
The Comptroller of Puerto Rico issues a qualified opinion on the internal controls and their effectiveness in the administration of security, logical and physical access, continuity of service, segregation of duties, and computerized equipment of the Office of Information Systems of the Performing Arts Center Corporation of Puerto Rico. A qualified opinion is issued when the instances of noncompliance, individually or in the aggregate, are significant but not pervasive.
The Report reveals that the Corporation had not prepared a risk analysis report of the computerized information systems, which makes it impossible to develop a business continuity plan with the corresponding control measures. In addition, the lack of a business continuity plan and of an alternate site to recover its operations in case of emergency may foster improvisation and affect the prompt reestablishment of the Corporation's functions.
The nine-finding audit notes multiple deficiencies related to the access accounts and the control of the information backups. Our auditors identified accounts of former employees not deactivated and that were used after their separation date. In addition, backups of the security events of the operating systems were not performed and, from 2010 to 2015, the information backups were not sent to the external company that stores them in the safe deposit box.
Contrary to Policy TIG-003 on the Security of Information Systems of Circular Letter 77-05, Standards on the Acquisition and Technological Implementation for Government Organizations, the analyst did not provide for examination the authorized supporting documents to grant administrator privileges to the five access accounts that had them assigned. These privileges allow users to start or cancel services, configure the system security, and administer the access accounts.
The audit detected five computers with 68 programs that were not authorized nor related to the work, a lack of training necessary for the analyst to perform his functions, and that the Corporation did not comply with the recommendations made in Audit Reports TI-02-06 of 2001 and TI-03-11 of 2003.
The Report covers the period from May 13, 2015 to May 27, 2016.
See Audit Report TI-18-07.
To see other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.