
The Comptroller of Puerto Rico issued a qualified opinion on the operations of the Information Technology Office and of the information systems of the Puerto Rico Tourism Company.
The Report points out that the Tourism Company lacks a risk analysis of the computerized information systems. The Company provided our auditors with a Contingency and Disaster Recovery Manual, but this document does not contain the basic aspects for a risk analysis, such as the inventory of existing assets with their classification according to the level of importance for the continuity of operations, among others. A similar situation had already been noted in Audit Report TI-07-04 of 2006.
The three-finding audit indicates that in the Company the records of security events and violations that the operating system itself alerts (security events logs) were not examined. This situation, contrary to Policy ATI-003 of Circular Letter 140-16, on the security of information systems and the general standards on the implementation of systems, prevents the detection of critical errors or problems with unauthorized access to the servers and computers.
Nor did the Company carry out periodic reviews of the user access accounts as provided by the Regulation for Users who manage Information Technology Systems. This situation may allow unauthorized persons to gain access to confidential information and make improper use of it, or for irregularities to be committed and/or the data contained in the information systems to be altered by error or deliberately.
The Report covers the period from January 22 to December 21, 2018.
See Audit Report TI-20-01.
To see other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.