
The Comptroller of Puerto Rico issues a qualified opinion on, among others, the controls for the continuity of the services, the logical access to the communication networks, and the processing and outputs of data of the Sage Fund Accounting (Sage MIP) application of the Office of Information Systems of the Corporación de Puerto Rico para la Difusión Pública. A qualified opinion is issued when the instances of noncompliance, individually or together, are significant but not pervasive.
During the audit a deficiency was detected in the withholding at source of the income tax of the Corporation's employees. To that effect, we referred this situation to the Secretary of the Treasury on April 25, 2018, for his analysis and consideration.
The Report reveals the lack of a business continuity plan that included the complete and updated specific plans of the OSI. The examination of the contingency plan provided to our auditors in December 2015 was not approved by the president of the Corporation's Board and did not contain the requirements to address emergency situations. In addition, the Corporation did not have an alternate center to restore its operations in case of emergency. Similar situations had already been commented on in Audit Report TI-02-11 of May 7, 2002.
The five-finding audit notes multiple deficiencies in the physical controls in the cabling distribution rooms. Our auditors also identified a lack of controls in the security parameters and access controls to the network and the lack of periodic reviews of the event logs of the servers' operating systems. For example, the policies related to passwords and the network access time for all the accounts had not been defined. Situations similar to these had been commented on in Audit Report TI-03-10 of May 12, 2003.
The Report mentions that the Office of Information Systems did not keep copies of the backups in a secure place outside the Corporation's premises, and the Backup Log did not include information about the content of the stored backups nor about the server to which they belonged. This situation, contrary to Policy TIG-003 of Circular Letter 77-05 on the Security of the Information Systems, deprives the Corporation of having control over the backups and, in case of emergency, of not being able to make use of them for the continuity of operations.
The Report covers the period from September 30, 2015, to September 15, 2016.
See Audit Report TI-18-10.
To view other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.