, the indirect cost rate for this award is stated in the budget documents
or other materials approved by FEMA and included in the award file.
Article 50 MT DES Specific Acknowledgements and Assurances
Sub -recipients must acknowledge and agree to comply with applicable provisions governing MT
DES access to records, accounts, documents, information, facilities, and staff.
1 . Sub -recipients must cooperate with any compliance reviews or compliance investigations
conducted by MT DES.
2. Sub -recipients must give MT DES access to, and the right to examine and copy, records,
accounts, and other documents and sources of information related to the federal financial
assistance award and permit access to facilities, personnel, and other individuals and
information as may be necessary, as required by MT DES regulations and other applicable
laws or program guidance.
3. Sub -recipients must submit timely, complete, and accurate reports to the appropriate MT
DES officials and maintain appropriate backup documentation to support the reports.
4. Sub -recipients must comply with all other special reporting, data collection, and evaluation
requirements, as prescribed by law or detailed in program guidance.
5. The State of Montana shall not be liable for any reimbursement amount greater than the
award amount available to each sub -recipient.
6. Failure of the sub -recipient to accomplish SLCGP objectives may result in the reduction or
withholding of funds, or other action, as determined by MT DES.
The State of Montana has the right to seek judicial enforcement of these obligations
Article 51 Accruals
As established within Montana Operations Manual Policy, accrual documentation is required of all
sub -recipients by the Montana Department of Administration, State Financial Services Division, and
must be submitted to MT DES no later than the second week of June, or as instructed by MT DES.
Article 52 Authorized Representative
As evidenced by the signatures found in the Letter of Obligation, the Sub -Recipient Signatory
Official agrees to appoint the Sub -Recipient Authorized Representative to act on behalf of City of
Kalispell. This individual shall be duly authorized with all necessary powers with regard to the
administration and oversight of the 2022 State and Local Cybersecurity Grant Program, 22SLCGP-
KAL-I IDS. The Catalog of Federal Domestic Assistance (CFDA) number associated with this grant is
97.137.
Article 53 Nationwide Cylbersecurity Review
Subrecipients of FY 2022 grant awards will be required to complete the Nationwide Cybersecurity
Review (NCSR), enabling agencies to benchmark and measure progress of improving their
cybersecurity posture. The Chief Information Officer (CIO), Chief Information Security Officer
(CISO), or equivalent for each recipient and subrecipient should complete the NCSR. If there is no
CIO or CISO, the most senior cybersecurity professional should complete the assessment. The
NCSR is available at no cost to the user and takes approximately 3-6 hours to complete. The 2024
NCSR will be open from October — February 2024. MT DES will provide subrecipients with
additional information upon opening of the review.
Article 54 Cylber Hygiene Services
Subrecipients of FY 2022 SLCGP are required to register and maintain CISA's no cost Cyber
Hygiene (CyHy) Services for vulnerability services and web application services as outline in the
Notice of Funding Opportunity. Subrecipients will report completion with performance progress
reports.
Obligating Document for Award
STATE GRANT NUMBER:
SUB -RECIPIENT NAME AND ADDRESS:
ISSUING STATE OFFICE AND ADDRESS:
22SLCGP-KAL-IDS
City of Kalispell
201 1 st Ave E
Montana Disaster and Emergency Services
P.O. Box 4789
FEDERAL AGREEMENT
Kalispell, MT 59901
1956 MT Majo Street
NUMBER:
Fort Hamison, MT 59636-4789
EMW-2022-CY-00027
AMENDMENT NUMBER:
NAME OF SUB-
SUB -RECIPIENT AUTHORIZED
REPRESENTATIVE CONTACT INFORMATION:
RECIPIENT AUTHORIZED
REPRESENTATIVE:
ebillietgkalispell.com
406-758-7751
En*ka Billiet
EFFECTIVE DATE OF THIS
METHOD OF PAYMENT:
NAME AND CONTACT INFORMATION OF MT
ACTION:
DES GRANT COORDINATOR:
EFT
11/21/2024
Emily Schuff
Emily. Schuffigmt.gov
406-417-9236
PERIOD OF PERFORMANCE:
From: To:
FEDERAL AWARD AMOUNT: $17,750.00
12/1/2024 09/30/2026
Budget Period:
ASSISTANCE
CFDA #:
ARRANGEMENT:
From: To:
97.137
12/1/2024 09/30/2026
Cost Reimbursement
SUB -RECIPIENT SIGNATORY OFFICIAL (Name and Title)
DATE
SUB -RECIPIENT AUTHORIZED REPRESENTATIVE (Name and Title)
DATE
MT DES SIGNATORY (Name, Title and Date)
Amanda Avard, Preparedness Program Manager, Authonized Organizational Representative
FFY 2022 State and Local Cybersecurity
Grant Program Guidance
Guidance Released: July 16, 2024
MONTANA DISASTER AND EMERGENCY SERVICES
'. &14 A
Ln a
;100
1061e
��49
P -Q 13
1956 Mt. Majo Street
PO Box 4789
Fort Harrison,, MT 59636
Application Due Date: 11:55 pm September 13, 2024
STATE & LOCAL CYBERSECURITY GRANT PROGRAM
TABLE OF CONTENTS
1.0
Overview .......................................................................................................................................... 4
2.0
Purpose and Objectives ...................................................................................................................
4
3.0
FUNDING ..........................................................................................................................................
5
4.0
Grant Requirements —State Entity ..................................................................................................
5
5.0
Eligibility Requirements for Local Applicants ...................................................................................
6
5.1
Eligible Applicants .......................................................................................................................
6
5.2
Applications .................................................................................................................................
6
5.3
Cost Share or Match ....................................................................................................................
6
5.4
Nationwide Cyber Security Review (NCSR) ................................................................................
6
5.5
CISA Services and Memberships ................................................................................................
6
6.0
Application and Submission Information ......................................................................................... 7
6.1
State Cybersecurity Plan Priorities — Attachment C .................................................................. 7
6.2
Application information .............................................................................................................
7
6.3
Unique Entity Identifier (UEQ .....................................................................................................
8
6.4
Applicant Agent or Authorized Representative .........................................................................
8
6.5
Electronic Signature ....................................................................................................................
8
6.6
Application Review and Recommendation ................................................................................
8
7.0
Project Categories and Activities .....................................................................................................
8
7.1
Planning .......................................................................................................................................
9
7.2
Organization ................................................................................................................................
9
7.3
Equipment ...................................................................................................................................
9
7.4
Training ......................................................................................................................................
10
7.5
Exercise ......................................................................................................................................
10
7.6
Management and Administration ............................................................................................
11
8.0
Unallowable Costs and Activities ...................................................................................................
11
8.1
Unallowable Costs ....................................................................................................................
11
8.2
Supplanting ...............................................................................................................................
11
8.3
Telecommunication, Video Surveillance Equipment and Services .........................................
11
9.0
Procurement ..................................................................................................................................
12
2
10.0
Award Administration Information ................................................................................................
13
10.1
Award Administration ..............................................................................................................
13
10.2
Nationwide Cybersecurity Review - Required .........................................................................
13
10.3
CYBER HYGIENE SERVICES - Required ......................................................................................
13
10.4
Environmental and Historic Preservation (EHP) Compliance ..................................................
14
11.0
Reporting .......................................................................................................................................
14
11.1
Quarterly Progress Reports ......................................................................................................
14
11.2
Financial Reporting (Payment Requests) .................................................................................
14
11.3
Accruals .....................................................................................................................................
15
12.0
Scope of Work and Budget Modifications .....................................................................................
15
13.0
Monitoring/Technical Assistance ...................................................................................................
15
13.1
Monitoring ................................................................................................................................
15
13.2
Technical Assistance .................................................................................................................
15
14.0
Project Closeout and De -Obligated Funds .....................................................................................
15
14.1
Closeout .....................................................................................................................................
15
14.2
De -obligated Funds ...................................................................................................................
15
15.0
MT DES Contact Information .........................................................................................................
16
Attachment A: State of Montana Cybersecurity Plan 2022-2024 .................................................................... 17
Attachment B: State of Montana Cybersecurity Planning Committee Charter .............................................. 48
Attachment C: FY 2022 SLCGP Project Priorities ................................................................................................. 55
AttachmentD: CISA Resources .............................................................................................................................. 57
3
State and Local Cybersecurity Grant Program
Funding for this program is provided to Montana Disaster and Emergency Services (MT DES). MT DES is
the State Administrative Authority for this program. Funding is provided by the U.S. Department of
Homeland Security (DHS), Federal Emergency Management Agency (FEMA), Grant Programs Directorate
(G P D).
Catalog of Federal Domestic Assistance (CFDA) Number: 97.137
CFDA Title: State and Local Cybersecurity Grant Program (SLCGP)
Applications will only be accepted on-line through the AmpliFund system. Please contact MT DES staff
for a link to the application. Applicants who have not been in AmpliFund prior to this will need to choose
11register" on the login page. Applicants who have logged into AmpliFund in the past may log in and start
the application.
KEY DATES:
• Application opens on July 16, 2024
• Application closes on Friday, September 13, 2024 at 11:55 PM MDT
• Projected period of performance (POP) is October 1, 2024 to June 30, 2026.
(extensions not permissible)
1.0 Overview
Our nation faces unprecedented cybersecurity risks, including increasingly sophisticated adversaries,
widespread vulnerabilities in commonly used hardware and software, and broad dependencies on
networked technologies for the day-to-day operation of critical infrastructure. Cyber risk management
is further complicated by the ability of malicious actors to operate remotely, linkages between cyber and
physical systems, and difficulty of reducing vulnerabilities.
The SLCGP grant requires the state to develop a Cybersecurity Plan, establish a Cybersecurity Planning
Committee to support the development of the plan, adopt key cybersecurity best practices, and identify
projects to implement using the SLCGP funding.
2.0 Purpose and Objectives
The purpose of the FY 2022 SLCGP is to strengthen cybersecurity practices and resilience of state and
local governments. Reference section 5.1 for a list of local governments eligible to apply. The SLCGP
provides funding from the Infrastructure Investment and Jobs Act to implement investments that
improve the security of critical infrastructure and improve the resilience of the services governments
provide their communities. The grant is a reimbursable pass -through grant program with an overall goal
to improve the cybersecurity posture of state and local government organizations by providing
assistance for managing and reducing systemic cyber risk through the following objectives:
0 Objective 1: Develop and establish appropriate governance structures, including developing,
implementing, or revising cybersecurity plans, to improve capabilities to respond to
cybersecurity incidents and ensure continuity of operations.
0
Objective 2: Understand their current cybersecurity posture and areas for improvement based
on continuous testing, evaluation, and structured assessments.
• Objective 3: Implement security protections commensurate with risk.
• Objective 4: Ensure organization personnel are appropriately trained in cybersecurity,
commensurate with responsibility.
3.0 FUNDING
The State of Montana was awarded $2,427,866.00 for the FY 2022 SLCGP. The SAA must obligate at
least 80 percent of funds awarded to local and tribal governments, with a minimum of 25 percent of the
overall award going to rural areas. 20 percent of the funds may be utilized for state level projects, with
the SAA retaining up to 5 percent of funds awarded for administration costs. The Cybersecurity
Committee's intent, per the cybersecurity plan, is with local consent, to have the state contract for
services directly on behalf of local units of government.
Funds will be allocated to projects through an application process.
For this grant, rural jurisdictions are defined as counties, tribes, and cities with a population of less than
50,000.
4.0 Grant Requirements — State Entity
SLCGP recipients are highly encouraged to prioritize the following activities using FY 2022 SLCGP funds,
all of which are statutorily required as a condition of the grant:
• Establish a Cybersecurity Planning Committee.
• Develop or revise a state-wide Cybersecurity Plan.
• Conduct assessment and evaluations as the basis for individual projects throughout the life of
the program.
Adopt key cybersecurity best practices.
bersecuritv PlanninE Committee
The Planning Committee is responsible for developing, implementing, and revising Cybersecurity Plans
(including individual projects); formally approving the Cybersecurity Plan (along with the chief
information officer or chief information security officer); assisting with determination of effective
funding priorities (i.e., work with entities within the eligible entity's jurisdiction to identify and prioritize
individual projects). This will be led by Montana State Information Technology Services Division (SITSD).
The Cybersecurity Planning Committee must include the following entities:
0 Eligible Entity (state administrative agency)
• County, City, and town representation
• Institutions of public education
• Institutions of public health
• As appropriate, representatives from rural, suburban, and high -population jurisdictions.
9
Montana formed its Cybersecurity Planning Committee and adopted the committee charter on
November 14, 2022. The committee includes 14 members and 2 advisory members representing the
required cybersecurity planning entities. Attachment B
CVbersecuritV Plan
Montana is required to submit a Cybersecurity Plan that adheres to the 16 required elements identified
in section 2220A of the Homeland Security Act of 2002 as amended by the BIL. The Cybersecurity Plan
must include a description of state and local roles, an assessment of capabilities for each element,
address resources and timeline for implementing the Plan, and identify metrics. State and local
governments are encouraged to take a holistic approach in the development of their Plan as entities
must be able to sustain capabilities once SLCGP funds are no longer available. The role of state entities
as coordinator and service provider to local entities should be encouraged and supported.
On November 28, 2023, DHS, FEMA approved the 2022-2024 State of Montana Cybersecurity Plan,
allowing the state to request funding holds to be released for approved projects. Attachment A
5.0 Eligibility Requirements for Local Applicants
5.1 Eligible Applicants
Eligible Applicants for competitive awards include local and tribal governments. Local government
means a city, town, county, consolidated city -county, special district, or school district or subdivision of
these entities. Nonprofit, for -profit, and other entities not deemed as a local government entity are not
eligible to receive SLCGP funds.
5.2 Applications
Eligible applicants listed above may only submit one FY 2022 SLCGP application. Each eligible applicant
may apply for projects within the identified focus areas listed in section 6 and will be asked to prioritize
each focus area within the application. Each applicant must detail in the application how the project
relates to improving, preventing, preparing for, protecting against, and responding to cybersecurity
incidents and best practices.
5.3 Cost Share or Match
Cost share or match is not required for the FFY 2022 SLCGP. Future awards will have cost share
requirements. Match amounts for future award years are as follows: FY 2023 20%, FY 2024 30%, FY 2025
40%. Local match may be in-kind/soft from eligible activities.
5.4 Nationwide Cyber Security Review (NCSR)
Applicants must agree to complete the NCSR, administered by MS-ISAC, to receive funding or services
under the SLCGP.
5.5 CISA Services and Memberships
Applicants must agree to adhere to or sign up for the following free CISA cyber hygiene services.
• vulnerability scanning
• web application scanning
Applicants are strongly encouraged to sign up for other services and memberships, such as IVIS-ISAC and
MT-ISAC, as outlined in Attachment D — CISA Resources
6.0 Application and Submission Information
6.1 State Cybersecurity Plan Priorities— Attachment C
The cybersecurity committee has identified eight key efforts in the Cybersecurity Plan to strengthen
cybersecurity across the state. All projects must align with the focus areas identified in the plan. Those
areas are:
1. Whole of state cybersecurity initiatives (state level project)
2. Perform security strategic assessments (state level project)
3. Perform security technical assessments (state level project)
4. Build security awareness
S. Migrate to GOV domains (identify if interested)
6. Build a cybersecurity workforce
7. Server and workstation behavior -based endpoint protection
8. Network monitoring and management intrusion detection systems for county networks
Only four of the eight focus areas listed above are currently open to eligible local and tribal governments
to apply:
1. Build security awareness
2. Build a cybersecurity workforce
3. Server and workstation behavior -based endpoint protection
4. Network monitoring and management intrusion detection systems for county networks
6.2 Application Information
Applicants are responsible for planning far enough in advance to complete their application prior to the
established deadline. The application deadline is set and will not be extended due to the competitive
nature of the grant. If technical difficulties occur, it is the responsibility of the applicant to inform MT
DES immediately to work on a resolution.
For FY 2022 SLCGP funds, applications are for approved projects meeting the outlined focus areas and
integral towards achieving an objective/outcome as outlined in the Cybersecurity Plan under Appendix
A. Before starting the application, it is highly recommended that applicants first review the project
focus areas and decide which will be applied for. Once applicants have a clear understanding of what
is being requested then begin the application and complete the SLCGP Focus Area information form of
the application next. The SLCGP Focus Area information form contains information that will help
applicants fill out the Project information and Budget sections of the application.
The application will consist of the following sections that must be completed:
1. Opportunity Details
2. Project Information
3. Application Forms
a. Applicant Entity Information
b. Applicant Assessment
c. SLCGP Baseline Requirements
d. SLCGP Focus Area Information —COMPLETE FIRST when beginning the application!
4. Budget
5. Submit
6.3 Unique Entity identifier (UEI)
The federal government now requires the Unique Entity Identifier (UEI) numbers that are created in
SAM.gov. This number is required to apply for and receive SLCGP funds. Jurisdictions that do not have a
UEI may request one through SAM.gov.
6.4 Applicant Agent or Authorized Representative
The applicant agent or authorized representative is the individual who is able or given authority to make
legally binding commitments for the applicant organization.
6.5 Electronic Signature
Applications submitted through AmpliFund constitute a submission as electronically signed applications.
When submitting the application, the name of the applicant's authorized representative will be typed
into the certification block.
6.6 Application Review and Recommendation
FY 2022 SLCGP applications will be evaluated by MT DES staff through a review process to determine the
application completeness and eligibility based on adherence to state and federal program guidance.
Eligible projects will then be reviewed and prioritized by the State Cybersecurity Planning Committee for
final recommendation to the SAA, CIO, and CISO for funding allocations. Prioritization and rankings are
used as recommendations but do not constitute an approval for funding.
7.0 Project Categories and Activities
Federal funds made available through this award may only be used for the purpose set forth in this
award and must be consistent with statutory authority for the award. Award funds may not be used for
matching funds for any other Federal award, lobbying, or intervention in federal regulatory or
adjudicatory proceedings. In addition, federal funds may not be used to sue the Federal Government or
any other government entity.
Sub -recipients must comply with all the requirements in 2 C.F.R. Part 200 (Uniform Administrative
Requirements, Cost Principles, and Audit Requirements for Federal Awards) https://www.ecfr.gov/cgi-
bin/text-idx?tpl=/ecfrbrowse/Title02/2cfr2OO main 02.tpl
Costs charged to SLCGP must be consistent with the Cost Principles for Federal Awards, 2 C.F.R Part 200,
Subpart E.
Applicants are encouraged to provide project and budget details related to Planning, Organization,
Equipment, Training, Exercise, and Management and Administration (M&A) activities. This list is not all-
inclusive.
7.1 Planning
Planning costs are allowable under this program. SLCGP funds may be used for a range of planning
activities, such as those associated with the development, review, and revision of the holistic, entity -
wide cybersecurity plan and other planning activities that support the program goals and objectives and
Cybersecurity Planning Committee requirements.
7.2 Organization
Organization costs are allowable underthis program. Sub -recipients mustjustify proposed expenditures
of SLCGP funds to support organization activities within their application. Organizational activities
include:
1. Program management;
2. Development of whole community partnerships that support the Cybersecurity Planning
Committee;
3. Structures and mechanisms for information sharing between the public and private sector;
and
4. Operational support.
Personnel hiring, overtime, and backfill expenses are permitted under this grant to perform allowable
SLCGP planning, organization, training, exercise, and equipment activities. Personnel expenses may
include, but are not limited to training and exercise coordinators, program managers and planners, and
cybersecurity navigators. Grant sub -recipients must demonstrate that the personnel will be sustainable.
7.3 Equipment
Equipment costs are allowable under this program. SLCGP equipment is intended to be used to address
cybersecurity risks and cybersecurity threats to information systems owned or operated by, or on behalf
of, state and local governments. The allowable equipment categories and equipment standards for
SLCGP are listed on the DHS Authorized Equipment List (AEL).
https://www.fema.gov/grants/tools/authorized-equipment-list
Unless otherwise stated, equipment must meet all mandatory regulatory and/or DHS/FEMA-adopted
standards to be eligible for purchase using these funds. In addition, agencies will be responsible for, at
their own expense, obtaining and maintaining all necessary certifications and licenses for the requested
equipment. Investments in emergency communications systems and equipment must meet applicable
SAFECOM Guidance recommendations. Such investments must be coordinated with the Statewide
Inoperability Coordinator (SWIC) and the State Interoperability Governing Body (SIGB) to ensure
interoperability and long-term compatibility.
SLCGP funds may be used to purchase maintenance contracts or agreements, warranty coverage,
licenses, and user fees in support of a system or equipment. These contracts may exceed the period
of performance if they are purchased incidental to the original purchase of the system or
equipment as long as the original purchase of the system or equipment is consistent with that
which is typically provided for, or available through, these types of agreements, warranties, or
contracts. When purchasing a stand-alone warranty or extending an existing maintenance contract
on an already -owned piece of equipment system, coverage purchased may not exceed the period of
performance of the award used to purchase the maintenance agreement or warranty, and it may
only cover equipment purchased with SLCGP funds or for equipment dedicated for SLCGP-related
purposes. As with warranties and maintenance agreements, this extends to licenses and user fees
as well.
The use of SLCGP funds may be used for maintenance contracts, warranties, repair or replacement
costs, upgrades, and user fees, unless otherwise noted. Except for maintenance plans or extended
warranties purchased incidental to the original purchase of the equipment, the period covered by
maintenance or warranty plan must not exceed the POP of the specific grant funds used to purchase the
plan or warranty. While these activities may be submitted, they are not a priority. General maintenance
and repairs are not allowable.
7.4 Training
Training costs are allowable under this program. Allowable training -related costs under SLCGP include
the establishment, support, conduct, and attendance of training and/or in conjunction with training by
other federal agencies. Training conducted using SLCGP funds must align to the states Cybersecurity
Plan and address a performance gap identified through assessments and contribute to building a
capability that will be evaluated through a formal exercise. Any training or training gaps, including
training related to underserved communities that may be more impacted by disasters, including
children, seniors, individuals with disabilities or access and functional needs, individuals with diverse
culture and language use, individuals with lower economic capacity and other underserved populations,
should be identified in an assessment and addressed in the eligible entity's training cycle. Sub -recipients
are encouraged to use existing training rather than developing new courses. When developing new
courses, recipients are encouraged to apply the Analyze, Design, Develop, Implement, and Evaluate
(ADDIE) model of instructional design.
Sub -recipients are also encouraged to utilize FEMA's National Preparedness Course Catalog. Trainings
include programs or courses developed for and delivered by institutions and organizations funded by
FEMA. This includes the Center for Domestic Preparedness (CDP), the Emergency Management Institute
(EMI), and FEMA's Training Partner Programs, including the Continuing Training Grants (CTG), the
National Domestic Preparedness Consortium (NDPQ the Rural Domestic Preparedness Consortium
(RDPQ and other partners.
The catalog features a wide range of course topics in multiple delivery modes to meet FEMA's mission
scope as well as the increasing training needs of federal, state, local, territorial, and tribal audiences. The
catalog can be accessed at http://www.firstrespondertraining.gov.
7.5 Exercise
Exercises conducted with grant funding should be managed and conducted consistent with the
Homeland Security Exercise and Evaluation Program (HSEEP). Sub -recipients are required to submit an
After -Action Repo rt/I m provement Plan (AAR/IP) for each SLCGP funded exercise. AAR/IPs should be
submitted to MT DES, through the quarterly Status Report, no more than 90 days after completion of
the exercise. Sub -recipients are reminded of the importance of implementing corrective actions. Sub-
10
recipients are required to use the HSEEP AAR/IP template that can be found at
https://des.mt.gov/Preparedness/Training Exercise/AAR-Oct-2018 --- Participant-Form.docx. The AAR/IP
must be submitted prior to requesting reimbursement.
7.6 Management and Administration
Management and Administration (M&A) activities are those directly relating to the management and
administration of SLCGP funds, such as financial management and monitoring. Sub -recipients may use a
maximum of up to 5% of funding for M&A purposes. SLCGP funds used for M&A must have supporting
documentation (i.e. timecards (salary), invoices/receipts (goods), and general ledgers). M&A must be
coded separately on the general ledger so that it is clear as to how many hours were allocated toward
M &A for the grant.
8.0 Unallowable Costs and Activities
8.1 Unallowable Costs
The grant specifically restricts the use of funds for construction and renovation. Any project that would
require an Environmental and Historic Preservation (EHP) review is not allowed. This is as minimal as
drilling a new hole in a wall, running cable, or hanging a shelf.
Other Unauthorized costs include, but are not limited to, the following:
• Any recipient cost -sharing contribution
• Pay a ransom
• Recreational or social purposes
• Cybersecurity insurance premiums
• General maintenance and repairs
• Parking tickets or other traffic tickets
• Sole source contracts and procurements not pre -approved by MT DES
• Stand-alone working meals
• Alcoholic beverages
• Supplanting any expense already budgeted
• Entertainment
• Laundry
• Late payment fees
• Drone training
Activities unrelated to the completion and implementation of the State and Local Cybersecurity Grant.
8.2 Supplanting
Grant funds must supplement, not supplant, replace, or offset state or local funds that have been
appropriated for the same purpose.
if supplanting is determined, sub -recipients will be required to repay grant funds expended in support
of those efforts.
8.3 Telecommunication, Video Surveillance Equipment and Services
Sub -recipients may not use any FEMA funds to procure or obtain China made or China affiliated
telecommunication, video surveillance equipment or services. Reference FEMA policy #405-143-1
11
https://www.fema.gov/sites/default/files/documents/fema Policy-405-143-1-prohibition-covered-
services-equipment-gpd.pd
Additional guidance is available at https://www.ecfr.gov/current/title-2/subtitle-A/chapter-II/part-
200/appendix-Appendix%2011%20to%2OPart%20200
Effective August 13, 2020, FEMA sub -recipients may not use any FEMA funds under open or new
awards to:
(1) Procure or obtain any equipment, system, or service that uses covered telecommunications
equipment or services as a substantial or essential component of any system, or as critical
technology of any system;
(2) Enter into, extend, or renew a contract to procure or obtain any equipment, system, or
service that uses covered telecommunications equipment or services as a substantial or
essential component of any system, or as critical technology of any system; or
(3) Enter into, extend, or renew contracts with entities that use covered telecommunications
equipment or services as a substantial or essential component of any system, or as critical
technology as part of any system.
Per section 889(f)(2)-(3) of the FY 2019 NDAA and 2 C.F.R. § 200.216, covered telecommunications
equipment or services means:
i. Telecommunications equipment produced by Huawei Technologies Company or ZTE
Corporation, (or any subsidiary or affiliate of such entities);
ii. For the purpose of public safety, security of Government facilities, physical security
surveillance of critical infrastructure, and other national security purposes, video surveillance
and telecommunications equipment produced by Hytera Communications Corporation,
Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any
subsidiary or affiliate of such entities);
iii. Telecommunications or video surveillance services provided by such entities or using such
equipment; or
iv. Telecommunications or video surveillance equipment or services produced or provided by an
entity that the Secretary of Defense, in consultation with the Director of National Intelligence or
the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or
controlled by, or otherwise connected to, the People's Republic of China.
Examples of the types of products covered by this prohibition include phones, internet, video
surveillance, and cloud servers when produced, provided, or used by the entities listed in the definition
of "covered telecommunications equipment or services." See 2 C.F.R. § 200.471.
Please reference the System for Award Management (SAM) for a consolidated exclusion list of
subsidiaries of telecommunication companies https://sam.gov/SAM/. Please contact your grant
coordinator to determine if equipment or services is eligible under this program.
9.0 Procurement
All FEMA awards are subject to the federal procurement standards under the Uniform Administrative
Requirements, Cost Principles, andAudit Requirementsfor FederalAwards found at 2 C.F.R. § 200.317-
12
LOO.327. Applicants selected for funding does not constitute award. Any costs incurred or obligated
prior to the execution of an award are not allowed.
When purchasing under a FEMA award, a state entity must follow its own procurement policies and
procedures pursuant to 2 C.F.R. § 200.317 as well as all other applicable state and federal laws,
executive orders, and implementing regulations.
When purchasing under a FEMA award, a non -state entity must have and use documented procurement
procedures, consistent with state, local, and Tribal laws and regulations and conforming to appliable
federal law and the procurement standards identified in 2 C.F.R. § 200.317-200.327. For a non -state
entity, where a difference exists between a federal procurement standard and a state, local, and/or
Tribal procurement standard or regulation, the non -state entity must apply the most restrictive
standard.
MT DES may request a copy of an entities documented procurement procedures which reflect
applicable state and local laws and regulations. Procurement procedures must conform to applicable
Federal law and the standards identified in 2 C.F.R. § 200.318
For more information on federal procurement see 2 C.F.R. § 200.320.
For more information on MT Procurement laws, rules, policies, and executive orders please visit State
Procurement Bureau.
10.0 Award Administration Information
10.1 Award Administration
Notification of award approval is made through the sub -recipient's authorized representative listed in
the application. Awards will be made to the sub -recipients no later than 45 days following the state's
acceptance of the Federal award and funds have been released. Sub -recipients who wish to decline the
award must provide a written notice of intent to decline.
The Principal Elected Official with the legal authority to enter into an agreement and the Authorized
Representative working on the project will be required to sign the Award Obligation Letter and email it
back to their respective grant coordinator prior to any funds being reimbursed on the project.
10.2 Nationwide Cybersecurity Review - Required
The NCSR is a free, anonymous, annual self -assessment designed to measure gaps and capabilities of a
SLT's cybersecurity programs. It is based on the National Institute of Standards and Technology
Cybersecurity Framework and is sponsored by DHS and the MS-ISAC. Sub -recipients are required to
complete the NCSR, administered by the MS-ISAC, during the first year of the award/subaward period of
performance and annually. The NCSR is available at no cost to the user and takes approximately 2-4
hours to complete. The NCSR is expected to be open from October — January.
For more information, visit Nationwide Cybersecurity Review (NCSR) (cisecurity.org).
10.3 CYBER HYGIENE SERVICES - Required
All awarded sub -recipients will be required to sign up for and utilize the following services:
13
Web Application Scanning: an "internet scanning -as -a -service." This service assesses the
"health" of your publicly accessible web applications by checking for known vulnerabilities and
weak configurations. Additionally, CISA can recommend ways to enhance security in accordance
with industry and government best practices and standards.
VulnerabilitV Scanning: evaluates external network presence by executing continuous scans of
public, static Ips for accessible services and vulnerabilities. This service provides weekly
vulnerability reports and ad -hoc alerts.
To register for these services, email vulnerability info@cisa.dhs.gov with the subject line
"Requesting Cyber Hygiene Services — SLCGP" to get started. Indicate in the body of your email that you
are requesting this service as part of the SLGCP.
For more information, visit CISA's Cyber Hygiene Information Page.
10.4 Environmental and Historic Preservation (EHP) Compliance
Projects which may have a potential impact to the environment or require an EHP review will not be
awarded. This is as minimal as drilling a new hole in a wall, running cable, or hanging a shelf.
11.0 Reporting
11.1 Quarterly Progress Reports
Sub -recipients are responsible for providing quarterly performance reports using the Performance
Progress Report form in AmpliFund detailing milestones and work accomplished during the reporting
period. Progress reports must be completed and approved to request reimbursement.
The following reporting periods and due dates apply for the progress reports:
Reporting Period
Report Due Date
October I — December 31
January 10
January I — March 31
April 10
April I —June 30
July 10
July I — September 30
October 10
Projects that extend beyond this timeframe are required to continue reporting.
11.2 Financial Reporting (Payment Requests)
Sub -recipients must submit at least one payment request upon completion of the project to receive
grant funds. However, quarterl payment requests as the project progresses are preferred. The
payment request must be done through AmpliFund. All payment requests must include supporting
documentation to substantiate claimed expenses.
Supporting Documentation must include:
• Proof of payment (i.e., general ledger or warrant check)
• Invoices
• Receipts
14
Reimbursements are made only for expenditures made during the grant period of performance.
Reimbursements requests will be rejected if any quarterly progress reports are outstanding. Projects
with outstanding quarterly progress reports may be subject to termination of project funding.
Sub -recipients receiving services in lieu of direct funding will only need to verify services provided. State
ITSD / IVIT DES will provide supporting documentation for the financial reimbursements.
11.3 Accruals
Sub -recipients with an open grant will be required to submit an accrual form prior to the end of the
State Fiscal Year (SFY) to account for any expenditures or valid obligations that have occurred in the SFY
and not been reimbursed prior to June 30. Sub -recipients that do not submit an accrual form and
supporting documentation and then request reimbursement for goods or services from the prior SFY are
at risk of non-payment due to lack of accrual funds.
12.0 Scope of Work and Budget Modifications
Any changes to the scope of work will be submitted via a request form. Any changes to the budget may
be made by filling out an amendment request in the AmpliFund system. Sub -recipients will need to
contact their grant coordinator if any changes are requested.
13.0 Monitoring/Technical Assistance
13.1 Monitoring
Sub -recipients will be monitored by IVIT DES staff, both programmatically and financially, to ensure that
the project goals, objectives, performance requirements, timelines, milestone completion, budgets, and
other related program criteria are being met.
13.2 Technical Assistance
Technical assistance will be provided through desk -based reviews of financial reimbursement requests
and project status reports. In addition, on -site technical assistance visits will be performed according to
IVIT DES schedules, as requested, or as needed. Technical assistance will involve the review of the
financial, programmatic, performance, compliance, administrative processes, policies, activities, and
other attributes of each Federal assistance award and will identify areas where further assistance,
corrective actions or other support may be needed.
14.0 Project Closeout and De -Obligated Funds
14.1 Closeout
Closeout of SLCGP projects will be administered by IVIT DES upon determination of grant completion in
accordance with 2 C.F.R. § 200.344 and upon receipt of a signed sub -recipient letter requesting closeout.
IVIT DES will complete a project and file review prior to closing out a project and provide the sub -
recipient with a closeout confirmation letter for the grant files.
14.2 De -obligated Funds
Projects that are completed under budget will have funds cle-obligated during the grant closeout
process and will no longer be available to the sub -recipient. De -obligated funds will be utilized during
the grant period of performance to fund additional projects. The Cybersecurity Planning Committee will
15
make recommendations for re -awarding grant funds to eligible and approved projects. The committee
reserves the right to conduct an interim application process for cle-obligated funds.
15.0 IVIT DES Contact Information
MT DES will provide programmatic support and technical assistance for the SLCGP Grant.
Preparedness Grant Coordinator
Emily Schuff
Emily.Schuff@mt.gov
Preparedness Grant Coordinator
Pamela Fruh
Pam.Fruh@mt.gov
Preparedness Program Manager
Amanda Avard
Amanda.Avard@mt.gov
16
ATTACH ME NT A
Montana Cybersecurity Plan
mod
Will
7W --W
4El _-Z
49l
JF
41i _zr_ --
- . 0, 41r
go Aoki
00
0 0
FATE UF NIL
WRARNIRI
I
I
oil
i
Approved by the State of Montana
.....................................................................................
Oil Cybersecurity Planning Committee
on September 25, 2023
Version 1.3
THIS PAGE INTENTIONALLY LEFT BLANK
State of Montana Cybersecurity Plan
2022-2024
TABLE OF CONTENTS
Letter from the Cybersecurity Planning Committee ................................................................................ 3
Introduction................................................................................................................................................... 4
Visionand Mission ........................................................................................................................................
Cybersecurity Program Goals and Objectives .............................................................................................
Cybersecurity Plan Elements ...................................................................................................................... 9
Manage, Monitor, and Track information systems and user accounts .....................................................
Monitor, Audit, and Track network traffic and activity ................................................................................
EnhancePreparedness ................................................................................................................................
Assessmentand Mitigation ..........................................................................................................................
Best Practices and Methodologies ..............................................................................................................
NISTPrinciples ..........................................................................................................................................
SupplyChain Risk Management ..............................................................................................................
Toolsand Tactics ......................................................................................................................................
SafeOnline Services .....................................................................................................................................
Continuityof Operations ...............................................................................................................................
Workforce......................................................................................................................................................
Continuity of Communications and Data Networks ....................................................................................
Assess and Mitigate Cybersecurity Risks and Threats to Critical Infrastructure and Key Resources .....
Cyber Threat Indicator Information Sharing ................................................................................................
LeverageCISA Services ................................................................................................................................
Information Technology and Operational Technology Modernization Review ..........................................
Cybersecurity Risk and Threat Strategies ...................................................................................................
RuralCommunities .......................................................................................................................................
Funding& Services .................................................................................................................................... . t7
9
9
... 10
... 10
Distribution to Local Governments ................................................................................................................. 17
AssessCapabilities .................................................................................................................................... 1s
ImplementationPlan ................................................................................................................................ . t9
Organization, Roles and Responsibilities ....................................................................................................... 19
Resource Overview and Timeline Summary ................................................................................................... 19
Metrics........................................................................................................................................................ 20
Appendix A: SAMPLE Cybersecurity Plan Capabilities Assessment .................................................... 25
Appendix 13: Project Summary Worksheet ............................................................................................. 28
Page 2
State of Montana Cybersecurity Plan
2022-2024
LETTER FROM THE CYBERSECURITY PLANNING COMMITTEE
Greetings,
The State of Montana Cybersecurity Planning Committee (the Committee) is pleased to present to you the
State of Montana Cybersecurity Plan (the Plan). The Plan represents the State of Montana's continued
commitment to improving cybersecurity and supporting our State, as well as cybersecurity practitioners
across our local jurisdictions. In addition, this update meets the requirement of the current U.S.
Department of Homeland Security guidelines for the State and Local Cybersecurity Grant Program (SLCGP)
Representatives from state, county, municipal, public health, and education sectors within Montana
formed the Committee to develop and update the Plan with actionable and measurable goals and
objectives that have champions identified to ensure completion. These goals and objectives focus
leveraging economies of scale to maximize funds to implement risk -based programs that directly benefit
the entities represented on the Committee. This document is structured to meet the required plan
elements defined in the Notice of Funding Opportunity.
As we continue to enhance the State of Montana's cybersecurity posture, we are committed to improving
our resilience across disciplines and jurisdictions. With help from FEMA, CISA, other federal partners, and
cybersecurity practitioners throughout the State of Montana, we will work to achieve the goals set forth in
The Plan and become a model for cyber resilience.
Sincerely,
Kevin Gilbertson
Chief Information Officer and
Chair of the Montana Cybersecurity Planning Committee
State of Montana
Department of Administration
Page 3
State of Montana Cybersecurity Plan 2022-2024
INTRODUCTION
Montana faces unprecedented cybersecurity risks, including increasingly sophisticated adversaries,
widespread vulnerabilities in commonly used hardware and software, and broad dependencies on networked
technologies for the day-to-day operation of critical infrastructure. Cyber risk management is further
complicated by the ability of malicious actors to operate remotely, linkages between cyber and physical
systems, and the difficulty of reducing vulnerabilities.
Considering the risk and potential consequences of cyber incidents, strengthening the cybersecurity practices
and resilience of state, local governments is an important homeland security mission and the primary focus
of State Local Cyber Grant Program (SLCGP). Through funding from the Infrastructure Investment and Jobs
Act, the SLCGP enables Montana to make targeted cybersecurity investments in government agencies, thus
improving the security of critical infrastructure and improving the resilience of the services Montana's
governments provide their communities.
The Statewide Cybersecurity Strategic Plan is to guide aspects of Montana's critical infrastructure sectors
and create a unity of effort. The approach focuses on how we will collectively reduce risk and build resilience
to cyber threats to the state's cybersecurity posture of all participants.
The Plan is a two-year strategic planning document for SLCGP years 2022-2024 that contains the following
components:
Vision and Mission: Articulates the vision and mission for improving cybersecurity resilience
interoperability over the next two years.
• Organization, and Roles and Responsibilities: Describes the current roles and responsibilities, and
any governance mechanisms for cybersecurity within the State of Montana as well as successes,
challenges, and priorities for improvement. This also includes a strategy for the cybersecurity
program and the organization structure that identifies how the cybersecurity program is supported.
In addition, this section includes governance that identifies authorities and requirements of the
State of Montana cybersecurity program. The Plan is a guiding document and does not create any
authority or direction over any of the State of Montana's or local systems or agencies.
• How feedback and input from local governments and associations was incorporated. Describes
how inputs from local governments was used to reduce overall cybersecurity risk across the eligible
entity. This is especially important in order to develop a holistic cybersecurity plan.
• Plan Elements: Outlines technology and operations needed to maintain and enhance resilience
across the cybersecurity landscape.
Funding: Describes funding sources and allocations to build cybersecurity capabilities within the
State of Montana along with methods and strategies for funding sustainment and enhancement to
meet long-term goals.
• Implementation Plan: Describes the State of Montana's plan to implement, maintain, and update
the Plan to enable continued evolution of and progress toward the identified goals. The
implementation plan must include the resources and timeline where practicable.
• Metrics: Describes how the State of Montana will measure the outputs and outcomes of the
program across the entity.
Page 4
State of Montana Cybersecurity Plan
2022-2024
The National Institute of Standards and Technology (NIST) Cybersecurity Framework', included in Figure 1,
and the CIS Security ControIS2, included in Figure 2, helps guide key decision points about risk
management activities through various levels of an organization from senior executives to business and
process level, as well as implementation and operations. CIS controls map to the NIST CSF and are often
used to help guide discussion with locals as they are more easily digested and have implementation
groups to guide maturity efforts.
i
NIST
Cyblel--�It�,
Y
F _--k
F—cfl—
Critical Infrastructure Support I
Figure 1: Achieving Cyber Resilience Through Comprehensive Cybersecurity Plans
Figure 2: The Critical Security Controls are a prioritized set of Safeguards to mitigate the most prevalent cyber-attacks.
' httos://www.nist.5-ov/cyberframework/5-etting-started
2 https://www.cisecurity.org/controls
Page 5
State of Montana Cybersecurity Plan
2022-2024
Vision and Mission
This section describes State of Montana's vision and mission for improving cybersecurity:
Vision:
To enhance the cybersecurity posture and increase the resilience of Montana governments by
unifying state and local experience and expertise.
Mission:
To unify State and Local resources to create a safer digital landscape for Montana.
Cybersecurity Program Goals and Objectives
State of Montana Cybersecurity goals and objectives that align with NIST Cyber Security Framework
include the following:
Program Goal Program Objectives
1. Identify Asset Management
1.1 Leverage the Montana Information Security Advisory
Council (MT-ISAC) to create a workgroup focused on
increased cybersecurity apprenticeships and internships
opportunities in Montana (CSF ID.AM-6)
Governance
1.2 Leverage MT-ISAC monthly sharing of cyber threat
information and industry best practices to all Montana's:
Governments, Critical Infrastructure, and Small
Businesses. Use MT-ISAC to also promote Council approved
groups and associations (Cyber406, CyberMontana, MT
National Guard, other ISACs, DHS, etc.) that are promoting
situational awareness (CSF ID.GV-4)
Risk Management Strategy
1.3 Leverage MT-ISAC and industry best practices to support
and standardize on NCSR as annual risk assessment.
Provide additional guidance for use of other Council NIST
based (CISA CPGs & CRE & CRR, & EDM, CIS Critical
Controls) approved assessments. (CSF ID.RM-1)
1.4 Deliver support for State and Local governments to move to
.GOV for email and websites. Explore options for K-12.
(CSF ID.RM-1)
Page 6
State of Montana Cybersecurity Plan
2022-2024
Program Goal
Program Objectives
1.5 Leverage MT-ISAC and industry best practices to create a
standard naming convention for government entities
moving to.GOV(CSF ID.RM-1)
2. Protect
Identity Management, Authentication and Access Control
2.1 Leverage MT-ISAC to create a guideline or reference an
established industry best practice on Multifactor
Authentication with options to use current state services
and contracts (CSF PR.AC-7, CIS Control 6.3, 6.4, 6.5)
2.2 Deliver solutions to Local Governments and K-12 to help
protect network integrity with proper network segmentation
(CSF PR.AC-5, CIS Control 12.2)
2.3 Leverage MT-ISAC to create a guideline or reference an
established industry best practice on prohibiting use of
known/fixed/ default passwords and credentials with
options to use current state services and contracts (CSF
PR.AC-1, CIS Control 4.7)
Awareness and Training
2.4 Deliver basic end user security awareness training for
Montana State & Local governments and K-12 (CSF PR-AT-
1, CIS Control 14)
2.5 Deliver cyber education to privileged users and cyber
professionals within Montana State & Local governments
and K-12 (CSF PR-AT-2, CIS Control 14.9)
2.6 Deliver access for Montana State & Local governments and
K-12 privileged users and cyber professionals to cyber
ranges (CSF PR-AT-2, CIS Control 14.9)
Data Security
2.7 Leverage MT-ISAC to create a guideline or reference an
established industry best practice on encryption for data at
rest and in transit with options to use current state services
and contracts (CSF PR.DS-1 & 2, CIS Control 3.6 & 3.9 &
3.10 & 3.11)
Information Protection Processes and Procedures
2.8 Leverage MT-ISAC to create a guideline or reference an
established industry best practice on limiting use of
unsupported/end of life (EOL) software and hardware and
ending the use of EOL on systems that are accessible from
the internet with options to use current state services and
contracts (CSF PR-IP-2, CIS Control 12.1 & 13.5 & 16.5)
2.9 Leverage MT-ISAC to create a guideline or reference an
established industry best practice on backup and recovery
with options to use current state services and contracts
(CSF PR-IP-4, CIS Control 11)
Protective Technology
Page 7
State of Montana Cybersecurity Plan
2022-2024
Program Goal
Program Objectives
2.10 Leverage MT-ISAC to create a guideline or reference an
established industry best practice on audit/log records with
options to use current state services and contracts (CSF
PR.PT-1, CIS Control 8)
3. Detect
Anomalies and Events
3.1 Deliver Network Monitoring and Management Intrusion
Detection Systems (IDS) solutions for County Governments
for better protection for Election Offices, Emergency
Services, and Public Water System Municipalities. (CSF
DE.CM-1, CIS Control 13.3)
3.2 Deliver support for State & Local governments and K-12 to
utilize MS-ISAC's no cost Malicious Domain Blocking and
Reporting (MDBR) or like service (CSF DE.CM-1 & PR.AC-5,
CIS Control 9.2)
Security Continuous Monitoring
3.3 Deliver Endpoint Detection and Response solution for
Montana Local Governments and K-12 (CSF DE.CM-4, CIS
Control 10)
3.4 Deliver supportfor all State and Local government public
facing IPs to have external vulnerability scanning with
weekly report to entity (CSF DE.CM-8, CIS Control 7.6)
4. Respond
Response Planning
4.1 Leverage MT-ISAC and industry best practices to create a
statewide incident response reporting process (CSF RS.RP-1
& PR.IP-9, CIS Control 17)
5. Recover
Recovery Planning
5.1 Leverage MT-ISAC and industry best practices by delivering
training, workshops, exercises on incident response and
recovery planning (CSF RC.RP-1 & PR.IP-10, CIS Control 17)
Page 8
State of Montana Cybersecurity Plan 2022-2024
CYBERSECURITY PLAN ELEMENTS
Manage, Monitor, and Track information systems and user accounts
Entities should establish procedures that effectively control and restrict access to information assets to
authorized users based on defined business and legal requirements. Mechanisms will be implemented
that provide for the control, administration, and tracking of access to, and the use of, information assets,
as well as the protection of such assets from unauthorized or unapproved activity and/or destruction.
The Cybersecurity Framework and CIS Security Controls both start with knowing what you have in both
hardware and software. This includes physical and virtual, on premises and off. It is hard to secure what
you do not know. Once you know what you have then the security frameworks turn to who has access to
those assets. This is addressed with Access Management. Poor practices in these areas lead to
com prom ised systems a nd data breaches. I n today's evercha ngi ng world of tech nology best practice is to
use security orchestration, automation and response technologies.
The State of Montana manages, monitors, and tracks information systems, applications, and user
accounts that are used to conduct state business. A combination of asset inventory tools with both active
and passive discovery are used to inventory and identify assets and users connected to the state's
networks. A Governance, Risk and Compliance (GRC) tool is used to inventory state systems and for
tracking risk and compliance against state policy.
Montana has a Network Security Operations Center (NSOC) and a Cyber team that ingests alerts and
responds to risks identified by these solutions.
The strategic approach for improvement is to assess the capabilities of this element across the whole of
Montana government and identify where gaps exist and identify the right tools that can be leveraged to
benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be
proposed to help address those gaps.
Monitor, Audit, and Track network traffic and activity
Entity asset owners, asset custodians, and information security and privacy officers should:
Ensure the information assets under their purview are assessed for security and privacy risks and
configured such that event logging is enabled to ensure an adequate level of situational awareness
regarding potential threats to the confidentiality, integrity, availability, and privacy of agency
information and information systems are identified and managed; and
Review and retain event logs in compliance with all applicable Local, State and Federal laws,
regulations, executive orders, circulars, directives, internal agency and state information security
policies, and contractual requirements.
Montana's methodology to monitor, audit, and track network activity includes Albert Sensors that are
placed strategically throughout our network. Defense in depth is used for our firewalls and edge devices.
All user traffic will cross a next generation firewall performing packet inspection for IDS/IPS, virus, URL and
DNS monitoring. A SIEM and monitoring agents are used to feed data into our security operations center.
The centralized log management approach is used for actionable data and long-term storage of logs so
that all statutory requirements are met.
Page 9
State of Montana Cybersecurity Plan
2022-2024
State of Montana is using a standardized XDR solution to better protect, detect, audit, and track network
traff ic and activity. This solution and its deployment allow for complex auditing and monitoring of attacks
and allows for quicker reaction and detection.
The strategic approach for improvement is to assess the capabilities of this element across the whole of
Montana government and identify where gaps exist and identify the right tools that can be leveraged to
benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be
proposed to help address those gaps.
Enhance Preparedness
Entities should implement continuous risk management processes that account for the identification,
assessment, treatment, and monitoring of risks that can adversely impact their operations, information
systems, and information. These processes will inform the exercise and execution of Incident Response
Plans, Continuity of Operations Plans and the State Emergency Operation Plan. Lessons Learned from
these exercises will be incorporated into future planning, inform organizational decisions, and
demonstrate additional equipment and training needs.
Montana is embracing preparedness in the following ways:
• Planning - Montana has worked with state agencies and others to develop Business Continuity
(BC) plans and has semi-annual Disaster Recovery (DR) tests.
• Organization - Montana takes a whole of government approach to protect the state and prepare for
disasters before they occur.
• Equipment - Montana is working on redundant systems and services to protect the state and its
citizens.
• Training - Montana is working with other entities in the state and expanding its testing of disaster
recovery and incident response.
• Exercise - Montana has held joint tabletop exercises with a variety of public and private partners to
better enhance our response capability. We work closely with the National Guard.
The solutions above are primarily from the perspective of Montana state government and do not
necessarily provide coverage for Montana local governments and K-12.
The strategic approach for improvement is to assess the capabilities of this element across the whole of
Montana government and identify where gaps exist and identify the right tools that can be leveraged to
benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be
proposed to help address those gaps.
Assessment and Mitigation
All information systems and applications should undergo security assessments to ensure adequate
security and privacy controls are implemented and risks are managed to acceptable levels throughout
their lifecycles. Risk management processes including identifying, assessing, and addressing security and
privacy risks at the inception of the project to build a system until the decommissioning of a system. These
actions enable State and Local Government entities to maintain security and privacy of a system
throughout its lifecycle. To aid in satisfying the ongoing assessment requirements, assessment results
from the following sources can be used: continuous monitoring, audits and authorizations, and other
system development life cycle activities.
Page 10
State of Montana Cybersecurity Plan
2022-2024
Montana has an Information Security Policy and Standards that define the processes and procedures the
State of Montana uses to identify, prioritize, and escalate for remediation, vulnerabilities in the State's IT
infrastructure. The plan outlines the various vulnerability identification processes that feed into the
program.
Montana currently participates in the CISA Cyber Hygiene services including vulnerability scanning of our
external facing network assets.
Montana uses a combination of both agent and non -agent -based, creclentialed, and non-credentialed,
internal and external, vulnerability scans. Critical, high, and exploitable vulnerabilities for state agencies
are imported into ESM for tracking and remediation.
Critical applications are reviewed on a yearly basis or as changes are made. The Incident Response &
Technical Security team along with the Policy and Risk Management team tracks any issues and works
with the responsible parties to work toward remediation.
The solutions above are primarily from the perspective of Montana state government and do not
necessarily provide coverage for Montana local governments.
As a condition of receiving SLCGP funding, the grant recipients will sign up for and maintain CISA's no cost
Vulnerability Scanning(CyHy) and Web Application Scanning services as well as complete annually the no
cost Nationwide Cybersecurity Review (NCSR) assessment administered by MS-ISAC. The NCSR is open to
complete in October through late February, check with IVIS-ISAC on availably.
The strategic approach for improvement is to assess the capabilities of this element across the whole of
Montana government and identify where gaps exist and identify the right tools that can be leveraged to
benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be
proposed to help address those gaps.
Best Practices and Methodologies
All State and Local governments should adopt and incorporate best practices and methodologies to
enhance cybersecurity. The following cybersecurity best practices must be included:
These are not required to be implemented immediately, but all cybersecurity plans must clearly articulate
efforts to implement these best practices across the eligible entity within a reasonable timeline. Individual
projects that assist SLTT entities adopt these best practices should also be prioritized.
Montana is adopting the following cybersecurity best practices:
Implement multi -factor authentication (MFA) - While used for state agencies, this is not fully
implemented for Local Governments or K-12 school districts.
Implement enhanced logging - Montana captures various log sources such as authentication logs,
device logs, network logs and firewall logs. Enhanced logging is enabled through our XDR solution.
Data encryption for data at rest and in transit - This is a state standard for encryption for agencies
and a potential opportunity for Local Governments or K-12 school districts.
End use of unsupported/end of life software and hardware that are accessible from the Internet -
This is an area of needed improvement, and we would like to use future funds from IIJA to address
this issue.
Prohibit use of known/fixed/clefault passwords and credentials - State agencies have adopted this
best practice, but Local Governments or K-12 school districts have much work in this area to
achieve compliance.
Page 11
State of Montana Cybersecurity Plan
2022-2024
Ensure the a bi I ity to reconstitute systems (backups) -This is another area that we would I ike to use
future years IIJA funds to improve our Local Governments or K-12 school districts.
Migration to the gov internet domain -While this process is ongoing there is more work to be done
here for the Local Governments or K-12 school districts.
The strategic approach for improving this element is to assess the capabilities of this element across the
whole of Montana government and identify where gaps exist. Through collaboration with the members of
the Committee, projects will be proposed to help address those gaps.
NIST Principles
Montana has adopted a cybersecurity framework that was developed from the NIST cybersecurity
framework (CSF). The Montana cybersecurity framework specifically applies to Montana State Information
Technology Services Division (SITSD) and the information assets under its control.
Supply Chain Risk Management
Montana Information Technology's Governance, Risk, and Compliance team uses the risk management
framework and is investigating using StateRamp to help address supply chain risk.
Tools and Tactics
The State of Montana's SITSD cyber team actively engages the Montana Analysis and Technical
Information Center (MATIC), MS-ISAC, CISA, FBI and other government and industry partners to share
knowledge of adversary tools and tactics.
The strategic approach for improvement is to assess the capabilities of this element across the whole of
Montana government and identify where gaps exist and identify the right tools that can be leveraged to
benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be
proposed to help address those gaps.
Safe Online Services
For Organizations eligible to receive funds under the SLCGP who have not previously migrated to the gov
domain, one of the projects under consideration is a managed service to assist with this migration.
Montana is promoting the gov domains to all our city, county, school and other partners. We believe there
are many benefits and are encouraging this move in the following ways:
State of Montana's Chief Information Security Officer (CISO) promotion of gov domain and benefits
at numerous conferences and presentations each year
Cannot be spoofed
Available at no cost
Helps the public quickly identify Local Governments as a trusted government website
Signed up multiple entities for this migration
Assisted several counties through CISA to get moved to gov domain
Page 12
State of Montana Cybersecurity Plan 2022-2024
Continuity of Operations
State and Local Government entities should develop, implement, test, and maintain contingency plans to
ensure continuity of operations for all information systems that deliver or support essential or critical
functions. Contingency planning is an important aspect of risk management. Ensuring availability for
critical and essential systems and components allows agencies to meet its mandates that are dictated by
statute, executive order, policy, or contract, and to ensure delivery of vital government services.
The State of Montana reviews the Continuity of Operations Plan (COOP) at least annually to align with
shifting industry trends, such as remote workforce and updated technologies. Communication is a
cornerstone of any continuity of operation plan. We believe that plans are of little value if not tested. The
State of Montana COOP includes the following:
1. Mission essential functions and business essential functions,
2. Alternate site determination to permit the storage and retrieval of information system backup
information, along with establishing alternate telecommunications services to permit the
resumption of essential missions and business functions within a defined period when primary
telecommunications capabilities are unavailable.
3. Disaster recovery tests are conducted semi-annually
4. Tabletop exercises are conducted throughout the year with key State and non -State stakeholders
through public -private partnerships. Lessons learned are documented and may require updates to
the plan. Incident response plans and procedures are also validated during these exercises to
ensure core security incident response team, responsibilities, incident reporting, escalation matrix,
and notification procedures are current.
Cloud -hosted solutions undergo a third -party risk assessment, which includes a thorough review of vendor
service level agreements (SLAs), disaster recovery tests, and business continuity plans. Availability is
agreed upon in contractual language. Vendor incidents impacting availability of systems is formally tracked
to ensure agreed -upon SLAs are met.
The strategic approach for improvement is to assess the capabilities of this element across the whole of
Montana government and identify where gaps exist and identify the right tools that can be leveraged to
benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be
proposed to help address those gaps.
Workforce
State and Local Government Entities should develop cybersecurity workforce retention and recruiting
policies to compete in a high demand/ low supply cybersecurity workforce job market. Askillecland
diverse cybersecurity workforce is key to protecting Montana businesses and citizens from global threats.
Montana has modified its job requests to better match skills. Employees have a training program that has
both technical and non -technical training.
Montana also works to take a whole of state training plan working through a phishing and cyber
awareness training and testing to assist in sending training to state entities and Local Governments or K-
12 school districts to promote knowledge of all employees to be cyber smart and have the knowledge and
information to understand how and what they should do when reacting to an event.
Montana also works through cybersecurity.mt.gov, Cyber406.org, CyberMontana.org websites to share
trainings, security information, and other information to state citizens and employees alike. Every year the
Page 13
State of Montana Cybersecurity Plan
2022-2024
website is updated to have links and information for National Cyber Security Awareness Month to highlight
that year's key action steps and insights.
Continuity of Communications and Data Networks
State of Montana participates in an annual tabletop exercise with scenarios involving multiple industry
sectors that include both State and Private entities. The tabletop exercise encourages continuity plans that
extend beyond a single entity and to include items like alternative communication networks for major
disasters.
State of Montana Continuity of Operations Plan contains these key elements:
1. Contact information for key stakeholders.
2. Mission Essential Functions:
a. Provide IT hosting, network connectivity, telephone service, and online security to
government entities.
b. Provide software development services to government entities.
c. Provide project management services to government entities.
d. Provide records management services to government entities.
e. Provide data center environment for state agencies.
3. Disaster Recovery Tiers defining recovery goals.
4. Incident response plan that addresses:
a. Core security incident response team.
b. Role's matrix identifying those responsible, accountable, consulted, and informed on
incident response tasks.
c. Incident reporting by staff or incidents detected and staff alerted by tools.
d. Federal and State notifications.
e. Continuous Improvement.
Assess and Mitigate 'C"ybersecurity Risks and Threats to Critical Infrastructure
and Key Resources
The approach to assess and mitigate cybersecurity risks and threats to critical infrastructure and key
resources is to partner with various State and Local Government Entities to ensure that critical
infrastructure and key resources across the state is identified and assessed. Any available training
through the training investment as well as open -source training will be promoted and made available.
The state has made progress over the last few years including whole of government approach, new
firewalls and edge devices, unification of state government, deployment of vulnerability analysis, increased
deployment of XDR and cross functional teams to address high risk and emerging threats. A cyber risk
management team helps to mitigate risks proactively by:
1. Implementing a third -party risk management program, which provides due diligence assessments
of vendor security controls to ensure State citizen data is safeguarded.
Page 14
State of Montana Cybersecurity Plan 2022-2024
2. Implementing NIST 800-37r2 Risk Management Framework for new systems, ensuring risk is
assessed throughout the system development life cycle.
3. Creating internal audit functions to continuously monitor security controls and ensure control
effectiveness.
Cyber Threat Indicator Information Sharing
The State of Montana Fusion Center (the MATIC) is the central information sharing hub for the state. The
Montana Information Security Advisory Council is a public/private collaborative group that shares
information and best practices.
Montana participates and shares indicators and threat information with instate partners. This information
is used to bolster defenses and distribute information within Montana for the protection of the network
and endpoints.
Montana CISO Office holds a weeklythreat brief with all state and federal partners. We also work with CISA
to understand threats and communicate what is allowable to our partners throughout the state.
Leverage CISA Services
The State of Montana and its various entities and committees utilizes services from CISA to assess and
enhance their cybersecurity posture. The State encourages all State and Local Government Entities to
utilize CISA and IVIS-ISAC free and low-cost services first, then build upon with additional layers of security.
Montana fully appreciates the help and support from CISA. Information provided through CISA is used to
help bolster our defenses in preemptive blocking while also being used to help guide threat hunting, threat
intelligence, and threat sharing throughout the state of Montana. Information from CISA is ingested
through a multitude of ways from automatic playbooks, threat intelligence team and more.
As a condition of receiving SLCGP funding, the grant recipients will sign up for and maintain CISA's no cost
Vulnerability Scanning(CyHy) and Web Application Scanning services as well as complete annually the no
cost Nationwide Cybersecurity Review (NCSR) assessment administered by MS-ISAC. The NCSR is open to
complete in October through late February, check with IVIS-ISAC on availably.
Information Technology and Operational Technology Modernization Review
Montana's SITSD team uses a project intake process to evaluate all new projects and their impact to
informational and operational technology. During this review process, the project management, customer
success, architects, and the security team are consulted before projects are initiated. Major projects
receiving approval to proceed follow the NIST 800-37r2 Risk Management Framework process to ensure
all aspects of risk, security, architectural review, and business are aligned, addressed, and assessed.
Cybersecurity Risk and Threat Strategies
The State of Montana Fusion Center (the MATIC) is the central information sharing hub for the state.
State of Montana conducts Cyber Assessments in coordination with all State of Montana entities. Based
off the NIST, Cybersecurity Framework and the Nationwide Cybersecurity Review (NCSR) these questions
assess each entity equally providing consistent insight into the entity and the State of Montana's overall
cyber security posture. Assessment results are analyzed, and areas of common concern are identified in
order to prioritize strategic efforts for making statewide improvements to network security.
Page 15
State of Montana Cybersecurity Plan
2022-2024
Rural Communities
Because of the services provided approach to this plan, the Committee can ensure that all licenses and
services are tracked and managed to make sure that rural areas are represented in the services provided
and meet or exceed the 25% minimum.
More than 80% of Montana Counties are rural areas. With such a large makeup, rural communities are the
core recipients of state cyber security tools and services.
Rural communities also have representation on the Committee.
Page 16
State of Montana Cybersecurity Plan 2022-2024
FUNDING &SERVICES
The Committee intends to focus on 8 key efforts to strengthen cybersecurity across the State. These
efforts include the goals and objectives section above and are detailed in Appendix B: Project Summary
Worksheet. Sustainable funding is required to ensure that projects enabled by grant funding can continue
to be successful. Funding sources can include local, state and federal organizations.
Distribution to Local Governments
To ensure 80% of the SLCGP funds are distributed to local units of government, it is the intent of the
committee to have the Montana Department of Administration or the MT SLCGP State Administrative
Agency (SAA), contract for services directly on behalf of local units of government with their consent. The
SAA may issue direct subawards to local units of government based on the applications received and
project prioritization by the committee. The SAA will ensure that 25% of the funds are directed to rural
communities or utilized with their consent. All project applications must align with the projects listed in
Appendix B.
As a condition of receiving SLCGP funding, the grant recipients will sign up for and maintain CISA's no cost
Vulnerability Scanning(CyHy) and Web Application Scanning services as well as complete annually the no
cost Nationwide Cybersecurity Review (NCSR) assessment administered by MS-ISAC. The NCSR is open to
complete in October through late February, check with MS-ISAC on availably.
Page 17
State of Montana Cybersecurity Plan
2022-2024
ASISESS CAPABILITIES
Montana's strategic approach will be to use the Nationwide Cybersecurity Review (NCSR) for annual
assessments. NSCR is a free service from IVIS-ISAC and the question set is built off the NIST Cybersecurity
Framework. Additional council approved NIST based assessments such as CISAs CPGs, CRE, CRR, CIS
Controls, and various Vulnerability assessments will also be used as supplemental assessments to help
further determine security current security posture.
Page 18
State of Montana Cybersecurity Plan
2022-2024
IMPLEMENTATION PLAN
Organization, Roles and Responsibilities
The State Chief Information Officer is responsible for managing and protecting the State network. The
State Chief Information Security Officer is responsible for advising and overseeing security strategy for
Executive Branch agencies without elected off ici a Is; for advising and consulting security strategy for
Executive Branch agencies with elected officials and the Judicial and Legislative Branches; and for
advising security strategy for all other local and municipal governments in the state. Both the State CIO
and the State CISO are members of the Montana Information Security Advisory Council (MT-ISAC).
The Montana Disaster and Emergency Services (MTDES) serves as the SAA for the State. The MTDES will
manage and administer the financial and programmatic responsibilities of the program, whereas State CIO
and the State CISO will serve in the role as project manager responsible for the Committee and their
assigned roles and responsibilities under the approved committee charter and per the SLCGP
requirements.
Resource Overview and Timeline Summary
The following information is provided to meet the requirement in the State and Local Cybersecurity
Improvement Act: e.2.E. This information represents the best estimation based on current reference
material. It is subject to revision over time.
When funding is approved, the first step is to develop a project plan. The project plan will be
managed by State CIO and State CISO, MTDES, and the IIJA committee members. Project plan will
outline scope, time and cost. The objective is to allocate and use funds within the allotted time
provided via IIJA specifications. Depending on availability of resources, funding could be utilized
over multiple years, not to exceed the guideline within the IIJA specifications. The guidelines will
follow the item below:
People - funding to be approved to hire appropriate contract staff to help the State & Local
Governments and K-12 school districts implement projects agreed upon per year one.
Process - MTDES will set up a process to allow State & Local Governments and K-12 school
districts to request funding for the committee approved projects to be implemented in their
areas. The funding amounts requested via projects will be voted on to be approved by the
committee.
Technology - Decision for technologies will be based on the decision by the committee. It is
the intent of the committee to have the Montana Department of Administration or the MT
SLCGP State Administrative Agency (SAA), contract for services directly on behalf of local units
of government to aggregate requests and purchase in bulk for cost advantage.
Upon approval of the Plan and distribution of the funds, the key initiatives will begin.
Page 19
State of Montana Cybersecurity Plan
2022-2024
METRICS
The below table should reflect the goals and objectives the Committee establishes.
State of Montana - Cybersecurity Program Metrics
Program
Program Sub -Objectives
Associated Metrics
Metric Description
Objectives
(details, source, frequency)
1. Asset
1.1 Leverage the Montana
# of Workgroup meetings
Reports from State CISO
Management
Information Security
office, MT-ISAC quarterly
Advisory Council (MT-ISAC)
# of apprenticeships and
to create a workgroup
internships
CSF ID.AM-6
focused on increased
cybersecurity
# of entities using either
apprenticeships and
apprenticeships and
internships opportunities in
internships based off of
Montana (CSF ID.AM-6)
program
2. Governance
1.2 Leverage MT-ISAC for
# of meetings
Reports from State CISO
monthly sharing of cyber
office, MT-ISAC quarterly
threat information and
# in attendance
industry best practices to all
CSF ID.GV-4
Montana's Governments,
# of individual entities
Critical Infrastructure, and
Small Businesses (CSF
ID.GV-4)
3. Risk
1.3 Leverage MT-ISAC and
- Completion of
Reports from State CISO
Management
industry best practices to
standardization of Risk
office, MT-ISAC quarterly
Strategy
support and standardize on
Assessment and guidance
NCSR as annual risk
CSF ID.RM-1
assessment. Additionally
% of State Agencies,
providing support for 3rd
Counties, Cities, K-12 that
Critical, High, Moderate, Low
party on site standardized
have taken NCSR
gaps identified from annual
assessments as MT-ISAC
assessments. Source:
determines per timeline
- Gap numbers from annual
NCSR, CISA Assessments
determined. (CSF ID.RM-1)
Risk Assessment guidance
(CPGs/CRE), CIS Controls or
other approved by the
1.4 Deliver support for
# of State Agencies,
Committee. Annual
State and Local
Counties, Cities, K-12 that
governments and K-12 to
have taken 3rd Party Risk
move to GOV domain for
Assessments
email and websites (CSF
ID.RM-1)
# of SLTT to move to GOV
1.5 Leverage MT-ISAC and
% of State Agencies,
industry best practices to
Counties, Cities, on.GOV
create a standard naming
-Completion of Standard
convention for government
naming convention for MT
entities moving to GOV (CSF
SLTT entities moving to GOV
ID.RM-1)
Page 20
State of Montana Cybersecurity Plan
2022-2024
4. Identity
Management,
2.1 Leverage MT-ISAC to
- Completion of guideline or
Reports from State CISO
Authentication
create a guideline or
industry best practice
office, MT-ISAC quarterly
and Access
reference an established
referenced on publicly
CSF Controls PR.AC-1 & 5 &
Control
industry best practice on
accessible site on MFA.
7
Multifactor Authentication
% of State Agencies,
with options to use current
Counties, Cities, K-12 using
CIS Controls 4.7 & 6.3 & 6.4
state services and
M FA for remote access
& 6.5 & 12.2
contracts. Create an
statewide action plan for
% of State Agencies,
Annual assessments.
funding improving the use.
Counties, Cities, K-12 using
Source: NCSR, CISA
(CSF PR.AC-7, CIS Control
MFA for accessing critical
Assessments (CPGs/CRE),
6.3, 6.4, 6.5)
systems
CIS Controls or other
2.2 Deliver solutions to
# of reviews of network for
approved by the Committee.
Local Governments and K-
proper segmentation with
Annual
12 to help protect network
documented guidance with
integrity with proper network
roadmap to address
segmentation (CSF PR.AC-5,
CIS Control 12.2)
- Completion of guideline or
2.3 Leverage MT-ISAC to
industry best practice
create a guideline or
referenced on publicly
reference an established
accessible site on
industry best practice on
prohibiting use of
prohibiting use of
known/fixed/clefault
known/fixed/ default
passwords and credentials.
passwords and credentials
with options to use current
state services and contracts
(CSF PR.AC-1, CIS Control
4.7)
5. Awareness and
Training
2.4 Deliver basic end user
# of State Agencies,
Reports from State CISO
security awareness training
Counties, Cities, K-12 taking
office, MT-ISAC quarterly
for Montana State & Local
annual security awareness
CSF PR-AT-1 & 2
governments and K-12 (CSF
training
PR-AT-1, CIS Control 14)
% of State Agencies,
CIS Control 14
2.5 Deliver cyber education
Counties, Cities, K-12 users
to privileged users and
fully completing annual
cyber professionals within
security awareness training
Montana State & Local
# of State Agencies,
governments and K- F
Counties, Cities, K-12 users
PR-AT-2, CIS Control 14.9)
taking cyber education
2.6 Deliver access for
# of State Agencies,
Montana State & Local
Counties, Cities, K-12 users
governments and K-12
using cyber ranges for
privileged users and cyber
learning how to better
professionals to cyber
defend their networks
ranges (CSF PR-AT-2' CIS
Control 14.9)
Page 21
State of Montana Cybersecurity Plan
2022-2024
6. Data Security
2.7 Leverage IMT-ISAC to
create a guideline or
reference an established
industry best practice on
encryption for data at . rest
and in transit with options to
use current state services
and contracts. Create a
statewide action plan for
funding improving the use.
(CSF PR.DS-1 & 2, CIS
Control 3.6 & 3.9 & 3.10 &
3.11)
- Completion of guideline or
industry best practice
referenced on encryption for
data at rest and in transit.
# of State Agencies,
Counties, Cities, K-12 using
fully using encryption at
desktop
# of State Agencies,
Counties, Cities, K-12 using
fully using encryption at
serverlevel
Reports from State CISO
office, IMT-ISAC quarterly
CSF PR-DS-1 & 2
CIS Control 3.6 & 3.9 &
3.10 & 3.11
Annual assessments and
reports. Source: NCSR, CISA
Assessments (CPGs/CRE),
CIS Controls or other
approved by the Committee.
Annual
7. Information
Protection
2.8 Leverage IMT-ISAC to
- Completion of guideline or
Reports from State CISO
Processes and
create a guideline or
industry best practice
office, IMT-ISAC quarterly
Procedures
reference an established
referenced on limiting use of
CSF PR-IP-2 & 4
industry best practice on
unsupported/end of life
limiting use of
software and hardware.
CIS Control 11 & 12.1 &
unsupported/end of life
- Completion of guideline or
13.5 & 16.5
(EOL) software and
industry best practice
hardware and ending the
referenced on backup and
use of EOL on systems that
Annual assessments &
are accessible from the
recovery.
Reports. Source: NCSR,
internet with options to use
# of State Agencies,
CISA Assessments
current state services and
Counties, Cities, K-12
(CPGs/CRE/Vuln Scans), CIS
contracts. (CSF PR-IP-2, CIS
having off line, encrypted
Controls or other approved
Control 12.1 & 13.5 & 16.5)
backups of critical data
bythe Committee. Annual
2.9 Leverage IMT-ISAC to
% of State Agencies,
create a guideline or
Counties, Cities, K-12
reference an established
having off line, encrypted
industry best practice on
backups of critical data
backup and recovery with
# of State Agencies,
options to use current state
Counties, Cities, K-12 using
services and contracts.
CISA Vulnerability Scanning
Create a statewide action
Service
plan for funding improving
the use. (CSF PR-IP-4, CIS
% of State Agencies,
Control 11)
Counties, Cities, K-12 using
CISA Vulnerability scanning
service
Page 22
State of Montana Cybersecurity Plan
2022-2024
8. Protective
Technology
2.10 Leverage MT-ISAC to
create a guideline or
reference an established
industry best practice on
audit/log records with
options to use current state
services and contracts.
Create an statewide action
plan for funding improving
the use. (CSF PRYT-1, CIS
Control 8)
- Completion of guideline or
industry best practice
referenced on audit/log
records.
# of State Agencies,
Counties, Cities, K-12 using
centralized logging server or
SIEM tool
% of State Agencies,
Counties, Cities, K-12 usin 9
centralized logging server or
SIEM tool
Reports from State CISO
office, MT-ISAC quarterly
CSF PR.PT-1
CIS Control 8
Annual assessments.
Source: NCSR, CISA
Assessments (CPGs/CRE),
CIS Controls or other
approved by the Committee.
Annual
9. Anomalies and
3.1 Deliver Network
# of State Agencies,
Reports from State CISO
Events
Monitoring and
Counties, Cities, K-12 using
office, MT-ISAC quarterly
Management Intrusion
MS-ISAC Albert Sensor or
CSF DE.CM-1 & PR.AC-5
Detection Systems (IDS)
like service (determined by
solutions for County
State CISO Office)
CIS Control 9.2 & 13.3
Governments for additional
% of State Agencies,
Annual assessments and
layer of alerting and visibility
Counties, Cities, K-12 using
reports. Source: NCSR, CISA
for Election Offices,
Albert Sensor or like service
Assessments (CPGs/CRE),
Emergency Services Offices,
(cleterm i ned by State CISO
CIS Controls or other
and Public Water System
Office)
approved by the Committee.
Municipalities. (CSF DE.CM-
Annual
1, CIS Control 13.3)
# of State Agencies,
3.2 Deliver support for
Counties, Cities, K-12 using
State & Local governments
MS-1 . SAC MDBR or like
and K-12 to utilize MS-
service (determined by State
ISAC's no cost Malicious
CISO Off ice)
Domain Blocking and
% of State Agencies,
Reporting (MDBR) service or
Counties, Cities, K-12 using
similar service (CSF DE.CM-
MDBR or like service
1 & PR.AC-5, CIS Control
(cleterm i ned by State CISO
9.2)
Office)
Page 23
State of Montana Cybersecurity Plan
2022-2024
10. Security
Continuous
3.3 Deliver Endpoint
# and % of State Agencies,
Reports from State CISO
Monitoring
Detection and Response
Counties, Cities, K-12 using
office, MT-ISAC quarterly
solution for Montana Local
a EDR solution that is
CSF DE.CM-4 & 8
Governments and K-12 (CSF
approved by State CISO
DE.CM-4, CIS Control 10)
Office
CIS Control 7.6 & 10
3.4 Deliver support for all
# and % of State Agencies,
Annual assessments &
State & Local governments
Counties, Cities, K-12 using
reports. Source: NCSR, CISA
and K-12 Schools Districts
CISA Vulnerability Scanning
Assessments
public facing IPs to have
Service
(CPGs/CRE/Vulnerability
external vulnerability
# and % of State Agencies,
Scanning), CIS Controls or
scanning with weekly report
Counties, Cities, K-12
other approved by the
to entity. Create a
conducting at a minimum
Committee. Annual
statewide action plan for
monthly Internal
improvingthe use. (CSF
Vulnerability Scanning
DE.CM-8, CIS Control 7.6)
Service
3.5 Deliver support for
identified State & Local
governments and K-12
School Districts to have
internal vulnerability scan.
11.Response
Planning
4.1 Leverage MT-ISAC and
- Completion of guideline or
Reports from State CISO
industry best practices to
industry best practice
office, MT-ISAC quarterly
create a statewide incident
referenced on incident
CSF RS.RP1 & PR.IP-9
response reporting process
response reporting
(CSF RS.RP-1 & PR.IP-9, CIS
# of State Agencies,
CIS Control 17
Control 17)
Counties, Cities, K-12
Annual assessments.
reported possible cyber
Source: NCSR, CISA
incidents
Assessments (CPGs/CRE),
CIS Controls or other
approved by the Committee.
Annual
12. Recovery
Planning
5.1 Leverage MT-ISAC and
# of State Agencies,
Reports from State CISO
industry best practices by
Counties, Cities, K-12
office, MT-ISAC quarterly
delivering training,
attending workshops or
CSF RC.RP1 & PR.IP-1O
workshops, exercises on
exercises on incident
incident response and
response and recovery
CIS Control 17
recovery planning (CSF
planning
Annual assessments,
RC.RP-1 & PR.IP-10, CIS
% of State Agencies,
Reports. Source: NCSR,
Control 17)
Counties, Cities, K-12
CISA Assessments
attending workshops or
(CPGs/CRE/Exercises), CIS
exercises on incident
Controls or other approved
response and recovery
bythe Committee. Annual
planning
Page 24
1�—
z
LLI
LLI
(f)
U)
LLI
a.
z
5
a.
LLI
(f)
it
LLI
LLI
-i
a.
x
a
z
LLI
a.
a.
0
0
LL
Cd
C6
(Yi
wmr-
C4
C4
70
_0
70
70
70
52:, (N
11
C)
('4
CO 70
(o
C)
c
0 a) �L
-3) 70
cl,
co
cl,
2 E
CO
0
Cc
E 0 Cc: 06
.2
+� >
m 70
.2
+1
C�� m
>
70
>
o6 E 70
+, —
C�� co a)
.2
+�
co co
>
-0
.F-
06 m
>
-0
CL 2 -d m E m —
>
-0 <
70
<
— m <
-0
-Fo
70
<
— 70
<
M 70 -0
m _0
C:
C:
Co C:
C C)
=3
C) 73
C) c
C) 73
C) 73
C) :3
o = < 0
LL LL -i
0
L.L co
0 0
-i LL
M
0 :3
-J LL CO
0 0
-J U-
0 0
-i U-
co
0 0
-j L.L
co
U)
U)
U)
E
E
E
E
E
E
m
m
m
co
co
m
0
0
0
0
0
0
co (n
m
(n
co
(n
m
(n
co
(n
co
(n
m
(n
a)
(n
D
(n
(n
D
(n
D
(n
D
>
>
>
>
>
>
-0
-0
-0
-0
-0
-0
co
,_.s
CO
CL
M
CL
M
CL C
M
CL
M
CL
co E
m
co
co E
co
co
E
C) "
a)
C)
a)
C)
a)
C)
a)
C)
a)
C)
Cj
a)
-0
-0
-0
�<
-0
-0
-0
co
0.
a)
70 L
-0
lu -0
a)
-0
M -0 a)
a)
-0
-0
a)
70
a)
m
CL
-0
-0
CL
CL
CL
-0
CL
C)
co
u m
u cc
u M
u co
u C,
a)
+�
co -0
—
aj CO
-0
—
(v co -0
aj -Fo -0
aj CO
-0
(v -Fo
-0
co
C)
0
C)
0
C)
0
C)
0
C)
0
C)
0
-j co
Ln -i
co
Ln -j co
Ln -i co
Ln -i
co
Ln -j
co
(Ii
cc
E
(n +CO'
cc
a)
0
_0
w
0
-r-
0
0 >N +,
CL
73 +, _0
-0 a)
0
co
C)
C: =3
o o
'-73 N
C: c -.r-
CO
(0
(1)
(1)
U)
z
8
W
2
4-
0
C-)
CL
0.
C)
+co c
0 .=
C) o
'-P
C)
C)
c:
(1)
a)
C)
_0
a)
_0
m
C)
co
.2 E
" a)
o
+�
0
C:
m
47
C)
ca
+1
E w
-o
0 in
4--
C:
C)
(o
4--
U)
0
a) -
V
C:
co
CL'- -0
4--
o
C)
o (n C)
o
E .2
0
CL �:,
a " m
0
C)
co
C)
a) c:
co . D
A)
W
a) +�
E C:
a)
E
LU
E
cc
co _0
A) 0
C: C: 4--
-0
a) a)
a)
LU
6
.0
+�
cc
C'O
= .F-
C-) (n
0 0 0 0
C:
co
0
-0
C)
a)
-a
'a
co
0
CO
E
a)
0
E
m
0 _0
4
0 co
co 'a
-0
-a a)
-0
-
+a,)
0
cc
2 +t
CL
m m
a)
E >N -o
C)
-0
<
E
C)
-0
0
LO
LO
N
CL
0
0
(N
00 C6
Ld C4
-0
70
(14
-0
(N
70
N
cq
cq
(N
N
_0
N a)
.2
E
.2
E
.2
E
.2
E
E
ac)
E
ac)
E
ac)
E
06 (o
8
.6 'm
.6
.6
.6 E
.6 E
.6 E
.6 E
�o E
06 _0
70
-0
-0
-Fo
_0
-Fo
-Fo
-Fo
-Fo
C:
-Fo
m
C:
_0
_0
70
76 70
76 70
c: LL
0 n
0 n
0 n
0 D
0 C
0 C
0 C
0 C
0 C:
C) :3
0 0
0 0
0 0
0 0
0 73
0 :3
0 n
0 n
0 73
0 0
LL
LL
LL
LL
LL
LL
LL
LL
LL
LL
U)
6
6
6
6
6
6
6
6
6
6
E
E
E
E
E
E
E
E
E
E
Ln
T
Ln
.(n
0 C:
0 C:
0
0 C:
0 C:
0 C:
0
0
0
0 C:
E
E
E
E
E
E
E
E
E
E
a)
22
22
22
D
L
D
L
D
L
D
L
D
L
D
L
>
>
>
>
>
>
>
>
>
-0
-0
-0
-0
-0
-0
-0
-0
-0
-0
CL
CL
CL
CL
CL
CL
CL
CL
CL
CL
m
m
m
m
m
m
m
m E
m
m E
C)
+2
C)
+2
C)
(N +2
C)
N +2
C)
N +2
C)
N
C)
(N
C)
Cj
C)
0 "
CA
-0
-0
-0
-0
_0
-0
-0
-0
-0
70
-0-0
-0-0
-0
-0
-0
-0-0
-0-0
-0.0
CL c
CL c
CL C:
CL C: -0
CL C: -0
CL C: -0
CL C:
CL C:
.0
CL C:
CL c
u
u
u
-Fo
u
u
-Fo
u
u
u
u
u
a) -0
m -0
a) -0
(v m -0
a) -0
0) 7-0 -0
a) M _0
0) 70- -0
a) M -0
0) 70--0
C)
0
C)
0 c:
C)
0 c:
C)
0 c:
C)
0
C)
0 c:
0
0
C)
0 c:
C)
0
C)
0 c:
—i
Ln -j m
0
0
+�
0
0
c -) (n .-0 +,
0
-F- o
0 0
0
0
C)
70
(n
m
0
0
0
CL
C: 0
73 >
72
E
C)
_0
0 m E
0
>
0
m 0
(n 3:
a)
0
0 0 0 0 3:
E
a) .4 -0
0
CL =
CL 0
+� a
>
0 (n
0
E
0
-0
C:
-0 (n
CL
(n
0
4-- 0
8 q w 75 E
-J 70
c
4-- 0
2
.2
+�
M
0
-0
m 0
> 70 C:
0 73
>, 70
(0 a) C: M
" — C: LL
0 0
C) :3
+,
:3 -0
a)
m
0
C: -- C:
_0
+1 C:
0 -0 3: 0 0
0
0
0
73 -?5 -0
m
0
C)
3: 0 0 C-)
E
3: >
E Z
cc))
4
'E-
0
75 E
zi
_0 t� c- 0
+ 5 32
a) > "
c)
(n a)
C:
(:n3
Z
2 E
-0 C: o
-0
C: -0
1E
c 0
70 (n (n
0
_0
_0 (n m
1E 3: -0
oc
a)
(n
E
(0 �
0
0 w
m 0 a) o c
E
o 'o
C-)
2
2 c
C:
0
_0
0 0 C:
LG
LD 2
a) m C 0
-0 a) c
(n a) -0
m
Lu m
0- �:c m
LU (n
w
E o
73 73
'-P :3 +, a)
C: a)
-0
(n a) C) C)
-0
0 0
W
0 L) -0
a) C:
0
_0
a)
s
uj .'s
C) -0 m 2 L)
uj m _0
< 70 m 0
6
C6
6
1
(0
CL
0
0
(N
00 m
r_� m (N C4
70
70
a)
Q)
c: E
c: E
.2
.2
E
2 (0
�< .2 (0
-0
LE5
�5
06 (0
_0
06 (0
_0
70
06 (0 C:
-0
06
72
0
E
E
(0 C:
0 73 7
70- C:
c) D
73
(0 C: LL
0 n ,
76 c: LL
0 73
0 0
LL
0 0
LL
0 0 a)
LL
0 0
LL
U)
U)
U)
U)
E
E
'-P
E
E
E
'-P
E
-r-
In
+�
-r-
In
+�
.In
0
0
0
0
0
0
a)
a)
D
L
D
L
D
>
>
>
>
0
c
c
0
Cj
-0
-0
-0
-0
-0
-0
-0-0
-0-0
-0-0
-0
CL
CL
CL
CL
CL
CL -0
m
u
m
u
m
u
m
u
m
u
cu
u
a) -0
0)
_0
a) -0
0) m _0
a)
-Fo
0) 70- 3:
-0
C)
0
0
C)
0
0 c:
0
0
C)
0 c:
0
0 73
(n
A)
o
a)
4
0 a)
0
E 0
0
0
.2 m
a)
(n
0 0 73 C-) c
a)
_0
(n
E"
0 0
+0,
t2
ui a)
E
0
0-5
73
,
0
a) >
a)
_0
E
a) CL
C) CL
o a) -0
0
E
:t�
-F, C) E c)
0 (n :F
0
0
-0
0
0 a)
0
C-)
-0
C)
C)
C)
C)
q:
.0 '0
>
m .F-
0
-C 3 0 -0
0 D
a) c
LD (1)
CL
.2
a)
c co
0
E ((nn a) --r- -�:
o (n 1)
m
m
+' C:
E
E
E 0
(0 M E
a)
a) 0 a) a) a) m +C'
_0
E
a)
0
8
8 -.r-
= 2 4 C:
> 8
-0 C) +,
c: 0 0 a) 0.
a>) I �o
C:
-0
+ CL >
E
S
Uc ,
J T, . S a)
Q) o
-j
E IF
— m E L -a o o
>1
m C)
ui
m . C:
(o 0
6
L6
Cd
CL
0
0
(N
1�—
LLI
LLI
0
LLI
0
it
a.
x
in
z
LLI
a.
a.
0
0
>
0 (f)
�7-
0
C-) C)
�7-
�7-
>
0 0
00
r- N
E C:
:3 co
6 co �-p
U a_ 0
E
0 'r- :29 :29
L) CL
E
u
LL
Z
C)
0 -0
0
0
0 0
E
41
w
L6 a)
N
0
L6 (N -0
0
:3 0
-0
00
i LO
u E LO
ir it
cu
E�
Mn
0
0'
(n
0
0)
x
LU
0
0-
0
cu
0
LU
0
07
LU
c
0
0
N .0
0
07
0)
—
!E
cu
0
0
=
+�
C)
Q
C-)
+�
cu
0
m E
am 0
a)
cu
(n
CS
Q-
z
in
Lu
U)
Q-
Q- cc
(,4 z
I -A
N
m
LO
(D
r-_
w r- t
E,
:3
F= 0
Z3
Z3
Z3
Z3
Z3
Z3
Z3
Z3 U
0 0 0 0 0 0 0 0
E
L) li CL
_0
_0 _0 a)
(h E
(0 -r- 0 (0 (1) 0 C:
'QO (1)
(D E
> (1) < 0
>
_E E 0)
o d: E D) C) E
0 " W
C) (i) E o ,f (1) 5
(1) -r- 0 E x
0 -c- 0 w -0 0 0)
CL (D
E (1) a 0 a) 0
w 70 a) = 0 75 f� t:
0 -r- (D FL
01—
FL Q 3:
CL u) — u) c:
-0 0
= c 0 E
-0 m -0 Z-
0 0 (D
J) 0 >
o — 0 E -o Z
E
2 (No 20 Q) )u 0 (1) c co 2 0 E 0 -o
3: c: -Z- CL,- —
z, 'E 0 0 :p 0- - 3: — c:
a) 70 tf m
D) 0 -0 -2:' (1) E �c :01 a) (1) C 0
x (j) D) _r :3 -SE (1) u) _C (D
(1) (1) -r- — 1 (1) E 2 (1) — — (1) (0 z
0 u) 0 c: a) c: -0 0 (1)
u) (D -0 0 :3 >
0 a C (1) 0 (,) _0
E� 75 (a')) E
(D 0 (D 0 (D (1) > -0 >
-0 z- M w Z- -0 -a 0
d
> < > > E -o
(D-0 (1) (D -E :3 (1) 2 75 -L- -:0'
0 2 q 0 c
(D --r- -0 0- 0- CL �- u) E EL.S� S� ui 0 a- 0 Q (D
CU
C-)
0 U) >
(1) — "F-
(1) cu
,
—
0
CU
-0 F-
>,
(-)
(f)
(3) — (n
Q- +(f,) cu
li CA
00
It
N
0
N
N
0
N
021
a)
a) a)
E E
LU
0
o
LU LU
E
E
E E
2 2
a)
a)
a)
a) a)
E M: 2 2 2 2
P.O :3 :3 :3 :3
LL 0 LL LL- LL LL
C: C14 C: C14
0 C) 0
C) co _0 m o _0 m o _0 m 0 -0 m 0 M -0 m
C: o m
0 co 0 0 C14 C) C) 04 04
L6 L m .2 &.2
o co
o &.2 LO L
C) m 4 Z- 6 6 It t� 6 6 o
LO C,4 64 L6 C, 6 C, 04 It -t:�
C14 _0 C14 _0 0 (D U -0
'I, L,- -0
-a �o (D _0 _0 C14 Z, C14 Co
04 -a I-i _0 C14 L Z, 70 Lo L CL, Z, '0 LO
tri -0 co >1 tri -0 co Q)- L -0 co >1 tri -0 co >1 L m 7cou >1 Q�, L 2, 7cou a>),
0
It
(D
-Ob
00
LO
00
(6
(Ii
C)
< m 0
0
0 �F)
a) cn m -Fa
—. C)
0
Co 0
cf)
a) C:
o
Co 0 0
3:
a) A-
4t: 0 _0
o w c
w
a)
0
C: — A_-
0
'Z,
E w -0 Co
a)
.- — Co
a a -t -F, w
M 0
co
W W
-0
C: >1
C,4
H
w E :3 W
0 a. (p C,4
-z- E
cn
w OL o co
a) -a
�w
T
— E w.2
0
> c 0
Co
C: M
0 C: 0 Q
-0 -a -.a
co w
a)
±_2
—
co w
LL > " w
o :3
co W
0 -
" a) 3:
w
OL co , co a)
C:
-i o 2
C:
a)
0 "
w " W 0
C) "
6 co co
Cl w w
C 0 >, 0
co — — a)
> .-
co
w (n w o co
C: — '.;
61-- co
— 0 3:
r-
< cl
cn 0 >, >1
0 "
�F) �C:
C: >
C: o
w W >
E o a)
E
co w
co cf) co
C,4
-i
cn
— 0 a)
a) a)
cf)
a) C)
WC: Co/) C:
Q
CIL 0 CIL 0
(� >,
Co >
u)
o 0
cf) >, (1) a) C)
OL
u) C—: 55 On)
co :3
Q
.2 -a (1)
.2 0
co
> LLJ " C.) C:
C) W
Co >
0
0
2 C: :—t o
(1) -Fa
M W M a) Co
o �F) -2 E '2 -0
0 Co
0 0
Cl —
o 2 -50, cu 2
OL w C) -0
0
.2 p
> Co
.2
in E . O-L 'w
0 a) W 0
OL c > o >
OL 2 2
OL
Cl C: :3
Cl
I
Cl W
:3 Co :3
Co 0
- 0
1-
-a 'E
c m
>
E
70
E
(1)
(1) E
42
(1) C: -0
(1) (n -i
-0 (1) co
Q) 0
z , co co 2 co
Q) co C.) u)
0
70 70
.2 Q)
(1) -Z, co (1)
70 co
o , -L)
(1) 0 w E OXL
78 .2 (1)
0 W M W co
> > CIL
0 0 E
>
2
> -a C.) Q
2 co >
=
CIL C:
0 (1) 0
> 2 t!
0
2 2 w 20 cn
co
-0 a)
a.
E L
a. - a) 0-
L 2
a Ej cn
>
>
>
C: 4- 0
0
-0 0 -0 0 4-
C: L 4-- (1)
E-
0
-F- +, 0 c 0 w
(D 0 C: - — — (1)
4- 4- 0 0
W.—
0
M M
4--
(f) > 0 C-) 0 4-
(1) (1)
(11 0-+, 3: E
)—ao FZ
0
>
— — 1- -0 0 4- o (o 4- (f)
0 (1)
0
(1) C: 0
co G 3:
U) �: do Lu 0- z 12 U)
(Y) I* LO (0 r- OD
0')
CA
M
a_
ATTACHMENT B
Montana Cybersecurity Planning Committee Charter
U-1-1
STATE OF MONTANA
STATE AND LOCAL CYBERSECURITY GRANT PROGRAM
MONTANA CYBERSECURITY
PLANNING COMMITTEE
CHARTER
State of Montana Cybersecurity Planning Committee Charter
Record of Change
DATE
DESCRIPTION OF CHANGE
INITIALS
2022.11.07
Initial Version — Draft
BSH
2022.11.09
Formatting updates — Draft
AMH
2022.11.10
Final Review Update
MT -CPC
Record of Distribution
DATE RECEIVING PARTNER AGENCY/ ORGANIZATION
2022.11.10 MT -CPC members & delegates
Table of Contents
Recordof Change .......................................................................................................................................... 2
Recordof Distribution ................................................................................................................................... 2
Tableof Contents .......................................................................................................................................... 2
MT -CPC Charter ............................................................................................................................................ 3
1. Official Designation ........................................................................................................................... 3
2. Authority ........................................................................................................................................... 3
3. Purpose and Scope of Activities ........................................................................................................ 3
4. Description of Duties ........................................................................................................................ 3
5. Committee Membership ................................................................................................................... 4
6. Committee Chairs ............................................................................................................................. 4
7. Meetings and Procedures ................................................................................................................. 5
8. Subcommittees ................................................................................................................................. 5
9. Recordation ....................................................................................................................................... 5
10. Amendment of Charter ................................................................................................................. 5
Appendix A —Committee Membership ........................................................................................................ 6
2022.11.10 *** FINAL *** Page 2
State of Montana Cybersecurity Planning Committee Charter
MT -CPC Charter
1. Official Designation
Montana Cybersecurity Planning Committee (MT -CPC)
2. Authority
Pursuant to the statute authorizing the State and Local Cybersecurity Planning Grant Program
(SLCGP), Section 2220A of the Homeland Security Act of 2002, as amended (Pub. L. No 107-296) (6
U.S.C. § 665g) and appropriated by the Infrastructure Investments and Jobs Appropriations Act (IIJA)
(Pub. L. No. 117-58), requiring the State Administrative Agency (SAA) to establish a Cybersecurity
Planning Committee. The State Administrative Agency for Montana is the Disaster and Emergency
Services Division (MT DES).
3. Purpose and Scope of Activities
The purpose of the MT -CPC is to conduct the following activities in support of the SLCGP
requirements:
• Assist with the development, implementation, and revision of the Cybersecurity Plan of the
eligible entity
• Formally approve the Cybersecurity Plan in coordination with the Chief Information Officer
(CIO) and or State Chief Information Security Officer (CISO)
0 Assist with the determination of effective funding priorities for a grant
The MT -CPC shall take a whole -of -state approach focusing on the priorities and objectives in the
SLCGP Notice of Funding Opportunity (NOFO). The MT -CPC will leverage other governing bodies for
expertise and guidance as applicable. The overall goal of the plan, and the projects that are funded,
is to improve the cybersecurity of resources and services in Montana.
4. Description of Duties
MT -CPC: The primary duties of the committee are to assist Montana's Chief Information Officer and
Chief Information Security Officer to develop a Statewide Cybersecurity Plan and supporting projects
that meet the objectives documented in the plan.
State Information Technology Services Division (SITSD): The CIO or CISO serving as MT -CPC Chair
conduct meetings, approve the final plan for submission, work with the committee on executing the
priority projects within the plan, coordinating with the SAA for grant management and
administration.
MT DES: oversight of all grant management administrative activities including but not limited to
application submission, subrecipient monitoring, and closeout. Ensuring all grant activities
2022.11.10 *** FINAL' Page 3
State of Montana Cybersecurity Planning Committee Charter
performed by the committee comply with the requirements set forth in the SLCGP and relevant
federal and state laws.
5. Committee Membership
State and Local Cybersecurity Grant program outlines the following composition and membership
requirements:
• COMPOSITION. A committee of an eligible entity established under paragraph (1) shall —
"(A) be comprised of representatives from "(i) the eligible entity; "(ii) if the eligible entity is
a State, counties, cities, and towns within the jurisdiction of the eligible entity; and "(iii)
institutions of public education and health within the jurisdiction of the eligible entity; and
"(13) include, as appropriate, representatives of rural, suburban, and high -population
jurisdictions.
• CYBERSECURITY EXPERTISE. Not less than one-half of the representatives of a committee
established under paragraph (1) shall have professional experience relating to cybersecurity
or information technology.
• RULE OF CONSTRUCTION REGARDING CONTROL OF INFORMATION SYSTEMS OF ELIGIBLE
ENTITIES. Nothing in this subsection shall be construed to permit a cybersecurity planning
committee of an eligible entity that meets the requirements of this subsection to make
decisions relating to information systems owned or operated by, or on behalf of, the eligible
entity.
Members may be voting or non -voting advisory members. Members may provide a proxy from their
organization if they are unable to attend. Designated alternates can vote in the absence of the
primary member and should come from the same organization or organization type (City, County,
Law Enforcement, Public Education, or Public Health) and with similar skillsets. See Appendix A for
the complete membership list in compliance with requirements above. Subject matter experts may
be invited to participate as non -voting members as requested.
6. Committee Chairs
0 The State CIO will serve as the Chair of the MT -CPC with the State CISO serving as the Vice
Chair of the MT -CPC.
The Vice Chair will assume the responsibilities of the Chair if the Chair is not present.
The Chair is a voting member.
The Vice Chair is only a voting member if the Chair is not present or if there is a tie vote.
The Chair will review committee member composition and ensure it is aligned with the law
and Notice of Funding Opportunity by appointing or replacing committee members.
2022.11.10 *** FINAL' Page 4
State of Montana Cybersecurity Planning Committee Charter
7. Meetings and Procedures
• The MT -CPC shall meet at a minimum quarterly or more frequently at the direction of the
Chair to effectively carry out the required duties and responsibilities as set forth in this
Charter.
• IVIT-CPC meetings will not be open to the public nor recorded due to the sensitive nature of
security controls and projects being discussed.
• When practical, the time and place of the MT -CPC meetings will be communicated to
members a minimum of two weeks prior to the meeting.
Meeting agendas will be provided to members prior to the meeting.
The committee will use a modified version of decision making based on Roberts Rules of
Order.
• A quorum is established with the Chair or the Vice Chair, and 50% of voting members or
their delegates must be present.
• For voting measures, a simple majority is 51% of present members or their delegates.
8. Subcommittees
Subcommittees may be created as needed to support the MT -CPC.
Subcommittees must be chaired by MT -CPC member who is appointed by the IVIT-CPC Chair.
9. Recordation
Agenda, meeting notes, and results from all regular and special meetings will be summarized and
approved by the voting members at the next regular meeting. Information about security controls,
weaknesses, or other sensitive details will not be disclosed publicly.
10. Amendment of Charter
This Charter may be amended by a simple majority vote of the IVIT-CPC after a proposed
amendment has received one reading at a regular IVIT-CPC meeting. Each voting member has
provided charter approval and agree to the terms of the charter.
This charter is hereby enacted by the MT -CPC this 14th day of November 2022.
Kevin Gilbertson, MIT CIO DATE
IVIT-CPC Chair
Andy Hanks, MIT CISO DATE
IVIT-CPC Vice Chair
2022.11.10 *** FINAL' Page 5
State of Montana Cybersecurity Planning Committee Charter
Appendix A —Committee Membershipi
NAME
ROLE
ORGANIZATION & TITLE
Kevin Gilbertson
Chair
Montana Department of Administration, State Information
Technology Services Division (State Chief Information Officer)
Montana Department of Administration, State Information
Andy Hanks
Vice Chair
Technology Services Division (State Chief Information Security
Officer)
Montana Department of Military Affairs, Division of Emergency
Burke Honzel
Administrator
Services (Bureau Chief) & State Administrative Agency (Point of
Contact)
Joe Frohlich
Advisor
Department of Homeland Security, Cybersecurity and
Infrastructure Security Agency (Cyber Security Advisor)
Anne Dormady
Voting
Montana Department of Justice, Division of Criminal Investigation
Member
(Crime Information Bureau Chief)
Voting
Montana Department of Military Affairs / National Guard
Buel Dickson
Member
(Brigadier General, Assistant Adjutant General)
Voting
Elder Grove School District (Technology Director) & Montana
Carol Phillips
Member
Educational Technologists Association (President)
Eric Bryson
Voting
Montana Association of Counties (Executive Director)
Member
Erika Billiet
Voting
City of Kalispell (Information Technology Director)
Member
Jacob
Voting
Billings Clinic (Chief Information Security Officer)
Hammersmith
Member
Jason Emery
Voting
Missoula County (Chief Information Officer)
Member
Jason Hecock
Voting
Kalispell Public Schools (Information Technology Director)
Member
Jody Faircloth
Voting
Partnership Health Center (Director of Infrastructure)
Member
Kelly Carrington
Voting
Carbon County Sheriff's Office (Sergeant)
Member
Neil Cardwell
Voting
City of Belgrade (City Manager)
Member
Victoria Lowe
Voting
Sheridan County (IT Manager)
Member
'Note: Appendix A will be updated as committee candidates accept appointment to the Cybersecurity
Planning Committee.
2022.11.10 *** FINAL*** Page 6
ATTACHMENT C
Montana State and Local Cybersecurity Grant Program
Cybersecurity Planning Committee Priorities
The State of Montana Cybersecurity Planning Committee has identified priority areas within the State
Cybersecurity Plan.
State -Level Projects
No more than Twenty (20%) percent of the total SHSP funds will be allocated to state -level projects
including the State Management and Administration costs. If not all the funds are allocated for state
level projects, funds will be available for local level projects.
1 IVIT DES M&A — up to 5% of State Award
2 Whole of State Coordinator
#1: Governance and Plan Development
#2: Support for Assessments, Plan Development
#3: MT-ISAC, Cyber Hygiene
#5: Support Migration to GOV
3 ITSID — Training (Projects #4; #6)
Total
Local Level -Projects
$121,393
$314,179
$50,000
$485,573
A minimum of eight (80) percent of the total SLCGP funds will be allocated to local level projects. This
includes a minimum of twenty-five (25) percent of the overall funding that must be allocated to rural
jurisdictions. Jurisdictions may receive state provided services in lieu of funding with local consent. The
following project areas have been identified as priorities to increase the capabilities across the state.
Priority will be for jurisdictions to implement best practices and increase the overall baseline capabilities
to secure the state's critical infrastructure. (See State of Montana Cybersecurity Plan 2022-2024)
4 Basic End User Security Awareness Training
- State Service (Know Before): $3.50/license
- Local Submitted End User Training
...............
5 Migrate to GOV domains — Solicit Interest
6 Cyber training for IT privileged users and cyber
professionals (approximately $4,200/course)
- SANS Training — State purchased and provided
- Other Professional Course — local purchased
55
7
Behavior based end -point detection and response
solution for servers and workstations
- Sentinel One managed service (State Contracted)
Network Monitoring and Management Intrusion Detection
Systems (Limited Eligibility to Critical Infrastructure
Election / Emergency Services)
- Albert Sensors (MS-ISAC)
- Comparable Service
$1,250,000
$450,000
56
Attachment D
Montana State and Local Cybersecurity Grant Program
CISA Recommended Resources, Assessments, and
Memberships
The following list of CISA resources are recommended products, services, and tools provided at
no cost to the federal and SLT governments, as well as public and private sector critical
infrastructure organizations:
• CYBER RESOURCE HUB
• Ransomware Guide (Sept. 2020)
• Malicious Domain Blocking and Reporting
• Cvber Resilience Review
• External Dependencies Management Assessment
• EDM Downloadable Resources
• Cyber Infrastructure Survey
• Validated Architecture Desian Review
0 Free Public and Private Sector Cybersecurily Tools and Services
CISA Central: TLIWgrt a cybersecurity incident, visit hl�2s://www.us-cert.gov/repo
For additional CISA services visit the CISA Services Catalog.
For additional information on memberships, visit Information Sharing and Analysis Organization
Standards Organization.
Membership in the Multi -State Information Sharin2 and Analysis Center (MS-ISAC)
and/or Election Infrastructure Information Sharing and Analysis Center (EI-ISAC):
Recipients and subrecipients are strongly encouraged become a member of the MS-ISAC
and/or EI-ISAC, as applicable. Membership is free.
The MS-ISAC receives support from and has been designated by DHS as the cybersecurity ISAC
for SLT governments. The MS-ISAC provides services and information sharing that significantly
enhances SLT governments' ability to prevent, protect against, respond to, and recover from
cyberattacks and compromises. DHS maintains operational -level coordination with the MS-
ISAC through the presence of MS-ISAC analysts in CISA Central to coordinate directly with its
own 24x7 operations center that connects with SLT government stakeholders on cybersecurity
threats and incidents. To register, please visit hl�2s://Ieam.cisecurily.org/ms-isac-registration. For
more information, visit MS-ISAC (cisecurily.org).
The EI-ISAC, is a collaborative partnership between the Center for Internet Security (CIS),
CISA, and the Election Infrastructure Subsector Government Coordinating Council. The El-
ISAC is funded through DHS grants and offers state and local election officials a suite of
57
elections -focused cyber defense tools, including threat intelligence products, incident
response and forensics, threat and vulnerability monitoring, cybersecurity awareness, and
training products. To register, please visit hLtps://Ieam.cisecuriiy.org/ei-isac-registration. For
more information, visit hl�2s://www.cisa.gov/election-securily.
58