Laserfiche WebLink
Kittitas County <br />Board of County Commissioners <br /> <br />4. An “Elevated Permissions” account <br />Previous Board Action: In 2013 the Board approved hiring the LET position in the Sheriff’s office <br />as Tier 1 and Sheriff specific technology support. <br />Analysis: First, our consideration of the Sheriff’s request reflects the position with <br />the Sheriff’s Office, not the current employee in that position. We <br />respect Jeremy Reynolds and his skills. We don't know who might be in <br />the LET position in the future and if we would have the same level of <br />trust in them. As Sheriff Myers has stated to Director Goeben, policies <br />and procedures are not written for the employees you have, but the <br />employee you could have. <br /> <br />Second, we have considered both technical capabilities of providing the <br />requested access, and the operational effects of doing so. <br /> <br />Technical Considerations <br />1. Network switches within Sheriff network scope <br />Currently, there are few servers and switches used only by the <br />Sheriff’s Office. At specific locations around county facilities <br />there are network switches that route traffic from multiple <br />offices/departments through multiple VLAN segmentations. <br />While it is possible to add an additional administrator to the <br />switch, that administrator would have full administrative rights <br />to all ports, including those not in the Sheriff’s scope. <br /> <br />To grant the LET privileged access to network switches, IT could <br />move the Sheriff’s traffic to separate Sheriff-only switches, at an <br />estimated cost of $38,520, 42 IT hours to regroom the switches, <br />plus MA/SH/IT cost of adding ethernet cables. All changes would <br />need to be pre-submitted to IT through the change management <br />process prior to being implemented. <br /> <br />2. Wi-Fi access point remote management <br />Currently all access points reside in one logical “site” per <br />location. Administrative access is provided by site. Providing <br />administrative privileges to a site would allow control of all <br />access points within that site. Additionally, access points are not <br />office/department specific but serve Wi-Fi traffic from multiple <br />departments. Changes affecting one access point would affect all <br />offices/departments connected to the access point. <br /> <br />IT could separate access points into a “Sheriff” site and an <br />“Everyone Else” site; however, this still would not separate <br />access points by office/department traffic, so changes would <br />affect all offices/departments using that access point. For