Legislation Details

File #: 26-1101    Version: 1
Type: Resolution Status: Agenda Ready
File created: 4/30/2026 In control: Board of Supervisors
On agenda: 7/28/2026 Final action:
Title: Adopt a Resolution updating Section 31A of the Napa County Policy Manual pertaining to technology use and security. (No Fiscal Impact; Discretionary)
Attachments: 1. Resolution, 2. Quick Reference Guide to Policy, 3. Policy - Redline, 4. Policy - Clean
Date Ver.Action ByActionResultAction DetailsMeeting DetailsVideo
No records to display.

 

TO:                     Board of Supervisors

FROM:                     Ryan J. Alsop, Chief Executive Officer

REPORT BY:                     Andrew M. Mize, Senior Legislative & Policy Advocate

SUBJECT:                     Update to Napa County Information Technology Use & Security Policy

 

RECOMMENDATION

title

Adopt a Resolution updating Section 31A of the Napa County Policy Manual pertaining to technology use and security. (No Fiscal Impact; Discretionary)

body

BACKGROUND

The Napa County Division of Information Technology Services (ITS) is broadly responsible for providing centralized hardware and software support for County departments and staff.  While ITS continues to innovate and meet its mandate each day in a rapidly shifting world, the policy documents in the Board of Supervisors’ policy manual do not reflect current practices.
Consequently, ITS seeks to update one of its foundational documents to reflect current practices and industry terminology.  This policy document is accompanied by an employee reference guide, posted to the Napa County intranet, which can be amended more efficiently than the policy document to better meet a changing IT landscape and reflect employee questions and feedback.  For this reason, staff also elected to put definitions in the employee reference guide, as the definitions of key terms are subject to frequent change by industry standard makers.
Because this update reflects a codification of current practices, employees will not experience any shift in their day-to-day interactions with Napa County-controlled hardware or software or obligations with respect thereto.  The updated policy document and accompanying reference guide provide clear and concise direction for employees as to their security obligations and outline proscribed conduct.  Pursuant to California Government Code Section 8314, which allows incidental personal use of County resources, the updates also provide guidance as to what incidental personal use means as it relates to Napa County-controlled technology assets.
As noted, this update, along with the Payment Card Industry Compliance Policy adopted by this Board in March, 2026, form cornerstones of the complete ITS policy package.  ITS plans to build on this foundation with two additional policies, one covering data classification and security and a second on the proper use of artificial intelligence by County staff and vendors.  ITS expects to bring these policies before this Board in winter of 2026-27.
This item has been placed on the Board’s consent calendar because it involves internal, rather than externally facing, operations.  This update codifies existing practices and does not involve any change to day-to-day employee use of ITS assets, substantially reducing the utility of an informational presentation by staff.
Requested Action: Adopt a Resolution updating Section 31A of the Napa County Policy Manual pertaining to technology use and security. 

 

FISCAL IMPACT

Is there a Fiscal Impact?

No

Is it Mandatory or Discretionary?

Discretionary

Discretionary Justification:

Adoption of the policy provides a strong foundation for future ITS policies. 

Consequences if not approved:

Failure to adopt this policy today will delay the presentation of the data classification and artificial intelligence policies to this Board.

Additional Information

Strategic initiative: Elevate County Service & Workforce Excellence.

 

ENVIRONMENTAL IMPACT

ENVIRONMENTAL DETERMINATION: The proposed action is not a project as defined by 14 California Code of Regulations 15378 (State CEQA Guidelines) and therefore CEQA is not applicable.