Press Releases

Audit Report TI-17-09 – Economic Development Bank for Puerto Rico, Information Systems Division

March 27, 2017

The Office of the Comptroller of Puerto Rico issues a favorable opinion with exceptions on the internal controls established for the administration of the security program, logical and physical access, service continuity, systems applications, and other controls of the Information Systems Division of the Economic Development Bank for Puerto Rico.

The seven-finding Report reveals deficiencies related to the generally accepted security practices for information systems in the banking industry and the Government. The Risk Assessment for 10 identified processes did not include an inventory of all information systems assets, did not detail the criticality classification of the 10 processes, nor did it include the possible threats or vulnerabilities of each process.

Our auditors identified the lack of a business continuity plan and of an alternate information systems center for the recovery of computerized operations when unexpected events arise that affect their operation. In addition, an applications developer official also performed conflicting operator functions, a fact that could allow changes to be made to the programming without the required authorization.

The Report notes that the systems continued to use an operating system discontinued by the provider in 2015, the documentation of the changes to the applications was incomplete, and the cables connecting the Bank's communication equipment are disorganized (see photos in Exhibit 1). In this regard, the policy established in Circular Letter 77-05 is that, to reasonably ensure the security of the equipment, the cables connecting the communication equipment must be kept organized.

The audit recommends in particular that the Bank ensure that, within a reasonable time, it addresses the recommendations of the external audits to correct 25 deficiencies noted in 2013 and eight commented on in 2015.

The Report covers the period from September 16, 2015 to March 4, 2016.

See Audit Report TI-17-09

To view other published reports, visit our Audit Reports section.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®