Skip to content

Chapter 22I — OFFICE OF CYBER SECURITY AND DUTIES OF THE CHIEF INFORMATION SECURITY…

San Francisco Administrative Code · 2025 edition · updated 2026-07-25 · San Francisco

Sec. 22I.1. Findings.

Sec. 22I.2. Purpose of Chapter.

Sec. 22I.3. Definitions.

Sec. 22I.4. Office of Cyber Security.

Sec. 22I.5. City Chief Information Security Officer.

Sec. 22I.6. City Departments.

SEC. 22I.1. FINDINGS.

On June 4, 2021, Mayor London Breed issued Executive Directive No. 21-02, announcing that protecting the City’s technology and information is vital to the proper functioning of the City and the ability of City departments and personnel to serve residents. In order to further the protection of City assets, the prevention, detection, and remediation of cyber-related incidents is a top priority of the City and essential to the security of San Francisco government and its residents. In the directive, the Mayor directed the City’s Chief Information Officer and the City Administrator to recommend changes to the Administrative Code to formalize and strengthen the City’s cyber security functions and programs.

(Added by Ord. 49-22, File No. 211294, App. 3/31/2022, Eff. 5/1/2022)

SEC. 22I.2. PURPOSE OF CHAPTER.

(a) The purpose of this Chapter 22I is to strengthen and coordinate the City’s security of information resources. The creation of the Office of Cyber Security will improve the City’s information security by doing the following:

(1) ensure coordination of City Departments’ response to cyber security threats;

(2) identify primary responsibility for the City’s response during emergencies caused by cyber security attacks;

(3) share best information security practices, procedures, and requirements with City Departments;

(4) provide review of proposed technology purchases by City Departments to address cyber security risks during procurement; and

(5) avoid uncoordinated and duplicative information or system security purchases by City Departments when such technology can be more effectively purchased as part of a coordinated City effort for maximum cost effectiveness and use.

(b) In enacting and implementing this Chapter 22I, the City is assuming an undertaking only to promote the general welfare. It is not assuming, nor is it imposing on its officers and employees, an obligation for breach of which it is liable in money damages to any person who claims that such breach proximately caused injury.

(c) Municipal Transportation Agency. Consistent with Charter Section 8A.101(d), the Municipal Transportation Agency shall comply with the provisions of this Chapter 22I and shall be solely responsible for its administration and enforcement with respect to matters within the Municipal Transportation Agency’s jurisdiction. The Municipal Transportation Agency Board of Directors shall provide the City Administrator with an annual report of reported incidents and its compliance with the established City information security standard.

(d) Public Utilities Commission. Consistent with Charter Section 8B.121(a), the Public Utilities Commission shall comply with the provisions of this Chapter 22I and shall be solely responsible for its administration and enforcement with respect to matters within the Public Utilities Commission’s jurisdiction. The Public Utilities Commission shall provide the City Administrator with an annual report of reported incidents and its compliance with the established City information security standard.

(Added by Ord. 49-22, File No. 211294, App. 3/31/2022, Eff. 5/1/2022)

SESC. 22I.3. DEFINITIONS.

For purposes of this Chapter 22I, the following definitions shall apply:

“City” means the City and County of San Francisco and all of its units or components of government.

“Chief Information Officer” means the Chief Information Officer for the City appointed pursuant to Administrative Code Section 22A.4.

“City Department” means any unit or component of City government, including but not limited to named departments, boards and commissions, offices, agencies, and officials.

“Committee on Information Technology” or “COIT” means the committee established in Administrative Code Section 22A.3.

“Information and Communications Technology” or “ICT” means information and communications technology and computer-based equipment and related services designed for the storage, manipulation, and retrieval of data by electronic or mechanical means, or both.

“Information Resources” means Information and Communications Technology operated by or for the City, including equipment, facilities, systems, applications, and cloud services that relate directly to data processing equipment or services which are directly managed by various departmental divisions for Management Information Systems (MIS), including but not limited to, the Controller’s Information Services Division (ISD), the Airport’s MIS Division, the Public Utilities Commission’s Bureau of MIS, and the Department of Public Health’s MIS.

“Information Security Standards” means standard requirements created by the Chief Information Security Officer for the protection and resiliency of the City’s information resources.

(Added by Ord. 49-22, File No. 211294, App. 3/31/2022, Eff. 5/1/2022)

SEC. 22I.4. OFFICE OF CYBER SECURITY.

(a) Establishment. The Office of Cyber Security is hereby created within the Department of Technology and shall be headed by the Chief Information Security Officer and staffed by such officers and employees as are authorized pursuant to the budgetary and fiscal provisions of the Charter.

(b) Mission and Purposes. The Office of Cyber Security shall have these missions and purposes:

(1) Advising the Mayor, the Board of Supervisors, the City Administrator, the City Chief Information Officer, and City Departments regarding information security for City Departments.

(2) Advising the Committee on Information Technology (COIT) on compliance with adopted information security standards, policies, and funding plans, and serving as a permanent member of COIT.

(3) Protecting City-connected technology and information resources.

(4) Continuously improving the City’s ability to detect cyber security events, contain and eradicate compromises to security, and restore information resources to a secure and operational status.

(5) Evaluating technology vendors and partners to identify cyber security risks to City operations.

(Added by Ord. 49-22, File No. 211294, App. 3/31/2022, Eff. 5/1/2022)

SEC. 22I.5. CITY CHIEF INFORMATION SECURITY OFFICER.

(a) Establishment of Position. There is hereby created the position of Chief Information Security Officer (CISO) for the City and County of San Francisco. The CISO shall:

(1) Be appointed by the Chief Information Officer following consultation with the City Administrator.

(2) Serve as a permanent member of COIT with the authority and responsibility to develop information security recommendations and implement COIT information security standards, policies, and procedures for all City Departments.

(3) Head the Office of Cyber Security.

(b) Purpose and Duties. The CISO’s duties shall include, but are not limited to the following:

(1) Develop and maintain a centralized cyber security detection, response, and recovery program, tools and operational capability for preventing and responding to compromises of City information resources for City Departments.

(2) Develop and maintain training, tools, and operational capability to minimize cyber security vulnerabilities of City information resources for City Departments.

(3) Provide a citywide information security standard to reduce the risk of compromise to the City’s information resources, including but not limited to receiving and responding to security incidents from City Departments, and mitigating the risks to City information resources.

(4) Conduct risk-based assessment of new vendor technologies or technology-related services during the procurement process.

(5) Support City Departments’ cyber emergency exercises and conduct periodic citywide cyber security emergency exercises with City Departments.

(6) Test cyber security preparedness of City Departments on a regular basis.

(7) Work with City Departments through the designated Departmental Information Security Officers to reduce the City’s risk to cyber security incidents.

(8) Develop and update citywide cyber security requirements to mitigate the City’s risk profile, and comply with legal and regulatory cyber security requirements.

(9) Support City Departments’ implementation of the City’s information security standards.

(10) Provide the Mayor and City Administrator with an annual report of reported incidents and each City Department’s compliance with the established City information security standard.

(Added by Ord. 49-22, File No. 211294, App. 3/31/2022, Eff. 5/1/2022)

SEC. 22I.6. CITY DEPARTMENTS.

(a) City Departments. Each City Department, (“Department”) shall:

(1) Appoint a Departmental Information Security Officer (DISO) to coordinate cyber security efforts with the CISO.

(2) Adopt the City’s information security standard for reducing the risk of compromise to the City’s information resources as a basis of their Department’s cyber security program.

(3) Consult with the Office of Cyber Security to evaluate cyber security risk prior to initiating new information technology projects, implementing major changes to information systems, or selecting vendors of technologies or vendors providing technology-related services.

(4) Support cyber incident response in accordance with the then-existing San Francisco Unified Cyber Command Plan.

(5) Conduct and update a Department cyber security risk assessment based on standards established by the Office of Cyber Security.

(6) Test and update the Department’s cyber security emergency response plan based on standards established by the Office of Cyber Security.

(7) Maintain Department cyber security requirements that are equivalent to or greater than the citywide information security standards and provide non-standard Department requirements to the Office of Information Security.

(8) Participate in citywide cyber security forum meetings organized by the Office of Cyber Security.

(b) Given the broad definition of “City Department” under Section 22I.3, and the wide range of sizes of City Departments, the requirement in subsection (a), above, that each City Department appoint a DISO shall not be understood to preclude the same person from serving as DISO for more than one City Department, nor preclude the DISO for a City Department from having other responsibilities.

(Added by Ord. 49-22, File No. 211294, App. 3/31/2022, Eff. 5/1/2022)

Get a plain-English answer with a citation back to this text.

Ask AI about this code
Contents — San Francisco Administrative Code
San Francisco Administrative Code
  1. Chapter 1 — GENERAL PROVISIONS
  2. Chapter 2 — BOARD OF SUPERVISORS
  3. Chapter 2A — EXECUTIVE BRANCH
  4. Chapter 2B
  5. Chapter 3 — BUDGET PROCEDURES
  6. Chapter 4 — CITY BUILDINGS E UIPMENT AND VEHICLES , Q,
  7. Chapter 5 — COMMITTEES
  8. Chapter 6 — PUBLIC WORKS CONTRACTING POLICIES AND PROCEDURES
  9. Chapter 7 — DISASTER COUNCIL
  10. Chapter 8 — DOCUMENTS RECORDS AND PUBLICATIONS ,
  11. Chapter 9A — FARMERS' MARKET
  12. Chapter 9B — FLEA MARKET
  13. Chapter 10 — FINANCE TAXATION AND OTHER FISCAL MATTERS ,,
  14. Chapter 10A — [REQUEST FOR SHERIFF’S SERVICES]
  15. Chapter 10B — SPECIAL LAW ENFORCEMENT AND PUBLIC WORKS SERVICES
  16. Chapter 10C — REIMBURSEMENT FOR TOWING AND STORAGE OF VEHICLES
  17. Chapter 10D — [RESERVED] CHAPTER 10E: PLANNING MONITORING
  18. Chapter 10F
  19. Chapter 10G
  20. Chapter 10H — RECOVERY OF COSTS OF EMERGENCY RESPONSE
  21. Chapter 11 — FRANCHISES
  22. Chapter 12 — HOUSING AUTHORITY
  23. Chapter 12A
  24. Chapter 12B — [REDESIGNATED]
  25. Chapter 12C — [REDESIGNATED]
  26. Chapter 12D — MINORITY/WOMEN/LOCAL BUSINESS UTILIZATION
  27. Chapter 12E — BAN ON CITY USE OF GAS-POWERED LANDSCAPING EQUIP…
  28. Chapter 12F — IMPLEMENTING THE MACBRIDE PRINCIPLES – NORTHERN …
  29. Chapter 12G — PROHIBITION ON USE OF PUBLIC FUNDS FOR POLITICAL…
  30. Chapter 12H — IMMIGRATION STATUS
  31. Chapter 12I — CIVIL IMMIGRATION DETAINERS
  32. Chapter 12J — CITY BUSINESS WITH BURMA PROHIBITED
  33. Chapter 12K — [REDESIGNATED]
  34. Chapter 12L
  35. Chapter 12M
  36. Chapter 12N — LESBIAN, GAY, BISEXUAL, TRANSGENDER, QUEER, AND …
  37. Chapter 12O — [REDESIGNATED]
  38. Chapter 12P — [REDESIGNATED]
  39. Chapter 12Q — [REDESIGNATED]
  40. Chapter 12R — [REDESIGNATED]
  41. Chapter 12S — WORKING FAMILIES CREDIT PROGRAM
  42. Chapter 12T — [REDESIGNATED]
  43. Chapter 12U
  44. Chapter 12V — [REDESIGNATED]
  45. Chapter 12W — [REDESIGNATED] 1
  46. Chapter 12X — [REPEALED]
  47. Chapter 12Y
  48. Chapter 12Z — [REDESIGNATED]
  49. Chapter 13 — JAILS AND PRISONERS
  50. Chapter 14 — [REDESIGNATED]
  51. Chapter 14A — DISADVANTAGED BUSINESS ENTERPRISE PROGRAM
  52. Chapter 14B — LOCAL BUSINESS ENTERPRISE UTILIZATION AND NON-DI…
  53. Chapter 14C — [EXPIRED]
  54. Chapter 15 — MENTAL HEALTH SERVICE
  55. Chapter 16 — OFFICERS AND EMPLOYEES GENERALLY
  56. Chapter 17 — PUBLIC OFF-STREET PARKING FACILITIES
  57. Chapter 18 — PAYROLL PROCEDURE
  58. Chapter 19 — PUBLIC SAFETY CAMERA ORDINANCE
  59. Chapter 19A — PUBLIC HEALTH
  60. Chapter 19B — ACQUISITION OF SURVEILLANCE TECHNOLOGY
  61. Chapter 20 — SOCIAL SERVICES
  62. Chapter 21 — ACQUISITION OF COMMODITIES AND SERVICES
  63. Chapter 21A — HEALTH-RELATED COMMODITIES AND SERVICES
  64. Chapter 21B — CORE INITIATIVES ADDRESSING HOMELESSNESS, DRUG O…
  65. Chapter 21C — [REDESIGNATED]
  66. Chapter 21D — FOOD PURCHASES AT HOSPITALS OPERATED BY THE DEPA…
  67. Chapter 21E — GOODS OR SERVICES CONTRACTS FOR INCARCERATED PER…
  68. Chapter 21F — SAN FRANCISCO PUBLIC UTILITIES COMMISSION SOCIAL…
  69. Chapter 21G
  70. Chapter 21H — PROCUREMENT OF FIREARMS AND AMMUNITION
  71. Chapter 22 — RADIO COMMUNICATION FACILITIES
  72. Chapter 22A — INFORMATION AND COMMUNICATION TECHNOLOGY
  73. Chapter 22B — TELECOMMUNICATIONS FACILITIES
  74. Chapter 22C — PUBLIC INTERNET ACCESS
  75. Chapter 22D — OPEN DATA POLICY
  76. Chapter 22E — CITY-OWNED FIBER-OPTIC FACILITIES
  77. Chapter 22G — OFFICE OF EMERGING TECHNOLOGY
  78. Chapter 22H — DESIGNATION UNDER HEALTH INSURANCE PORTABILITY A…
  79. Chapter 22I — OFFICE OF CYBER SECURITY AND DUTIES OF THE CHIEF…
  80. Chapter 22J — ARTIFICIAL INTELLIGENCE TOOLS
  81. Chapter 23 — REAL PROPERTY TRANSACTIONS
  82. Chapter 23A — SURPLUS PUBLIC LANDS ORDINANCE
  83. Chapter 24 — REDEVELOPMENT AGENCY
  84. Chapter 24A — ADMINISTRATIVE STRUCTURE LOCAL RENT SUPPLEMENT P…
  85. Chapter 24B — RELOCATION APPEALS BOARD
  86. Chapter 25 — STREET LIGHTING
  87. Chapter 26 — [RESERVED]
  88. Chapter 27 — HEALTHY NAIL SALON RECOGNITION PROGRAM
  89. Chapter 28 — ADMINISTRATIVE DEBARMENT PROCEDURE
  90. Chapter 29 — FINDINGS OF FISCAL RESPONSIBILITY AND FEASIBILITY
  91. Chapter 29A — APPROVAL OF POWER PLANT PLANNING CODE SEC. 303 C…
  92. Chapter 29B — CHILD CARE FEASIBILITY STUDY FOR CITY AND CITY-F…
  93. Chapter 30 — CENTRALIZATION OF WORKFORCE DEVELOPMENT
  94. Chapter 31 — CALIFORNIA ENVIRONMENTAL QUALITY ACT PROCEDURES A…
  95. Chapter 32 — RESIDENTIAL REHABILITATION LOAN PROGRAM
  96. Chapter 33 — COMMISSION ON THE STATUS OF WOMEN
  97. Chapter 33A — LOCAL IMPLEMENTATION OF THE UNITED NATIONS CONVE…
  98. Chapter 34 — NOTIFICATION TO ASSESSOR CONCERNING ZONING RECLAS…
  99. Chapter 35 — RESIDENTIAL HOTEL AND PDR COMPATIBILITY AND PROTE…
  100. Chapter 36 — COMMUNITY IMPROVEMENTS AREA PLANS AND PROGRAMS
  101. Chapter 37 — RESIDENTIAL RENT STABILIZATION AND ARBITRATION OR…
  102. Chapter 37A — RENT STABILIZATION AND ARBITRATION FEE
  103. Chapter 37B — MIDTOWN PARK APARTMENTS
  104. Chapter 37C — [EXPIRED]
  105. Chapter 38 — COMMERCIAL LANDLORDS; ACCESS IMPROVEMENT OBLIGATI…
  106. Chapter 39 — [RIGHT TO RETURN TO REVITALIZED PUBLIC HOUSING]
  107. Chapter 40 — HOUSING CODE ENFORCEMENT LOAN PROGRAM
  108. Chapter 41 — RESIDENTIAL HOTEL UNIT CONVERSION AND DEMOLITION
  109. Chapter 41A — RESIDENTIAL UNIT CONVERSION AND DEMOLITION
  110. Chapter 41B — COMMUNITY OPPORTUNITY TO PURCHASE ACT
  111. Chapter 41C — TIME-SHARE CONVERSION ORDINANCE
  112. Chapter 41D — RESIDENTIAL HOTEL VISITOR POLICIES
  113. Chapter 41E — RESIDENTIAL HOTEL MAIL RECEPTACLE ORDINANCE
  114. Chapter 41F
  115. Chapter 41G — RESIDENTIAL HOTEL COVID-19 PROTECTIONS
  116. Chapter 41H — [EXPIRED]
  117. Chapter 42 — INDUSTRIAL DEVELOPMENT AUTHORITY
  118. Chapter 43 — MUNICIPAL FINANCE LAW
  119. Title 1 — GENERAL PROVISIONS AND DEFINITIONS SEC. 43.1.1. TITLE.
  120. Title 2 — FINANCING RESIDENCES SEC. 43.1.7. LOANS FOR RESIDENC…
  121. Title 3 — BONDS
  122. Title 4 — SUPPLEMENTAL PROVISIONS
  123. Title 1 — GENERAL PROVISIONS AND DEFINITIONS SEC. 43.2.1. TITLE.
  124. Title 2 — FINANCING FACILITIES
  125. Title 3 — BONDS SEC. 43.2.17. ISSUANCE OF BONDS.
  126. Title 4 — SUPPLEMENTAL PROVISIONS SEC. 43.2.27. LIBERAL CONSTR…
  127. Title 1 — GENERAL PROVISIONS SEC. 43.10.1. TITLE.
  128. Title 2 — PROVISIONS RELATING TO FORMATION OF DISTRICTS SEC. 4…
  129. Title 3 — PROVISIONS RELATING TO BONDS SEC. 43.10.18. ALTERNAT…
  130. Title 4 — SUPPLEMENTAL PROVISIONS SEC. 43.10.22. LIBERAL CONST…
  131. Title 5 — CHANGE PROCEEDINGS SEC. 43.10.26. ALTERNATE PROCEDUR…
  132. Title 1 — GENERAL PROVISIONS AND DEFINITIONS SEC. 43.15.1. TIT…
  133. Title 2 — RESIDENCES SEC. 43.15.6. LOANS TO QUALIFIED 501(c)(3…
  134. Title 3 — BONDS SEC. 43.15.15. ISSUANCE OF BONDS; LOANS TO QUA…
  135. Title 4 — SUPPLEMENTAL PROVISIONS SEC. 43.15.25. LIBERAL CONST…

GoCodebook provides public access, search, citation, multilingual explanation, and practical interpretation of legally adopted building regulations. It is not a substitute for the official ICC or California code publications.