Press Releases

Audit Report TI-20-10, Land Authority of Puerto Rico Information Systems Office

June 15, 2020

The Office of the Comptroller of Puerto Rico issued a qualified opinion on the operations of the Information Systems Office of the Land Authority of Puerto Rico. A qualified opinion is issued when the instances of noncompliance, individually or in the aggregate, are significant but not pervasive.

The Report reveals that the approved Risk Analysis did not include the ArcGIS geographic information systems, which identify the maps of the Authority's estates and manage the land inventories. The Risk Analysis also did not include the control measures to protect the assets against possible threats. This situation prevents estimating the impact that the risk elements would have on its equipment and critical systems in order to protect them and reduce the loss of information.

The six-finding audit notes that the Authority had not formalized a written agreement for the use of an alternate site, at which the computerized information systems could be restored in case of emergency. This situation, contrary to what is established in the Federal Information Systems Controls and Audit Manual issued by the Government Accountability Office, had been commented on in Audit Report TI-07-09 of 2007.

The Authority also did not keep a copy of the backups outside the Authority's premises. The information backups of the Authority's 21 servers were performed in the Veeam Backup and Replication application.

The auditors found multiple deficiencies with the account control, audit, assigned privileges, and security option policies. These situations can foster the commission of irregularities or the alteration by error of the data contained in the systems. In addition, they prevent maintaining a record of unusual events in order to take corrective or preventive measures in time.

Contrary to the Standards and Procedures for the Installation and Configuration of the Network, the Authority lacked the evidence of the requests for access to the information systems. For the period evaluated, no evidence was found of seven users who began working between 2017 and 2018, nor of the modification of privileges of two users who changed positions.

The audit recommends establishing environmental controls to correct the lack of equipment to detect smoke and the fire alarms; and establishing a work plan to organize and identify the cabling of the communication equipment. These deficiencies had already been commented on in Audit Report TI-08-02 of 2007.

The Report covers the period from April 8 to August 27, 2019.

See Audit Report TI-20-10.

To view other published reports, visit our Audit Reports section.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®