
The Office of the Comptroller of Puerto Rico published an evaluation of the controls established for the computerized information systems of the government entities and the municipalities. The information was obtained from the responses to the Technological Infrastructure Questionnaire of the Commonwealth of Puerto Rico from 198 entities.
The government entities and the municipalities are responsible for establishing the internal controls to guarantee the security and reliability of their information systems, the integrity and availability of the data, and the continuity of operations. In addition, the entities must ensure the effectiveness of said controls and of the processes used in the planning, development and implementation of the technology projects.
The Report reveals that 30 entities did not have an area to administer the systems, six did not have designated or support personnel to attend to the systems, and five entities described as low the impact of the information systems on their operations. In addition, 129 entities maintain their information systems within the entity itself, and only one maintains its system at an external facility, in the cloud and within the entity itself.
Of the 198 entities evaluated, 171 have applications to process financial, human-resources, payroll and attendance transactions, and 134 have invested $459.5 million in information-technology projects in the last two years. In addition, 156 entities communicate and offer their services to the community over the Internet, 47 use mobile applications and 174 on social networks.
The Report notes that 94 entities did not have a risk analysis, 58 of the 104 with a risk analysis reported that their controls were not updated, and 35 had not implemented cybersecurity controls. Another finding indicates that 89 entities had not conducted internal or external audits of their information systems, 91 do not have an incident-management plan, and 134 use obsolete operating systems.
These security controls are what allow ensuring the accuracy, integrity and protection of the critical processes and resources. The controls include the preparation of a risk-analysis report, adopting rules that secure the computerized operations and establishing cybersecurity measures, among others.
From the information obtained, it is concluded that 67 entities do not have controls for the continuity of service, 56 had not updated their contingency plans and 53 did not have a disaster-recovery plan. In addition, 20 entities do not maintain backups of the data processed in their main applications and 20 do not keep the backups off the entity's premises.
The controls for the continuity of service are essential to minimize the risks of interruptions, and so that the service is available even in cases of emergency. These controls are achieved by developing continuity plans, establishing alternate centers to restore critical systems and preparing tests of data restoration and recovery, among others.
The evaluation also reveals that 76 entities do not perform recovery tests of the backups. This situation is attributed, among other reasons, to the lack of technological resources and trained personnel, to the fact that the projects in process consider the tests in their infrastructure, or to the lack of awareness of the situation.
The Report publishes that 40 entities do not have written rules for the creation of accounts for access to the information systems, 76 entities do not have procedures to safeguard the information, and 30 entities do not document the access requests and authorizations. The logical-access controls to the computerized information systems provide guarantees only to those who are authorized and limit inappropriate access to the information-technology resources.
Another of the results indicates that 63 entities did not have an updated diagram of the communication-network infrastructure. The diagram allows identifying the equipment connected to the network, the existing connections and their configuration.
The Special Report concludes that technology is key to guaranteeing a transparent government that is responsive to the needs of society. These tools allow an efficient administration, reduce irregularities and improve labor efficiency.
However, technological advances alone do not guarantee the success of an entity; rather, the entity must guarantee the security of the systems and the confidentiality of the citizens' information.
The Special Report contains illustrative graphics that facilitate the comprehension of the data, as well as valuable and complete information on the technological challenges for the government and concrete recommendations to the entities. The Report, dated October 25, 2023, indicates that the responses received from September 4, 2022 to February 23, 2023 were considered.
See Audit Report OC-24-22.
To see other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.