Information security is defined as the administrative, technical, or physical safeguards used to access, collect, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle confidential information. This policy covers all electronic information resources, including network servers, workstations (staff and public), network equipment, telecommunications equipment, and peripherals.
Cybersecurity Responsibility
The IT Director is responsible for overseeing cybersecurity and the development of the Cybersecurity Program. This role may be designated as the Cybersecurity Lead, responsible for ensuring organizational compliance and coordinating activities to comply with this policy.
Annual Policy Review
This security policy must be reviewed at least once per year and updated as needed to maintain alignment with applicable regulatory, audit, and NIST cybersecurity framework requirements.
Security Awareness and Training
All employees must complete security awareness training upon employment at least once per year. The training will be sufficient to provide necessary role-based knowledge and awareness.
Asset Inventory
An inventory of all computers, servers, network equipment, and important software will be maintained. The inventory will be updated as changes occur and reviewed at least once per year.
Data Classification and Protection
Maintain a documented data management process and Records Retention Schedule that addresses data sensitivity, ownership, handling, retention limits, and secure disposal requirements. Documentation shall be reviewed and updated annually.
Vendor compliance
We will work with our partners and service providers to ensure compliance with our cyber security policy.
Vulnerability and Patch Management
Computer systems, software, and other assets must be kept up to date with security patches. Vulnerability remediation times will generally align with manufacturer recommendations based on severity.
Password Management
Employees and asset owners must ensure password requirements are met for all responsible systems and accounts. Passwords must meet organizational requirements. Passwords will need to be updated according to organizational timelines. User passwords must be changed if there is reason to believe they may have been compromised.
Network Security Controls
Network security measures shall be implemented to prevent unauthorized access to library networks, systems and data from unauthorized access.
Anti-Malware Protection
Anti-malware (antivirus) software must be installed, enabled, and active on all computers and devices. Exceptions for specialized devices must be documented and mitigated through equivalent controls.
Incident Response and Contingency Plan
An incident response and contingency plan must be maintained, reviewed, and updated annually or after major incidents. The plan must be tested through tabletop exercises at least once per year and retained in both digital and printed forms.
Public Records Exemptions
In accordance with ORC 149.43 and 149.433, cybersecurity program documents, incident reports, and security procurement records (including hardware/software details and vendor names) are not public records.
Physical and Additional Controls
Restrict physical access to laptops and computers when in public spaces.
Sign out / Lock or turn off unused computers or equipment.
Keep electronic equipment (cameras, tablets, etc.) in locked cabinets when not in use.
Assign unique user IDs to each authorized user; do not share credentials.
Policy Revisions
Cybersecurity matters can change rapidly, the Board of Trustees hereby authorizes the Library Director to revise this policy, which shall go into effect for the Elyria Public Library System, upon being posted prominently.
(Approved by the Board of Trustees on June 8, 2026)