Press Releases

Audit Report TI-19-04, Music Conservatory Corporation of Puerto Rico, Information System Office

February 11, 2019

The Office of the Comptroller of Puerto Rico issued a qualified opinion on the operations of the Information System Office of the Music Conservatory of Puerto Rico. A qualified opinion is issued when the noncompliances, individually or in the aggregate, are significant but not pervasive.

The audit reveals that as of March 27, 2018, the Music Conservatory of Puerto Rico did not have a risk analysis report of the computerized information systems. The lack of this analysis prevents estimating the impact of the risk elements on the critical areas and systems in order to protect them from threats.

In addition, the Conservatory did not have a business continuity plan or a contingency plan. These plans are necessary to restore operations and critical applications in the event of an emergency or risks such as voltage variations, computer viruses, or natural disasters.

The four-finding Report notes that the Conservatory's Information Systems Office did not keep a copy of the backups off the Conservatory's premises. The guidelines in the Federal Information System Controls Audit Manual (FISCAM) establish that information backups and computerized programs must be stored in a secure place distant from the entity's premises.

Our auditors identified that the entity lacks a registry of programs installed on each of the computers. This situation and others noted are attributed to the rector's lack of knowledge about the specific tasks of the ISO.

The Report covers the period from January 22 to May 25, 2018.

See Audit Report TI-19-04.

To view other published reports, visit our Audit Reports section.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®