The Office of the Comptroller of Puerto Rico issued a qualified opinion of the operations of the computerized information systems of the Municipality of Toa Alta. A qualified opinion is issued when individual or combined noncompliance is significant, but not pervasive.
The Report reveals that the Municipality did not have a risk analysis of the computerized information systems. Instead, the Municipality presented a Technological Evaluation report from 2017, but it does not contain the basic aspects of a risk analysis.
A risk analysis identifies the system's assets, their vulnerabilities and the possible threats. With this knowledge, it is ensured that the security measures and controls established are cost-effective. The lack of such analysis prevents the Municipality from estimating the impact of the risk elements and taking measures to protect them.
The three-finding audit points out that, as of February 14, 2020, the Municipality did not have a contingency plan as provided by the guidelines established in the Federal Information Systems Controls Audit Manual (FISCAM) issued by the United States Government Accountability Office (General Accountant Office – GAO). This situation may encourage improvisation and that, in cases of emergency, inappropriate measures be taken.
The Comptroller's auditors identified multiple deficiencies with the documentation and justification of the security roles granted to users of the INGRESYS accounting module of the Integrated System for Advanced Municipalities (SIMA).
The examination performed found 78 security roles granted to users that were not related to the functions or the position, 44 security roles granted to seven users not authorized in the documents, and 14 security roles granted to one user, without documentary evidence. These situations may allow unauthorized persons to access confidential information or for irregularities to be committed.
The Report recommends, among others, that the Office of Municipal Management ensure that the Municipality complies with the Corrective Action Plan of the Office of the Comptroller. The report covers the period from January 24, 2020 to January 29, 2021.
See Audit Report TI-22-05.
To see other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.