Muyni
← Back to Walker

Personnel Committee

Regular Meeting

Walker, MI · June 23, 2025

Agenda

Agenda

PERSONNEL COMMITTEE AGENDA COMMISSION CONFERENCE ROOM 4243 REMEMBRANCE RD. NW. MONDAY, JUNE 23, 2025 5:00 PM Call Meeting to Order - Record Attendance 1. Committee Members: Mayor Carey (Chair), Jessica Babcock, Steven Gilbert, and Elaina Huizenga-Chase (Alternate) Discussion Items 1. Approval of Minutes from May 12, 2025 2. IT Position Description Approval - Cybersecurity Analyst & IT Specialist 3. WIFC 2025 Wage Table Approval 4. 59th District Court Wage Study Approval 5. IT & Cybersecurity Policy Approval 6. Section 120 Policies Approval 7. Supporting Documents Adjournment Page 1 of 31 PERSONNEL COMMITTEE MEETING MINUTES COMMISSION CONFERENCE ROOM MONDAY, MAY 12, 2025 12:00 AM Call Meeting to Order - Record Attendance Committee Members: Mayor Carey (Chair), Jessica Babcock, Steven Gilbert, and Elaina Huizenga-Chase (Alternate) City Staff: Darrel Schmalzel, Frank Wash, Shannon Bales, Gary Postema, and Jake Gardner Discussion Items Approval of Minutes from December 16, 2024 Motion by Jessica Babcock, seconded by Steven Gilbert to approve the December 16, 2025 Meeting Minutes. Motion Carried. DPW Policy Requests HR Director Shannon Bales introduced the proposed policy updates, noting that the requests are similar to policies adopted by other local municipalities. DPW Director Gary Postema reported that a wage study was conducted by DPW staff and information was used to draft the proposed policies. He detailed how alternate shifts operate within the department and the justification for additional compensation for those shifts. G. Postema also provided information regarding winter supervisor on-call duties and the associated request for a stipend for these responsibilities. Deputy Director Jake Gardner addressed the request to increase minimum on- call pay. Shannon Bales outlined the proposed increase to the holiday premium wage J. Gardner introduced the concept of a comp time policy and G. Postema provided further clarification. Committee discussion included the maximum allowable comp time hours and the method of implementation. Personnel Committee Minutes 5-12-25 Page 1 of 2 Page 2 of 31 Motion by Commissioner Gilbert, seconded by Commissioner Babcock to move forward with the DPW policy requests. Personnel Manual Policy Updates:  Section 130.01 Earned Sick Time  Section 60.0 Employee Classifications  Section 90.0 Compensation  Section 110 Benefits Policies (Multiple Sections) HR Director Bales presented proposed changes to the Earned Sick Time (ESTA) policy stating that the policy has been reviewed by the City's attorney and employees have been notified of the updates S. Bales explained that sections 60, 90, and 110 of the Personnel Manual have been reviewed and revised to align with ESTA guidelines. Definitions were updated where OPEB is referenced. She also noted a minor change to section 110.1clarifying dental coverage language. Comp Time Discussion The committee and staff discussed comp time policies implemented by other City departments, including the Police and Fire Departments. Next Meeting Director Bales requested a meeting to be held in June to discuss additional policy changes, IT and AI policies, IT job description changes, and WIFC and Court compensation changes. Next meeting to be scheduled June 23rd at 5:00PM Adjourned at 5:50 PM Personnel Committee Minutes 5-12-25 Page 2 of 2 Page 3 of 31 Cybersecurity Analyst Department: Information Technology Classification: Full-Time / Exempt Reports To: IT Director Date: June 2025 Position Description Objective The Cybersecurity Analyst works with the IT Director and an outsourced SOC team to provide day- to-day operations of the security program. This includes monitoring systems and networks for threats, managing the vulnerability management program, responding to security events, and supporting the implementation of security controls and tools. The Cybersecurity Analyst plays a critical role in safeguarding the confidentiality, integrity, and availability of the city’s information systems across all internal infrastructure and cloud-based services. This role supports both the City of Grandville and the City of Walker. Essential Job Functions An employee in this position is required to perform the following essential functions with or without reasonable accommodation. 1. Deploys, configures, maintains, and monitors security technologies (e.g., SIEM, EDR, MFA, DLP, email filtering) to enforce protection and visibility across the environment. 2. Conducts scheduled vulnerability scans and remediation activities. 3. Supports the implementation and maintenance of endpoint protection, secure configurations, and baseline system controls. This includes maintaining a whitelist and blacklist of applications and devices. 4. Manages service tickets and issues to resolution. Primary focus will be on issues related to Cybersecurity, such as phishing reports, but assists with other tickets and projects on a as needed basis. 5. Conducts security awareness training. 6. Assists the IT Systems Administrator with troubleshooting and maintenance of servers dedicated to the security function, including Linux servers. 7. Assists in the tracking of cyber risks to the city. 8. Updates and maintains documentation and standard operating procedures. 9. Participates in an after-hours on-call rotation. 10. Performs other related duties as required. Minimum Qualifications and Required Knowledge, Skills and Abilities 1. Associates degree in a related field and 1-2 years of relative work experience, or in leu of a degree, 1-2 years of additional relative work experience. Work experience and/or education requirements can be supplemented with security certifications such as Security+. 2. Experience with security frameworks such as NIST, and CIS preferred. 3. Experience supporting security technologies, such as SIEM, EDR, MFA, DLP, email filtering, and vulnerability management. 4. Proficient with Active Directory, Microsoft 365 and Linux. 5. Basic understanding of networking concepts and protocols. 6. Any knowledge of securing SCADA based systems is a plus. 7. Possession of, or in the process of obtaining, cybersecurity related certifications. 8. This position has a large amount of responsibility and autonomy. Must be an initiative-taker, able to exercise good judgement, able prioritize work appropriately, and know when to seek guidance. 9. Requires a valid State of Michigan driver's license, satisfactory driving record and the ability to maintain one throughout employment. Page 4 of 31 Position Description Cybersecurity Analyst 10. Excellent oral communication skills, ability to perform a wide variety of tasks during busy, sometimes stressful times. 11. Ability to exercise good judgment, initiative and resourcefulness in dealing with the public, members, elected officials, community leaders and co-workers. 12. Must demonstrate appropriate customer service competencies and behaviors in accordance with department policies and procedures. 13. Ability to concentrate and pay attention to details; also, ability to organize, prioritize and work independently and in a busy environment where priorities change as well as schedules. 14. Manual dexterity to work effectively for extended periods. Lifts and carries supplies equipment etc. weighing up to 30 pounds to waist-high-level. Physical Demands and Work Environment The physical demands and work environment described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the job. An employee in this position spends a portion of their time in-person in an office setting with a controlled climate where they sit and work on a computer for extended periods of time; communicate by telephone, e-mail or in person, and move around the office or travel to other locations to attend meetings and site visits. This position is eligible, after six months, to work remotely up to two days a week per the City of Walker’s remote work policy. Due to the nature of this position, remote work may not always be possible and may have to report to the office on a scheduled remote workday if the need arises. Additionally, this position spends a portion of their time traveling between facilities conducting inspections, repairs, and installations which typically involve moderate physical activity and exertion. An employee must have the strength, stamina and physical coordination required to complete physical inspections, repairs, and installations. This work occasionally involves crawling, stooping, climbing or otherwise accessing all areas of the site, and the employee is required to have the vision capabilities needed to complete visual inspections. Approvals The above is intended to describe the general content of and requirements for other performance of the job. It is not to be construed as an exhaustive statement of duties, responsibilities or requirements. This job description has been approved by all levels of management. City Manager Date Employee signature below constitutes employee's understanding of the requirements, essential functions and duties of the position. Employee Date Page 2 of 2 Page 5 of 31 IT Specialist – General Government Department: Information Technology Classification: Full-Time / Exempt Reports To: IT Director Date: June 2025 Position Description Objective The IT Specialist – General Government focuses on supporting the Information Technology used by the City Hall departments, Public Works departments, and the Walker Ice and Fitness Center departments. Position also assists with other departments as needed. The position assists in systems administration for the assigned departments along with expanding the use of technology for the assigned departments. Essential Job Functions An employee in this position is required to perform the following essential functions with or without reasonable accommodation. 1. Over time gains, then maintains, an in-depth level of understanding of the technology in use at the assigned departments supported by the City of Walker IT Department, currently the Cities of Grandville and Walker. 2. Manages service tickets and issues to resolution. Primarily focus will be on the assigned departments but assists with other departments as needed. 3. Installs, upgrades, and configures hardware and software on desktops, mobile environments, laptops, and PC peripherals such as printers, monitors, scanners, modems, air cards, and related hardware. 4. Assists the IT Systems Administrator with troubleshooting and maintenance of servers dedicated to the assigned departments. 5. Assists the assigned departments in increasing efficiency and keeping up to date with latest technology. 6. Updates and maintain documentation and standard operating procedures. 7. Participates in an after-hours on-call rotation. 8. Performs other related duties as required. Minimum Qualifications and Required Knowledge, Skills and Abilities 1. Associates degree in a related field and 2-4 years of relative work experience, or in leu of a degree, 1-2 years of additional relative work experience. 2. Proficient with Active Directory, file/print services, Microsoft 365. 3. In-depth understanding of Microsoft Windows and iOS (iPhones, iPads). 4. Experience supporting software such as BS&A, Cityworks, and OnBase is preferred but not required. 5. Basic understanding of networking concepts and protocols. 6. Possession of, or in the process of obtaining, CompTIA, Cisco, or Microsoft Certifications preferred. 7. Requires a valid State of Michigan driver's license, satisfactory driving record and the ability to maintain one throughout employment. 8. Excellent oral communication skills, ability to perform a wide variety of tasks during busy, sometimes stressful times. 9. Ability to exercise good judgment, initiative and resourcefulness in dealing with the public, members, elected officials, community leaders and co-workers. 10. Must demonstrate appropriate customer service competencies and behaviors in accordance with department policies and procedures. Page 6 of 31 Position Description IT Specialist – General Government 11. Ability to concentrate and pay attention to details; also ability to organize, prioritize and work independently and in a busy environment where priorities change as well as schedules. 12. Manual dexterity to work effectively for extended periods. Lifts and carries supplies equipment etc. weighing up to 30 pounds to waist-high-level. Physical Demands and Work Environment The physical demands and work environment described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodations may be made to enable individuals with disabilities to perform the job. An employee in this position spends a portion of their time in-person in an office setting with a controlled climate where they sit and work on a computer for extended periods of time; communicate by telephone, e-mail or in person, and move around the office or travel to other locations to attend meetings and site visits. This position will also spend a portion of their time in garage settings, working on in-vehicle technology. This position is eligible, after six months, to work remotely up to two days a week per the City of Walker’s remote work policy. Due to the nature of this position, remote work may not always be possible, and may have to report to the office on a scheduled remote work day if the need arises. Additionally, this position spends a portion of their time traveling between facilities conducting inspections, repairs, and installations which typically involves moderate physical activity and exertion. An employee must have the strength, stamina and physical coordination required to complete physical inspections, repairs, and installations. This work occasionally involves crawling, stooping, climbing or otherwise accessing all areas of the site, and the employee is required to have the vision capabilities needed to complete visual inspections. Approvals The above is intended to describe the general content of and requirements for other performance of the job. It is not to be construed as an exhaustive statement of duties, responsibilities or requirements. This job description has been approved by all levels of management. City Manager Date Employee signature below constitutes employee's understanding of the requirements, essential functions and duties of the position. Employee Date Page 2 of 2 Page 7 of 31 City of Walker / WIFC Compensation Plan Pay Tier 1 Classification Approved Pay as of 09/2023 Proposed as of 7/1/2025 Concessions Seasonal Minimum Wage - $14 per hour Minimum Wage ($12.48) - $17 per hour Skate Rental Seasonal Pro Shop Seasonal Fitness Attendant Variable PT Pay Tier 2 Zamboni Driver & Front Desk Variable PT $12 - 16 per hour $15 - 24 per hour Fitness Staff Variable PT Maint/Janitorial Variable PT Pay Tier 3 Manager on Duty Variable PT $17 - 26 per hour Parks & Recreation Assistant Variable PT Program Fee Based Static Pay Classification Per game/event based Adult League Hockey Referees Program Based $50.00 $50.00 Adult League Scorekeepers Program Based $20.00 $20.00 Page 8 of 31 Adult League Hockey Game Ref Coordinator Program Based $5.00 $5.00 Learn to Skate Instructors Program Based up to $20.00 up to $20.00 Learn to Skate Head Coach Program Based $25.00 $25.00 Adult Softball Umpires Program Based $25.00 $26.00 - 27.00 Youth Soccer Officials Program Based $12.00-18.00 $12.50 - 20.00 (1S $12.50, 2&3S $14, 4&5S $15, Asst Sup $18, Sup $20) Personal Trainers Program Based 60% fee to trainer/40% fee to WIFC $28 - 45 per hour Fitness Class Instructors Program Based $20.00 starting $20.00 - 35.00 For Tier 1, 2, and 3; no COLA increase. Annual review of competitive wages. For Program Fee Based Static Pay, no COLA increase. Annual review of program fees and comptetitive wages. Adjustment of program fees to accommodate wage changes. Scheduled 24 hours per week minimum, Regular Part Time employees Regular Part Time Fringe Benefits - Vacation, 401 Retirement, Short/Long Term Disability, Life Insurance Recreation Supervisor Regular PT Grade 6 Classification 28 hours Membership Specialist Regular PT Grade 3 Classification 24 hours Adult League Coordinator Regular PT Grade 3 Classification 35 hours Full-Time Supplemental Services Manager Full-Time Grade 4 Building Maintenance Full-Time Grade 4 Fitness Manager Full-Time Grade 6 Ice Director Full-Time Grade 10 Facilities Director Full-Time Grade 10 Regular PT and FT participates in the City's classification and compensation policy including COLA, merit increases, and years of service adjustments when applicable. Information Technology & Cybersecurity Policies Approved June 2025 Jason Rottman Darrel Schmalzel IT Director City Manger Page 9 of 31 Information Technology & Cybersecurity Table of Contents Table of Contents ..................................................................................................... 2 Introduction............................................................................................................... 3 Scope ....................................................................................................................... 3 Security Policy.......................................................................................................... 4 Acceptable Use ........................................................................................................ 5 Data Management.................................................................................................... 6 Identity and Access Control ..................................................................................... 7 Malware Protection .................................................................................................. 8 Secure System Deployment ..................................................................................... 8 Passwords and Passphrases ................................................................................. 11 Remote Access ...................................................................................................... 12 Page | 2 Page 10 of 31 Information Technology & Cybersecurity Introduction The City of Walker (City) is dedicated to safeguarding its electronic information and systems. This Information Security Policy outlines our strategies for protecting digital assets, ensuring information remains confidential, maintains its integrity, and is available. Our approach is grounded in the latest cybersecurity best practices, as defined by the NIST Cybersecurity Framework, ensuring the City employs up-to-date methods to protect both municipal and constituent information. The Information Technology (IT) Department is responsible for the implementation and maintenance of this policy. The IT Director is accountable for its daily execution and is tasked with regularly reviewing and updating the policy to address emerging risks and advancements in technology. This policy covers all aspects of how we manage and secure our technology and information. It provides clear guidelines for everyone who uses or interacts with the City's digital systems, helping us work together to maintain a strong and secure digital environment for our community. This policy outlines the essential statements that must be adhered to by all Users. Additional procedures, guidelines, and job aids are maintained to provide detailed information regarding how to implement the requirements specified in this policy. This policy is intended to establish a baseline for Information Technology & Cybersecurity Policies. This policy adds to, but does not take away from, mandated compliance policies, such as Criminal Justice Information Systems (CJIS) or Payment Card Industry (PCI). Departments that fall under those compliance frameworks must also adhere to them. Scope Who Does This Policy Apply To? This Information Security Policy applies to everyone who uses or has access to the City of Walker's digital systems and information. This includes: • City Leaders: Elected officials, executives, and department directors • Employees: All staff members, whether full-time or part-time • Volunteers: Anyone volunteering their time to help the city • External Partners: Any outside individuals such as vendors, contractors, or civic organizations that have access to our network, systems, or data. What Does This Policy Cover? The policy covers: • All city business processes and data. • All information systems and technology used by the city. • All personnel who work with or for the city • All physical areas where city information is stored or accessed. Page | 3 Page 11 of 31 Information Technology & Cybersecurity In simple terms, if you work for, volunteer at, or partner with the City of Walker, and you use any of our digital systems or information, this policy applies to you and your activities. Security Policy The City is dedicated to safeguarding its data, network, and system resources through a comprehensive security strategy that incorporates multiple layers of protection. This approach includes the implementation of overlapping controls, ongoing monitoring, and secure authentication methods. This policy aims to strengthen the security of the City's information and systems by establishing effective controls, clarifying roles and responsibilities for information security across the City, and ensuring that all users adhere to relevant laws and obligations concerning data protection. General Policies: 1. The IT Director is responsible for leading the City’s Information Security program. This includes guiding elected officials, leaders, employees, and system users, while ensuring the protection of the City’s data. 2. Standardized configurations will be implemented on user workstations, servers, firewalls, and network devices to establish a baseline secure configuration that complies with industry best practices as well as the City’s legal and regulatory requirements. 3. The City will centrally log all workstation, server, network, and firewall activity. Any unusual or suspicious activities will be investigated. 4. The IT department will conduct internal and external vulnerability scans monthly, or more often if necessary, depending on data sensitivity, and will patch any identified vulnerabilities. 5. Change management procedures are to be followed when implementing changes to any City owned or operated IT systems. 6. All employees will receive security training upon hire and annually. Those with access to confidential data will receive additional specialized training upon hire and annually to reinforce safe data handling practices. 7. All employment candidates, including contractors and third-party users, must undergo pre-employment background checks tailored to the types of data they will access. 8. City Information Security policies are to be followed when working offsite or remote. 9. Any complaints regarding violations of this policy should be reported to the IT Director for further guidance. 10. Before engaging a new vendor, the City will conduct due diligence to ensure the vendor can deliver the requested services and meet the City's security requirements. This process confirms the vendor's capability and commitment to maintaining essential security standards. 11. The IT Director will periodically conduct a risk assessment to evaluate potential risks to City operations, IT assets, and personnel arising from the use of City information systems and the processing, storage, or transmission of confidential Page | 4 Page 12 of 31 Information Technology & Cybersecurity data. 12. The City provides users with a reasonable level of privacy but reserves the right to monitor the use of City-owned systems at any time without notice. Users should not expect complete privacy when using these systems. 13. Violations of the Information Security Policy may lead to disciplinary actions as outlined in the City’s Personnel Policy Manual. Acceptable Use Purpose: This Acceptable Use Policy outlines the responsibilities and expected behavior of all users accessing the City of Walker's information systems and assets. It aims to protect the integrity, confidentiality, and availability of the City's information resources. Users will: • Be responsible and use City resources wisely. • Read and understand this policy when they start their job and every year after. • Talk to their manager or the IT Director if they have questions about their responsibilities or this policy. • Report any lost or stolen laptops or mobile devices to the IT Help Desk right away. • Remember that any data created on City systems belongs to the City. The City cannot guarantee that personal data stored on its systems or devices will be kept private. • Lock their computers when they step away from their desks. • Only use external drives, USB sticks, and memory cards if they have been approved by IT. • Not use any removable drives that contain City information on non-City devices or systems. • Be careful when opening emails or attachments from people they don’t recognize and use the ‘Report Phish’ button if needed. Users will not: • Violate anyone's rights protected by copyright, trade secrets, patents, or other intellectual property laws. • Copy copyrighted materials without permission, such as music, videos, or software for which the City does not have a license. • Disrupt the proper functioning of the City’s network and systems. • Introduce malware to the City’s network, servers, or computers. • Share passwords or let others use their accounts. • Use City systems to send or receive offensive materials or anything that violates harassment laws. • Bypass security measures on any systems or accounts. • Use City Systems (computers, network, Wi-Fi) for adult content or illegal materials. • Disable or change antivirus or security software on any device used to connect to the City's network. • Access City systems on public computers, smartphones, or tablets. • Harass anyone via email, messaging, phone calls, or texts. Page | 5 Page 13 of 31 Information Technology & Cybersecurity • Install software on City owned systems that was not purchased by the City or approved by the IT Director. Data Management Data is an important resource for a modern government. Managing data well can help the city’s work in several ways, such as: • Making data more consistent and reliable • Allowing quicker and easier access to information • Enhancing security and control over data • Facilitating sharing and cooperation between different departments Management Responsibilities Department heads are responsible for ensuring the proper classification and management of data processed by their department. Leaders are responsible for: • Identifying and organizing the data that their department uses or collects. • Creating and following guidelines for how to manage both public and confidential data properly within their department. • Documenting and implementing processes and procedures for the processing, storage, and disclosure (release) of confidential data. • Providing training for staff members who deal with confidential data. Data Classification All data processed or stored by the City should be classified to ensure the proper Security controls are used to protect the data. Record Type Data Class Description Open Public Data available for public access or release or subject to release under F.O.I.A. Confidential Sensitive Data intended for release on a need-to-know basis. Data regulated by privacy laws or regulations or restricted by a regulatory agency or contract, grant, or other agreement terms and conditions. • Personally Identifiable Information (PHI) • Information under NDA Protected Data that triggers requirement for notification to affected parties in the event of a data breach. Such as: • Income Tax information • Social Security numbers • Credit Card data • Electronic Personal Health Information Restricted Data that is legally restricted and requires specific authorization to access such as: • Criminal Justice Information Page | 6 Page 14 of 31 Information Technology & Cybersecurity Data Handling All information resources will be classified and protected based on their specific classification requirements. 1. Data owners are responsible for classifying data and ensuring that users handle it safely according to its level of sensitivity. 2. Data owners, with help from the IT department, will create guidelines for storing and sharing data securely. 3. Confidential records, both physical and electronic, will be kept and disposed of according to record retention obligations. 4. Before sharing confidential data, the security policies of the recipient must be reviewed. A non-disclosure agreement may be necessary. If the recipient cannot adequately protect the data, the IT Director must be notified to determine the next steps. 5. Electronic confidential data must be encrypted when sent over insecure channels to protect it during transmission. 6. Access to locked storage with confidential data will be limited to those who need it, and all access will be recorded. 7. Confidential data should not be stored for a long time on personal computers or mobile devices. 8. Whenever possible, electronic copies of confidential data will be encrypted when stored. 9. Data backups will be protected with the same security standards as the original data. Identity and Access Control Systems 1. Access to systems will be limited to the minimum necessary for each user to do their job effectively. 2. At least two people must have full access rights to any City-owned server that stores or sends confidential data; including any cloud services used by the City. 3. Each user will have their own unique ID for accessing networks and systems, and they must prove their identity through methods like passwords, multi-factor authentication, or security tokens. 4. Multi-factor authentication will be required whenever accessing City systems from outside a city building. 5. Users must keep their usernames and passwords private and may not write them down or store them in unprotected electronic files. 6. All City of Walker networks and systems will require strong passwords which must be changed once a year. 7. Default passwords on systems must be changed during setup unless doing so would break the system. If that happens, extra security steps will be taken, and all admin accounts will be given strong passwords. 8. When an employee is terminated, their access will be disabled immediately. System owners will review user access every six months. 9. If an employee is on leave of absence for more than ninety (90) days, access will be disabled until they are set to return to work. Page | 7 Page 15 of 31 Information Technology & Cybersecurity 10. If employees move to a different role, their access to systems will be updated to fit their new position. 11. The IT department will monitor login attempts and failures, as well as successful logins, including the date and time. 12. Any actions taken by system administrators will be logged whenever possible. 13. Staff with admin access should use regular accounts for everyday tasks, not their admin accounts. 14. Users should not have local admin rights on their workstations unless it is specifically needed and approved by the IT Director. 15. Access to admin accounts will be restricted to maintain minimal privileges and ensure that staff use lower-level accounts for regular tasks. Physical Access 1. The City will maintain physical access controls to protect all City locations. 2. Only authorized personnel will have access to physically secure non-public locations. The City will maintain and keep a current list of authorized personnel. 3. Access to areas containing confidential data will be granted only after management approval is provided, is based on job function needs. 4. When access is required by a vendor or contractor with a valid business need the Access Control Form is required to be completed and approved by the manager of the area. 5. Access to City locations will be removed upon termination of employment or the engagement with the vendor or contractor. 6. Access rights will be reviewed semi-annually. 7. Physical access privileges will be terminated when no longer required for an employee’s job function. 8. Employees will not permit anyone to follow them into a City secure area. Piggybacking/tailgating at entries is prohibited. Malware Protection All Windows, Mac, or Linux computers and servers, as part of the secure system deployment process, will have Endpoint Protection software installed to protect against Malware and Viruses. Email protection from Phishing, Credential Theft, and the transmission of malware will be deployed by the IT Department. Secure System Deployment Secure system deployment standards are included to ensure minimum security baselines are achieved. The IT department is responsible for creating and implementing procedures for the secure deployment and maintenance of City IT systems. Firewall configuration: 1. Update to a Vendor-Supported and Licensed Version 2. Disable Default User Accounts Page | 8 Page 16 of 31 Information Technology & Cybersecurity 3. Change Passwords on Administrator Accounts 4. Integrate Identity and Access Management (IAM) 5. Implement Multi-Factor Authentication (MFA) 6. Configure Centralized Logging 7. Implement Monitoring Solutions 8. Disable Insecure Protocols. 9. Disable Unused Services, Ports, and Protocols 10. Configure Secure Management Protocols 11. Conduct Vulnerability Scan after implementation 12. Implement a Default Deny Policy 13. Implement Security Configuration Baseline (CIS) 14. Configure Intrusion Prevention/Detection Systems (IPS/IDS) 15. Document Configuration Changes 16. Implement a Backup and Recovery Plan Network Equipment: 1. Use Vendor-Supported and Licensed Software. 2. Disable Default User Accounts 3. Change Administrator Passwords 4. Implement and Integrate Identity and Access Management (IAM) 5. Configure Multi-Factor Authentication (MFA) 6. Configure Centralized Logging 7. Configure Monitoring Solutions 8. Disable Insecure Protocols 9. Turn Off Unused Services, Ports, and Protocols 10. Implement Secure Management Protocols 11. Conduct Vulnerability Scans after Implementation 12. Create Management Access Control Lists (ACLs) and VLANs 13. Connect to a Firewall for Internet Perimeter Connectivity 14. Document Configuration Changes 15. Implement a Backup and Recovery Plan Server Deployment: 1. Use Supported and Updated Operating System 1.1. Install the latest version of Windows Server that is supported and licensed. 1.2. Ensure all critical updates and patches are applied before deployment. 2. Implement Basic Security Configuration 2.1. Disable Guest Account 2.2. Rename Default Administrator Account 2.3. Change Default Administrator Password 3. Join the Server to the Active Directory Domain 3.1. Configure the server with a static IP address. 3.2. Use System Properties to join the server to the Active Directory Domain. 3.3. Restart the server after joining the domain. 4. Configure Active Directory User Accounts 4.1. Create necessary user accounts with the principle of least privilege. Page | 9 Page 17 of 31 Information Technology & Cybersecurity 4.2. Implement organizational units (OUs) and group policies for user and computer management. 5. Enable Multi-Factor Authentication (MFA) 6. Deploy Endpoint Protection Agent 6.1. Install and configure the Endpoint Protection Agent for real-time malware protection. 6.2. Install the XDR agent to enhance security monitoring and incident response. 7. Configure Windows Event Logging 8. Set Up System Monitoring Tools 9. Disable Insecure Protocols and Services 9.1. Disable insecure protocols (e.g., SMBv1) and services that are not needed. 9.2. Ensure RDP is secured using Network Level Authentication and other best practices. 10. Turn Off Unused Windows Features and Services 11. Configure Windows Firewall 12. Implement Microsoft Baseline Security Analyzer (MBSA) 13. Implement Security Configuration Baseline (CIS) 14. Secure Remote Desktop Services 15. Create Security Policies using Group Policy 16. Conduct Vulnerability Scans after implementation 17. Implement a Backup and Recovery Strategy 18. Document Configuration Changes 19. Update CMDB with Server Hostname and IP Address End User Workstation: 1. Install Supported and Updated Operating System 1.1. Install the latest version of Windows that is supported and licensed. 1.2. Ensure all critical updates and patches are applied before deployment. 2. Implement Baseline Security Configuration 2.1. Disable Guest Account 2.2. Rename Default Local Administrator Account 2.3. Implement Local Administrator Password Solution (LAPS) 3. User Account Management 3.1. Ensure end users are assigned standard user accounts and are not local administrators on their workstations. 3.2. Use Active Directory for centralized management of user accounts and apply the principle of least privilege. 4. Enable BitLocker Drive Encryption 4.1. Store recovery keys securely in Active Directory or another designated secure location. 5. Deploy Endpoint Protection and Security Software 5.1. Install and configure Endpoint Protection (Antivirus) to provide real-time protection against malware. 5.2. Install the XDR agent to enhance security monitoring and incident response. 6. Install Business Applications 7. Configure Windows Defender Firewall Page | 10 Page 18 of 31 Information Technology & Cybersecurity 8. Configure Windows Update Settings 9. Implement Windows Security Baselines 10. Configure Windows Event Logging 11. Disable Insecure Protocols and Services 12. Set Up System Monitoring Tools as applicable 13. Implement Security Configuration Baseline (CIS) 14. Configure Browser Security 14.1. Secure web browsers by applying security settings, such as enabling pop- up blockers, disabling unnecessary plugins, and configuring privacy settings. 14.2.Apply appropriate GPO’s to centrally manage Microsoft Edge and Chrome. 15. Implement Group Policy Settings 15.1.Use Group Policy Objects (GPOs) to enforce security and configuration settings across all workstations in the domain. 15.2.Apply appropriate GPO’s to centrally manage Microsoft Edge and Chrome. 16. Deploy and Configure OneDrive to back up the Desktop and Documents folders. Passwords and Passphrases Passwords and passphrases are essential for keeping our systems and information safe. If someone uses a weak password or passphrase, it can allow unauthorized access to the City of Walker's resources. Everyone, including contractors, volunteers and vendors, needs to follow these guidelines for creating and managing their passwords and passphrases. Password and Passphrase Guidelines 1. All passwords and passphrases for users and administrators must follow these tips. 2. A passphrase is a longer password made up of several words, providing better security. 3. Don’t use the same password or passphrase for City accounts and personal accounts (like personal email or banking). 4. Do not use the same password for different City systems. 5. Accounts that have special privileges should have their own unique passwords or passphrases that are different such as more complex or longer than normal user accounts. 6. When passwords and/or Passphrases are used, they must meet or exceed the following specifications: 6.1. Contain at least 14 characters. 6.2. You cannot use a previous password or passphrase. 6.3. Mix It Up: While not required, using a mix of uppercase letters, lowercase letters, numbers, and symbols is a good idea. 6.4. Don’t use more than two of the same character next to each other (like "aaaaaa" or "1234abcd") 6.5. Password or passphrases cannot be on the “banned” list which will be maintained by IT. 7. Always change any default passwords and passphrases during your first login. Page | 11 Page 19 of 31 Information Technology & Cybersecurity 8. Passwords and Passphrases must only be changed when there is evidence of a breach. All employees are expected to use the City’s password management tool, though exceptions can be made with approval from the IT Director. If you try to use a password or passphrase that doesn’t meet the requirements, the system will tell you why and ask you to choose a different one that fits the guidelines. Password and Passphrase Protection 1. Never share your passwords or passphrases with anyone. Treat them as sensitive information that needs to be kept private. IT employees will never ask for your password. 2. Don’t send your passwords or passphrases in emails or any other electronic messages. 3. Don't say your passwords or passphrases over the phone to anyone. 4. Don’t give any clues about how you create your password or passphrase, like mentioning your last name. 5. Keep your passwords and passphrases to yourself, even from people like assistants, managers, coworkers, or family members. 6. Don't write down your passwords or store them in your office. Also, don’t save them on your computer or mobile devices unless they are in a password manager. 7. If you think someone may have discovered your password, let the IT Department know right away and change all your passwords. If you try to log in unsuccessfully five times, your account will be locked for 30 minutes. If you need help right away, call the City’s IT Helpdesk at (616) 791-6810. Remote Access Purpose and Scope This section provides guidance for securely connecting to the City of Walker's network from outside locations. It applies to all City employees, contractors, vendors, and agents (referred to as "Authorized Users") who need remote access to the City's network. Our goal is to protect sensitive data, systems, and the City's reputation while enabling productive remote work. General Guidelines 1. Remote access is granted only when necessary for job duties and must be approved by the IT Department. Access is provided through City-issued devices only; personal devices are not permitted. 2. Authorized Users are responsible for maintaining the security of their remote connections and preventing unauthorized access. They must comply with the City's Acceptable Use Policy and use remote access solely for City business. 3. All remote connections must use the city provided VPN client. 4. Multi-factor authentication is required for all remote access. 5. Devices used for remote access must have up-to-date Endpoint Protection Page | 12 Page 20 of 31 Information Technology & Cybersecurity software and security patches installed. 6. When working remotely, users should be cautious in public spaces, never leave devices unattended, and ensure the use of the VPN for transmission of Confidential data. Third-Party Access Third parties requiring remote access must complete a Third-Party Connection Agreement and receive approval from the IT Department. Their access is limited to necessary resources only and is monitored and logged. Third parties such as vendors will be assigned a remote access portal to utilize and are not permitted to directly connect or VPN connect to the City’s network or systems. Third parties are prohibited from installing remote access software such as TeamViewer, Screen Connect, or other software on City owned or operated systems without the explicit permission of the IT Director. Support and Assistance For remote access setup, troubleshooting, or security questions, contact the IT Helpdesk: Email: Helpdesk@walker.city Phone: (616) 791-6810 Page | 13 Page 21 of 31 SECTION 120.0 ATTENDANCE, WORKING HOURS AND TIME OFF The City's successful operations depend in large part upon the regular attendance of each of its employees. This section of the personnel manual addresses working hours, attendance, and overtime. Unnecessary and unexcused absences, therefore, are not acceptable because they affect not only the City operations but also the way in which co-employees are able to do their jobs. All employees are expected to report for work on time and when scheduled. While certain allowances will be made for occurrences beyond the control of an employee, chronic or excessive violations will be cause for disciplinary action up to and including dismissal. Employees should consult the appropriate sections of the Personnel Manual for specific policies on vacation, sick, and other leaves of absence. Employees who are employed under a collective bargaining agreement should refer to their contract for details related to working hours, attendance, and overtime. Any employee who is unable to report for work or who will be delayed must notify his/her supervisor within 30 minutes before the regularly scheduled starting time or, in an emergency, as soon as is practical. • Management may require a doctor's certificate from an employee who has been absent. In cases of continued unsatisfactory employee attendance or punctuality, the immediate supervisor, upon concurrence with the City Manager or his/her designee, will issue a written warning to the employee and a copy will be placed in the employee's personnel file. Further incidence of tardiness or absence will be grounds for disciplinary action. Section Date Original Issued Date Last Revised Approval Personnel 120.0 10/15/93 5/10/9904/24/2025 CommitteeCVM Page 22 of 31 SECTION 120.1 WORKDAY AND WEEK PURPOSE This policy establishes the operating hours of all City offices. POLICY City office hours are set in accordance with department needs. The following is a list of city offices and their hours of operation: City Hall and Police and Fire administrative office hours are open 7:30 a.m. to 5:00 p.m., Monday through Thursday, and 7:30 a.m. to 11:30 a.m. on Friday. Department of Public Works, and Engineering Department office hours are 7:00 a.m. to 3:30 p.m. Monday through Friday. , Walker Ice and Fitness Center is open to the public from 5:00 a.m. to 9:00 p.m. Monday through Friday and 7:00 a.m. to 7:00 p.m. on Saturday and Sunday. Summer hours (May 1st through September 30th) are 5:00 a.m. to 9:00 p.m. Monday through Friday and 7:00 a.m. to 5:00 p.m. on Saturday and Sunday, Police, Court and Fire Departments will schedule work hours in accordance with department needs. 59th District Court office hours are Monday through Wednesday 7:30 a.m. – 5:00 p.m., Thursday 8:00 a.m. – 5:00 p.m., and Friday 7:30 a.m. – 3:00 p.m. Department supervisors may establish different hours of operation depending on department needs. Any changes to these office hours will be posted publicly on city websites, social medias, and physically on building doors when possible. Lunch and Breaks • Full-time, regular part-time, part-time and temporary employees are accorded one hour for lunch and a 15-minute personal break in the morning and afternoon. Employees working an 8-hour shift or longer are afforded a minimum of a thirty (30) minute unpaid lunch break and two 15-minute paid personal breaks (one in the morning and one in the afternoon). Some employees may be eligible for a one-hour lunch break, depending on their work schedule. Full-time Firefighters are paid for all break times. Employees working less than 8 hours in a shift should coordinate break time with their supervisor. If an employee’s break time is thirty (30) minutes or longer, the break is unpaid. Lunch/personal breaks and work schedules may be developed by the appropriate department supervisor as necessary to maintain minimal disruption in work. Combining the morning personal break and/or the afternoon personal break with the lunch hour is not permitted. Under no circumstances shall these breaks be abused. Abuses may result in disciplinary action by any supervisor. Page 23 of 31 PROCUDURES The City Manager will set hours of operation for all city offices. Department Heads can modify an employee’s schedule based on department needs. Any change in schedule will be communicated to employees as timely as possible, understanding that some positions are subject to matters of weather and other emergency conditions/situations and advanced notification may be difficult. Section Date Original Issued Date Last Revised Approval Personnel 120.1 10/15/93 6/25/1204/30/2025 CommitteeDPS Page 24 of 31 SECTION 120.2 OVERTIME PURPOSE On occasions, employee workload requires more than the usual workday to maintain the City's high standards of service. While employees are not usually required to work overtime, cooperation under these circumstances is appreciated. This policy covers details separate from any Fair Labor Standards Act (FLSA) rules and regulations pertaining to overtime. POLICY The Assistant City Manager or his/her designee shall establish a schedule of regular work hours for employees (normally forty ([40]) hours per week) which may be modified by the department head to accommodate City's operations within budget or for other reasons as deemed necessary. • Overtime is time in excess of fifteen (15) minutes beyond the scheduled work hours in a working day. It shall constitute authorized work in excess of the normal number of scheduled hours, excluding meal time, for any calendar week. All overtime must be authorized by the department supervisor prior to working the overtime hours. If overtime is not authorized by the department supervisor prior to its occurrence, the employee must subsequently have the overtime approved by justifying the overtime to the department supervisor. In all cases, it is the duty of the department supervisors to exercise control over all overtime work. Non-Exempt Employees (excluding police and firefighting personnel) are entitled to overtime pay and will be paid at the rate of one- and one-a-half (1and-1/2) times regular hourly rates for hours worked in excess of forty (40) hours in a seven-day (7) work week. Time-off in lieu of overtime pay is not permitted unless otherwise allowed by department policy. Non-Exempt Police Employees are entitled to overtime pay as outlined in their collective bargaining agreement. Non-Exempt Firefighting Employees are entitled to overtime pay and will be paid at the rate of one and a half (1 and ½) times regular hourly rates for hours worked in excess of 106 hours in a fourteen (14) day pay period. Time off in lieu of overtime pay is not permitted. Exempt Employees are not eligible for overtime compensation. Paid on Call Fire Department personnel working who also work full-time in another position for the City will be compensated at their regular full-time rate of pay if they are called to a fire before the end of their regular workdaycalled out on a fire call prior to the end of his/her regular day shall be paid at the rate of his/her regular full-time employment. Any time spent working as a firefighter in excess of his/her their regular workday hoursas a fire fighter shall be paid at the same rates as established for Paid on Call fire fighters. Any hours worked in excess of FLSA thresholds depending on employee position will be paid at one and a half (1 and ½) times regular hourly rate. Page 25 of 31 If attendance for any approved meeting is required, the employee will receive compensation in accordance with all pay policies mentioned above including overtime when applicable. An approved employee meeting is defined as being any meeting where attendance is required and sponsored by the City of Walker for its employees as approved by the City Manager. Vacation, sick time, and holiday pay are excluded from overtime calculation. See Section 130.0 Vacation and 130.3 Holidays for details regarding additional overtime pay qualifiers. PROCEDURE Employees will report hours worked on their timesheet. If an employee’s hours are going to exceed their regularly scheduled work week, employees should notify their supervisor of the impending overtime if they are not already aware. Department Heads should authorize the overtime or adjust the employee’s schedule for the remainder of the workweek to account for the time worked. Any eligible overtime reported to payroll for qualifying employees will be paid at one and one half (1 and ½) times the employee’s regular hourly rate. Section Date Original Issued Date Last Revised Approval Personnel 120.2 10/15/93 3/15/1006/17/2025 CommitteeDPS Page 26 of 31 SECTION 120.3 UNEXCUSED ABSENCEATTENDANCE PURPOSE Punctual and regular attendance is an essential responsibility of each employee. This policy outlines the City of Walker’s rules and procedures for handling employee absences and tardiness to promote efficient City operations and minimize absences. POLICY Employees are expected to report to work as scheduled, on time and prepared to start working. Employees also are expected to remain at work for their entire work schedule. Late arrival, early departure and other absences from scheduled hours are disruptive and must be reasonably avoided. This policy does not apply to absences covered by the Family and Medical Leave Act (FMLA), the Michigan Earned Sick Time Act (ESTA), or leave provided as a reasonable accommodation under the Americans with Disabilities Act (ADA). These exceptions are described in separate policies. Absence "Absence" is defined as the failure of an employee to report for work when he or she is scheduled to work. The two types of absences are defined below: • Excused absence occurs when all the following conditions are met: o The employee provides sufficient notice to the employee’s supervisor prior to the start of an employee’s shift or as far in advance of absence as is reasonably possible. o The employee has sufficient accrued time off to cover the absence. o If it is necessary for an employee to be absent or late for work because of a qualified reason under the ESTA, the employee must follow Section 130.1 for reporting and use of earned sick time. • Unexcused absence occurs when any of the above conditions are not met. Any absence that is not approved by the immediate supervisor is an unexcused absence. Penalty for such absence will be loss of pay for the period involved. All excused absences must use available leave time from employee accrual banks for each specific type of leave unless otherwise allowed by City or department policy. Unexcused absences will be unpaid. • Employees are expected to notify their supervisors at once if they cannot work because of an illness, injury, etc. • Any employee who fails to report to work for a period of is on unexcused absence for three (3) consecutive workdays without providing proper notice under this policy will be considered as having voluntarily resigned thereby terminating the employment relationship. If an unexcused absence occurs on the day preceding or following a scheduled holiday, the employee will not receive pay for the holiday. Tardiness and Early Departure Employees are expected to report to work and return from scheduled breaks on time. If employees cannot report to work as scheduled, they must notify their supervisor no later than their regular Page 27 of 31 starting time. This notification does not necessarily excuse the tardiness, but simply notifies the supervisor that a schedule change may be necessary. Employees who must leave work before the end of their scheduled shift must notify a supervisor immediately. Disciplinary Action Unexcused absenteeism and excessive tardiness may result in immediate disciplinary action. In cases of continued unsatisfactory employee attendance or punctuality, the department head upon concurrence with the City Manager or his/her designee, will issue a written warning to the employee and a copy will be placed in the employee's personnel file. Further incidence of tardiness or absence will be grounds for disciplinary action, up to and including discharge. Time off qualified and designated as earned sick time under Section 130.1 will not be utilized as the basis for attendance points or disciplinary action. PROCEDURE Department Heads should communicate the appropriate method for employee’s to report an absence or tardiness within their department. Employee’s should report any absences, tardiness, or early departures as soon as possible. If the employee is aware of future obligations that will impact their ability to work their scheduled shifts, they should report these absences to their supervisor as soon as possible to allow the supervisor to adjust work assignments as needed. All excused absences should be reported on an employee’s timesheet using the appropriate leave time requested. Department Heads should confer with the Human Resources Department for any reoccurring attendance issues that may require disciplinary action. Section Date Original Issued Date Last Revised Approval Personnel 120.3 10/15/93 5/10/9904/24/2025 CommitteeCVM Page 28 of 31 SECTION 120.4 SEVERE/INCLEMENT WEATHER PURPOSE It is the policy of the City of Walker to remain open for business during most periods of inclement weather; however, where extraordinary circumstances warrant, due to weather or other unforeseen circumstances, the City reserves the right to close City offices. POLICY The City Manager or his/her their designee will determine whether the City administrative offices will be closed due to inclement weather. Department heads will be notified by phone, and will be responsible for contacting their respective department employees. Notice will be given as early as possible. Any City office closure will also be reported to news agencies and City of Walker social media platforms. If inclement weather necessitates the closing of City Hall, employees shall be paid for the time not worked. If City Hall remains open and inclement weather prevents an employee from getting to his/hertheir work station, the employee will not be paid for the time not worked. The employee may, with approval of the City Manager or his/her their designee, charge the time to vacation or other appropriate leave. PROCEDURE The City Manager will determine if City offices will be closed as soon as possible. They will notify department heads (via phone call or text message). Social media will be updated with the notification and news agencies will be notified. Department heads will notify their department employees directly after they are notified by management. Department heads will include regular scheduled hours on employee’s timesheets for the missed work day(s). Department heads should contact Human Resources with any questions on how to apply this time. Employees should notify their supervisor if they cannot report to work due to inclement weather as soon as possible using Section 120.3 Attendance as a reference. Section Date Original Issued Date Last Revised Approval 120.4 5/10/99 04/30/2025 Personnel Committee Page 29 of 31 SECTION 120.5 RECORD OF HOURS WORKED - TIME REPORTS PURPOSE This policy outlines rules to ensure accurate reporting of time worked by employees which assists the City of Walker to comply with labor laws and maintain efficient payroll processes. This policy applies to all non-exempt employees and includes guidelines for exempt employees. POLICY It is the responsibility of each City non-exempt hourly employee to accurately record actual time worked, whether through digital timekeeping system, paper timesheet, or time clock. Exempt employees are expected to record all hours worked to the nearest quarter hour for workload management purposes. Department supervisors are expected to enforce the following procedures within their department. PROCEDURE Instructions for use of the digital timekeeping system are available on the citywide drive. Please check with the Human Resources (HR) department for further details and instructions if necessary. HR will provide new employees with onboarding training of the digital timekeeping platform at time of hire. Employees using paper timesheets or a time clock will receive training from their supervisor on correctly recording time. Employees are to record their time on the City of Walker Time Sheet in the proper categories to accurately and completely report hours worked for each workday on a timesheet, either digital or paper, or use a time clock for logging hours. Employees are not compensated for unused break periods. Time is to be recorded in no less than one-quarter (1/4) hour increments. Employees should ensure that appropriate payroll activities are entered into the timekeeping system for any entry that requires one. Employees shall record only their own time on their own time sheets. Time sheets are not to be tampered with or falsified. Violations may result in immediate dismissal. Falsifying time sheets may result in immediate dismissal for all employees involved. An employee must not request or permit an unauthorized employee to report their time worked. An employee must not falsify or incorrectly report the time worked of another employee or instruct/advise another employee to falsify or incorrectly report time. Any of these actions are grounds for corrective action, up to and including termination. The City of Walker Time Sheet form can be obtained in the Employee Benefits Office or on the City’s intranet Finance Folder. In the event of an error in reporting time, employees must immediately report the problem to the department supervisor. All supervisors are responsible for the following: Page 30 of 31 o Supervisors must ensure that employees are paid for all time worked. o Supervisors must not falsify, alter, or incorrectly report time worked by an employee, or instruct/advise an employee to do the same. Any of these actions are grounds for corrective action, up to and including termination. o Supervisors should not expect employees to log in and record hours on days they are not expected to work. o Supervisors must ensure that an employee who misses a meal period or whose meal period is interrupted is paid for the meal period. o Supervisors must ensure that they review all timekeeping records and submit corrections for any errors or omissions before they are submitted for payment. o Supervisors must discuss and document any changes to the timekeeping record created by an employee. Under no circumstances may an employee be paid for less time than they actually worked. Department heads should review all timekeeping records at the conclusion of each pay period and submit them to HR by noon 12:00 PM on Monday succeeding the conclusion of the pay period. If a department head is unavailable, they should delegate their responsibility to another manager within the department or their supervisor. Any changes to hours worked from previous pay periods should be submitted to HR in writing by the department head. HR will adjust timekeeping records as appropriate and retain records accordingly. If retroactive pay is owed to the employee, payment will be made according to the rules outlined in Section 90.1 Pay Period. Section Date Original Issued Date Last Revised Approval Personnel 120.5 10/15/93 6/21/0104/30/2025 CommitteeCVM Page 31 of 31

Get email alerts for Walker

A daily email when new agendas and minutes are posted.

Report an issue with this meeting