Press Releases

Audit Report TI-21-03, Department of Labor and Human Resources, Office of Computing and Information Systems

November 23, 2020

The Office of the Comptroller of Puerto Rico issued a qualified opinion on the operations of the Office of Computing and Information Systems of the Department of Labor and Human Resources. A qualified opinion is issued when the instances of noncompliance, individually or in the aggregate, are significant but not pervasive.

The Report reveals that the Operational Plan and the Contingency Plan approved in 2017 for the continuity of operations were not updated. Both plans contained contact names of former officials and former employees, and referenced an alternate location and external vault that no longer exist. In particular, the Contingency Plan did not contain requirements necessary to address emergency situations, such as the detail of the critical equipment configuration or the procedures for when the network cannot provide services.

In addition, the Department had not identified an alternate center to restore the computerized operations of the network operations center in the event of an emergency. These situations may foster improvisation and represent a high risk of incurring excessive expenses or prolonged interruptions of services to users.

The three-finding audit notes that a copy of the data backups, such as the chauffeur's social security, the financial and human resources applications, and others, was not kept off the Department's premises but rather on a shelf located in the same place where the backup was found. A similar situation was commented on in Audit Report TI-09-14 of 2009. The Report recommends that the chief information officer ensure that a procedure is drafted requiring a copy of the backups to be kept in a secure location distant from the Department's operations center.

Contrary to the regulations in force on information systems security, the parameters in the main server were not configured for the allowed failed access attempts before locking an account (account lockout threshold). This situation fosters the commission of irregularities or the alteration of data contained in the systems.

The report covers the period from April 29 to October 25, 2019.

See the Audit Report TI-21-03.

To view other published reports, visit our Audit Reports section.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®