
The Comptroller of Puerto Rico issued a qualified opinion on the operations of the Computerized Information Systems of the Civil Rights Commission (Commission). A qualified opinion is issued when noncompliance, individually or in the aggregate, is significant but not pervasive.
The Report reveals that the Commission's Emergency Response Plan (Plan) lacks updated information to maintain the continuity of services. The Plan is missing a list of the equipment, the operating systems, and applications, as well as a restoration schedule and the contact of the primary Internet provider. This situation could lead to improvisation, and to measures being taken without any order, in the event of an emergency.
The two-finding audit notes that on the main server the requirement that the password have a minimum of eight characters had been disabled. In addition, the configuration setting the time parameters for changing passwords, with minimum and maximum periods, was at 0 days (minimum/maximum password age: 0). The current regulations provide that the passwords of administrative accounts must be changed at least every four months and those of users every six months. This situation can lead to irregularities or data alterations being committed in the system, without their being detected in time to assign responsibility.
The Report evidences the absence of audit policies that would allow the production of records of account activation and deactivation, of actions performed on a program, or of changes to security options. In addition, 21% of the active user accounts on the main server had never been used.
This Report covers the period from December 9, 2019 to August 31, 2020.
See Audit Report T-21-17.
To see other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.