Press Releases

Audit Report TI-20-09, Municipality of Cayey Information Technology Office

June 10, 2020

The Comptroller of Puerto Rico issued a qualified opinion on the operations of the Information Technology Office of the Municipality of Cayey. A qualified opinion is issued when the noncompliance items, individually or together, are significant, but not pervasive.

The audit reveals the lack of a risk analysis report for the information systems, and of a written procedure for incident handling in Cayey. This situation, contrary to the provisions of Circular Letter 140-16, on the Implementation of Systems for the Purchase of Equipment and Programs and the Use of Information Technology, prevents the Municipality from estimating the impact that risk elements would have on the main areas and systems in order to protect them. In addition, the lack of an incident management plan may cause duplication of effort and time in the event of unexpected situations.

The Report, with four findings, states that the Municipality does not have a contingency plan that identifies, among others, an alternate data processing center, the identification and configuration of critical equipment and files, as well as the procedures for when the computing center cannot receive or transmit information to users. What is described represents a high risk of incurring excessive and unnecessary expenses of resources, and prolonged interruptions of the services offered to users.

The Report indicates that the Municipality did not have standards or procedures to configure the security policies on the main server. This situation, contrary to the policies established in Circular Letter 140-16 and to the guidelines established in the Federal Information Systems Controls Audit Manual (FISCAM), may allow unauthorized persons to gain access to confidential information and make improper use of it. The evaluation conducted also found that 90% of the access privileges assigned to personnel do not have the authorization and justification documents for the privileges granted.

As of July 2, 2019, the Municipality did not perform periodic backups of the stored information, nor of the main server configuration. During Hurricane Maria the main server was damaged and had to be configured from scratch; a situation that would have been avoided had there been a backup. In addition, the director of Human Resources indicated that the backup of the ABS application for managing attendance records and the balances of employees' accrued leave was recorded on an external medium (pen drive) and no copy was kept off the office premises.

The Report recommends that the Office of Management and Budget ensure that the Municipality complies with the Corrective Action Plan. In addition, it recommends that the mayor have a risk analysis report prepared and ensure that it is kept up to date, among others.

The Report covers the period from March 13 to August 2, 2019.

See Audit Report TI-20-09.

To see other published reports, visit our Audit Reports section.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®