Cyber Security and Network Managed Services Enhancements

Page 1

IT Governance Compliance Business Case Cyber Security and Network Managed Services Enhancements Technology Solutions

Background The Cyber security program was created in FY18 and since that time we have made significant progress in our efforts to align to the National Institute of Standards and Technology (NIST) 800 framework, a federal best practice guide for the management of a cybersecurity organization. This case will align to the Detect, Respond, Protect and Recover layers of the NIST Framework Cyber Security Posture. Additionally, with the launch of the new city fiber network next fiscal year, TS requires the resources to manage and maintain the network as we will be the sole responsible party acting as the Competitive Local Exchange Carrier (CLEC).

1st Business Problem: Need to Increase Cyber Security Capabilities within the NIST Detect and Response Layer

In the Detect and Respond NIST Framework Layer, there is a lack of visibility of what devices are on the network.

Current Pain Points as the result of the first business problem Cyber Security: Detect and Respond NIST Layer •

TS does not have the capabilities to identify and continuously monitor connected assets.

TS does not have the capabilities to identify devices that come on the network that do not have the mandated security requirements.

TS does not have enough staff to manage cyber security for the City.

1st Business Problem: Need to Increase Cyber Security Capabilities within the NIST Protect and Recover Layer In the Protect and Recover NIST framework layer, the second business problem TS is attempting to solve with this case is the expansion of the Data Protection capabilities as part of the total Cyber Security posture in alignment to the NIST framework. There are several existing technologies that require additional expansion based on the growth of data. Those technologies include: •

Rubrik – This is the primary data backup and recovery system

Microsoft azure cloud storage – This is the cloud location that the City stores the data backups

Acronis – This is the critical end point backup and imaging recovery system

1st Business Problem Current Pain Points within the NIST Protect and Recovery layer There is a need for more capacity to backup data due to the growth of data created within the City. •

Rubrik needs additional capacity on-premises to back up data

The current budget for Microsoft Azure cloud does not allow for expansion to store more data from on-premises.

Replace the existing solution to backup PC images

2nd Business Problem: Need to Increase Resources Required to Manage the City’s New Fiber Network The final business problem TS is attempting to solve with this case is gaining the resources to manage the new multi-million dollar fiber network. The City is transitioning from using a provider (Spectrum/Charter) to becoming our own provider. This transition requires additional resources to manage and maintain the network cable plant, backbone equipment, and performance value of the network. TS will need additional resources to manage this new network. The management of the network was outsourced and is now being insourced. TS has also asked for an additional FTE to manage the multiple vendors that will be needed to maintain this network 24/7/365.

2nd Business Problem Current Pain Points Fiber Network Managed Services •

TS does not currently have the management oversight required to manage the multiple additional partners that are required to maintain the network. There is a budget initiative for a Network Managed Services manager to be added to TS as a result of this need.

TS currently does not have the staff to manage the operations of the network.

Desired Business Value 1st Business Problem City of Durham’s Strategic Plan Goal: Innovative & High Performing Organization Initiative: Develop and implement a continuous improvement model that includes evaluation and process improvement to analyze and improve City services Cyber Security •

Provide the TS Cyber Security division with the ability to monitor devices that are on the network for compliance.

Expand the data protection resources and deploy critical end point recovery technologies.

Desired Business Value 2nd Business Problem City of Durham’s Strategic Plan Goal: Sustainable Natural and Built Environment Initiative: Develop and implement City of Durham fiber optic network in partnership with Duke and Durham County Network Managed Services •

Provide the capability for TS to manage and operate the new fiber network by adding staff and engaging in contractual relationships with partners to sustain the network.

Future State Benefits for the Cyber Security Program Bring increased security aligned to the Protect, Detect, Respond, and Recover layers of the NIST framework by: •

Being able to determine a classification by type for devices on the network.

Understand the patch and vulnerability levels for all of the devices that connect.

Institute the controls to add the security and automate the policy enforcement for compliance.

Expanding the on premise and cloud data center storage capabilities to align to the data growth.

Adding an end point imaging tool that will be able to fully recover key end points in the event of malware attack.

Future State Benefits for the City Fiber Network Management Fiber Network Managed Services With the approved resources including the FTE position, TS will be able to: •

Manage a 24/7/365 Network Operations Center supporting the fiber optic network through the user of partners.

Support the physical infrastructure of the new Fiber Network.

Maintain the hardware of the network with the appropriate agreements.

Recommended Solution and Analysis

Recommended Cyber Security Solution: Forescout Implementation Description



Forescout which was beta tested in TS, will require professional services to implement across the entire network.

Gain complete visibility of devices connected to the City network

Non-compliant system managed by Forescout can be controlled by restricting access

Restrict non-corporate domain/guests systems connecting to network

Integration with patch management tools

Automatic enforcement of policy


2nd Recommended Cyber Security Solution: Data Protection Expansion


Funding is required to expand these platforms that protect data. TS has already invested in these platforms and they are proven products. The data protection platforms are the following: Rubrik, Veeam, Azure, and Acronis.


All Data is protected within the licensing of the data protection solutions.



Recommended Fiber Network Management Solution Description



Contract with managed service provider and other operations support vendors that will provide network operations center (NOC) services, physical fiber infrastructure support, and fiber backbone hardware maintenance.

• Vendor that has the experience and expertise to manage the CLEC portion of the network. This portion is unfamiliar to TS as we have never been our own carrier before. • It is a positive benefit to have the City’s core network equipment to be covered under maintenance. TS did not cover the maintenance of the equipment until we forecasted the time that it would be deployed which will be in FY23. • Mitigates support staff turnover

• The skillset will not be in-house, will rely on external partners which carries a small amount of risk

Financials Estimate: Forescout and Data Protection Expansion COST ESTIMATES Description

FUNDING Annual Run Costs (Hours)/ KTLO

Year 1 Costs (Hours)

Departmental Funding Amount:


Labor $ (Hours) Internal TS:

2,580 hours

2,440 hours

50 hours

0 hours

2,530 hours

2,440 hours


0 Hours

0 hours

Internal Department:

0 hours

0 hours

Business Analysis TS Services

Professional Services


Non-Labor $ Hardware: Software: DP/Rubrik $16,670 DP/Azure $38,400 DP/Acronis $5,730 NIM/Forescout: In budget Total: $60,800 Other:


Funding Requested (Y/N): Project One Time Costs


Project Run Cost (External)


*Total Project Funding for Year 1 * Minus recurring funding within TS budget $0 Total Year 1 Funding Requested Total Recurring Cost *Minus recurring funding within TS budget $0 Additional Recurring Cost per year required






*Total Project Funding Requested (External), includes External Year 1 Run Costs and Non-Labor

$91,400 $18,000 $74,400 $78,800 $18,000 $60,800

Financials Estimate: Fiber Network Managed Services COST ESTIMATES Description


Year 1 Costs (Hours)

Annual Run Costs (Hours)/ KTLO

Departmental Funding Amount:


Labor $ (Hours) Internal TS:

2,390 hours

2,080 hours

60 hours

0 hours

2,250 hours

2,080 hours


80 Hours

Internal Department:

0 hours

Business Analysis TS Services

Professional Services


Software: CISCO SmartNet (Hardware Maintenance) Other: (NOC) Managed Network Services Support costs


Project One Time Costs


0 hours

Project Run Cost (External)


0 hours

*Total Project Funding Requested for Year 1


*Minus existing recurring funding within TS Budget


Total Year 1 additional funds requested


Total Recurring Cost


*Minus existing recurring funding within TS Budget


*Additional funds requested for recurring costs



Non-Labor $


Funding Requested (Y/N):







Risk Identification: Cyber Security Description of Risk

Risk Impact

Mitigated (Y/N)


Poor execution




Project team turnover




Vendor performance




Cyber Security




Risk Identification: Fiber Network MS Description of Risk

Risk Impact

Mitigated (Y/N)


Poor execution




Project team turnover




Vendor performance




Cyber Security




Mitigation Risk (Costs) •

Cyber Security: No cost increases

Fiber Network Managed Services: Potential costs of contract staff

Contingency Risk (Costs) •

Cyber Security: No cost increases

Fiber Network Managed Services: Potential increases for changing partners / vendors

Our Ask

We are asking the IT Governance Steering Committee to approve the business case to grow Technology Solutions Department’s Cyber Security program and the Network Managed Services capabilities for submission to the City Manager for approval and funding through the BMS department.

Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.