
The Office of the Comptroller of Puerto Rico issued a qualified opinion of the operations of the computerized information systems of the Municipality of Juncos. A qualified opinion is issued when the noncompliances, individually or in the aggregate, are significant but not pervasive.
The Report reveals that, as of July 20, 2022, the Municipality of Juncos did not have a risk analysis report of the computerized information systems. The risk analysis is a process that must be carried out, at least every 24 months, in which the systems' assets, their vulnerabilities, and the threats are identified, in order to implement adequate security measures and controls. The lack of a risk report prevents the Municipality from being able to estimate the impact and plan the protection of the information systems.
The two-finding audit also notes that, as of July 20, 2022, the Municipality did not have a contingency plan to recover its operations in case of emergency. The Federal Information System Controls Audit Manual (FISCAM) establishes that every governmental entity must have a documented and approved contingency plan, which includes the updated information of the computerized information systems and the detailed procedures to recover its operations.
The lack of a contingency plan could lead the Municipality to take improvised measures, which could entail excessive and unnecessary expenses to address the emergency situations.
The Report recommends to the Office of Municipal Management that it ensure that the Municipality complies with the Corrective Action Plan established by the Office of the Comptroller.
This report on the Municipality of Juncos covers the period from January 1, 2021 to July 22, 2022
Audit Report TI-23-05 can be obtained on our website: www.ocpr.gov.pr.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.