
The Comptroller of Puerto Rico issued a qualified opinion on the operations of the Office of Informatics and the computerized information systems of the Department of Natural and Environmental Resources (Department). A qualified opinion is issued when the individual or combined noncompliances are significant, but not pervasive.
The Report reveals that $262,951 was invested, without obtaining benefits, in two projects to implement computerized systems to invoice the extraction and use of water, and to automate the collection of fines. After 10 years, the projects were not being used, and the processes were carried out manually.
This situation deprives the Water Franchises and the Billing and Collection divisions of the tools to administer the use permits and invoice the use of water. The franchise is a written permit that grants the right to use a specified volume of water for common or private uses.
The seven-finding audit notes that the Department did not have a risk analysis report of the computerized information systems, nor a procedure for incident handling. The Department also did not have a business continuity plan, nor an alternate center for the recovery of the computerized operations. Situations similar to these had been commented on in the Audit Report TI-03-07 of 2003.
The Comptroller detected multiple deficiencies with the security parameters and access controls in the operating system, since the password policy that requires at least 8 characters had not been defined. In addition, the examination of the 702 active user accounts to access the network revealed that 108 of the accounts had not been used since they were created and that the last access (last logon) in 152 of them exceeded 30 days of inactivity, up to eight years. This situation fosters that unauthorized persons may gain access to confidential information and make improper use of it, among others.
Contrary to the regulations in force, the Department did not keep copies of the backups of the data saved on the computers and servers in a secure location outside the Department's premises. In addition, it did not provide for examination the authorization documents that grant the informatics managers the privileges of administrator of the operating systems.
The Comptroller's auditors found that the Department did not have an updated inventory, nor did the Office of Informatics maintain a record of the programs acquired and installed on each computer. These situations foster an environment for the improper use or disappearance of property, and prevent exercising effective control of the programs and licenses. This second and final Report on the Department covers the period from February 21, 2017 to May 31, 2018.
See the Audit Report TI-21-11.
To see other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.