Press Releases

Audit Report TI-18-09, Puerto Rico Planning Board Information Systems Program

May 10, 2018

The Comptroller of Puerto Rico issues a qualified opinion on the controls for the administration of security, logical access, continuity of service, segregation of duties, and computerized equipment of the Information Systems Program of the Puerto Rico Planning Board. A qualified opinion is issued when the instances of noncompliance, individually or in the aggregate, are significant but not pervasive.

The Report reveals that as of August 16, 2016, the Board had not prepared a risk analysis report or a business impact analysis of the computerized information systems. These situations make it impossible to estimate the impact that risk elements would have on critical systems in order to protect them, and make it difficult to develop control measures that, in the event of a contingency, would minimize the risks.

The four-finding audit notes that the Board lacked a business continuity plan and an alternate site to restore its critical operations in case of emergency. The purpose of such a plan is to achieve the prompt functioning of the systems and restore the Board's operations in case of risks such as: voltage variations, computer viruses, malicious attacks on the network, or natural disasters, among others.

Our auditors identified that in case of emergency, the Board cannot make use of the information backups since periodic backups of the computerized information were not performed. In addition, from July 1, 2015 to May 5, 2017, the Board did not use a security file for the backups, which it had leased for $7,500 from an external company.

Contrary to what is established in Policy TIG-003 of Circular Letter 77-05 on adequate controls in computerized information systems, an electronic systems programmer of the Board performed conflicting functions as a programmer and other additional tasks. This situation is aggravated since there was no alternate supervisory control by the director of information systems.

The Report covers the period from May 31, 2016 to June 13, 2017.

See Audit Report TI-18-09.

To see other published reports, visit our Audit Reports section.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®