Loading...
E5. FY 22 Award - SLCGP - Network Intrusion Detection SystemKalispell IT Department CITY-7F (406) 758-7751 itkkali spell. com OF 201 Ist Ave. East Kalispell, Montana, 59901 KALISPELL www.kalispell.com REPORT TO: Doug Russell, City Manager FROM: Erika Billiet, Information Technology Director SUBJECT: State and Local Cybersecurity Grant Program NIIEETINGDATE: Apri121,2025 BACKGROUND: The city of Kalispell has been awarded $17,750 for a network intrusion detection system, funded by the State and Local Cybersecurity Grant Program's (SLCGP) FY 22 award letter. The purpose of the FY 22 SLCGP is to strengthen cybersecurity practices and resilience of state and local governments. Four of the eight included focus areas of the SLCGP grant were open in the FY 22 SLCGP. Network monitoring and management intrusion detection systems for county and city networks was one of the four focus areas open. RECOMMENDATION: It is recommended that the City Council accept the grant award of $17,750 from the State and Local Cybersecurity Grant Program and authorize the city manager to sign the necessary documents. FISCAL EFFECTS: The city of Kalispell is not required to match the FY 22 SLCGP $17,750 award. ALTERNATIVES: As suggested and approved by City Council. ATTACHNILENT: SLCGP FY 22 Award Letter with Agreement ­'s DE CD J:Ss rn A 13 Doug Russell City of Kalispell 201 1 st Ave E Kalispell MT 59901 City Manager Doug Russell, State and Local Cybersecurity Grant Program FY 2022 Award Letter Congratulations, on behalf of Montana Disaster and Emergency Services (MT DES), the application for financial assistance submitted under the Fiscal Year (FY) 2022 State and Local Cybersecunity Grant Program, Network Intrusion Detection System (IDS), has been approved in the amount of $17,750.00 to provide services to local entities. City of Kalispell is not required to match this award with any amount of non -Federal funds. Before City of Kalispell requests and receives any of the Federal funds, acceptance of the award must be established. By accepting this award, City of Kalispell acknowledges that the terms of the following documents are incorporated into the terms of this award: • Agreement Articles (attached to this Award Letter) • Obligating Document for Award (attached to this Award Letter) • FY 22 State and Local Cybersecunity Grant Program Notice of Funding Opportunity Per the Notice of Funding Opportunity (NOFO), all sub -recipients are required to complete the following: • Complete the Nationwide Cybersecurity Review (NCSR) • Register and maintain CISA's no cost Cyber Hygiene Services (CyHy) Please make sure you read, understand, and maintain a copy of these documents in the official file for this award. In order to establish acceptance of the award and its terms, please complete, sign and return the Obligating Document for Award to your MT DES Grant Coordinator. For additional assistance, please contact your MT DES Grant Coordinator. Sincerely, Burke S. Honzel Preparedness Bureau Chief Montana Disaster and Emergency Services CC Erika Billiet Page 1 of 12 Agreement 0/8', 0 CD EE S 'M 0;o' AGREEMENT ARTICLES State and Local Cybersecurity Grant Program SUB -RECIPIENT: City of Kalispell PROGRAM: State and Local Cybersecurity Grant STATE GRANT NUMBER: 22SLCGP-KAL-IDS TABLE OF CONTENTS Article I Summary Description of Award Article 2 SLCGP Performance Goal Article 3 DHS Standard Terms and Conditions Generally Article 4 Assurances, Administrative Requirements, Cost Principles, Representations and Certifications Article 5 General Acknowledgements and Assurances Article 6 Acknowledgement of Federal Funding from DHS Article 7 Activities Conducted Abroad Article 8 Age Discrimination Act of 1975 Article 9 Americans with Disabilities Act of 1990 Article 10 Best Practices for Collection and Use of Personally Identifiable Information Article I I Civil Rights Act of 1964 — Title VI Article 12 Civil Rights Act of 1968 Article 13 Copyright Article 14 Debarment and Suspension Article 15 Drug -Free Workplace Regulations Article 16 Duplication of Benefits Article 17 Education Amendments of 1972 (Equal Opportunity in Education Act) — Title IX Article 18 Energy Policy and Conservation Act Article 19 False Claims Act and Program Fraud Civil Remedies Article 20 Federal Debt Status Article 21 Federal Leadership on Reducing Text Messaging while Driving Article 22 Fly America Act of 1974 Article 23 Hotel and Motel Fire Safety Act of 1990 Article 24 John S. McCain National Defense Authorization Act of Fiscal Year 2019 Article 25 Limited English Proficiency (Civil Rights Act of 1964, Title VI) Article 26 Lobbying Prohibitions Article 27 National Environmental Policy Act Article 28 Nondiscrimination in Matters Pertaining to Faith -Based Organizations Article 29 Non -Supplanting Requirement Article 30 Notice of Funding Opportunity Requirements Article 31 Patents and Intellectual Property Rights Article 32 Procurement of Recovered Materials Article 33 Rehabilitation Act of 1973 Article 34 Reporting of Matters Related to Recipient Integrity and Perfon-nance Article 35 Reporting Subawards and Executive Compensation Article 36 Required Use of American Iron, Steel, Manufactured Products, and Construction Materials Article 37 SAFECOM Article 38 Terrorist Financing Article 39 Trafficking Victims Protection Act of 2000 (TVPA) Article 40 Universal Identifier and System of Award Management Article 41 USA PATRIOT Act of 2001 Article 42 Use of DHS Seal, Logo and Flags Article 43 Whistleblower Protection Act Article 44 Envirom-nental Planning and Historic Preservation (EHP) Review Article 45 Applicability of DHS Standard Tenns and Conditions to Tribes Article 46 Acceptance of Post Award Changes Article 47 Disposition of Equipment Acquired Under the Federal Award Article 48 Prior Approval for Modification of Approved Budget Article 49 Indirect Cost Rate Article 50 MT DES Specific Acknowledgements and Assurances Article 51 Accruals Article 52 Authorized Representative Article 53 Nationwide Cybersecurity Review Article 54 Cyber Hygiene Services Article 1 Summary Description of Award The purpose of the Fiscal Year 2022 State and Local Cybersecurity Grant Program (SLCGP) is to assist state, local, and territorial (SLT) governments with managing and reducing systemic cyber risk. Through funding from the Infrastructure Investment and Jobs Act, also known as the Bipartisan Infrastructure Law, the SLCGP enables DHS to make targeted cybersecurity investments in SILT government agencies, thus improving the security of critical infrastructure and improving the resilience of the services SILT governments provide their community. This SLCGP award provides funding in the amount of: $2,427,866 for the state of Montana. Of this amount, up to $121,393 can be retained by the State Administrative Agency (SAA) for management and administrative expenses. The terms of the approved Investment Justification(s) and Budget Detail Worksheet(s) submitted by the recipient are incorporated into the terms of this Federal award, subject to the additional description and limitations stated in this Agreement Article and the limitations stated in subsequent reviews by FEMA and CISA of the award budget. Post -award documents uploaded into ND Grants for this award are also incorporated into the terms and conditions of this award, subject to any limitations stated in subsequent approvals by FEMA and CISA of changes to the award. Investments not listed in this Agreement Article are not approved for funding under this award. Article 2 SLCGP Performance Goal In addition to the Performance Progress Report (PPR) recipients must demonstrate how the grant - funded projects address the capability gaps identified in their Cybersecurity Plan or other relevant documentation or sustains existing capabilities per the CISA-approved Investment Justification. The capability gap reduction or capability sustainment must be addressed in Performance Narrative. Article 3 DHS Standard Terms and Conditions Generally The Fiscal Year (FY) 2022 DHS Standard Terms and Conditions apply to all new federal financial assistance awards funded in FY 2022. These terms and conditions flow down to subrecipients unless an award term or condition specifically indicates otherwise. The United States has the right to seek judicial enforcement of these obligations. All legislation and digital resources are referenced with no digital links. The FY 2022 DHS Standard Terms and Conditions will be housed on dhs.gov at www.dhs..qov/publication/fvl 5-dhs-standard- terms-and-conditions. Article 4 Assurances, Administrative Requirements, Cost Principles, Representations and Certifications 1. DHS financial assistance recipients must complete either the Office of Management and Budget (OMB) Standard Form 424B Assurances - Non -Construction Programs, or OMB Standard Form 424D Assurances - Construction Programs, as applicable. Certain assurances in these documents may not be applicable to your program, and the DHS financial assistance office (DHS FAO) may require applicants to certify additional assurances. Applicants are required to fill out the assurances as instructed by the awarding agency. 11. DHS financial assistance recipients are required to follow the applicable provisions of the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards located at Title 2, Code of Federal Regulations (C. F. R.) Part 200 and adopted by DHS at 2 C.F.R. Part 3002. 111. By accepting this agreement, recipients, and their executives, as defined in 2 C.F.R. section 170.315, certify that their policies are in accordance with OMB's guidance located at 2 C.F.R. Part 200, all applicable federal laws, and relevant Executive guidance. Article 5 General Acknowledgements and Assurances All recipients, subrecipients, successors, transferees, and assignees must acknowledge and agree to comply with applicable provisions governing DHS access to records, accounts, documents, information, facilities, and staff. 1. Recipients must cooperate with any DHS compliance reviews or compliance investigations conducted by DHS. 11. Recipients must give DHS access to examine and copy records, accounts, and other documents and sources of information related to the federal financial assistance award and permit access to facilities or personnel. 111. Recipients must submit timely, complete, and accurate reports to the appropriate DHS officials and maintain appropriate backup documentation to support the reports. IV. Recipients must comply with all other special reporting, data collection, and evaluation requirements, as prescribed by law, or detailed in program guidance. V. Recipients (as defined in 2 C.F.R. Part 200 and including recipients acting as pass - through entities) of federal financial assistance from DHS or one of its awarding component agencies must complete the DHS Civil Rights Evaluation Tool within thirty (30) days of receipt of the Notice of Award for the first award under which this term applies. Recipients of multiple awards of DHS financial assistance should only submit one completed tool for their organization, not per award. After the initial submission, recipients are required to complete the tool once every two (2) years if they have an active award, not every time an award is made. Recipients should submit the completed tool, including supporting materials, to CivilRightsEvaluation@hq.dhs.gov. This tool clarifies the civil rights obligations and related reporting requirements contained in the DHS Standard Terms and Conditions. Subrecipients are not required to complete and submit this tool to DHS. The evaluation tool can be found at https://www.dhs.gov/publication/dhs-civi1-rights-evaluation-tool. The DHS Office for Civil Rights and Civil Liberties will consider, in its discretion, granting an extension if the recipient identifies steps and a timeline for completing the tool. Recipients should request extensions by emailing the request to CivilRightsEvaluation@hq.dhs.gov prior to expiration of the 30-day deadline. Article 6 Acknowledgement of Federal Funding from DHS Recipients must acknowledge their use of federal funding when issuing statements, press releases, requests for proposal, bid invitations, and other documents describing projects or programs funded in whole or in part with federal funds. Article 7 Activities Conducted Abroad Recipients must ensure that project activities performed outside the United States are coordinated as necessary with appropriate government authorities and that appropriate licenses, permits, or approvals are obtained. Article 8 Age Discrimination Act of 1975 Recipients must comply with the requirements of the Age Discrimination Act of 1975, Pub. L. No. 94- 135 (codified as amended at 42 U.S.C. § 6101 et seq.), which prohibits discrimination on the basis of age in any program or activity receiving federal financial assistance. Article 9 Americans with Disabilities Act of 1990 Recipients must comply with the requirements of Titles 1, 11, and III of the Americans with Disabilities Act, Pub. L. No. 101-336 (1990) (codified as amended at 42 U.S.C. §§ 12101— 12213), which prohibits recipients from discriminating on the basis of disability in the operation of public entities, public and private transportation systems, places of public accommodation, and certain testing entities. Article 10 Best Practices for Collection and Use of Personally Identifiable Information Recipients who collect personally identifiable information (PII) as part of carrying out the scope of work under a federal award are required to have a publicly available privacy policy that describes standards on the usage and maintenance of the PII they collect. DHS defines PII as any information that permits the identity of an individual to be directly or indirectly inferred, including any information that is linked or linkable to that individual. Recipients may also find the DHS Privacy Impact Assessments: Privacy Guidance and Privacy Template as useful resources respectively. Article 11 Civil Rights Act of 1964 — Title VI Recipients must comply with the requirements of Title VI of the Civil Rights Act of 1964, Pub. L. No. 88-352 (codified as amended at 42 U.S.C. § 2000d et seq.), which provides that no person in the United States will, on the grounds of race, color, or national origin, be excluded from participation in, be denied the benefits of, or be subjected to discrimination under any program or activity receiving federal financial assistance. DHS implementing regulations for the Act are found at 6 C.F.R. Part 21. Recipients of an award from the Federal Emergency Management Agency (FEMA) must also comply with FEMA's implementing regulations at 44 C. F. R. Part 7. Article 12 Civil Rights Act of 1968 Recipients must comply with Title VIII of the Civil Rights Act of 1968, Pub. L. No. 90-284 (codified as amended at 42 U.S.C. § 3601 et seq.) which prohibits recipients from discriminating in the sale, rental, financing, and advertising of dwellings, or in the provision of services in connection. therewith, on the basis of race, color, national origin, religion, disability, familial status, and sex, as implemented by the U.S. Department of Housing and Urban Development at 24 C.F.R. Part 100. The prohibition on disability discrimination includes the requirement that new multifamily housing with four or more dwelling units— i.e., the public and common use areas and individual apartment units (all units in buildings with elevators and ground -floor units in buildings without elevators) —be designed and constructed with certain accessible features. (See 24 C.F.R. Part 100, Subpart D.) Article 13 Copyright Recipients must affix the applicable copyright notices of 17 U.S.C. §§ 401 or 402 to any work first produced under federal awards and also include an acknowledgement that the work was produced under a federal award (including the federal award number and federal awarding agency). As detailed in 2 C.F.R. § 200.315, a federal awarding agency reserves a royalty -free, nonexclusive, and irrevocable right to reproduce, publish, or otherwise use the work for federal purposes and to authorize others to do so. Article 14 Debarment and Suspension Recipients must comply with the non -procurement debarment and suspension regulations implementing Executive Orders (E.O.) 12549 and 12689 set forth at 2 C.F.R. Part 180 as implemented by DHS at 2 C.F.R. Part 3000. These regulations prohibit recipients from entering into covered transactions (such as subawards and contracts) with certain parties that are debarred, suspended, or otherwise excluded from or ineligible for participation in federal assistance programs or activities. Article 15 Drug -Free Workplace Regulations Recipients must comply with drug -free workplace requirements in Subpart B (or Subpart C, if the recipient is an individual) of 2 C.F.R. Part 3001, which adopts the Government- wide implementation (2 C.F.R. Part 182) of the Drug -Free Workplace Act of 1988 (41 U.S.C. §§ 8101-8106). Article 16 Duplication of Benefits Recipients are prohibited from charging any cost to this federal award that will be included as a cost or used to meet cost sharing or matching requirements of any other federal award in either the current or a prior budget period. (See 2 C.F.R. § 200.403(f)). However, recipients may shift costs that are allowable under two or more federal awards where otherwise permitted by federal statutes, regulations, or the federal financial assistance award terms and conditions. Article 17 Education Amendments of 1972 (Equal Opportunity in Education Act) — Title IX Recipients must comply with the requirements of Title IX of the Education Amendments of 1972, Pub. L. No. 92-318 (codified as amended at 20 U.S.C. § 1681 et seq.), which provide that no person in the United States will, on the basis of sex, be excluded from participation in, be denied the benefits of, or be subjected to discrimination under any educational program or activity receiving federal financial assistance. DHS implementing regulations are codified at 6 C.F.R. Part 17. Recipients of an award from the Federal Emergency Management Agency (FEMA) must also comply with FEMA's implementing regulations at 44 C.F.R. Part 19. Article 18 Energy Policy and Conservation Act Recipients must comply with the requirements of the Energy Policy and Conservation Act, Pub. L. No. 94-163 (1975) (codified as amended at 42 U.S.C. § 6201 et seq.), which contain policies relating to energy efficiency that are defined in the state energy conservation plan issued in compliance with this Act. Article 19 False Claims Act and Program Fraud Civil Remedies Recipients must comply with the requirements of the False Claims Act, 31 U.S.C. §§ 3729- 3733, which prohibit the submission of false or fraudulent claims for payment to the Federal Government. (See 31 U.S.C. §§ 3801-3812, which details the administrative remedies for false claims and statements made.) Article 20 Federal Debt Status All recipients are required to be non -delinquent in their repayment of any federal debt. Examples of relevant debt include delinquent payroll and other taxes, audit disallowances, and benefit overpayments. (See OM B Circular A-1 29.) Article 21 Federal Leadership on Reducing Text Messaging while Driving Recipients are encouraged to adopt and enforce policies that ban text messaging while driving recipient -owned, recipient -rented, or privately owned vehicles when on official government business or when performing any work for or on behalf of the Federal Government. Recipients are also encouraged to conduct the initiatives of the type described in Section 3(a) of E.O. 13513. Article 22 Fly America Act of 1974 Recipients must comply with Preference for U.S. Flag Air Carriers (a list of certified air carriers can be found at: Certificated Air Carriers List I US Department of Transportation, https://www.transportation.gov/policy/aviation-policy/certificated- air-carriers-list)for international air transportation of people and property to the extent that such service is available, in accordance with the International Air Transportation Fair Competitive Practices Act of 1974, 49 U.S.C. § 40118, and the interpretative guidelines issued by the Comptroller General of the United States in the March 31, 1981, amendment to Comptroller General Decision B-1 38942. Article 23 Hotel and Motel Fire Safety Act of 1990 Recipients must ensure that all conference, meeting, convention, or training space funded entirely or in part by federal award funds complies with the fire prevention and control guidelines of Section 6 of the Hotel and Motel Fire Safety Act of 1990, 15 U.S.C. § 2225a. Article 24 John S. McCain National Defense Authorization Act of Fiscal Year 2019 Recipients, subrecipients, and their contractors and subcontractors are subject to the prohibitions described in section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019, Pub. L. No. 115-232 (2018) and 2 C.F.R. 200.216, 200.327, 200.471, and Appendix 11 to 2 C. F. R. Part 200. The statute — as it applies to DHS recipients, subrecipients, and their contractors and subcontractors — prohibits obligating or expending federal award funds on certain telecommunications and video surveillance products and contracting with certain entities for national security reasons. Article 25 Limited English Proficiency (Civil Rights Act of 1964, Title VI) Recipients must comply with Title VI of the Civil Rights Act of 1964 (42 U.S.C. § 2000d et seq.) prohibition against discrimination on the basis of national origin, which requires that recipients of federal financial assistance take reasonable steps to provide meaningful access to persons with limited English proficiency (LEP) to their programs and services. For additional assistance and information regarding language access obligations, please refer to the DHS Recipient Guidance: https://www.dhs.gov/guidance-published-help- department -supported- organ izations-provide- mean i ngful-access-people-I imited and additional resources on http://www.lep.gov. Article 26 Lobbying Prohibitions Recipients must comply with 31 U.S.C. § 1352 and 6 C.F.R. Part 9, which provide that none of the funds provided under a federal award may be expended by the recipient to pay any person to influence, or attempt to influence an officer or employee of any agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with any federal action related to a federal award or contract, including any extension, continuation, renewal, amendment, or modification. Per 6 C.F.R. Part 9, recipients must file a lobbying certification form as described in Appendix A to 6 C.F.R. Part 9 or available on Grants.gov as the Grants.gov Lobbying Form and file a lobbying disclosure form as described in Appendix B to 6 C.F.R. Part 9 or available on Grants.gov as the Disclosure of Lobbying Activities (SF-LLL). Article 27 National Environmental Policy Act Recipients must comply with the requirements of the National Environmental Policy Act of 1969, Pub. L. No. 91-190 (1970) (codified as amended at 42 U.S.C. § 4321 et seq.) (NEPA) and the Council on Environmental Quality (CEQ) Regulations for Implementing the Procedural Provisions of NEPA, which require recipients to use all practicable means within their authority, and consistent with other essential considerations of national policy, to create and maintain conditions under which people and nature can exist in productive harmony and fulfill the social, economic, and other needs of present and future generations of Americans. Article 28 Nondiscrimination in Matters Pertaining to Faith -Based Organizations It is DHS policy to ensure the equal treatment of faith -based organizations in social service programs administered or supported by DHS or its component agencies, enabling those organizations to participate in providing important social services to beneficiaries. Recipients must comply with the equal treatment policies and requirements contained in 6 C.F.R. Part 19 and other applicable statues, regulations, and guidance governing the participations of faith- based organizations in individual DHS programs. Article 29 Non -Supplanting Requirement Recipients of federal awards under programs that prohibit supplanting by law must ensure that federal funds supplement but do not supplant non-federal funds that, in the absence of such federal funds, would otherwise have been made available for the same purpose. Article 30 Notice of Funding Opportunity Requirements All the instructions, guidance, limitations, scope of work, and other conditions set forth in the Notice of Funding Opportunity (NOFO) for this federal award are incorporated by reference. All recipients must comply with any such requirements set forth in the NOFO. If a condition of the NOFO is inconsistent with these terms and conditions and any such terms of the Award, the condition in the NOFO shall be invalid to the extent of the inconsistency. The remainder of that condition and all other conditions set forth in the NOFO shall remain in effect. Article 31 Patents and Intellectual Property Rights Recipients are subject to the Bayh-Dole Act, 35 U.S.C. § 200 et seq. and applicable regulations governing inventions and patents, including the regulations issued by the Department of Commerce at 37 C.F.R. Part 401 (Rights to Inventions Made by Nonprofit Organizations and Small Business Firms under Government Awards, Contracts, and Cooperative Agreements) and the standard patent rights clause set forth at 37 C.F.R. § 401.14. Article 32 Procurement of Recovered Materials States, political subdivisions of states, and their contractors must comply with Section 6002 of the Solid Waste Disposal Act, Pub. L. No. 89-272 (1965) (codified as amended by the Resource Conservation and Recovery Act at 42 U.S.C. § 6962) and 2 C.F.R. § 200.323. The requirements of Section 6002 include procuring only items designated in guidelines of the Environmental Protection Agency (EPA) at 40 C. F. R. Part 247 that contain the highest percentage of recovered materials practicable, consistent with maintaining a satisfactory level of competition. Article 33 Rehabilitation Act of 1973 Recipients must comply with the requirements of Section 504 of the Rehabilitation Act of 1973, Pub. L. No. 93-112 (codified as amended at 29 U.S.C. § 794), which provides that no otherwise qualified handicapped individuals in the United States will, solely by reason of the handicap, be excluded from participation in, be denied the benefits of, or be subjected to discrimination under any program or activity receiving federal financial assistance. Article 34 Reporting of Matters Related to Recipient Integrity and Performance If the total value of any currently active grants, cooperative agreements, and procurement contracts from all federal awarding agencies exceeds $10,000,000 for any period of time during the period of performance of the federal award, then the recipient must comply with the requirements set forth in the government -wide Award Term and Condition for Recipient Integrity and Performance Matters located at 2 C.F.R. Part 200, Appendix XII, the full text of which is incorporated by reference. Article 35 Reporting Subawards and Executive Compensation For federal awards that equal or exceed $30,000, recipients are required to comply with the requirements set forth in the government -wide award term on Reporting Subawards and Executive Compensation set forth at 2 C.F.R. Part 170, Appendix A, the full text of which is incorporated by reference. Article 36 Required Use of American Iron, Steel, Manufactured Products, and Construction Materials Recipients of an award of Federal financial assistance from a program for infrastructure are hereby notified that none of the funds provided under this award may be used for a project for infrastructure unless: (1) all iron and steel used in the project are produced in the United States —this means all manufacturing processes, from the initial melting stage through the application of coatings, occurred in the United States; (2) all manufactured products used in the project are produced in the United States —this means the manufactured product was manufactured in the United States; and the cost of the components of the manufactured product that are mined, produced, or manufactured in the United States is greater than 55 percent of the total cost of all components of the manufactured product, unless another standard for determining the minimum amount of domestic content of the manufactured product has been established under applicable law or regulation; and (3) all construction materials are manufactured in the United States —this means that all manufacturing processes for the construction material occurred in the United States. The Buy America preference only applies to articles, materials, and supplies that are consumed in, incorporated into, or affixed to an infrastructure project. As such, it does not apply to tools, equipment, and supplies, such as temporary scaffolding, brought to the construction site and removed at or before the completion of the infrastructure project. Nor does a Buy America preference apply to equipment and furnishings, such as movable chairs, desks, and portable computer equipment, that are used at or within the finished infrastructure project but are not an integral part of the structure or permanently affixed to the infrastructure project. Waivers, when necessary, recipients may apply for, and the agency may grant, a waiver from these requirements. The agency should notify the recipient for information on the process for requesting a waiver from these requirements. (a) When the Federal agency has determined that one of the following exceptions applies, the awarding official may waive the application of the domestic content procurement preference in any case in which the agency determines that: (1) applying the domestic content procurement preference would be inconsistent with the public interest; (2) the types of iron, steel, manufactured products, or construction materials are not produced in the United States in sufficient and reasonably available quantities or of a satisfactory quality; or (3) the inclusion of iron, steel, manufactured products, or construction materials produced in the United States will increase the cost of the overall project by more than 25 percent. A request to waive the application of the domestic content procurement preference must be in writing. The agency will provide instructions on the format, contents, and supporting materials required for any waiver request. Waiver requests are subject to public comment periods of no less than 15 days and must be reviewed by the Made in America Office. There may be instances where an award qualifies, in whole or in part, for an existing waiver described as "Buy America" Preference in FEMA Financial Assistance Programs for Infrastructure I FEMA.gov. Definitions The definitions applicable to this term are set forth at 2 C.F.R. § 184.3, the full text of which is incorporated by reference. Article 37 SAFECOM Recipients receiving federal financial assistance awards made under programs that provide emergency communication equipment and its related activities must comply with the SAFECOM Guidance for Emergency Communication Grants, including provisions on technical standards that ensure and enhance interoperable communications. The SAFECOM Guidance is updated annually and can be found at Funding and Sustainment I CISA. Article 38 Terrorist Financing Recipients must comply with E.O. 13224 and applicable statutory prohibitions on transactions with, and the provisions of resources and support to, individuals and organizations associated with terrorism. Recipients are legally responsible for ensuring compliance with the E.O. and laws. Article 39 Trafficking Victims Protection Act of 2000 (TVPA) Recipients must comply with the requirements of the government -wide financial assistance award term which implements Trafficking Victims Protection Act of 2000, Pub. L. No. 106-386, § 106 (codified as amended at 22 U.S.C. § 7104). The award term is located at 2 C. F. R. § 175.15, the full text of which is incorporated by reference. Article 40 Universal Identifier and System of Award Management Recipients are required to comply with the requirements set forth in the government -wide financial assistance award term regarding the System for Award Management and Universal Identifier Requirements located at 2 C.F.R. Part 25, Appendix A, the full text of which is incorporated reference. Article 41 USA PATRIOT Act of 2001 Recipients must comply with requirements of Section 817 of the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 (USA PATRIOT Act), which amends 18 U.S.C. §§ 175-175c. Article 42 Use of DHS Seal, Logo and Flags Recipients must obtain written permission from DHS prior to using the DHS seals, logos, crests, or reproductions of flags, or likenesses of DHS agency officials. This includes use of DHS components (e.g., FEMA, CISA, etc.) seals, logos, crests, or reproductions of flags, or likenesses of component officials. Article 43 Whistleblower Protection Act Recipients must comply with the statutory requirements for whistleblower protections at 10 U.S.0 § 470141 U.S.C. § 4712. Article 44 Environmental Planning and Historic Preservation (EHP) Review DHS/FEMA funded activities that may require an Environmental Planning and Historic Preservation (EHP) review are subject to the FEMA EHP review process. This review does not address all federal, state, and local requirements. Acceptance of federal funding requires the recipient to comply with all federal, state and local laws. DHS/FEMA is required to consider the potential impacts to natural and cultural resources of all projects funded by DHS/FEMA grant funds, through its EHP review process, as mandated by: the National Environmental Policy Act; National Historic Preservation Act of 1966, as amended; National Flood Insurance Program regulations; and any other applicable laws and executive orders. General guidance for FEMA's EHP process is available on the DHS/FEMA Website at: https://www.fema.gov/grants/guidance-tools/environmental-historic. Specific applicant guidance on how to submit information for EHP review depends on the individual grant program and applicants should contact their grant Program Officer to be put into contact with EHP staff responsible for assisting their specific grant program. The EHP review process must be completed before funds are released to carry out the proposed project; otherwise, DHS/FEMA may not be able to fund the project due to noncompliance with EHP laws, executive orders, regulations, and policies. If ground disturbing activities occur during construction, the applicant will monitor ground disturbance, and if any potential archaeological resources are discovered the applicant will immediately cease work in that area and notify the pass -through entity, if applicable, and DHS/FEMA. Article 45 Applicability of DHS Standard Terms and Conditions to Tribes The DHS Standard Terms and Conditions are a restatement of general requirements imposed upon recipients and flow down to sub -recipients as a matter of law, regulation, or executive order. If the requirement does not apply to Indian tribes or there is a federal law or regulation exempting its application to Indian tribes, then the acceptance by Tribes of, or acquiescence to, DHS Standard Terms and Conditions does not change or alter its inapplicability to an Indian tribe. The execution of grant documents is not intended to change, alter, amend, or impose additional liability or responsibility upon the Tribe where it does not already exist. Article 46 Acceptance of Post Award Changes In the event FEMA determines that an error in the award package has been made, or if an administrative change must be made to the award package, recipients will be notified of the change in writing. Once the notification has been made, any subsequent requests for funds will indicate recipient acceptance of the changes to the award. Please call FEMA Grant Management Operations at (866) 927-5646 or via e-mail to: ASK-GMD@fema.dhs.gov if you have any questions. Article 47 Disposition of Equipment Acquired Under the Federal Award For purposes of original or replacement equipment acquired under this award by a non -state recipient or non -state sub -recipients, when that equipment is no longer needed for the original project or program or for other activities currently or previously supported by a federal awarding agency, you must request instructions from FEMA to make proper disposition of the equipment pursuant to 2 C.F.R. section 200.313. State recipients and state sub -recipients must follow the disposition requirements in accordance with state laws and procedures. Article 48 Prior Approval for Modification of Approved Budget Before making any change to the FEMA approved budget for this award, you must request prior written approval from FEMA where required by 2 C.F.R. section 200.308. For purposes of non -construction projects, FEMA is utilizing its discretion to impose an additional restriction under 2 C.F.R. section 200.308(f) regarding the transfer of funds among direct cost categories, programs, functions, or activities. Therefore, for awards with an approved budget where the federal share is greater than the simplified acquisition threshold (currently $250,000), you may not transfer funds among direct cost categories, programs, functions, or activities without prior written approval from FEMA where the cumulative amount of such transfers exceeds or is expected to exceed ten percent (10%) of the total budget FEMA last approved. For purposes of awards that support both construction and non - construction work, FEMA is utilizing its discretion under 2 C.F.R. section 200.308(h)(5) to require the recipient to obtain prior written approval from FEMA before making any fund or budget transfers between the two types of work. You must report any deviations from your FEMA approved budget in the first Federal Financial Report (SF-425) you submit following any budget deviation, regardless of whether the budget deviation requires prior written approval. Article 49 Indirect Cost Rate 2 C. F. R. section 200.211 (b)(1 5) requires the terms of the award to include the indirect cost rate for the federal award. If applicable, the indirect cost rate for this award is stated in the budget documents or other materials approved by FEMA and included in the award file. Article 50 MT DES Specific Acknowledgements and Assurances Sub -recipients must acknowledge and agree to comply with applicable provisions governing MT DES access to records, accounts, documents, information, facilities, and staff. 1 . Sub -recipients must cooperate with any compliance reviews or compliance investigations conducted by MT DES. 2. Sub -recipients must give MT DES access to, and the right to examine and copy, records, accounts, and other documents and sources of information related to the federal financial assistance award and permit access to facilities, personnel, and other individuals and information as may be necessary, as required by MT DES regulations and other applicable laws or program guidance. 3. Sub -recipients must submit timely, complete, and accurate reports to the appropriate MT DES officials and maintain appropriate backup documentation to support the reports. 4. Sub -recipients must comply with all other special reporting, data collection, and evaluation requirements, as prescribed by law or detailed in program guidance. 5. The State of Montana shall not be liable for any reimbursement amount greater than the award amount available to each sub -recipient. 6. Failure of the sub -recipient to accomplish SLCGP objectives may result in the reduction or withholding of funds, or other action, as determined by MT DES. The State of Montana has the right to seek judicial enforcement of these obligations Article 51 Accruals As established within Montana Operations Manual Policy, accrual documentation is required of all sub -recipients by the Montana Department of Administration, State Financial Services Division, and must be submitted to MT DES no later than the second week of June, or as instructed by MT DES. Article 52 Authorized Representative As evidenced by the signatures found in the Letter of Obligation, the Sub -Recipient Signatory Official agrees to appoint the Sub -Recipient Authorized Representative to act on behalf of City of Kalispell. This individual shall be duly authorized with all necessary powers with regard to the administration and oversight of the 2022 State and Local Cybersecurity Grant Program, 22SLCGP- KAL-I IDS. The Catalog of Federal Domestic Assistance (CFDA) number associated with this grant is 97.137. Article 53 Nationwide Cylbersecurity Review Subrecipients of FY 2022 grant awards will be required to complete the Nationwide Cybersecurity Review (NCSR), enabling agencies to benchmark and measure progress of improving their cybersecurity posture. The Chief Information Officer (CIO), Chief Information Security Officer (CISO), or equivalent for each recipient and subrecipient should complete the NCSR. If there is no CIO or CISO, the most senior cybersecurity professional should complete the assessment. The NCSR is available at no cost to the user and takes approximately 3-6 hours to complete. The 2024 NCSR will be open from October — February 2024. MT DES will provide subrecipients with additional information upon opening of the review. Article 54 Cylber Hygiene Services Subrecipients of FY 2022 SLCGP are required to register and maintain CISA's no cost Cyber Hygiene (CyHy) Services for vulnerability services and web application services as outline in the Notice of Funding Opportunity. Subrecipients will report completion with performance progress reports. Obligating Document for Award STATE GRANT NUMBER: SUB -RECIPIENT NAME AND ADDRESS: ISSUING STATE OFFICE AND ADDRESS: 22SLCGP-KAL-IDS City of Kalispell 201 1 st Ave E Montana Disaster and Emergency Services P.O. Box 4789 FEDERAL AGREEMENT Kalispell, MT 59901 1956 MT Majo Street NUMBER: Fort Hamison, MT 59636-4789 EMW-2022-CY-00027 AMENDMENT NUMBER: NAME OF SUB- SUB -RECIPIENT AUTHORIZED REPRESENTATIVE CONTACT INFORMATION: RECIPIENT AUTHORIZED REPRESENTATIVE: ebillietgkalispell.com 406-758-7751 En*ka Billiet EFFECTIVE DATE OF THIS METHOD OF PAYMENT: NAME AND CONTACT INFORMATION OF MT ACTION: DES GRANT COORDINATOR: EFT 11/21/2024 Emily Schuff Emily. Schuffigmt.gov 406-417-9236 PERIOD OF PERFORMANCE: From: To: FEDERAL AWARD AMOUNT: $17,750.00 12/1/2024 09/30/2026 Budget Period: ASSISTANCE CFDA #: ARRANGEMENT: From: To: 97.137 12/1/2024 09/30/2026 Cost Reimbursement SUB -RECIPIENT SIGNATORY OFFICIAL (Name and Title) DATE SUB -RECIPIENT AUTHORIZED REPRESENTATIVE (Name and Title) DATE MT DES SIGNATORY (Name, Title and Date) Amanda Avard, Preparedness Program Manager, Authonized Organizational Representative FFY 2022 State and Local Cybersecurity Grant Program Guidance Guidance Released: July 16, 2024 MONTANA DISASTER AND EMERGENCY SERVICES '. &14 A Ln a ;100 1061e ��49 P -Q 13 1956 Mt. Majo Street PO Box 4789 Fort Harrison,, MT 59636 Application Due Date: 11:55 pm September 13, 2024 STATE & LOCAL CYBERSECURITY GRANT PROGRAM TABLE OF CONTENTS 1.0 Overview .......................................................................................................................................... 4 2.0 Purpose and Objectives ................................................................................................................... 4 3.0 FUNDING .......................................................................................................................................... 5 4.0 Grant Requirements —State Entity .................................................................................................. 5 5.0 Eligibility Requirements for Local Applicants ................................................................................... 6 5.1 Eligible Applicants ....................................................................................................................... 6 5.2 Applications ................................................................................................................................. 6 5.3 Cost Share or Match .................................................................................................................... 6 5.4 Nationwide Cyber Security Review (NCSR) ................................................................................ 6 5.5 CISA Services and Memberships ................................................................................................ 6 6.0 Application and Submission Information ......................................................................................... 7 6.1 State Cybersecurity Plan Priorities — Attachment C .................................................................. 7 6.2 Application information ............................................................................................................. 7 6.3 Unique Entity Identifier (UEQ ..................................................................................................... 8 6.4 Applicant Agent or Authorized Representative ......................................................................... 8 6.5 Electronic Signature .................................................................................................................... 8 6.6 Application Review and Recommendation ................................................................................ 8 7.0 Project Categories and Activities ..................................................................................................... 8 7.1 Planning ....................................................................................................................................... 9 7.2 Organization ................................................................................................................................ 9 7.3 Equipment ................................................................................................................................... 9 7.4 Training ...................................................................................................................................... 10 7.5 Exercise ...................................................................................................................................... 10 7.6 Management and Administration ............................................................................................ 11 8.0 Unallowable Costs and Activities ................................................................................................... 11 8.1 Unallowable Costs .................................................................................................................... 11 8.2 Supplanting ............................................................................................................................... 11 8.3 Telecommunication, Video Surveillance Equipment and Services ......................................... 11 9.0 Procurement .................................................................................................................................. 12 2 10.0 Award Administration Information ................................................................................................ 13 10.1 Award Administration .............................................................................................................. 13 10.2 Nationwide Cybersecurity Review - Required ......................................................................... 13 10.3 CYBER HYGIENE SERVICES - Required ...................................................................................... 13 10.4 Environmental and Historic Preservation (EHP) Compliance .................................................. 14 11.0 Reporting ....................................................................................................................................... 14 11.1 Quarterly Progress Reports ...................................................................................................... 14 11.2 Financial Reporting (Payment Requests) ................................................................................. 14 11.3 Accruals ..................................................................................................................................... 15 12.0 Scope of Work and Budget Modifications ..................................................................................... 15 13.0 Monitoring/Technical Assistance ................................................................................................... 15 13.1 Monitoring ................................................................................................................................ 15 13.2 Technical Assistance ................................................................................................................. 15 14.0 Project Closeout and De -Obligated Funds ..................................................................................... 15 14.1 Closeout ..................................................................................................................................... 15 14.2 De -obligated Funds ................................................................................................................... 15 15.0 MT DES Contact Information ......................................................................................................... 16 Attachment A: State of Montana Cybersecurity Plan 2022-2024 .................................................................... 17 Attachment B: State of Montana Cybersecurity Planning Committee Charter .............................................. 48 Attachment C: FY 2022 SLCGP Project Priorities ................................................................................................. 55 AttachmentD: CISA Resources .............................................................................................................................. 57 3 State and Local Cybersecurity Grant Program Funding for this program is provided to Montana Disaster and Emergency Services (MT DES). MT DES is the State Administrative Authority for this program. Funding is provided by the U.S. Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), Grant Programs Directorate (G P D). Catalog of Federal Domestic Assistance (CFDA) Number: 97.137 CFDA Title: State and Local Cybersecurity Grant Program (SLCGP) Applications will only be accepted on-line through the AmpliFund system. Please contact MT DES staff for a link to the application. Applicants who have not been in AmpliFund prior to this will need to choose 11register" on the login page. Applicants who have logged into AmpliFund in the past may log in and start the application. KEY DATES: • Application opens on July 16, 2024 • Application closes on Friday, September 13, 2024 at 11:55 PM MDT • Projected period of performance (POP) is October 1, 2024 to June 30, 2026. (extensions not permissible) 1.0 Overview Our nation faces unprecedented cybersecurity risks, including increasingly sophisticated adversaries, widespread vulnerabilities in commonly used hardware and software, and broad dependencies on networked technologies for the day-to-day operation of critical infrastructure. Cyber risk management is further complicated by the ability of malicious actors to operate remotely, linkages between cyber and physical systems, and difficulty of reducing vulnerabilities. The SLCGP grant requires the state to develop a Cybersecurity Plan, establish a Cybersecurity Planning Committee to support the development of the plan, adopt key cybersecurity best practices, and identify projects to implement using the SLCGP funding. 2.0 Purpose and Objectives The purpose of the FY 2022 SLCGP is to strengthen cybersecurity practices and resilience of state and local governments. Reference section 5.1 for a list of local governments eligible to apply. The SLCGP provides funding from the Infrastructure Investment and Jobs Act to implement investments that improve the security of critical infrastructure and improve the resilience of the services governments provide their communities. The grant is a reimbursable pass -through grant program with an overall goal to improve the cybersecurity posture of state and local government organizations by providing assistance for managing and reducing systemic cyber risk through the following objectives: 0 Objective 1: Develop and establish appropriate governance structures, including developing, implementing, or revising cybersecurity plans, to improve capabilities to respond to cybersecurity incidents and ensure continuity of operations. 0 Objective 2: Understand their current cybersecurity posture and areas for improvement based on continuous testing, evaluation, and structured assessments. • Objective 3: Implement security protections commensurate with risk. • Objective 4: Ensure organization personnel are appropriately trained in cybersecurity, commensurate with responsibility. 3.0 FUNDING The State of Montana was awarded $2,427,866.00 for the FY 2022 SLCGP. The SAA must obligate at least 80 percent of funds awarded to local and tribal governments, with a minimum of 25 percent of the overall award going to rural areas. 20 percent of the funds may be utilized for state level projects, with the SAA retaining up to 5 percent of funds awarded for administration costs. The Cybersecurity Committee's intent, per the cybersecurity plan, is with local consent, to have the state contract for services directly on behalf of local units of government. Funds will be allocated to projects through an application process. For this grant, rural jurisdictions are defined as counties, tribes, and cities with a population of less than 50,000. 4.0 Grant Requirements — State Entity SLCGP recipients are highly encouraged to prioritize the following activities using FY 2022 SLCGP funds, all of which are statutorily required as a condition of the grant: • Establish a Cybersecurity Planning Committee. • Develop or revise a state-wide Cybersecurity Plan. • Conduct assessment and evaluations as the basis for individual projects throughout the life of the program. Adopt key cybersecurity best practices. bersecuritv PlanninE Committee The Planning Committee is responsible for developing, implementing, and revising Cybersecurity Plans (including individual projects); formally approving the Cybersecurity Plan (along with the chief information officer or chief information security officer); assisting with determination of effective funding priorities (i.e., work with entities within the eligible entity's jurisdiction to identify and prioritize individual projects). This will be led by Montana State Information Technology Services Division (SITSD). The Cybersecurity Planning Committee must include the following entities: 0 Eligible Entity (state administrative agency) • County, City, and town representation • Institutions of public education • Institutions of public health • As appropriate, representatives from rural, suburban, and high -population jurisdictions. 9 Montana formed its Cybersecurity Planning Committee and adopted the committee charter on November 14, 2022. The committee includes 14 members and 2 advisory members representing the required cybersecurity planning entities. Attachment B CVbersecuritV Plan Montana is required to submit a Cybersecurity Plan that adheres to the 16 required elements identified in section 2220A of the Homeland Security Act of 2002 as amended by the BIL. The Cybersecurity Plan must include a description of state and local roles, an assessment of capabilities for each element, address resources and timeline for implementing the Plan, and identify metrics. State and local governments are encouraged to take a holistic approach in the development of their Plan as entities must be able to sustain capabilities once SLCGP funds are no longer available. The role of state entities as coordinator and service provider to local entities should be encouraged and supported. On November 28, 2023, DHS, FEMA approved the 2022-2024 State of Montana Cybersecurity Plan, allowing the state to request funding holds to be released for approved projects. Attachment A 5.0 Eligibility Requirements for Local Applicants 5.1 Eligible Applicants Eligible Applicants for competitive awards include local and tribal governments. Local government means a city, town, county, consolidated city -county, special district, or school district or subdivision of these entities. Nonprofit, for -profit, and other entities not deemed as a local government entity are not eligible to receive SLCGP funds. 5.2 Applications Eligible applicants listed above may only submit one FY 2022 SLCGP application. Each eligible applicant may apply for projects within the identified focus areas listed in section 6 and will be asked to prioritize each focus area within the application. Each applicant must detail in the application how the project relates to improving, preventing, preparing for, protecting against, and responding to cybersecurity incidents and best practices. 5.3 Cost Share or Match Cost share or match is not required for the FFY 2022 SLCGP. Future awards will have cost share requirements. Match amounts for future award years are as follows: FY 2023 20%, FY 2024 30%, FY 2025 40%. Local match may be in-kind/soft from eligible activities. 5.4 Nationwide Cyber Security Review (NCSR) Applicants must agree to complete the NCSR, administered by MS-ISAC, to receive funding or services under the SLCGP. 5.5 CISA Services and Memberships Applicants must agree to adhere to or sign up for the following free CISA cyber hygiene services. • vulnerability scanning • web application scanning Applicants are strongly encouraged to sign up for other services and memberships, such as IVIS-ISAC and MT-ISAC, as outlined in Attachment D — CISA Resources 6.0 Application and Submission Information 6.1 State Cybersecurity Plan Priorities— Attachment C The cybersecurity committee has identified eight key efforts in the Cybersecurity Plan to strengthen cybersecurity across the state. All projects must align with the focus areas identified in the plan. Those areas are: 1. Whole of state cybersecurity initiatives (state level project) 2. Perform security strategic assessments (state level project) 3. Perform security technical assessments (state level project) 4. Build security awareness S. Migrate to GOV domains (identify if interested) 6. Build a cybersecurity workforce 7. Server and workstation behavior -based endpoint protection 8. Network monitoring and management intrusion detection systems for county networks Only four of the eight focus areas listed above are currently open to eligible local and tribal governments to apply: 1. Build security awareness 2. Build a cybersecurity workforce 3. Server and workstation behavior -based endpoint protection 4. Network monitoring and management intrusion detection systems for county networks 6.2 Application Information Applicants are responsible for planning far enough in advance to complete their application prior to the established deadline. The application deadline is set and will not be extended due to the competitive nature of the grant. If technical difficulties occur, it is the responsibility of the applicant to inform MT DES immediately to work on a resolution. For FY 2022 SLCGP funds, applications are for approved projects meeting the outlined focus areas and integral towards achieving an objective/outcome as outlined in the Cybersecurity Plan under Appendix A. Before starting the application, it is highly recommended that applicants first review the project focus areas and decide which will be applied for. Once applicants have a clear understanding of what is being requested then begin the application and complete the SLCGP Focus Area information form of the application next. The SLCGP Focus Area information form contains information that will help applicants fill out the Project information and Budget sections of the application. The application will consist of the following sections that must be completed: 1. Opportunity Details 2. Project Information 3. Application Forms a. Applicant Entity Information b. Applicant Assessment c. SLCGP Baseline Requirements d. SLCGP Focus Area Information —COMPLETE FIRST when beginning the application! 4. Budget 5. Submit 6.3 Unique Entity identifier (UEI) The federal government now requires the Unique Entity Identifier (UEI) numbers that are created in SAM.gov. This number is required to apply for and receive SLCGP funds. Jurisdictions that do not have a UEI may request one through SAM.gov. 6.4 Applicant Agent or Authorized Representative The applicant agent or authorized representative is the individual who is able or given authority to make legally binding commitments for the applicant organization. 6.5 Electronic Signature Applications submitted through AmpliFund constitute a submission as electronically signed applications. When submitting the application, the name of the applicant's authorized representative will be typed into the certification block. 6.6 Application Review and Recommendation FY 2022 SLCGP applications will be evaluated by MT DES staff through a review process to determine the application completeness and eligibility based on adherence to state and federal program guidance. Eligible projects will then be reviewed and prioritized by the State Cybersecurity Planning Committee for final recommendation to the SAA, CIO, and CISO for funding allocations. Prioritization and rankings are used as recommendations but do not constitute an approval for funding. 7.0 Project Categories and Activities Federal funds made available through this award may only be used for the purpose set forth in this award and must be consistent with statutory authority for the award. Award funds may not be used for matching funds for any other Federal award, lobbying, or intervention in federal regulatory or adjudicatory proceedings. In addition, federal funds may not be used to sue the Federal Government or any other government entity. Sub -recipients must comply with all the requirements in 2 C.F.R. Part 200 (Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards) https://www.ecfr.gov/cgi- bin/text-idx?tpl=/ecfrbrowse/Title02/2cfr2OO main 02.tpl Costs charged to SLCGP must be consistent with the Cost Principles for Federal Awards, 2 C.F.R Part 200, Subpart E. Applicants are encouraged to provide project and budget details related to Planning, Organization, Equipment, Training, Exercise, and Management and Administration (M&A) activities. This list is not all- inclusive. 7.1 Planning Planning costs are allowable under this program. SLCGP funds may be used for a range of planning activities, such as those associated with the development, review, and revision of the holistic, entity - wide cybersecurity plan and other planning activities that support the program goals and objectives and Cybersecurity Planning Committee requirements. 7.2 Organization Organization costs are allowable underthis program. Sub -recipients mustjustify proposed expenditures of SLCGP funds to support organization activities within their application. Organizational activities include: 1. Program management; 2. Development of whole community partnerships that support the Cybersecurity Planning Committee; 3. Structures and mechanisms for information sharing between the public and private sector; and 4. Operational support. Personnel hiring, overtime, and backfill expenses are permitted under this grant to perform allowable SLCGP planning, organization, training, exercise, and equipment activities. Personnel expenses may include, but are not limited to training and exercise coordinators, program managers and planners, and cybersecurity navigators. Grant sub -recipients must demonstrate that the personnel will be sustainable. 7.3 Equipment Equipment costs are allowable under this program. SLCGP equipment is intended to be used to address cybersecurity risks and cybersecurity threats to information systems owned or operated by, or on behalf of, state and local governments. The allowable equipment categories and equipment standards for SLCGP are listed on the DHS Authorized Equipment List (AEL). https://www.fema.gov/grants/tools/authorized-equipment-list Unless otherwise stated, equipment must meet all mandatory regulatory and/or DHS/FEMA-adopted standards to be eligible for purchase using these funds. In addition, agencies will be responsible for, at their own expense, obtaining and maintaining all necessary certifications and licenses for the requested equipment. Investments in emergency communications systems and equipment must meet applicable SAFECOM Guidance recommendations. Such investments must be coordinated with the Statewide Inoperability Coordinator (SWIC) and the State Interoperability Governing Body (SIGB) to ensure interoperability and long-term compatibility. SLCGP funds may be used to purchase maintenance contracts or agreements, warranty coverage, licenses, and user fees in support of a system or equipment. These contracts may exceed the period of performance if they are purchased incidental to the original purchase of the system or equipment as long as the original purchase of the system or equipment is consistent with that which is typically provided for, or available through, these types of agreements, warranties, or contracts. When purchasing a stand-alone warranty or extending an existing maintenance contract on an already -owned piece of equipment system, coverage purchased may not exceed the period of performance of the award used to purchase the maintenance agreement or warranty, and it may only cover equipment purchased with SLCGP funds or for equipment dedicated for SLCGP-related purposes. As with warranties and maintenance agreements, this extends to licenses and user fees as well. The use of SLCGP funds may be used for maintenance contracts, warranties, repair or replacement costs, upgrades, and user fees, unless otherwise noted. Except for maintenance plans or extended warranties purchased incidental to the original purchase of the equipment, the period covered by maintenance or warranty plan must not exceed the POP of the specific grant funds used to purchase the plan or warranty. While these activities may be submitted, they are not a priority. General maintenance and repairs are not allowable. 7.4 Training Training costs are allowable under this program. Allowable training -related costs under SLCGP include the establishment, support, conduct, and attendance of training and/or in conjunction with training by other federal agencies. Training conducted using SLCGP funds must align to the states Cybersecurity Plan and address a performance gap identified through assessments and contribute to building a capability that will be evaluated through a formal exercise. Any training or training gaps, including training related to underserved communities that may be more impacted by disasters, including children, seniors, individuals with disabilities or access and functional needs, individuals with diverse culture and language use, individuals with lower economic capacity and other underserved populations, should be identified in an assessment and addressed in the eligible entity's training cycle. Sub -recipients are encouraged to use existing training rather than developing new courses. When developing new courses, recipients are encouraged to apply the Analyze, Design, Develop, Implement, and Evaluate (ADDIE) model of instructional design. Sub -recipients are also encouraged to utilize FEMA's National Preparedness Course Catalog. Trainings include programs or courses developed for and delivered by institutions and organizations funded by FEMA. This includes the Center for Domestic Preparedness (CDP), the Emergency Management Institute (EMI), and FEMA's Training Partner Programs, including the Continuing Training Grants (CTG), the National Domestic Preparedness Consortium (NDPQ the Rural Domestic Preparedness Consortium (RDPQ and other partners. The catalog features a wide range of course topics in multiple delivery modes to meet FEMA's mission scope as well as the increasing training needs of federal, state, local, territorial, and tribal audiences. The catalog can be accessed at http://www.firstrespondertraining.gov. 7.5 Exercise Exercises conducted with grant funding should be managed and conducted consistent with the Homeland Security Exercise and Evaluation Program (HSEEP). Sub -recipients are required to submit an After -Action Repo rt/I m provement Plan (AAR/IP) for each SLCGP funded exercise. AAR/IPs should be submitted to MT DES, through the quarterly Status Report, no more than 90 days after completion of the exercise. Sub -recipients are reminded of the importance of implementing corrective actions. Sub- 10 recipients are required to use the HSEEP AAR/IP template that can be found at https://des.mt.gov/Preparedness/Training Exercise/AAR-Oct-2018 --- Participant-Form.docx. The AAR/IP must be submitted prior to requesting reimbursement. 7.6 Management and Administration Management and Administration (M&A) activities are those directly relating to the management and administration of SLCGP funds, such as financial management and monitoring. Sub -recipients may use a maximum of up to 5% of funding for M&A purposes. SLCGP funds used for M&A must have supporting documentation (i.e. timecards (salary), invoices/receipts (goods), and general ledgers). M&A must be coded separately on the general ledger so that it is clear as to how many hours were allocated toward M &A for the grant. 8.0 Unallowable Costs and Activities 8.1 Unallowable Costs The grant specifically restricts the use of funds for construction and renovation. Any project that would require an Environmental and Historic Preservation (EHP) review is not allowed. This is as minimal as drilling a new hole in a wall, running cable, or hanging a shelf. Other Unauthorized costs include, but are not limited to, the following: • Any recipient cost -sharing contribution • Pay a ransom • Recreational or social purposes • Cybersecurity insurance premiums • General maintenance and repairs • Parking tickets or other traffic tickets • Sole source contracts and procurements not pre -approved by MT DES • Stand-alone working meals • Alcoholic beverages • Supplanting any expense already budgeted • Entertainment • Laundry • Late payment fees • Drone training Activities unrelated to the completion and implementation of the State and Local Cybersecurity Grant. 8.2 Supplanting Grant funds must supplement, not supplant, replace, or offset state or local funds that have been appropriated for the same purpose. if supplanting is determined, sub -recipients will be required to repay grant funds expended in support of those efforts. 8.3 Telecommunication, Video Surveillance Equipment and Services Sub -recipients may not use any FEMA funds to procure or obtain China made or China affiliated telecommunication, video surveillance equipment or services. Reference FEMA policy #405-143-1 11 https://www.fema.gov/sites/default/files/documents/fema Policy-405-143-1-prohibition-covered- services-equipment-gpd.pd Additional guidance is available at https://www.ecfr.gov/current/title-2/subtitle-A/chapter-II/part- 200/appendix-Appendix%2011%20to%2OPart%20200 Effective August 13, 2020, FEMA sub -recipients may not use any FEMA funds under open or new awards to: (1) Procure or obtain any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology of any system; (2) Enter into, extend, or renew a contract to procure or obtain any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology of any system; or (3) Enter into, extend, or renew contracts with entities that use covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. Per section 889(f)(2)-(3) of the FY 2019 NDAA and 2 C.F.R. § 200.216, covered telecommunications equipment or services means: i. Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation, (or any subsidiary or affiliate of such entities); ii. For the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities); iii. Telecommunications or video surveillance services provided by such entities or using such equipment; or iv. Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the People's Republic of China. Examples of the types of products covered by this prohibition include phones, internet, video surveillance, and cloud servers when produced, provided, or used by the entities listed in the definition of "covered telecommunications equipment or services." See 2 C.F.R. § 200.471. Please reference the System for Award Management (SAM) for a consolidated exclusion list of subsidiaries of telecommunication companies https://sam.gov/SAM/. Please contact your grant coordinator to determine if equipment or services is eligible under this program. 9.0 Procurement All FEMA awards are subject to the federal procurement standards under the Uniform Administrative Requirements, Cost Principles, andAudit Requirementsfor FederalAwards found at 2 C.F.R. § 200.317- 12 LOO.327. Applicants selected for funding does not constitute award. Any costs incurred or obligated prior to the execution of an award are not allowed. When purchasing under a FEMA award, a state entity must follow its own procurement policies and procedures pursuant to 2 C.F.R. § 200.317 as well as all other applicable state and federal laws, executive orders, and implementing regulations. When purchasing under a FEMA award, a non -state entity must have and use documented procurement procedures, consistent with state, local, and Tribal laws and regulations and conforming to appliable federal law and the procurement standards identified in 2 C.F.R. § 200.317-200.327. For a non -state entity, where a difference exists between a federal procurement standard and a state, local, and/or Tribal procurement standard or regulation, the non -state entity must apply the most restrictive standard. MT DES may request a copy of an entities documented procurement procedures which reflect applicable state and local laws and regulations. Procurement procedures must conform to applicable Federal law and the standards identified in 2 C.F.R. § 200.318 For more information on federal procurement see 2 C.F.R. § 200.320. For more information on MT Procurement laws, rules, policies, and executive orders please visit State Procurement Bureau. 10.0 Award Administration Information 10.1 Award Administration Notification of award approval is made through the sub -recipient's authorized representative listed in the application. Awards will be made to the sub -recipients no later than 45 days following the state's acceptance of the Federal award and funds have been released. Sub -recipients who wish to decline the award must provide a written notice of intent to decline. The Principal Elected Official with the legal authority to enter into an agreement and the Authorized Representative working on the project will be required to sign the Award Obligation Letter and email it back to their respective grant coordinator prior to any funds being reimbursed on the project. 10.2 Nationwide Cybersecurity Review - Required The NCSR is a free, anonymous, annual self -assessment designed to measure gaps and capabilities of a SLT's cybersecurity programs. It is based on the National Institute of Standards and Technology Cybersecurity Framework and is sponsored by DHS and the MS-ISAC. Sub -recipients are required to complete the NCSR, administered by the MS-ISAC, during the first year of the award/subaward period of performance and annually. The NCSR is available at no cost to the user and takes approximately 2-4 hours to complete. The NCSR is expected to be open from October — January. For more information, visit Nationwide Cybersecurity Review (NCSR) (cisecurity.org). 10.3 CYBER HYGIENE SERVICES - Required All awarded sub -recipients will be required to sign up for and utilize the following services: 13 Web Application Scanning: an "internet scanning -as -a -service." This service assesses the "health" of your publicly accessible web applications by checking for known vulnerabilities and weak configurations. Additionally, CISA can recommend ways to enhance security in accordance with industry and government best practices and standards. VulnerabilitV Scanning: evaluates external network presence by executing continuous scans of public, static Ips for accessible services and vulnerabilities. This service provides weekly vulnerability reports and ad -hoc alerts. To register for these services, email vulnerability info@cisa.dhs.gov with the subject line "Requesting Cyber Hygiene Services — SLCGP" to get started. Indicate in the body of your email that you are requesting this service as part of the SLGCP. For more information, visit CISA's Cyber Hygiene Information Page. 10.4 Environmental and Historic Preservation (EHP) Compliance Projects which may have a potential impact to the environment or require an EHP review will not be awarded. This is as minimal as drilling a new hole in a wall, running cable, or hanging a shelf. 11.0 Reporting 11.1 Quarterly Progress Reports Sub -recipients are responsible for providing quarterly performance reports using the Performance Progress Report form in AmpliFund detailing milestones and work accomplished during the reporting period. Progress reports must be completed and approved to request reimbursement. The following reporting periods and due dates apply for the progress reports: Reporting Period Report Due Date October I — December 31 January 10 January I — March 31 April 10 April I —June 30 July 10 July I — September 30 October 10 Projects that extend beyond this timeframe are required to continue reporting. 11.2 Financial Reporting (Payment Requests) Sub -recipients must submit at least one payment request upon completion of the project to receive grant funds. However, quarterl payment requests as the project progresses are preferred. The payment request must be done through AmpliFund. All payment requests must include supporting documentation to substantiate claimed expenses. Supporting Documentation must include: • Proof of payment (i.e., general ledger or warrant check) • Invoices • Receipts 14 Reimbursements are made only for expenditures made during the grant period of performance. Reimbursements requests will be rejected if any quarterly progress reports are outstanding. Projects with outstanding quarterly progress reports may be subject to termination of project funding. Sub -recipients receiving services in lieu of direct funding will only need to verify services provided. State ITSD / IVIT DES will provide supporting documentation for the financial reimbursements. 11.3 Accruals Sub -recipients with an open grant will be required to submit an accrual form prior to the end of the State Fiscal Year (SFY) to account for any expenditures or valid obligations that have occurred in the SFY and not been reimbursed prior to June 30. Sub -recipients that do not submit an accrual form and supporting documentation and then request reimbursement for goods or services from the prior SFY are at risk of non-payment due to lack of accrual funds. 12.0 Scope of Work and Budget Modifications Any changes to the scope of work will be submitted via a request form. Any changes to the budget may be made by filling out an amendment request in the AmpliFund system. Sub -recipients will need to contact their grant coordinator if any changes are requested. 13.0 Monitoring/Technical Assistance 13.1 Monitoring Sub -recipients will be monitored by IVIT DES staff, both programmatically and financially, to ensure that the project goals, objectives, performance requirements, timelines, milestone completion, budgets, and other related program criteria are being met. 13.2 Technical Assistance Technical assistance will be provided through desk -based reviews of financial reimbursement requests and project status reports. In addition, on -site technical assistance visits will be performed according to IVIT DES schedules, as requested, or as needed. Technical assistance will involve the review of the financial, programmatic, performance, compliance, administrative processes, policies, activities, and other attributes of each Federal assistance award and will identify areas where further assistance, corrective actions or other support may be needed. 14.0 Project Closeout and De -Obligated Funds 14.1 Closeout Closeout of SLCGP projects will be administered by IVIT DES upon determination of grant completion in accordance with 2 C.F.R. § 200.344 and upon receipt of a signed sub -recipient letter requesting closeout. IVIT DES will complete a project and file review prior to closing out a project and provide the sub - recipient with a closeout confirmation letter for the grant files. 14.2 De -obligated Funds Projects that are completed under budget will have funds cle-obligated during the grant closeout process and will no longer be available to the sub -recipient. De -obligated funds will be utilized during the grant period of performance to fund additional projects. The Cybersecurity Planning Committee will 15 make recommendations for re -awarding grant funds to eligible and approved projects. The committee reserves the right to conduct an interim application process for cle-obligated funds. 15.0 IVIT DES Contact Information MT DES will provide programmatic support and technical assistance for the SLCGP Grant. Preparedness Grant Coordinator Emily Schuff Emily.Schuff@mt.gov Preparedness Grant Coordinator Pamela Fruh Pam.Fruh@mt.gov Preparedness Program Manager Amanda Avard Amanda.Avard@mt.gov 16 ATTACH ME NT A Montana Cybersecurity Plan mod Will 7W --W 4El _-Z 49l JF 41i _zr_ -- - . 0, 41r go Aoki 00 0 0 FATE UF NIL WRARNIRI I I oil i Approved by the State of Montana ..................................................................................... Oil Cybersecurity Planning Committee on September 25, 2023 Version 1.3 THIS PAGE INTENTIONALLY LEFT BLANK State of Montana Cybersecurity Plan 2022-2024 TABLE OF CONTENTS Letter from the Cybersecurity Planning Committee ................................................................................ 3 Introduction................................................................................................................................................... 4 Visionand Mission ........................................................................................................................................ Cybersecurity Program Goals and Objectives ............................................................................................. Cybersecurity Plan Elements ...................................................................................................................... 9 Manage, Monitor, and Track information systems and user accounts ..................................................... Monitor, Audit, and Track network traffic and activity ................................................................................ EnhancePreparedness ................................................................................................................................ Assessmentand Mitigation .......................................................................................................................... Best Practices and Methodologies .............................................................................................................. NISTPrinciples .......................................................................................................................................... SupplyChain Risk Management .............................................................................................................. Toolsand Tactics ...................................................................................................................................... SafeOnline Services ..................................................................................................................................... Continuityof Operations ............................................................................................................................... Workforce...................................................................................................................................................... Continuity of Communications and Data Networks .................................................................................... Assess and Mitigate Cybersecurity Risks and Threats to Critical Infrastructure and Key Resources ..... Cyber Threat Indicator Information Sharing ................................................................................................ LeverageCISA Services ................................................................................................................................ Information Technology and Operational Technology Modernization Review .......................................... Cybersecurity Risk and Threat Strategies ................................................................................................... RuralCommunities ....................................................................................................................................... Funding& Services .................................................................................................................................... . t7 9 9 ... 10 ... 10 Distribution to Local Governments ................................................................................................................. 17 AssessCapabilities .................................................................................................................................... 1s ImplementationPlan ................................................................................................................................ . t9 Organization, Roles and Responsibilities ....................................................................................................... 19 Resource Overview and Timeline Summary ................................................................................................... 19 Metrics........................................................................................................................................................ 20 Appendix A: SAMPLE Cybersecurity Plan Capabilities Assessment .................................................... 25 Appendix 13: Project Summary Worksheet ............................................................................................. 28 Page 2 State of Montana Cybersecurity Plan 2022-2024 LETTER FROM THE CYBERSECURITY PLANNING COMMITTEE Greetings, The State of Montana Cybersecurity Planning Committee (the Committee) is pleased to present to you the State of Montana Cybersecurity Plan (the Plan). The Plan represents the State of Montana's continued commitment to improving cybersecurity and supporting our State, as well as cybersecurity practitioners across our local jurisdictions. In addition, this update meets the requirement of the current U.S. Department of Homeland Security guidelines for the State and Local Cybersecurity Grant Program (SLCGP) Representatives from state, county, municipal, public health, and education sectors within Montana formed the Committee to develop and update the Plan with actionable and measurable goals and objectives that have champions identified to ensure completion. These goals and objectives focus leveraging economies of scale to maximize funds to implement risk -based programs that directly benefit the entities represented on the Committee. This document is structured to meet the required plan elements defined in the Notice of Funding Opportunity. As we continue to enhance the State of Montana's cybersecurity posture, we are committed to improving our resilience across disciplines and jurisdictions. With help from FEMA, CISA, other federal partners, and cybersecurity practitioners throughout the State of Montana, we will work to achieve the goals set forth in The Plan and become a model for cyber resilience. Sincerely, Kevin Gilbertson Chief Information Officer and Chair of the Montana Cybersecurity Planning Committee State of Montana Department of Administration Page 3 State of Montana Cybersecurity Plan 2022-2024 INTRODUCTION Montana faces unprecedented cybersecurity risks, including increasingly sophisticated adversaries, widespread vulnerabilities in commonly used hardware and software, and broad dependencies on networked technologies for the day-to-day operation of critical infrastructure. Cyber risk management is further complicated by the ability of malicious actors to operate remotely, linkages between cyber and physical systems, and the difficulty of reducing vulnerabilities. Considering the risk and potential consequences of cyber incidents, strengthening the cybersecurity practices and resilience of state, local governments is an important homeland security mission and the primary focus of State Local Cyber Grant Program (SLCGP). Through funding from the Infrastructure Investment and Jobs Act, the SLCGP enables Montana to make targeted cybersecurity investments in government agencies, thus improving the security of critical infrastructure and improving the resilience of the services Montana's governments provide their communities. The Statewide Cybersecurity Strategic Plan is to guide aspects of Montana's critical infrastructure sectors and create a unity of effort. The approach focuses on how we will collectively reduce risk and build resilience to cyber threats to the state's cybersecurity posture of all participants. The Plan is a two-year strategic planning document for SLCGP years 2022-2024 that contains the following components: Vision and Mission: Articulates the vision and mission for improving cybersecurity resilience interoperability over the next two years. • Organization, and Roles and Responsibilities: Describes the current roles and responsibilities, and any governance mechanisms for cybersecurity within the State of Montana as well as successes, challenges, and priorities for improvement. This also includes a strategy for the cybersecurity program and the organization structure that identifies how the cybersecurity program is supported. In addition, this section includes governance that identifies authorities and requirements of the State of Montana cybersecurity program. The Plan is a guiding document and does not create any authority or direction over any of the State of Montana's or local systems or agencies. • How feedback and input from local governments and associations was incorporated. Describes how inputs from local governments was used to reduce overall cybersecurity risk across the eligible entity. This is especially important in order to develop a holistic cybersecurity plan. • Plan Elements: Outlines technology and operations needed to maintain and enhance resilience across the cybersecurity landscape. Funding: Describes funding sources and allocations to build cybersecurity capabilities within the State of Montana along with methods and strategies for funding sustainment and enhancement to meet long-term goals. • Implementation Plan: Describes the State of Montana's plan to implement, maintain, and update the Plan to enable continued evolution of and progress toward the identified goals. The implementation plan must include the resources and timeline where practicable. • Metrics: Describes how the State of Montana will measure the outputs and outcomes of the program across the entity. Page 4 State of Montana Cybersecurity Plan 2022-2024 The National Institute of Standards and Technology (NIST) Cybersecurity Framework', included in Figure 1, and the CIS Security ControIS2, included in Figure 2, helps guide key decision points about risk management activities through various levels of an organization from senior executives to business and process level, as well as implementation and operations. CIS controls map to the NIST CSF and are often used to help guide discussion with locals as they are more easily digested and have implementation groups to guide maturity efforts. i NIST Cyblel--�It�, Y F _--k F—cfl— Critical Infrastructure Support I Figure 1: Achieving Cyber Resilience Through Comprehensive Cybersecurity Plans Figure 2: The Critical Security Controls are a prioritized set of Safeguards to mitigate the most prevalent cyber-attacks. ' httos://www.nist.5-ov/cyberframework/5-etting-started 2 https://www.cisecurity.org/controls Page 5 State of Montana Cybersecurity Plan 2022-2024 Vision and Mission This section describes State of Montana's vision and mission for improving cybersecurity: Vision: To enhance the cybersecurity posture and increase the resilience of Montana governments by unifying state and local experience and expertise. Mission: To unify State and Local resources to create a safer digital landscape for Montana. Cybersecurity Program Goals and Objectives State of Montana Cybersecurity goals and objectives that align with NIST Cyber Security Framework include the following: Program Goal Program Objectives 1. Identify Asset Management 1.1 Leverage the Montana Information Security Advisory Council (MT-ISAC) to create a workgroup focused on increased cybersecurity apprenticeships and internships opportunities in Montana (CSF ID.AM-6) Governance 1.2 Leverage MT-ISAC monthly sharing of cyber threat information and industry best practices to all Montana's: Governments, Critical Infrastructure, and Small Businesses. Use MT-ISAC to also promote Council approved groups and associations (Cyber406, CyberMontana, MT National Guard, other ISACs, DHS, etc.) that are promoting situational awareness (CSF ID.GV-4) Risk Management Strategy 1.3 Leverage MT-ISAC and industry best practices to support and standardize on NCSR as annual risk assessment. Provide additional guidance for use of other Council NIST based (CISA CPGs & CRE & CRR, & EDM, CIS Critical Controls) approved assessments. (CSF ID.RM-1) 1.4 Deliver support for State and Local governments to move to .GOV for email and websites. Explore options for K-12. (CSF ID.RM-1) Page 6 State of Montana Cybersecurity Plan 2022-2024 Program Goal Program Objectives 1.5 Leverage MT-ISAC and industry best practices to create a standard naming convention for government entities moving to.GOV(CSF ID.RM-1) 2. Protect Identity Management, Authentication and Access Control 2.1 Leverage MT-ISAC to create a guideline or reference an established industry best practice on Multifactor Authentication with options to use current state services and contracts (CSF PR.AC-7, CIS Control 6.3, 6.4, 6.5) 2.2 Deliver solutions to Local Governments and K-12 to help protect network integrity with proper network segmentation (CSF PR.AC-5, CIS Control 12.2) 2.3 Leverage MT-ISAC to create a guideline or reference an established industry best practice on prohibiting use of known/fixed/ default passwords and credentials with options to use current state services and contracts (CSF PR.AC-1, CIS Control 4.7) Awareness and Training 2.4 Deliver basic end user security awareness training for Montana State & Local governments and K-12 (CSF PR-AT- 1, CIS Control 14) 2.5 Deliver cyber education to privileged users and cyber professionals within Montana State & Local governments and K-12 (CSF PR-AT-2, CIS Control 14.9) 2.6 Deliver access for Montana State & Local governments and K-12 privileged users and cyber professionals to cyber ranges (CSF PR-AT-2, CIS Control 14.9) Data Security 2.7 Leverage MT-ISAC to create a guideline or reference an established industry best practice on encryption for data at rest and in transit with options to use current state services and contracts (CSF PR.DS-1 & 2, CIS Control 3.6 & 3.9 & 3.10 & 3.11) Information Protection Processes and Procedures 2.8 Leverage MT-ISAC to create a guideline or reference an established industry best practice on limiting use of unsupported/end of life (EOL) software and hardware and ending the use of EOL on systems that are accessible from the internet with options to use current state services and contracts (CSF PR-IP-2, CIS Control 12.1 & 13.5 & 16.5) 2.9 Leverage MT-ISAC to create a guideline or reference an established industry best practice on backup and recovery with options to use current state services and contracts (CSF PR-IP-4, CIS Control 11) Protective Technology Page 7 State of Montana Cybersecurity Plan 2022-2024 Program Goal Program Objectives 2.10 Leverage MT-ISAC to create a guideline or reference an established industry best practice on audit/log records with options to use current state services and contracts (CSF PR.PT-1, CIS Control 8) 3. Detect Anomalies and Events 3.1 Deliver Network Monitoring and Management Intrusion Detection Systems (IDS) solutions for County Governments for better protection for Election Offices, Emergency Services, and Public Water System Municipalities. (CSF DE.CM-1, CIS Control 13.3) 3.2 Deliver support for State & Local governments and K-12 to utilize MS-ISAC's no cost Malicious Domain Blocking and Reporting (MDBR) or like service (CSF DE.CM-1 & PR.AC-5, CIS Control 9.2) Security Continuous Monitoring 3.3 Deliver Endpoint Detection and Response solution for Montana Local Governments and K-12 (CSF DE.CM-4, CIS Control 10) 3.4 Deliver supportfor all State and Local government public facing IPs to have external vulnerability scanning with weekly report to entity (CSF DE.CM-8, CIS Control 7.6) 4. Respond Response Planning 4.1 Leverage MT-ISAC and industry best practices to create a statewide incident response reporting process (CSF RS.RP-1 & PR.IP-9, CIS Control 17) 5. Recover Recovery Planning 5.1 Leverage MT-ISAC and industry best practices by delivering training, workshops, exercises on incident response and recovery planning (CSF RC.RP-1 & PR.IP-10, CIS Control 17) Page 8 State of Montana Cybersecurity Plan 2022-2024 CYBERSECURITY PLAN ELEMENTS Manage, Monitor, and Track information systems and user accounts Entities should establish procedures that effectively control and restrict access to information assets to authorized users based on defined business and legal requirements. Mechanisms will be implemented that provide for the control, administration, and tracking of access to, and the use of, information assets, as well as the protection of such assets from unauthorized or unapproved activity and/or destruction. The Cybersecurity Framework and CIS Security Controls both start with knowing what you have in both hardware and software. This includes physical and virtual, on premises and off. It is hard to secure what you do not know. Once you know what you have then the security frameworks turn to who has access to those assets. This is addressed with Access Management. Poor practices in these areas lead to com prom ised systems a nd data breaches. I n today's evercha ngi ng world of tech nology best practice is to use security orchestration, automation and response technologies. The State of Montana manages, monitors, and tracks information systems, applications, and user accounts that are used to conduct state business. A combination of asset inventory tools with both active and passive discovery are used to inventory and identify assets and users connected to the state's networks. A Governance, Risk and Compliance (GRC) tool is used to inventory state systems and for tracking risk and compliance against state policy. Montana has a Network Security Operations Center (NSOC) and a Cyber team that ingests alerts and responds to risks identified by these solutions. The strategic approach for improvement is to assess the capabilities of this element across the whole of Montana government and identify where gaps exist and identify the right tools that can be leveraged to benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be proposed to help address those gaps. Monitor, Audit, and Track network traffic and activity Entity asset owners, asset custodians, and information security and privacy officers should: Ensure the information assets under their purview are assessed for security and privacy risks and configured such that event logging is enabled to ensure an adequate level of situational awareness regarding potential threats to the confidentiality, integrity, availability, and privacy of agency information and information systems are identified and managed; and Review and retain event logs in compliance with all applicable Local, State and Federal laws, regulations, executive orders, circulars, directives, internal agency and state information security policies, and contractual requirements. Montana's methodology to monitor, audit, and track network activity includes Albert Sensors that are placed strategically throughout our network. Defense in depth is used for our firewalls and edge devices. All user traffic will cross a next generation firewall performing packet inspection for IDS/IPS, virus, URL and DNS monitoring. A SIEM and monitoring agents are used to feed data into our security operations center. The centralized log management approach is used for actionable data and long-term storage of logs so that all statutory requirements are met. Page 9 State of Montana Cybersecurity Plan 2022-2024 State of Montana is using a standardized XDR solution to better protect, detect, audit, and track network traff ic and activity. This solution and its deployment allow for complex auditing and monitoring of attacks and allows for quicker reaction and detection. The strategic approach for improvement is to assess the capabilities of this element across the whole of Montana government and identify where gaps exist and identify the right tools that can be leveraged to benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be proposed to help address those gaps. Enhance Preparedness Entities should implement continuous risk management processes that account for the identification, assessment, treatment, and monitoring of risks that can adversely impact their operations, information systems, and information. These processes will inform the exercise and execution of Incident Response Plans, Continuity of Operations Plans and the State Emergency Operation Plan. Lessons Learned from these exercises will be incorporated into future planning, inform organizational decisions, and demonstrate additional equipment and training needs. Montana is embracing preparedness in the following ways: • Planning - Montana has worked with state agencies and others to develop Business Continuity (BC) plans and has semi-annual Disaster Recovery (DR) tests. • Organization - Montana takes a whole of government approach to protect the state and prepare for disasters before they occur. • Equipment - Montana is working on redundant systems and services to protect the state and its citizens. • Training - Montana is working with other entities in the state and expanding its testing of disaster recovery and incident response. • Exercise - Montana has held joint tabletop exercises with a variety of public and private partners to better enhance our response capability. We work closely with the National Guard. The solutions above are primarily from the perspective of Montana state government and do not necessarily provide coverage for Montana local governments and K-12. The strategic approach for improvement is to assess the capabilities of this element across the whole of Montana government and identify where gaps exist and identify the right tools that can be leveraged to benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be proposed to help address those gaps. Assessment and Mitigation All information systems and applications should undergo security assessments to ensure adequate security and privacy controls are implemented and risks are managed to acceptable levels throughout their lifecycles. Risk management processes including identifying, assessing, and addressing security and privacy risks at the inception of the project to build a system until the decommissioning of a system. These actions enable State and Local Government entities to maintain security and privacy of a system throughout its lifecycle. To aid in satisfying the ongoing assessment requirements, assessment results from the following sources can be used: continuous monitoring, audits and authorizations, and other system development life cycle activities. Page 10 State of Montana Cybersecurity Plan 2022-2024 Montana has an Information Security Policy and Standards that define the processes and procedures the State of Montana uses to identify, prioritize, and escalate for remediation, vulnerabilities in the State's IT infrastructure. The plan outlines the various vulnerability identification processes that feed into the program. Montana currently participates in the CISA Cyber Hygiene services including vulnerability scanning of our external facing network assets. Montana uses a combination of both agent and non -agent -based, creclentialed, and non-credentialed, internal and external, vulnerability scans. Critical, high, and exploitable vulnerabilities for state agencies are imported into ESM for tracking and remediation. Critical applications are reviewed on a yearly basis or as changes are made. The Incident Response & Technical Security team along with the Policy and Risk Management team tracks any issues and works with the responsible parties to work toward remediation. The solutions above are primarily from the perspective of Montana state government and do not necessarily provide coverage for Montana local governments. As a condition of receiving SLCGP funding, the grant recipients will sign up for and maintain CISA's no cost Vulnerability Scanning(CyHy) and Web Application Scanning services as well as complete annually the no cost Nationwide Cybersecurity Review (NCSR) assessment administered by MS-ISAC. The NCSR is open to complete in October through late February, check with IVIS-ISAC on availably. The strategic approach for improvement is to assess the capabilities of this element across the whole of Montana government and identify where gaps exist and identify the right tools that can be leveraged to benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be proposed to help address those gaps. Best Practices and Methodologies All State and Local governments should adopt and incorporate best practices and methodologies to enhance cybersecurity. The following cybersecurity best practices must be included: These are not required to be implemented immediately, but all cybersecurity plans must clearly articulate efforts to implement these best practices across the eligible entity within a reasonable timeline. Individual projects that assist SLTT entities adopt these best practices should also be prioritized. Montana is adopting the following cybersecurity best practices: Implement multi -factor authentication (MFA) - While used for state agencies, this is not fully implemented for Local Governments or K-12 school districts. Implement enhanced logging - Montana captures various log sources such as authentication logs, device logs, network logs and firewall logs. Enhanced logging is enabled through our XDR solution. Data encryption for data at rest and in transit - This is a state standard for encryption for agencies and a potential opportunity for Local Governments or K-12 school districts. End use of unsupported/end of life software and hardware that are accessible from the Internet - This is an area of needed improvement, and we would like to use future funds from IIJA to address this issue. Prohibit use of known/fixed/clefault passwords and credentials - State agencies have adopted this best practice, but Local Governments or K-12 school districts have much work in this area to achieve compliance. Page 11 State of Montana Cybersecurity Plan 2022-2024 Ensure the a bi I ity to reconstitute systems (backups) -This is another area that we would I ike to use future years IIJA funds to improve our Local Governments or K-12 school districts. Migration to the gov internet domain -While this process is ongoing there is more work to be done here for the Local Governments or K-12 school districts. The strategic approach for improving this element is to assess the capabilities of this element across the whole of Montana government and identify where gaps exist. Through collaboration with the members of the Committee, projects will be proposed to help address those gaps. NIST Principles Montana has adopted a cybersecurity framework that was developed from the NIST cybersecurity framework (CSF). The Montana cybersecurity framework specifically applies to Montana State Information Technology Services Division (SITSD) and the information assets under its control. Supply Chain Risk Management Montana Information Technology's Governance, Risk, and Compliance team uses the risk management framework and is investigating using StateRamp to help address supply chain risk. Tools and Tactics The State of Montana's SITSD cyber team actively engages the Montana Analysis and Technical Information Center (MATIC), MS-ISAC, CISA, FBI and other government and industry partners to share knowledge of adversary tools and tactics. The strategic approach for improvement is to assess the capabilities of this element across the whole of Montana government and identify where gaps exist and identify the right tools that can be leveraged to benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be proposed to help address those gaps. Safe Online Services For Organizations eligible to receive funds under the SLCGP who have not previously migrated to the gov domain, one of the projects under consideration is a managed service to assist with this migration. Montana is promoting the gov domains to all our city, county, school and other partners. We believe there are many benefits and are encouraging this move in the following ways: State of Montana's Chief Information Security Officer (CISO) promotion of gov domain and benefits at numerous conferences and presentations each year Cannot be spoofed Available at no cost Helps the public quickly identify Local Governments as a trusted government website Signed up multiple entities for this migration Assisted several counties through CISA to get moved to gov domain Page 12 State of Montana Cybersecurity Plan 2022-2024 Continuity of Operations State and Local Government entities should develop, implement, test, and maintain contingency plans to ensure continuity of operations for all information systems that deliver or support essential or critical functions. Contingency planning is an important aspect of risk management. Ensuring availability for critical and essential systems and components allows agencies to meet its mandates that are dictated by statute, executive order, policy, or contract, and to ensure delivery of vital government services. The State of Montana reviews the Continuity of Operations Plan (COOP) at least annually to align with shifting industry trends, such as remote workforce and updated technologies. Communication is a cornerstone of any continuity of operation plan. We believe that plans are of little value if not tested. The State of Montana COOP includes the following: 1. Mission essential functions and business essential functions, 2. Alternate site determination to permit the storage and retrieval of information system backup information, along with establishing alternate telecommunications services to permit the resumption of essential missions and business functions within a defined period when primary telecommunications capabilities are unavailable. 3. Disaster recovery tests are conducted semi-annually 4. Tabletop exercises are conducted throughout the year with key State and non -State stakeholders through public -private partnerships. Lessons learned are documented and may require updates to the plan. Incident response plans and procedures are also validated during these exercises to ensure core security incident response team, responsibilities, incident reporting, escalation matrix, and notification procedures are current. Cloud -hosted solutions undergo a third -party risk assessment, which includes a thorough review of vendor service level agreements (SLAs), disaster recovery tests, and business continuity plans. Availability is agreed upon in contractual language. Vendor incidents impacting availability of systems is formally tracked to ensure agreed -upon SLAs are met. The strategic approach for improvement is to assess the capabilities of this element across the whole of Montana government and identify where gaps exist and identify the right tools that can be leveraged to benefit State, Local and K-12. Through collaboration with the members of the Committee, projects will be proposed to help address those gaps. Workforce State and Local Government Entities should develop cybersecurity workforce retention and recruiting policies to compete in a high demand/ low supply cybersecurity workforce job market. Askillecland diverse cybersecurity workforce is key to protecting Montana businesses and citizens from global threats. Montana has modified its job requests to better match skills. Employees have a training program that has both technical and non -technical training. Montana also works to take a whole of state training plan working through a phishing and cyber awareness training and testing to assist in sending training to state entities and Local Governments or K- 12 school districts to promote knowledge of all employees to be cyber smart and have the knowledge and information to understand how and what they should do when reacting to an event. Montana also works through cybersecurity.mt.gov, Cyber406.org, CyberMontana.org websites to share trainings, security information, and other information to state citizens and employees alike. Every year the Page 13 State of Montana Cybersecurity Plan 2022-2024 website is updated to have links and information for National Cyber Security Awareness Month to highlight that year's key action steps and insights. Continuity of Communications and Data Networks State of Montana participates in an annual tabletop exercise with scenarios involving multiple industry sectors that include both State and Private entities. The tabletop exercise encourages continuity plans that extend beyond a single entity and to include items like alternative communication networks for major disasters. State of Montana Continuity of Operations Plan contains these key elements: 1. Contact information for key stakeholders. 2. Mission Essential Functions: a. Provide IT hosting, network connectivity, telephone service, and online security to government entities. b. Provide software development services to government entities. c. Provide project management services to government entities. d. Provide records management services to government entities. e. Provide data center environment for state agencies. 3. Disaster Recovery Tiers defining recovery goals. 4. Incident response plan that addresses: a. Core security incident response team. b. Role's matrix identifying those responsible, accountable, consulted, and informed on incident response tasks. c. Incident reporting by staff or incidents detected and staff alerted by tools. d. Federal and State notifications. e. Continuous Improvement. Assess and Mitigate 'C"ybersecurity Risks and Threats to Critical Infrastructure and Key Resources The approach to assess and mitigate cybersecurity risks and threats to critical infrastructure and key resources is to partner with various State and Local Government Entities to ensure that critical infrastructure and key resources across the state is identified and assessed. Any available training through the training investment as well as open -source training will be promoted and made available. The state has made progress over the last few years including whole of government approach, new firewalls and edge devices, unification of state government, deployment of vulnerability analysis, increased deployment of XDR and cross functional teams to address high risk and emerging threats. A cyber risk management team helps to mitigate risks proactively by: 1. Implementing a third -party risk management program, which provides due diligence assessments of vendor security controls to ensure State citizen data is safeguarded. Page 14 State of Montana Cybersecurity Plan 2022-2024 2. Implementing NIST 800-37r2 Risk Management Framework for new systems, ensuring risk is assessed throughout the system development life cycle. 3. Creating internal audit functions to continuously monitor security controls and ensure control effectiveness. Cyber Threat Indicator Information Sharing The State of Montana Fusion Center (the MATIC) is the central information sharing hub for the state. The Montana Information Security Advisory Council is a public/private collaborative group that shares information and best practices. Montana participates and shares indicators and threat information with instate partners. This information is used to bolster defenses and distribute information within Montana for the protection of the network and endpoints. Montana CISO Office holds a weeklythreat brief with all state and federal partners. We also work with CISA to understand threats and communicate what is allowable to our partners throughout the state. Leverage CISA Services The State of Montana and its various entities and committees utilizes services from CISA to assess and enhance their cybersecurity posture. The State encourages all State and Local Government Entities to utilize CISA and IVIS-ISAC free and low-cost services first, then build upon with additional layers of security. Montana fully appreciates the help and support from CISA. Information provided through CISA is used to help bolster our defenses in preemptive blocking while also being used to help guide threat hunting, threat intelligence, and threat sharing throughout the state of Montana. Information from CISA is ingested through a multitude of ways from automatic playbooks, threat intelligence team and more. As a condition of receiving SLCGP funding, the grant recipients will sign up for and maintain CISA's no cost Vulnerability Scanning(CyHy) and Web Application Scanning services as well as complete annually the no cost Nationwide Cybersecurity Review (NCSR) assessment administered by MS-ISAC. The NCSR is open to complete in October through late February, check with IVIS-ISAC on availably. Information Technology and Operational Technology Modernization Review Montana's SITSD team uses a project intake process to evaluate all new projects and their impact to informational and operational technology. During this review process, the project management, customer success, architects, and the security team are consulted before projects are initiated. Major projects receiving approval to proceed follow the NIST 800-37r2 Risk Management Framework process to ensure all aspects of risk, security, architectural review, and business are aligned, addressed, and assessed. Cybersecurity Risk and Threat Strategies The State of Montana Fusion Center (the MATIC) is the central information sharing hub for the state. State of Montana conducts Cyber Assessments in coordination with all State of Montana entities. Based off the NIST, Cybersecurity Framework and the Nationwide Cybersecurity Review (NCSR) these questions assess each entity equally providing consistent insight into the entity and the State of Montana's overall cyber security posture. Assessment results are analyzed, and areas of common concern are identified in order to prioritize strategic efforts for making statewide improvements to network security. Page 15 State of Montana Cybersecurity Plan 2022-2024 Rural Communities Because of the services provided approach to this plan, the Committee can ensure that all licenses and services are tracked and managed to make sure that rural areas are represented in the services provided and meet or exceed the 25% minimum. More than 80% of Montana Counties are rural areas. With such a large makeup, rural communities are the core recipients of state cyber security tools and services. Rural communities also have representation on the Committee. Page 16 State of Montana Cybersecurity Plan 2022-2024 FUNDING &SERVICES The Committee intends to focus on 8 key efforts to strengthen cybersecurity across the State. These efforts include the goals and objectives section above and are detailed in Appendix B: Project Summary Worksheet. Sustainable funding is required to ensure that projects enabled by grant funding can continue to be successful. Funding sources can include local, state and federal organizations. Distribution to Local Governments To ensure 80% of the SLCGP funds are distributed to local units of government, it is the intent of the committee to have the Montana Department of Administration or the MT SLCGP State Administrative Agency (SAA), contract for services directly on behalf of local units of government with their consent. The SAA may issue direct subawards to local units of government based on the applications received and project prioritization by the committee. The SAA will ensure that 25% of the funds are directed to rural communities or utilized with their consent. All project applications must align with the projects listed in Appendix B. As a condition of receiving SLCGP funding, the grant recipients will sign up for and maintain CISA's no cost Vulnerability Scanning(CyHy) and Web Application Scanning services as well as complete annually the no cost Nationwide Cybersecurity Review (NCSR) assessment administered by MS-ISAC. The NCSR is open to complete in October through late February, check with MS-ISAC on availably. Page 17 State of Montana Cybersecurity Plan 2022-2024 ASISESS CAPABILITIES Montana's strategic approach will be to use the Nationwide Cybersecurity Review (NCSR) for annual assessments. NSCR is a free service from IVIS-ISAC and the question set is built off the NIST Cybersecurity Framework. Additional council approved NIST based assessments such as CISAs CPGs, CRE, CRR, CIS Controls, and various Vulnerability assessments will also be used as supplemental assessments to help further determine security current security posture. Page 18 State of Montana Cybersecurity Plan 2022-2024 IMPLEMENTATION PLAN Organization, Roles and Responsibilities The State Chief Information Officer is responsible for managing and protecting the State network. The State Chief Information Security Officer is responsible for advising and overseeing security strategy for Executive Branch agencies without elected off ici a Is; for advising and consulting security strategy for Executive Branch agencies with elected officials and the Judicial and Legislative Branches; and for advising security strategy for all other local and municipal governments in the state. Both the State CIO and the State CISO are members of the Montana Information Security Advisory Council (MT-ISAC). The Montana Disaster and Emergency Services (MTDES) serves as the SAA for the State. The MTDES will manage and administer the financial and programmatic responsibilities of the program, whereas State CIO and the State CISO will serve in the role as project manager responsible for the Committee and their assigned roles and responsibilities under the approved committee charter and per the SLCGP requirements. Resource Overview and Timeline Summary The following information is provided to meet the requirement in the State and Local Cybersecurity Improvement Act: e.2.E. This information represents the best estimation based on current reference material. It is subject to revision over time. When funding is approved, the first step is to develop a project plan. The project plan will be managed by State CIO and State CISO, MTDES, and the IIJA committee members. Project plan will outline scope, time and cost. The objective is to allocate and use funds within the allotted time provided via IIJA specifications. Depending on availability of resources, funding could be utilized over multiple years, not to exceed the guideline within the IIJA specifications. The guidelines will follow the item below: People - funding to be approved to hire appropriate contract staff to help the State & Local Governments and K-12 school districts implement projects agreed upon per year one. Process - MTDES will set up a process to allow State & Local Governments and K-12 school districts to request funding for the committee approved projects to be implemented in their areas. The funding amounts requested via projects will be voted on to be approved by the committee. Technology - Decision for technologies will be based on the decision by the committee. It is the intent of the committee to have the Montana Department of Administration or the MT SLCGP State Administrative Agency (SAA), contract for services directly on behalf of local units of government to aggregate requests and purchase in bulk for cost advantage. Upon approval of the Plan and distribution of the funds, the key initiatives will begin. Page 19 State of Montana Cybersecurity Plan 2022-2024 METRICS The below table should reflect the goals and objectives the Committee establishes. State of Montana - Cybersecurity Program Metrics Program Program Sub -Objectives Associated Metrics Metric Description Objectives (details, source, frequency) 1. Asset 1.1 Leverage the Montana # of Workgroup meetings Reports from State CISO Management Information Security office, MT-ISAC quarterly Advisory Council (MT-ISAC) # of apprenticeships and to create a workgroup internships CSF ID.AM-6 focused on increased cybersecurity # of entities using either apprenticeships and apprenticeships and internships opportunities in internships based off of Montana (CSF ID.AM-6) program 2. Governance 1.2 Leverage MT-ISAC for # of meetings Reports from State CISO monthly sharing of cyber office, MT-ISAC quarterly threat information and # in attendance industry best practices to all CSF ID.GV-4 Montana's Governments, # of individual entities Critical Infrastructure, and Small Businesses (CSF ID.GV-4) 3. Risk 1.3 Leverage MT-ISAC and - Completion of Reports from State CISO Management industry best practices to standardization of Risk office, MT-ISAC quarterly Strategy support and standardize on Assessment and guidance NCSR as annual risk CSF ID.RM-1 assessment. Additionally % of State Agencies, providing support for 3rd Counties, Cities, K-12 that Critical, High, Moderate, Low party on site standardized have taken NCSR gaps identified from annual assessments as MT-ISAC assessments. Source: determines per timeline - Gap numbers from annual NCSR, CISA Assessments determined. (CSF ID.RM-1) Risk Assessment guidance (CPGs/CRE), CIS Controls or other approved by the 1.4 Deliver support for # of State Agencies, Committee. Annual State and Local Counties, Cities, K-12 that governments and K-12 to have taken 3rd Party Risk move to GOV domain for Assessments email and websites (CSF ID.RM-1) # of SLTT to move to GOV 1.5 Leverage MT-ISAC and % of State Agencies, industry best practices to Counties, Cities, on.GOV create a standard naming -Completion of Standard convention for government naming convention for MT entities moving to GOV (CSF SLTT entities moving to GOV ID.RM-1) Page 20 State of Montana Cybersecurity Plan 2022-2024 4. Identity Management, 2.1 Leverage MT-ISAC to - Completion of guideline or Reports from State CISO Authentication create a guideline or industry best practice office, MT-ISAC quarterly and Access reference an established referenced on publicly CSF Controls PR.AC-1 & 5 & Control industry best practice on accessible site on MFA. 7 Multifactor Authentication % of State Agencies, with options to use current Counties, Cities, K-12 using CIS Controls 4.7 & 6.3 & 6.4 state services and M FA for remote access & 6.5 & 12.2 contracts. Create an statewide action plan for % of State Agencies, Annual assessments. funding improving the use. Counties, Cities, K-12 using Source: NCSR, CISA (CSF PR.AC-7, CIS Control MFA for accessing critical Assessments (CPGs/CRE), 6.3, 6.4, 6.5) systems CIS Controls or other 2.2 Deliver solutions to # of reviews of network for approved by the Committee. Local Governments and K- proper segmentation with Annual 12 to help protect network documented guidance with integrity with proper network roadmap to address segmentation (CSF PR.AC-5, CIS Control 12.2) - Completion of guideline or 2.3 Leverage MT-ISAC to industry best practice create a guideline or referenced on publicly reference an established accessible site on industry best practice on prohibiting use of prohibiting use of known/fixed/clefault known/fixed/ default passwords and credentials. passwords and credentials with options to use current state services and contracts (CSF PR.AC-1, CIS Control 4.7) 5. Awareness and Training 2.4 Deliver basic end user # of State Agencies, Reports from State CISO security awareness training Counties, Cities, K-12 taking office, MT-ISAC quarterly for Montana State & Local annual security awareness CSF PR-AT-1 & 2 governments and K-12 (CSF training PR-AT-1, CIS Control 14) % of State Agencies, CIS Control 14 2.5 Deliver cyber education Counties, Cities, K-12 users to privileged users and fully completing annual cyber professionals within security awareness training Montana State & Local # of State Agencies, governments and K- F Counties, Cities, K-12 users PR-AT-2, CIS Control 14.9) taking cyber education 2.6 Deliver access for # of State Agencies, Montana State & Local Counties, Cities, K-12 users governments and K-12 using cyber ranges for privileged users and cyber learning how to better professionals to cyber defend their networks ranges (CSF PR-AT-2' CIS Control 14.9) Page 21 State of Montana Cybersecurity Plan 2022-2024 6. Data Security 2.7 Leverage IMT-ISAC to create a guideline or reference an established industry best practice on encryption for data at . rest and in transit with options to use current state services and contracts. Create a statewide action plan for funding improving the use. (CSF PR.DS-1 & 2, CIS Control 3.6 & 3.9 & 3.10 & 3.11) - Completion of guideline or industry best practice referenced on encryption for data at rest and in transit. # of State Agencies, Counties, Cities, K-12 using fully using encryption at desktop # of State Agencies, Counties, Cities, K-12 using fully using encryption at serverlevel Reports from State CISO office, IMT-ISAC quarterly CSF PR-DS-1 & 2 CIS Control 3.6 & 3.9 & 3.10 & 3.11 Annual assessments and reports. Source: NCSR, CISA Assessments (CPGs/CRE), CIS Controls or other approved by the Committee. Annual 7. Information Protection 2.8 Leverage IMT-ISAC to - Completion of guideline or Reports from State CISO Processes and create a guideline or industry best practice office, IMT-ISAC quarterly Procedures reference an established referenced on limiting use of CSF PR-IP-2 & 4 industry best practice on unsupported/end of life limiting use of software and hardware. CIS Control 11 & 12.1 & unsupported/end of life - Completion of guideline or 13.5 & 16.5 (EOL) software and industry best practice hardware and ending the referenced on backup and use of EOL on systems that Annual assessments & are accessible from the recovery. Reports. Source: NCSR, internet with options to use # of State Agencies, CISA Assessments current state services and Counties, Cities, K-12 (CPGs/CRE/Vuln Scans), CIS contracts. (CSF PR-IP-2, CIS having off line, encrypted Controls or other approved Control 12.1 & 13.5 & 16.5) backups of critical data bythe Committee. Annual 2.9 Leverage IMT-ISAC to % of State Agencies, create a guideline or Counties, Cities, K-12 reference an established having off line, encrypted industry best practice on backups of critical data backup and recovery with # of State Agencies, options to use current state Counties, Cities, K-12 using services and contracts. CISA Vulnerability Scanning Create a statewide action Service plan for funding improving the use. (CSF PR-IP-4, CIS % of State Agencies, Control 11) Counties, Cities, K-12 using CISA Vulnerability scanning service Page 22 State of Montana Cybersecurity Plan 2022-2024 8. Protective Technology 2.10 Leverage MT-ISAC to create a guideline or reference an established industry best practice on audit/log records with options to use current state services and contracts. Create an statewide action plan for funding improving the use. (CSF PRYT-1, CIS Control 8) - Completion of guideline or industry best practice referenced on audit/log records. # of State Agencies, Counties, Cities, K-12 using centralized logging server or SIEM tool % of State Agencies, Counties, Cities, K-12 usin 9 centralized logging server or SIEM tool Reports from State CISO office, MT-ISAC quarterly CSF PR.PT-1 CIS Control 8 Annual assessments. Source: NCSR, CISA Assessments (CPGs/CRE), CIS Controls or other approved by the Committee. Annual 9. Anomalies and 3.1 Deliver Network # of State Agencies, Reports from State CISO Events Monitoring and Counties, Cities, K-12 using office, MT-ISAC quarterly Management Intrusion MS-ISAC Albert Sensor or CSF DE.CM-1 & PR.AC-5 Detection Systems (IDS) like service (determined by solutions for County State CISO Office) CIS Control 9.2 & 13.3 Governments for additional % of State Agencies, Annual assessments and layer of alerting and visibility Counties, Cities, K-12 using reports. Source: NCSR, CISA for Election Offices, Albert Sensor or like service Assessments (CPGs/CRE), Emergency Services Offices, (cleterm i ned by State CISO CIS Controls or other and Public Water System Office) approved by the Committee. Municipalities. (CSF DE.CM- Annual 1, CIS Control 13.3) # of State Agencies, 3.2 Deliver support for Counties, Cities, K-12 using State & Local governments MS-1 . SAC MDBR or like and K-12 to utilize MS- service (determined by State ISAC's no cost Malicious CISO Off ice) Domain Blocking and % of State Agencies, Reporting (MDBR) service or Counties, Cities, K-12 using similar service (CSF DE.CM- MDBR or like service 1 & PR.AC-5, CIS Control (cleterm i ned by State CISO 9.2) Office) Page 23 State of Montana Cybersecurity Plan 2022-2024 10. Security Continuous 3.3 Deliver Endpoint # and % of State Agencies, Reports from State CISO Monitoring Detection and Response Counties, Cities, K-12 using office, MT-ISAC quarterly solution for Montana Local a EDR solution that is CSF DE.CM-4 & 8 Governments and K-12 (CSF approved by State CISO DE.CM-4, CIS Control 10) Office CIS Control 7.6 & 10 3.4 Deliver support for all # and % of State Agencies, Annual assessments & State & Local governments Counties, Cities, K-12 using reports. Source: NCSR, CISA and K-12 Schools Districts CISA Vulnerability Scanning Assessments public facing IPs to have Service (CPGs/CRE/Vulnerability external vulnerability # and % of State Agencies, Scanning), CIS Controls or scanning with weekly report Counties, Cities, K-12 other approved by the to entity. Create a conducting at a minimum Committee. Annual statewide action plan for monthly Internal improvingthe use. (CSF Vulnerability Scanning DE.CM-8, CIS Control 7.6) Service 3.5 Deliver support for identified State & Local governments and K-12 School Districts to have internal vulnerability scan. 11.Response Planning 4.1 Leverage MT-ISAC and - Completion of guideline or Reports from State CISO industry best practices to industry best practice office, MT-ISAC quarterly create a statewide incident referenced on incident CSF RS.RP1 & PR.IP-9 response reporting process response reporting (CSF RS.RP-1 & PR.IP-9, CIS # of State Agencies, CIS Control 17 Control 17) Counties, Cities, K-12 Annual assessments. reported possible cyber Source: NCSR, CISA incidents Assessments (CPGs/CRE), CIS Controls or other approved by the Committee. Annual 12. Recovery Planning 5.1 Leverage MT-ISAC and # of State Agencies, Reports from State CISO industry best practices by Counties, Cities, K-12 office, MT-ISAC quarterly delivering training, attending workshops or CSF RC.RP1 & PR.IP-1O workshops, exercises on exercises on incident incident response and response and recovery CIS Control 17 recovery planning (CSF planning Annual assessments, RC.RP-1 & PR.IP-10, CIS % of State Agencies, Reports. Source: NCSR, Control 17) Counties, Cities, K-12 CISA Assessments attending workshops or (CPGs/CRE/Exercises), CIS exercises on incident Controls or other approved response and recovery bythe Committee. Annual planning Page 24 1�— z LLI LLI (f) U) LLI a. z 5 a. LLI (f) it LLI LLI -i a. x a z LLI a. a. 0 0 LL Cd C6 (Yi wmr- C4 C4 70 _0 70 70 70 52:, (N 11 C) ('4 CO 70 (o C) c 0 a) �L -3) 70 cl, co cl, 2 E CO 0 Cc E 0 Cc: 06 .2 +� > m 70 .2 +1 C�� m > 70 > o6 E 70 +, — C�� co a) .2 +� co co > -0 .F- 06 m > -0 CL 2 -d m E m — > -0 < 70 < — m < -0 -Fo 70 < — 70 < M 70 -0 m _0 C: C: Co C: C C) =3 C) 73 C) c C) 73 C) 73 C) :3 o = < 0 LL LL -i 0 L.L co 0 0 -i LL M 0 :3 -J LL CO 0 0 -J U- 0 0 -i U- co 0 0 -j L.L co U) U) U) E E E E E E m m m co co m 0 0 0 0 0 0 co (n m (n co (n m (n co (n co (n m (n a) (n D (n (n D (n D (n D > > > > > > -0 -0 -0 -0 -0 -0 co ,_.s CO CL M CL M CL C M CL M CL co E m co co E co co E C) " a) C) a) C) a) C) a) C) a) C) Cj a) -0 -0 -0 �< -0 -0 -0 co 0. a) 70 L -0 lu -0 a) -0 M -0 a) a) -0 -0 a) 70 a) m CL -0 -0 CL CL CL -0 CL C) co u m u cc u M u co u C, a) +� co -0 — aj CO -0 — (v co -0 aj -Fo -0 aj CO -0 (v -Fo -0 co C) 0 C) 0 C) 0 C) 0 C) 0 C) 0 -j co Ln -i co Ln -j co Ln -i co Ln -i co Ln -j co (Ii cc E (n +CO' cc a) 0 _0 w 0 -r- 0 0 >N +, CL 73 +, _0 -0 a) 0 co C) C: =3 o o '-73 N C: c -.r- CO (0 (1) (1) U) z 8 W 2 4- 0 C-) CL 0. C) +co c 0 .= C) o '-P C) C) c: (1) a) C) _0 a) _0 m C) co .2 E " a) o +� 0 C: m 47 C) ca +1 E w -o 0 in 4-- C: C) (o 4-- U) 0 a) - V C: co CL'- -0 4-- o C) o (n C) o E .2 0 CL �:, a " m 0 C) co C) a) c: co . D A) W a) +� E C: a) E LU E cc co _0 A) 0 C: C: 4-- -0 a) a) a) LU 6 .0 +� cc C'O = .F- C-) (n 0 0 0 0 C: co 0 -0 C) a) -a 'a co 0 CO E a) 0 E m 0 _0 4 0 co co 'a -0 -a a) -0 - +a,) 0 cc 2 +t CL m m a) E >N -o C) -0 < E C) -0 0 LO LO N CL 0 0 (N 00 C6 Ld C4 -0 70 (14 -0 (N 70 N cq cq (N N _0 N a) .2 E .2 E .2 E .2 E E ac) E ac) E ac) E 06 (o 8 .6 'm .6 .6 .6 E .6 E .6 E .6 E �o E 06 _0 70 -0 -0 -Fo _0 -Fo -Fo -Fo -Fo C: -Fo m C: _0 _0 70 76 70 76 70 c: LL 0 n 0 n 0 n 0 D 0 C 0 C 0 C 0 C 0 C: C) :3 0 0 0 0 0 0 0 0 0 73 0 :3 0 n 0 n 0 73 0 0 LL LL LL LL LL LL LL LL LL LL U) 6 6 6 6 6 6 6 6 6 6 E E E E E E E E E E Ln T Ln .(n 0 C: 0 C: 0 0 C: 0 C: 0 C: 0 0 0 0 C: E E E E E E E E E E a) 22 22 22 D L D L D L D L D L D L > > > > > > > > > -0 -0 -0 -0 -0 -0 -0 -0 -0 -0 CL CL CL CL CL CL CL CL CL CL m m m m m m m m E m m E C) +2 C) +2 C) (N +2 C) N +2 C) N +2 C) N C) (N C) Cj C) 0 " CA -0 -0 -0 -0 _0 -0 -0 -0 -0 70 -0-0 -0-0 -0 -0 -0 -0-0 -0-0 -0.0 CL c CL c CL C: CL C: -0 CL C: -0 CL C: -0 CL C: CL C: .0 CL C: CL c u u u -Fo u u -Fo u u u u u a) -0 m -0 a) -0 (v m -0 a) -0 0) 7-0 -0 a) M _0 0) 70- -0 a) M -0 0) 70--0 C) 0 C) 0 c: C) 0 c: C) 0 c: C) 0 C) 0 c: 0 0 C) 0 c: C) 0 C) 0 c: —i Ln -j m 0 0 +� 0 0 c -) (n .-0 +, 0 -F- o 0 0 0 0 C) 70 (n m 0 0 0 CL C: 0 73 > 72 E C) _0 0 m E 0 > 0 m 0 (n 3: a) 0 0 0 0 0 3: E a) .4 -0 0 CL = CL 0 +� a > 0 (n 0 E 0 -0 C: -0 (n CL (n 0 4-- 0 8 q w 75 E -J 70 c 4-- 0 2 .2 +� M 0 -0 m 0 > 70 C: 0 73 >, 70 (0 a) C: M " — C: LL 0 0 C) :3 +, :3 -0 a) m 0 C: -- C: _0 +1 C: 0 -0 3: 0 0 0 0 0 73 -?5 -0 m 0 C) 3: 0 0 C-) E 3: > E Z cc)) 4 'E- 0 75 E zi _0 t� c- 0 + 5 32 a) > " c) (n a) C: (:n3 Z 2 E -0 C: o -0 C: -0 1E c 0 70 (n (n 0 _0 _0 (n m 1E 3: -0 oc a) (n E (0 � 0 0 w m 0 a) o c E o 'o C-) 2 2 c C: 0 _0 0 0 C: LG LD 2 a) m C 0 -0 a) c (n a) -0 m Lu m 0- �:c m LU (n w E o 73 73 '-P :3 +, a) C: a) -0 (n a) C) C) -0 0 0 W 0 L) -0 a) C: 0 _0 a) s uj .'s C) -0 m 2 L) uj m _0 < 70 m 0 6 C6 6 1 (0 CL 0 0 (N 00 m r_� m (N C4 70 70 a) Q) c: E c: E .2 .2 E 2 (0 �< .2 (0 -0 LE5 �5 06 (0 _0 06 (0 _0 70 06 (0 C: -0 06 72 0 E E (0 C: 0 73 7 70- C: c) D 73 (0 C: LL 0 n , 76 c: LL 0 73 0 0 LL 0 0 LL 0 0 a) LL 0 0 LL U) U) U) U) E E '-P E E E '-P E -r- In +� -r- In +� .In 0 0 0 0 0 0 a) a) D L D L D > > > > 0 c c 0 Cj -0 -0 -0 -0 -0 -0 -0-0 -0-0 -0-0 -0 CL CL CL CL CL CL -0 m u m u m u m u m u cu u a) -0 0) _0 a) -0 0) m _0 a) -Fo 0) 70- 3: -0 C) 0 0 C) 0 0 c: 0 0 C) 0 c: 0 0 73 (n A) o a) 4 0 a) 0 E 0 0 0 .2 m a) (n 0 0 73 C-) c a) _0 (n E" 0 0 +0, t2 ui a) E 0 0-5 73 , 0 a) > a) _0 E a) CL C) CL o a) -0 0 E :t� -F, C) E c) 0 (n :F 0 0 -0 0 0 a) 0 C-) -0 C) C) C) C) q: .0 '0 > m .F- 0 -C 3 0 -0 0 D a) c LD (1) CL .2 a) c co 0 E ((nn a) --r- -�: o (n 1) m m +' C: E E E 0 (0 M E a) a) 0 a) a) a) m +C' _0 E a) 0 8 8 -.r- = 2 4 C: > 8 -0 C) +, c: 0 0 a) 0. a>) I �o C: -0 + CL > E S Uc , J T, . S a) Q) o -j E IF — m E L -a o o >1 m C) ui m . C: (o 0 6 L6 Cd CL 0 0 (N 1�— LLI LLI 0 LLI 0 it a. x in z LLI a. a. 0 0 > 0 (f) �7- 0 C-) C) �7- �7- > 0 0 00 r- N E C: :3 co 6 co �-p U a_ 0 E 0 'r- :29 :29 L) CL E u LL Z C) 0 -0 0 0 0 0 E 41 w L6 a) N 0 L6 (N -0 0 :3 0 -0 00 i LO u E LO ir it cu E� Mn 0 0' (n 0 0) x LU 0 0- 0 cu 0 LU 0 07 LU c 0 0 N .0 0 07 0) — !E cu 0 0 = +� C) Q C-) +� cu 0 m E am 0 a) cu (n CS Q- z in Lu U) Q- Q- cc (,4 z I -A N m LO (D r-_ w r- t E, :3 F= 0 Z3 Z3 Z3 Z3 Z3 Z3 Z3 Z3 U 0 0 0 0 0 0 0 0 E L) li CL _0 _0 _0 a) (h E (0 -r- 0 (0 (1) 0 C: 'QO (1) (D E > (1) < 0 > _E E 0) o d: E D) C) E 0 " W C) (i) E o ,f (1) 5 (1) -r- 0 E x 0 -c- 0 w -0 0 0) CL (D E (1) a 0 a) 0 w 70 a) = 0 75 f� t: 0 -r- (D FL 01— FL Q 3: CL u) — u) c: -0 0 = c 0 E -0 m -0 Z- 0 0 (D J) 0 > o — 0 E -o Z E 2 (No 20 Q) )u 0 (1) c co 2 0 E 0 -o 3: c: -Z- CL,- — z, 'E 0 0 :p 0- - 3: — c: a) 70 tf m D) 0 -0 -2:' (1) E �c :01 a) (1) C 0 x (j) D) _r :3 -SE (1) u) _C (D (1) (1) -r- — 1 (1) E 2 (1) — — (1) (0 z 0 u) 0 c: a) c: -0 0 (1) u) (D -0 0 :3 > 0 a C (1) 0 (,) _0 E� 75 (a')) E (D 0 (D 0 (D (1) > -0 > -0 z- M w Z- -0 -a 0 d > < > > E -o (D-0 (1) (D -E :3 (1) 2 75 -L- -:0' 0 2 q 0 c (D --r- -0 0- 0- CL �- u) E EL.S� S� ui 0 a- 0 Q (D CU C-) 0 U) > (1) — "F- (1) cu , — 0 CU -0 F- >, (-) (f) (3) — (n Q- +(f,) cu li CA 00 It N 0 N N 0 N 021 a) a) a) E E LU 0 o LU LU E E E E 2 2 a) a) a) a) a) E M: 2 2 2 2 P.O :3 :3 :3 :3 LL 0 LL LL- LL LL C: C14 C: C14 0 C) 0 C) co _0 m o _0 m o _0 m 0 -0 m 0 M -0 m C: o m 0 co 0 0 C14 C) C) 04 04 L6 L m .2 &.2 o co o &.2 LO L C) m 4 Z- 6 6 It t� 6 6 o LO C,4 64 L6 C, 6 C, 04 It -t:� C14 _0 C14 _0 0 (D U -0 'I, L,- -0 -a �o (D _0 _0 C14 Z, C14 Co 04 -a I-i _0 C14 L Z, 70 Lo L CL, Z, '0 LO tri -0 co >1 tri -0 co Q)- L -0 co >1 tri -0 co >1 L m 7cou >1 Q�, L 2, 7cou a>), 0 It (D -Ob 00 LO 00 (6 (Ii C) < m 0 0 0 �F) a) cn m -Fa —. C) 0 Co 0 cf) a) C: o Co 0 0 3: a) A- 4t: 0 _0 o w c w a) 0 C: — A_- 0 'Z, E w -0 Co a) .- — Co a a -t -F, w M 0 co W W -0 C: >1 C,4 H w E :3 W 0 a. (p C,4 -z- E cn w OL o co a) -a �w T — E w.2 0 > c 0 Co C: M 0 C: 0 Q -0 -a -.a co w a) ±_2 — co w LL > " w o :3 co W 0 - " a) 3: w OL co , co a) C: -i o 2 C: a) 0 " w " W 0 C) " 6 co co Cl w w C 0 >, 0 co — — a) > .- co w (n w o co C: — '.; 61-- co — 0 3: r- < cl cn 0 >, >1 0 " �F) �C: C: > C: o w W > E o a) E co w co cf) co C,4 -i cn — 0 a) a) a) cf) a) C) WC: Co/) C: Q CIL 0 CIL 0 (� >, Co > u) o 0 cf) >, (1) a) C) OL u) C—: 55 On) co :3 Q .2 -a (1) .2 0 co > LLJ " C.) C: C) W Co > 0 0 2 C: :—t o (1) -Fa M W M a) Co o �F) -2 E '2 -0 0 Co 0 0 Cl — o 2 -50, cu 2 OL w C) -0 0 .2 p > Co .2 in E . O-L 'w 0 a) W 0 OL c > o > OL 2 2 OL Cl C: :3 Cl I Cl W :3 Co :3 Co 0 - 0 1- -a 'E c m > E 70 E (1) (1) E 42 (1) C: -0 (1) (n -i -0 (1) co Q) 0 z , co co 2 co Q) co C.) u) 0 70 70 .2 Q) (1) -Z, co (1) 70 co o , -L) (1) 0 w E OXL 78 .2 (1) 0 W M W co > > CIL 0 0 E > 2 > -a C.) Q 2 co > = CIL C: 0 (1) 0 > 2 t! 0 2 2 w 20 cn co -0 a) a. E L a. - a) 0- L 2 a Ej cn > > > C: 4- 0 0 -0 0 -0 0 4- C: L 4-- (1) E- 0 -F- +, 0 c 0 w (D 0 C: - — — (1) 4- 4- 0 0 W.— 0 M M 4-- (f) > 0 C-) 0 4- (1) (1) (11 0-+, 3: E )—ao FZ 0 > — — 1- -0 0 4- o (o 4- (f) 0 (1) 0 (1) C: 0 co G 3: U) �: do Lu 0- z 12 U) (Y) I* LO (0 r- OD 0') CA M a_ ATTACHMENT B Montana Cybersecurity Planning Committee Charter U-1-1 STATE OF MONTANA STATE AND LOCAL CYBERSECURITY GRANT PROGRAM MONTANA CYBERSECURITY PLANNING COMMITTEE CHARTER State of Montana Cybersecurity Planning Committee Charter Record of Change DATE DESCRIPTION OF CHANGE INITIALS 2022.11.07 Initial Version — Draft BSH 2022.11.09 Formatting updates — Draft AMH 2022.11.10 Final Review Update MT -CPC Record of Distribution DATE RECEIVING PARTNER AGENCY/ ORGANIZATION 2022.11.10 MT -CPC members & delegates Table of Contents Recordof Change .......................................................................................................................................... 2 Recordof Distribution ................................................................................................................................... 2 Tableof Contents .......................................................................................................................................... 2 MT -CPC Charter ............................................................................................................................................ 3 1. Official Designation ........................................................................................................................... 3 2. Authority ........................................................................................................................................... 3 3. Purpose and Scope of Activities ........................................................................................................ 3 4. Description of Duties ........................................................................................................................ 3 5. Committee Membership ................................................................................................................... 4 6. Committee Chairs ............................................................................................................................. 4 7. Meetings and Procedures ................................................................................................................. 5 8. Subcommittees ................................................................................................................................. 5 9. Recordation ....................................................................................................................................... 5 10. Amendment of Charter ................................................................................................................. 5 Appendix A —Committee Membership ........................................................................................................ 6 2022.11.10 *** FINAL *** Page 2 State of Montana Cybersecurity Planning Committee Charter MT -CPC Charter 1. Official Designation Montana Cybersecurity Planning Committee (MT -CPC) 2. Authority Pursuant to the statute authorizing the State and Local Cybersecurity Planning Grant Program (SLCGP), Section 2220A of the Homeland Security Act of 2002, as amended (Pub. L. No 107-296) (6 U.S.C. § 665g) and appropriated by the Infrastructure Investments and Jobs Appropriations Act (IIJA) (Pub. L. No. 117-58), requiring the State Administrative Agency (SAA) to establish a Cybersecurity Planning Committee. The State Administrative Agency for Montana is the Disaster and Emergency Services Division (MT DES). 3. Purpose and Scope of Activities The purpose of the MT -CPC is to conduct the following activities in support of the SLCGP requirements: • Assist with the development, implementation, and revision of the Cybersecurity Plan of the eligible entity • Formally approve the Cybersecurity Plan in coordination with the Chief Information Officer (CIO) and or State Chief Information Security Officer (CISO) 0 Assist with the determination of effective funding priorities for a grant The MT -CPC shall take a whole -of -state approach focusing on the priorities and objectives in the SLCGP Notice of Funding Opportunity (NOFO). The MT -CPC will leverage other governing bodies for expertise and guidance as applicable. The overall goal of the plan, and the projects that are funded, is to improve the cybersecurity of resources and services in Montana. 4. Description of Duties MT -CPC: The primary duties of the committee are to assist Montana's Chief Information Officer and Chief Information Security Officer to develop a Statewide Cybersecurity Plan and supporting projects that meet the objectives documented in the plan. State Information Technology Services Division (SITSD): The CIO or CISO serving as MT -CPC Chair conduct meetings, approve the final plan for submission, work with the committee on executing the priority projects within the plan, coordinating with the SAA for grant management and administration. MT DES: oversight of all grant management administrative activities including but not limited to application submission, subrecipient monitoring, and closeout. Ensuring all grant activities 2022.11.10 *** FINAL' Page 3 State of Montana Cybersecurity Planning Committee Charter performed by the committee comply with the requirements set forth in the SLCGP and relevant federal and state laws. 5. Committee Membership State and Local Cybersecurity Grant program outlines the following composition and membership requirements: • COMPOSITION. A committee of an eligible entity established under paragraph (1) shall — "(A) be comprised of representatives from "(i) the eligible entity; "(ii) if the eligible entity is a State, counties, cities, and towns within the jurisdiction of the eligible entity; and "(iii) institutions of public education and health within the jurisdiction of the eligible entity; and "(13) include, as appropriate, representatives of rural, suburban, and high -population jurisdictions. • CYBERSECURITY EXPERTISE. Not less than one-half of the representatives of a committee established under paragraph (1) shall have professional experience relating to cybersecurity or information technology. • RULE OF CONSTRUCTION REGARDING CONTROL OF INFORMATION SYSTEMS OF ELIGIBLE ENTITIES. Nothing in this subsection shall be construed to permit a cybersecurity planning committee of an eligible entity that meets the requirements of this subsection to make decisions relating to information systems owned or operated by, or on behalf of, the eligible entity. Members may be voting or non -voting advisory members. Members may provide a proxy from their organization if they are unable to attend. Designated alternates can vote in the absence of the primary member and should come from the same organization or organization type (City, County, Law Enforcement, Public Education, or Public Health) and with similar skillsets. See Appendix A for the complete membership list in compliance with requirements above. Subject matter experts may be invited to participate as non -voting members as requested. 6. Committee Chairs 0 The State CIO will serve as the Chair of the MT -CPC with the State CISO serving as the Vice Chair of the MT -CPC. The Vice Chair will assume the responsibilities of the Chair if the Chair is not present. The Chair is a voting member. The Vice Chair is only a voting member if the Chair is not present or if there is a tie vote. The Chair will review committee member composition and ensure it is aligned with the law and Notice of Funding Opportunity by appointing or replacing committee members. 2022.11.10 *** FINAL' Page 4 State of Montana Cybersecurity Planning Committee Charter 7. Meetings and Procedures • The MT -CPC shall meet at a minimum quarterly or more frequently at the direction of the Chair to effectively carry out the required duties and responsibilities as set forth in this Charter. • IVIT-CPC meetings will not be open to the public nor recorded due to the sensitive nature of security controls and projects being discussed. • When practical, the time and place of the MT -CPC meetings will be communicated to members a minimum of two weeks prior to the meeting. Meeting agendas will be provided to members prior to the meeting. The committee will use a modified version of decision making based on Roberts Rules of Order. • A quorum is established with the Chair or the Vice Chair, and 50% of voting members or their delegates must be present. • For voting measures, a simple majority is 51% of present members or their delegates. 8. Subcommittees Subcommittees may be created as needed to support the MT -CPC. Subcommittees must be chaired by MT -CPC member who is appointed by the IVIT-CPC Chair. 9. Recordation Agenda, meeting notes, and results from all regular and special meetings will be summarized and approved by the voting members at the next regular meeting. Information about security controls, weaknesses, or other sensitive details will not be disclosed publicly. 10. Amendment of Charter This Charter may be amended by a simple majority vote of the IVIT-CPC after a proposed amendment has received one reading at a regular IVIT-CPC meeting. Each voting member has provided charter approval and agree to the terms of the charter. This charter is hereby enacted by the MT -CPC this 14th day of November 2022. Kevin Gilbertson, MIT CIO DATE IVIT-CPC Chair Andy Hanks, MIT CISO DATE IVIT-CPC Vice Chair 2022.11.10 *** FINAL' Page 5 State of Montana Cybersecurity Planning Committee Charter Appendix A —Committee Membershipi NAME ROLE ORGANIZATION & TITLE Kevin Gilbertson Chair Montana Department of Administration, State Information Technology Services Division (State Chief Information Officer) Montana Department of Administration, State Information Andy Hanks Vice Chair Technology Services Division (State Chief Information Security Officer) Montana Department of Military Affairs, Division of Emergency Burke Honzel Administrator Services (Bureau Chief) & State Administrative Agency (Point of Contact) Joe Frohlich Advisor Department of Homeland Security, Cybersecurity and Infrastructure Security Agency (Cyber Security Advisor) Anne Dormady Voting Montana Department of Justice, Division of Criminal Investigation Member (Crime Information Bureau Chief) Voting Montana Department of Military Affairs / National Guard Buel Dickson Member (Brigadier General, Assistant Adjutant General) Voting Elder Grove School District (Technology Director) & Montana Carol Phillips Member Educational Technologists Association (President) Eric Bryson Voting Montana Association of Counties (Executive Director) Member Erika Billiet Voting City of Kalispell (Information Technology Director) Member Jacob Voting Billings Clinic (Chief Information Security Officer) Hammersmith Member Jason Emery Voting Missoula County (Chief Information Officer) Member Jason Hecock Voting Kalispell Public Schools (Information Technology Director) Member Jody Faircloth Voting Partnership Health Center (Director of Infrastructure) Member Kelly Carrington Voting Carbon County Sheriff's Office (Sergeant) Member Neil Cardwell Voting City of Belgrade (City Manager) Member Victoria Lowe Voting Sheridan County (IT Manager) Member 'Note: Appendix A will be updated as committee candidates accept appointment to the Cybersecurity Planning Committee. 2022.11.10 *** FINAL*** Page 6 ATTACHMENT C Montana State and Local Cybersecurity Grant Program Cybersecurity Planning Committee Priorities The State of Montana Cybersecurity Planning Committee has identified priority areas within the State Cybersecurity Plan. State -Level Projects No more than Twenty (20%) percent of the total SHSP funds will be allocated to state -level projects including the State Management and Administration costs. If not all the funds are allocated for state level projects, funds will be available for local level projects. 1 IVIT DES M&A — up to 5% of State Award 2 Whole of State Coordinator #1: Governance and Plan Development #2: Support for Assessments, Plan Development #3: MT-ISAC, Cyber Hygiene #5: Support Migration to GOV 3 ITSID — Training (Projects #4; #6) Total Local Level -Projects $121,393 $314,179 $50,000 $485,573 A minimum of eight (80) percent of the total SLCGP funds will be allocated to local level projects. This includes a minimum of twenty-five (25) percent of the overall funding that must be allocated to rural jurisdictions. Jurisdictions may receive state provided services in lieu of funding with local consent. The following project areas have been identified as priorities to increase the capabilities across the state. Priority will be for jurisdictions to implement best practices and increase the overall baseline capabilities to secure the state's critical infrastructure. (See State of Montana Cybersecurity Plan 2022-2024) 4 Basic End User Security Awareness Training - State Service (Know Before): $3.50/license - Local Submitted End User Training ............... 5 Migrate to GOV domains — Solicit Interest 6 Cyber training for IT privileged users and cyber professionals (approximately $4,200/course) - SANS Training — State purchased and provided - Other Professional Course — local purchased 55 7 Behavior based end -point detection and response solution for servers and workstations - Sentinel One managed service (State Contracted) Network Monitoring and Management Intrusion Detection Systems (Limited Eligibility to Critical Infrastructure Election / Emergency Services) - Albert Sensors (MS-ISAC) - Comparable Service $1,250,000 $450,000 56 Attachment D Montana State and Local Cybersecurity Grant Program CISA Recommended Resources, Assessments, and Memberships The following list of CISA resources are recommended products, services, and tools provided at no cost to the federal and SLT governments, as well as public and private sector critical infrastructure organizations: • CYBER RESOURCE HUB • Ransomware Guide (Sept. 2020) • Malicious Domain Blocking and Reporting • Cvber Resilience Review • External Dependencies Management Assessment • EDM Downloadable Resources • Cyber Infrastructure Survey • Validated Architecture Desian Review 0 Free Public and Private Sector Cybersecurily Tools and Services CISA Central: TLIWgrt a cybersecurity incident, visit hl�2s://www.us-cert.gov/repo For additional CISA services visit the CISA Services Catalog. For additional information on memberships, visit Information Sharing and Analysis Organization Standards Organization. Membership in the Multi -State Information Sharin2 and Analysis Center (MS-ISAC) and/or Election Infrastructure Information Sharing and Analysis Center (EI-ISAC): Recipients and subrecipients are strongly encouraged become a member of the MS-ISAC and/or EI-ISAC, as applicable. Membership is free. The MS-ISAC receives support from and has been designated by DHS as the cybersecurity ISAC for SLT governments. The MS-ISAC provides services and information sharing that significantly enhances SLT governments' ability to prevent, protect against, respond to, and recover from cyberattacks and compromises. DHS maintains operational -level coordination with the MS- ISAC through the presence of MS-ISAC analysts in CISA Central to coordinate directly with its own 24x7 operations center that connects with SLT government stakeholders on cybersecurity threats and incidents. To register, please visit hl�2s://Ieam.cisecurily.org/ms-isac-registration. For more information, visit MS-ISAC (cisecurily.org). The EI-ISAC, is a collaborative partnership between the Center for Internet Security (CIS), CISA, and the Election Infrastructure Subsector Government Coordinating Council. The El- ISAC is funded through DHS grants and offers state and local election officials a suite of 57 elections -focused cyber defense tools, including threat intelligence products, incident response and forensics, threat and vulnerability monitoring, cybersecurity awareness, and training products. To register, please visit hLtps://Ieam.cisecuriiy.org/ei-isac-registration. For more information, visit hl�2s://www.cisa.gov/election-securily. 58