Press Releases

Audit Report TI-21-06, Agricultural Enterprise Development Administration Information Systems Office

December 18, 2020

The Office of the Comptroller of Puerto Rico issued a qualified opinion on the operations of the Information Systems Office (OSI) and on the systems of the Agricultural Enterprise Development Administration (ADEA). A qualified opinion is issued when the instances of noncompliance, individually or in the aggregate, are significant but not pervasive.

The Report reveals that after three years and an investment of $253,651, the Pilot Program for the Implementation of an Electronic Cattle Identification System and the Database Application at ADEA has not been completed. This electronic identification technology consists of placing a ruminal bolus in the animal's stomach, which serves to identify it, prevent its theft, and as a perpetual inventory control measure. The bolus is a device that records information that is transferred to ADEA's database.

The Comptroller's auditors detected that, in the inventory of the 40,000 ruminal boluses in 2018, 352 boluses assigned to the regional offices of Arecibo, Mayagüez, Ponce, and Utuado were not located, and no evidence was found of transfer authorizations of boluses to the Regional Office of Lares, Utuado, and Arecibo, among others. In this regard, the Administration is recommended to evaluate the Procedure for the Requisition and Management of the Ruminal Bolus Program, to ensure that it includes detailed instructions and uniform forms.

The nine-finding audit points out multiple deficiencies in the database of the cattle registry by farmer of the Pilot Program; for example, 107 duplicate bolus numbers, incorrect or blank records of the farmer's social security, or blank farmer addresses were found. This situation deprives the Administration of reliable information necessary to meet the objectives of the Pilot Program.

Contrary to the systems security and government continuity policies, ADEA had not prepared a risk analysis report of the computerized information systems, nor a procedure for handling security incidents. In addition, it lacked a business continuity plan, as well as an alternate center to operate after an emergency.

The Report indicates multiple deficiencies with the access accounts in the operating system of the servers since the password policies had not been defined. In addition, the information technology coordinator did not periodically examine, nor make backups of, the security records to detect possible violations that could occur on the main server. The fact that OSI could not provide the monitoring records of seven access accounts with remote connection privileges hindered the scope of the Comptroller's examination. A similar situation had already been commented on in Audit Report CPED-96-5 of 1996.

With respect to the access accounts, ADEA could not identify 17 accounts out of the 306 active ones, 10 assigned accounts lacked the request and authorization document, and two accounts were assigned to two former employees who had ceased their functions in 2013. In addition, from a sample of the employees who had ceased working at ADEA, it was found that 60% of their accounts had not been deactivated despite more than five years having elapsed since their separation from employment.

The audit reveals that the Administration also did not make periodic backups of the information for the management of the employee payroll in the CDI Premium application. This situation is attributed to the lack of clear procedures and to the lack of memory capacity on the hard drive as indicated by the information technology coordinator. The report covers the period from February 16, 2017, to May 15, 2018.

See Audit Report TI-21-06.

To see other published reports, visit our Audit Reports section.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®