
The Office of the Comptroller of Puerto Rico issued a qualified opinion on the operations of the information systems of the Information Technology Area of the Puerto Rico Highways and Transportation Authority.
The Report revealed that, as of October 26, 2016, the Authority had not prepared a risk analysis report of the computerized information systems. This situation prevents the Authority from estimating the impact that risk elements would cause to the information systems and from establishing how to protect them. In addition, it makes it difficult to develop a business continuity plan in which the control measures and the steps to follow in the event of a security threat are determined.
In fact, the two-finding audit notes that the Authority lacked a business continuity plan for the audited period. In addition, the Contingency Plan was not up to date and did not include necessary requirements to address emergency situations such as: details of the configuration of critical equipment, content of the backups, and the measures to restore such backups.
Contrary to what is established in the Contingency Planning of the Federal Information System Controls Audit Manual, the Authority had not formalized a written agreement for the use of an alternate site for the restoration of its operations in cases of emergency. A similar situation had been commented on in Audit Report TI-07-10 of June 4, 2007. The Report covers the period from July 11, 2016 to June 30, 2017.
See the Audit Report TI-19-07.
To see other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.