Section 282.318(4)(d)(e)(g), F.S. The following information is confidential and exempt and may not be disclosed except as provided in the subsection: risk assessment information to determine security threats to data, information, and information technology resources of the agency; internal policies and procedures to assure the security of the data and information technology resources that, if disclosed, could facilitate the unauthorized modification, disclosure, or destruction of data, information, or information technology resources; and results of periodic internal audits and evaluations of the information technology security program for an agency’s data and information technology resources. Section 282.318(5), F.S. Portions of risk assessments and other reports of a state agency’s cybersecurity program are confidential and exempt if disclosure would facilitate unauthorized access to or unauthorized modification, disclosure or destruction of data or information as described in the exemption. Disclosure is authorized as provided in the exemption. Section 282.318(7), F.S. Those portions of a public meeting which would reveal records which are confidential under subsection (5) are exempt from s. 286.011. All exempt portions shall be recorded and transcribed. Disclosure is authorized as provided in the exemption. (Florida Office of the Attorney General // © March 9, 2023)