Police Records Management System IT General Controls Follow up Report

Size: px
Start display at page:

Download "Police Records Management System IT General Controls Follow up Report"

Transcription

1 Police Records Management System IT General Controls Follow up Report March 2015 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor

2 The Auditor of the City and County of Denver is independently elected by the citizens of Denver. He is responsible for examining and evaluating the operations of City agencies for the purpose of ensuring the proper and efficient use of City resources and providing other audit services and information to City Council, the Mayor and the public to improve all aspects of Denver s government. He also chairs the City s Audit Committee. The Audit Committee is chaired by the Auditor and consists of seven members. The Audit Committee assists the Auditor in his oversight responsibilities of the integrity of the City s finances and operations, including the integrity of the City s financial statements. The Audit Committee is structured in a manner that ensures the independent oversight of City operations, thereby enhancing citizen confidence and avoiding any appearance of a conflict of interest. Audit Committee Dennis Gallagher, Chair Maurice Goodgaine Leslie Mitchell Rudolfo Payan Robert Bishop Jeffrey Hart Timothy O Brien, Vice Chair Audit Management Kip Memmott, Director, MA, CGAP, CRMA John Carlson, Deputy Director, JD, MBA, CIA, CGAP, CRMA Audrey Donovan, Deputy Director, CIA, CGAP, CRMA Audit Staff Shannon Kuhn, IT Audit Supervisor, CISA Nicholas Jimroglou, Lead IT Auditor, CISA Jakki Boline, IT Senior Auditor Karin Doughty, IT Senior Auditor, CISA You can obtain copies of this report by contacting us at: Office of the Auditor 201 West Colfax Avenue, Department 705 Denver CO, (720) Fax (720)

3 Or download and view an electronic copy by visiting our website at: Report number A

4 City and County of Denver 201 West Colfax Avenue, Department 705 Denver, Colorado FAX Dennis J. Gallagher Auditor March 16, 2015 Ms. Stephanie O Malley, Executive Director of Safety Mr. Frank Daidone, Chief Information Officer, Technology Services City and County of Denver Re: Police Records Management System IT General Controls Audit Follow Up Report Dear Ms. O Malley and Mr. Daidone: In keeping with professional auditing standards and the Audit Services Division s policy, as authorized by D.R.M.C , our Division has a responsibility to monitor and follow up on audit recommendations to ensure audit findings are being addressed and to aid us in planning future audits. This report is to inform you that we have completed our follow up effort for the Police Records Management System IT General Controls Performance Audit issued December 20, Our review determined that the Department of Safety and Technology Services has implemented eight of the twenty three findings found in the audit report. For your reference, this report includes a Highlights page that provides background and summary information on the original audit and the completed follow up effort. Following the Highlights page is a detailed implementation status update for each recommendation. In addition to the eight recommendations that were implemented, fifteen recommendations were not implemented. Despite the Agencies efforts, auditors determined that the risk associated with the audit team s initial findings has not been fully mitigated. As a result, the Division may revisit these risk areas in future audits to ensure appropriate corrective action is taken. This concludes audit follow up work related to this audit. I would like to express our sincere appreciation to you and to Department of Safety and Technology Services personnel who assisted us throughout the audit and follow up process. If you have any questions, please feel free to contact me at or Shannon Kuhn, IT Audit Supervisor, at Sincerely, KRM/sk Kip Memmott, MA, CGAP, CRMA Director of Audit Services cc: Honorable Michael Hancock, Mayor Honorable Members of City Council To promote open, accountable, efficient and effective government by performing impartial reviews and other audit services that provide objective and useful information to improve decision making by management and the people. We will monitor and report on recommendations and progress towards their implementation.

5 Members of Audit Committee Ms. Cary Kennedy, Deputy Mayor, Chief Financial Officer Ms. Janice Sinden, Chief of Staff Mr. David P. Edinger, Chief Performance Officer Ms. Beth Machann, Controller Mr. Scott Martinez, City Attorney Ms. Janna Young, City Council Executive Staff Director Mr. L. Michael Henry, Staff Director, Board of Ethics To promote open, accountable, efficient and effective government by performing impartial reviews and other audit services that provide objective and useful information to improve decision making by management and the people. We will monitor and report on recommendations and progress towards their implementation.

6 City and County of Denver Office of the Auditor Audit Services Division REPORT HIGHLIGHTS Police Records Management Systems IT General Controls Follow up Report: March 2015 The Department of Safety and Technology Services have implemented 35 percent of the recommendations made in the December 2012 audit report. Background The Denver Police Department has been using the Versaterm Records Management System (RMS) since The system can be accessed from desktop computers and from laptop computers, known as mobile data terminals (MDTs), which are installed in police cars. RMS contains general offense records including officer statements, neighborhood surveys, and lab reports. As one of the Denver Police Department s main records systems, RMS is accessed by approximately 1,700 users, including 1,400 sworn police officers, and personnel from other agencies, such as the District Attorney, City Attorney, Denver Sheriff, and Denver County Courts. Purpose The purpose and overall objective of the audit was to examine and assess the IT general controls related to the Police Department's Records Management System to ensure that they provide a sound foundation to support the system s proper operation and security. Highlights from Original Audit Our audit identified issues surrounding critical Police, Fire, and Sheriff Computer systems residing in a data center that offers little to no assurance that it can recover from a disaster. Of eight serious backup and recovery concerns, the most notable are the failure to send backup files offsite and the failure to provide enough disk space for the data backup server. In addition, there are several other important issues concerning user administration, antivirus and system patching, data center security, and change management: Backups are not stored offsite Dangerously low disk space threatens the viability of system backups User administration controls do not ensure timely termination of access or adequate user activity monitoring System software patches and antivirus updates are not monitored for successful installation and sometimes not applied at all The Department of Safety data center has no automated fire suppression and lacks adequate physical access controls Minor project change management does not provide adequate segregation of duties Findings at Follow up Technology Services and the Department of Safety have implemented eight of the twenty three recommendations made in the 2012 audit report. Additional storage was purchased for the backup of the Records Management System. Initial and periodic review of users with access to the Police Record System has been created and is being performed. Technology Services has established a server patching and change management process. Environmental and physical safety controls have been installed in the data center. For a complete copy of this report, visit Audit Contact Person: Shannon Kuhn [email protected]

7 Recommendations: Status of Implementation Recommendation Auditee Action Status Finding 1: Police, Fire and Sheriff Department Electronic Records Are At Risk of Total Loss Should There Be a Data Center Disaster 1.1 Offsite Technology Services must relocate the backup server offsite, away from the Safety data center. The new location should be far enough away so that the new location is not subject to the same hazards, such as fire, broken water pipes, or a tornado. The new location should also meet CJIS access control requirements. 1.2 Disk Space Technology Services and the Denver Safety Departments should collaborate to secure the necessary financial resources to acquire adequate disk capacity for backups. 1.3 Key Personnel Dependency Technology Services should ensure that critical job functions and essential duties related to monitoring system backups can still be performed by other staff when key employees are out of the office, such as on vacation. Documenting and operationalizing job duties and procedures will aid those who temporarily take over backuprelated job functions. 1.4 Disaster Recovery Plan Technology Services and the Denver Police Department should collaborate to develop an RMS disaster recovery plan. The previous Chief Information Officer was able to use special funds to purchase a new backup system and physical disk storage. The systems are shared solutions for both the Safety and Gov domains. Page 1 Office of the Auditor

8 Recommendations: Status of Implementation Recommendation Auditee Action Status 1.5 Disaster Recovery Test Technology Services and the Denver Police Department should schedule tests of the RMS disaster recovery plan in whole or in part to demonstrate recovery capability. 1.6 Backup Methodology The backup methodology and exception procedures used for RMS should be documented. This would include the frequency of both full and incremental backups, the number of backup generations, and how long backup generations are retained. 1.7 Frequency of Backup Technology Services and the Denver Police Department should collaborate to conduct an RMS risk assessment to determine the appropriate type and frequency of backup that is necessary. 1.8 Service Level Agreement Technology Services and the Denver Safety Department should jointly review their Service Level Agreement to ensure that it is both realistic and understood. Key performance metrics should be identified and automated reporting should be developed to alert both Technology Services and Denver Safety Department management of process failures, such as missed data backups. Agreed/Not City and County of Denver Page 2

9 Recommendations: Status of Implementation Recommendation Auditee Action Status Finding 2: User Administration Controls Do Not Ensure Timely Termination of Access or Adequate User Activity Monitoring 2.1 The Denver Police Department should manually review the list of 911 users provided by the auditors to determine the appropriateness of access granted, and disable accounts in RMS as necessary. 2.2 Technology Services should review the results from the Denver Police Department review of RMS access to ensure that the network accounts (Active Directory) of separated users is removed. The list of questionable accounts was reviewed. Several were authorized and worked for areas of responsibility that had authorized access to the RMS. Some of the areas of responsibility included the Denver Police Reserves, Denver Safety Cadets, District Attorney's office, City Attorney's office, Denver Sheriff Department, Denver Fire Arson Investigators, Crime Lab Civilians, Denver Police Victim Assistance volunteers, Electronic Engineering Bureau, Technology Services Enterprise Support, Metro Auto Theft Task Force, Missing Persons volunteers, and Crime Lab volunteers. Based on our review, 427 accounts were appropriate and 484 individuals separated from the department and the accounts were disabled. Page 3 Office of the Auditor

10 Recommendations: Status of Implementation Recommendation Auditee Action Status 2.3 The Denver Police Department should modify its procedures to notify the Information Management Unit when employees transfer or separate to allow the timely removal of their RMS access. 2.4 Technology Services should correct the processing logic of the automated process to ensure that separated users have their network accounts disabled. 2.5 The Denver Police Department should collaborate with Technology Services and the RMS vendor to collect the appropriate data and generate the reports necessary to allow review of user activity in accordance with CJIS requirements (section ). Further, the Denver Police Department should perform weekly RMS user activity reviews as required by CJIS. 2.6 Technology Services should ensure that local accounts on Linux servers and the Oracle database are administered in accordance with either City or CJIS requirements as appropriate. DPD recognizes the need for better communication between the Human Resource Bureau and the Information Management Unit. New procedures have been adopted to provide the Information Management Unit timely information within one business day of an employee separation. The notification is handled by the Information Management Unit on the same business day modifying the personnel's account. The Denver Police Department has implemented a manual process, as Technology Services and the RMS vendor have not completed the data collection and report generation piece of this recommendation. The current process has Human Resources providing a notification via e mail whenever an employee separates. The IMU disables the RMS account the same day. City and County of Denver Page 4

11 Recommendations: Status of Implementation Recommendation Auditee Action Status Finding 3: System Software Patches and Antivirus Updates Are Not Monitored for Successful Installation and Sometimes Not Applied At All 3.1 Technology Services should develop procedures to ensure that software patching and antivirus updates are applied successfully and that failures are investigated and resolved. 3.2 Technology Services should install antivirus software on all RMS servers including Linux servers. 3.3 Technology Services should adopt software patching procedures for all RMS servers. 3.4 Technology Services and the Denver Police Department should collaborate on solutions for applying software patches and antivirus updates for the nearly 500 MDTequipped police cars in the City. TS has adopted and implemented patching procedure for all RMS servers, and it includes an exception for RMS Linux serves. The vendor is responsible for installing patches. Agree/ Not Agree/ Not Agree/ Not Finding 4: The Safety Data Center Has No Automated Fire Suppression and Lacks Adequate Physical Access Controls 4.1 Technology Services and the Denver Safety Department should collaborate regarding how an automated fire suppression system can be installed for the Safety data center. Auditors toured the Safety data center and noted that a fire suppression system was installed. Page 5 Office of the Auditor

12 Recommendations: Status of Implementation Recommendation Auditee Action Status 4.2 Technology Services and the Denver Safety Department should collaborate to install a card reader to replace the barrel bolts on one of the Safety data center doors to support accountability for access. 4.3 Technology Services should institute a visitor sign in log recording access to the Safety data center in compliance with CJIS requirements. A door with a lock was installed on the Safety Center door in lieu of a badge reader. Facilities and the Data Center Manager are the only personnel with keys to the lock. Auditors attempted to open the Safety Data center door and noted it was locked. Auditors noted that a log book was present in the data center. Finding 5: Minor Project Change Management Does Not Provide Adequate Segregation of Duties 5.1 To provide segregation of duties, the Denver Police Department should require supervisory or other approval of all changes submitted to the RMS vendor. 5.2 The Denver Police Department should retain records of all changes submitted to the RMS vendor along with evidence of approval for both the changes and the test results. DPD created a new process by which a request is created by the Information Management Unit to the supervisor. The supervisor approves the request, which is then coordinated between the IMU and the vendor, Versaterm. IMU tests and confirms that the change has been made as expected. Change records are stored in the Service Now change management application. Additionally, the Change Advisory Board keeps minutes and a spreadsheet of approved changes. Auditors verified that RMS changes have been submitted and approved in the Service Now application. City and County of Denver Page 6

13 Conclusion The Department of Safety has completed all five recommendations directed to the agency in the Police Records Management System IT General Controls audit, which includes an initial and periodic review of users with access to the Police Record System. Additionally, the Department of Safety has worked with the RMS vendor, Versaterm, to ensure that system changes are incorporated into the Change Management process. We found that Technology Services has implemented three of the recommendations made; others have yet to be acted upon or fully implemented. Despite Technology Services efforts, auditors determined that risks to Police, Fire, and Sheriff Department records still exist due to outstanding recommendations. Backup and storage efforts are still in progress to address off site backup and storage, a backup frequency methodology, backup activity monitoring, reporting, and cross training for backup personnel. The removal of Police Records Management personnel from the records management system is occurring; however, Technology Services is working towards collecting the data to fully remove users from the associated server, database, and network accounts. Monitoring, patching, and anti virus updates are not fully implemented, leaving the database and operating system on servers vulnerable to security threats. As a result, the Audit Services Division may revisit these risk areas in future audits to ensure appropriate corrective action is taken. On behalf of the citizens of the City and County of Denver, we thank staff and leadership from the Department of Safety and Technology Services for their cooperation during our follow up effort and their dedicated public service. Page 7 Office of the Auditor

Citywide Identity Management Follow up Report

Citywide Identity Management Follow up Report Citywide Identity Management Follow up Report July 2015 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver

More information

DIA Network Security Management Follow up Report

DIA Network Security Management Follow up Report DIA Network Security Management Follow up Report March 2015 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver

More information

Denver 311 Follow up Report

Denver 311 Follow up Report Denver 311 Follow up Report December 2014 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is independently

More information

Assessor s Office Performance Audit

Assessor s Office Performance Audit Assessor s Office Performance Audit June 2012 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is independently

More information

911 Data Center Operations Performance Audit

911 Data Center Operations Performance Audit 911 Data Center Operations Performance Audit June 2010 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is

More information

Police Records Management System IT General Controls Performance Audit

Police Records Management System IT General Controls Performance Audit Police Records Management System IT General Controls Performance Audit December 2012 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the

More information

DIA Network Device Security Management Performance Audit

DIA Network Device Security Management Performance Audit DIA Network Device Security Management Performance Audit June 2014 Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is independently

More information

PeopleSoft IT General Controls

PeopleSoft IT General Controls PeopleSoft IT General Controls Performance Audit December 2009 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of

More information

Citywide Identity Management Performance Audit

Citywide Identity Management Performance Audit Citywide Identity Management Performance Audit March 2014 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver

More information

Network Security Management Phase 1 Performance Audit

Network Security Management Phase 1 Performance Audit Network Security Management Phase 1 Performance Audit March 2012 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of

More information

Network Security Management Phase 2 Performance Audit

Network Security Management Phase 2 Performance Audit Network Security Management Phase 2 Performance Audit July 2012 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of

More information

Fixed Assets Management Performance Audit

Fixed Assets Management Performance Audit Fixed Assets Management Performance Audit May 2010 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is independently

More information

Denver 311 Performance Audit

Denver 311 Performance Audit Denver 311 Performance Audit August 2012 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is independently

More information

City Attorney s Office: Litigation and Claims Management Performance Audit

City Attorney s Office: Litigation and Claims Management Performance Audit City Attorney s Office: Litigation and Claims Management Performance Audit June 2013 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the

More information

Denver International Airport Planning and Development Division Performance Audit

Denver International Airport Planning and Development Division Performance Audit Denver International Airport Planning and Development Division Performance Audit June 2013 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor

More information

Office of Emergency Management and Homeland Security Performance Audit

Office of Emergency Management and Homeland Security Performance Audit Office of Emergency Management and Homeland Security Performance Audit November 2011 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the

More information

OFFICE OF THE AUDITOR

OFFICE OF THE AUDITOR OFFICE OF THE AUDITOR CAREER SERVICE AUTHORITY AND PUBLIC WORKS PARKING MANAGEMENT EMPLOYEES VOLUNTARY SALARY REDIRECTION PLAN FOR TRANSPORTATION BENEFITS QUALIFIED PARKING PROGRAM UNIT FEBRUARY 2005 Dennis

More information

Retention & Destruction

Retention & Destruction Last Updated: March 28, 2014 This document sets forth the security policies and procedures for WealthEngine, Inc. ( WealthEngine or the Company ). A. Retention & Destruction Retention & Destruction of

More information

SECTION 15 INFORMATION TECHNOLOGY

SECTION 15 INFORMATION TECHNOLOGY SECTION 15 INFORMATION TECHNOLOGY 15.1 Purpose 15.2 Authorization 15.3 Internal Controls 15.4 Computer Resources 15.5 Network/Systems Access 15.6 Disaster Recovery Plan (DRP) 15.1 PURPOSE The Navajo County

More information

Written Information Security Plan (WISP) for. HR Knowledge, Inc. This document has been approved for general distribution.

Written Information Security Plan (WISP) for. HR Knowledge, Inc. This document has been approved for general distribution. Written Information Security Plan (WISP) for HR Knowledge, Inc. This document has been approved for general distribution. Last modified January 01, 2014 Written Information Security Policy (WISP) for HR

More information

October 21, 2004. Ms. Joan A. Cusack Chairwoman NYS Crime Victims Board 845 Central Avenue, Room 107 Albany, New York 12206-1588

October 21, 2004. Ms. Joan A. Cusack Chairwoman NYS Crime Victims Board 845 Central Avenue, Room 107 Albany, New York 12206-1588 ALAN G. HEVESI COMPTROLLER 110 STATE STREET ALBANY, NEW YORK 12236 STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER October 21, 2004 Ms. Joan A. Cusack Chairwoman NYS Crime Victims Board 845 Central Avenue,

More information

AGENDA HIP Ho AA w i rivacy d The B reach Happen? I P nc AA Secu dent R rit esp y o nse Corrective Action Plan What We Learned ACRONYMS USED

AGENDA HIP Ho AA w i rivacy d The B reach Happen? I P nc AA Secu dent R rit esp y o nse Corrective Action Plan What We Learned ACRONYMS USED Michael Almvig Skagit County Information Services Director 1 AGENDA 1 2 HIPAA How Did Privacy The Breach Happen? HIPAA Incident Security Response 3 Corrective Action Plan 4 What We Learned Questions? ACRONYMS

More information

HIPAA Compliance Evaluation Report

HIPAA Compliance Evaluation Report Jun29,2016 HIPAA Compliance Evaluation Report Custom HIPAA Risk Evaluation provided for: OF Date of Report 10/13/2014 Findings Each section of the pie chart represents the HIPAA compliance risk determinations

More information

City Vehicle Fleet Management Performance Audit

City Vehicle Fleet Management Performance Audit City Vehicle Fleet Management Performance Audit January 2011 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver

More information

OFFICE OF THE AUDITOR

OFFICE OF THE AUDITOR OFFICE OF THE AUDITOR DEPARTMENT OF AVIATION INTERNAL CONTROL REVIEW AND CONTRACT COMPLIANCE AUDIT NOVEMBER 2007 Dennis J. Gallagher Auditor Dennis J. Gallagher Auditor Mr. Turner West, Manager Department

More information

Audit Report. Effectiveness of IT Controls at the Global Fund Follow-up report. GF-OIG-15-20b 26 November 2015 Geneva, Switzerland

Audit Report. Effectiveness of IT Controls at the Global Fund Follow-up report. GF-OIG-15-20b 26 November 2015 Geneva, Switzerland Audit Report Effectiveness of IT Controls at the Global Fund Follow-up report GF-OIG-15-20b Geneva, Switzerland Table of Contents I. Background and scope... 3 II. Executive Summary... 4 III. Status of

More information

OFFICE OF THE CITY AUDITOR

OFFICE OF THE CITY AUDITOR OFFICE OF THE CITY AUDITOR PERFORMANCE AUDIT OF FUEL SERVICE CARDS Paul T. Garner Assistant City Auditor Prepared by: Theresa Hampden, CPA Audit Manager Regina Cannon Auditor October 29, 2004 Memorandum

More information

FINAL. Internal Audit Report. Data Centre Operations and Security

FINAL. Internal Audit Report. Data Centre Operations and Security FINAL Internal Audit Report Data Centre Operations and Security Document Details: Reference: Report nos from monitoring spreadsheet/2013.14 Senior Manager, Internal Audit & Assurance: ext. 6567 Engagement

More information

Patch Management Procedure. Andrew Marriott [email protected] 01253 658578 PATCH MANAGEMENT PROCEDURE.DOCX Version: 1.1

Patch Management Procedure. Andrew Marriott andrew.marriott@fylde.gov.uk 01253 658578 PATCH MANAGEMENT PROCEDURE.DOCX Version: 1.1 Title: Patch Management Andrew Marriott [email protected] 01253 658578 PATCH MANAGEMENT PROCEDURE.DOCX Version: 1.1 Contents 1. Introduction... 4 2. Objectives... 4 3. Context... 4 4. Responsibility...

More information

Denver International Airport Facility Management Performance Audit

Denver International Airport Facility Management Performance Audit Denver International Airport Facility Management Performance Audit February 2012 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City

More information

FINAL May 2005. Guideline on Security Systems for Safeguarding Customer Information

FINAL May 2005. Guideline on Security Systems for Safeguarding Customer Information FINAL May 2005 Guideline on Security Systems for Safeguarding Customer Information Table of Contents 1 Introduction 1 1.1 Purpose of Guideline 1 2 Definitions 2 3 Internal Controls and Procedures 2 3.1

More information

LAMAR STATE COLLEGE - ORANGE INFORMATION RESOURCES SECURITY MANUAL. for INFORMATION RESOURCES

LAMAR STATE COLLEGE - ORANGE INFORMATION RESOURCES SECURITY MANUAL. for INFORMATION RESOURCES LAMAR STATE COLLEGE - ORANGE INFORMATION RESOURCES SECURITY MANUAL for INFORMATION RESOURCES Updated: June 2007 Information Resources Security Manual 1. Purpose of Security Manual 2. Audience 3. Acceptable

More information

Audit Follow-Up. The City s Parking Program (Report #0622, Issued September 8, 2006) As of September 30, 2007. Summary. Report #0806 January 11, 2008

Audit Follow-Up. The City s Parking Program (Report #0622, Issued September 8, 2006) As of September 30, 2007. Summary. Report #0806 January 11, 2008 Audit Follow-Up As of September 30, 2007 Sam M. McCall, CPA, CGFM, CIA, CGAP City Auditor The City s Parking Program (Report #0622, Issued September 8, 2006) Report #0806 January 11, 2008 Summary This

More information

Property Room. Records Management System

Property Room. Records Management System Property Room Records Management System Louisville Metro Police Department Property Room Records Management System Table of Contents Transmittal Letter... 2 Introduction... 2 Scope... 3 Opinion... 3 Corrective

More information

IT Security Standard: Computing Devices

IT Security Standard: Computing Devices IT Security Standard: Computing Devices Revision History: Date By Action Pages 09/30/10 ITS Release of New Document Initial Draft Review Frequency: Annually Responsible Office: ITS Responsible Officer:

More information

Information Technology General Controls And Best Practices

Information Technology General Controls And Best Practices Paul M. Perry, FHFMA, CITP, CPA Alabama CyberNow Conference April 5, 2016 Information Technology General Controls And Best Practices 1. IT General Controls - Why? 2. IT General Control Objectives 3. Documentation

More information

Denver Sheriff Department Jail Operations Performance Audit

Denver Sheriff Department Jail Operations Performance Audit Denver Sheriff Department Jail Operations Performance Audit March 2015 Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is independently

More information

AUGUST 28, 2013 INFORMATION TECHNOLOGY INCIDENT RESPONSE PLAN. 1250 Siskiyou Boulevard Ashland OR 97520

AUGUST 28, 2013 INFORMATION TECHNOLOGY INCIDENT RESPONSE PLAN. 1250 Siskiyou Boulevard Ashland OR 97520 AUGUST 28, 2013 INFORMATION TECHNOLOGY INCIDENT RESPONSE PLAN 1250 Siskiyou Boulevard Ashland OR 97520 Revision History Revision Change Date 1.0 Initial Incident Response Plan 8/28/2013 Official copies

More information

July 6, 2015. Mr. Michael L. Joseph Chairman of the Board Roswell Park Cancer Institute Elm & Carlton Streets Buffalo, NY 14263

July 6, 2015. Mr. Michael L. Joseph Chairman of the Board Roswell Park Cancer Institute Elm & Carlton Streets Buffalo, NY 14263 July 6, 2015 Mr. Michael L. Joseph Chairman of the Board Roswell Park Cancer Institute Elm & Carlton Streets Buffalo, NY 14263 Re: Security Over Electronic Protected Health Information Report 2014-S-67

More information

TECHNOLOGY AND INNOVATION DEPARTMENT BACKUP AND RECOVERY REVIEW AUDIT 14-08 SEPTEMBER 23, 2014

TECHNOLOGY AND INNOVATION DEPARTMENT BACKUP AND RECOVERY REVIEW AUDIT 14-08 SEPTEMBER 23, 2014 TECHNOLOGY AND INNOVATION DEPARTMENT BACKUP AND RECOVERY REVIEW AUDIT 14-08 SEPTEMBER 23, 2014 CITY OF TAMPA Bob Buckhorn, Mayor Internal Audit Department Christine Glover, Internal Audit Director September

More information

Top Ten Technology Risks Facing Colleges and Universities

Top Ten Technology Risks Facing Colleges and Universities Top Ten Technology Risks Facing Colleges and Universities Chris Watson, MBA, CISA, CRISC Manager, Internal Audit and Risk Advisory Services [email protected] April 23, 2012 Overview Technology

More information

2.1 To define the backup strategy for systems and data within the Cape Winelands District Municipality (CWDM).

2.1 To define the backup strategy for systems and data within the Cape Winelands District Municipality (CWDM). BACKUP POLICY POLICY ADOPTED BY COUNCIL ON 25 APRIL 2012 AT ITEM C.14.3 POLICY AMENDED BY COUNCIL ON 24 APRIL 2014 AT ITEM C.14.1 Cape Winelands District Municipality Backup Policy 1. 1. INTRODUCTION Computer

More information

Los Angeles County Metropolitan Transportation Authority Office of the Inspector General Medicare Part B Reimbursements to Retirees

Los Angeles County Metropolitan Transportation Authority Office of the Inspector General Medicare Part B Reimbursements to Retirees Los Angeles County Metropolitan Transportation Authority Medicare Part B Reimbursements to Retirees Several procedural refinements are needed to ensure that reimbursements are discontinued for deceased

More information

Information Technology General Controls Review (ITGC) Audit Program Prepared by:

Information Technology General Controls Review (ITGC) Audit Program Prepared by: Information Technology General Controls Review (ITGC) Audit Program Date Prepared: 2012 Internal Audit Work Plan Objective: IT General Controls (ITGC) address the overall operation and activities of the

More information

Information Security Awareness Training

Information Security Awareness Training Information Security Awareness Training Presenter: William F. Slater, III M.S., MBA, PMP, CISSP, CISA, ISO 27002 1 Agenda Why are we doing this? Objectives What is Information Security? What is Information

More information

Audit Report on the New York City Police Department Data Center 7A06-093

Audit Report on the New York City Police Department Data Center 7A06-093 Audit Report on the New York City Police Department Data Center 7A06-093 August 14, 2006 THE CITY OF NEW YORK OFFICE OF THE COMPTROLLER 1 CENTRE STREET NEW YORK, N.Y. 10007-2341 WILLIAM C. THOMPSON, JR.

More information

White Paper: Librestream Security Overview

White Paper: Librestream Security Overview White Paper: Librestream Security Overview TABLE OF CONTENTS 1 SECURITY OVERVIEW... 3 2 USE OF SECURE DATA CENTERS... 3 3 SECURITY MONITORING, INTERNAL TESTING AND ASSESSMENTS... 4 3.1 Penetration Testing

More information

12 05 City Cash Receipts Audit Report

12 05 City Cash Receipts Audit Report O FFICE O F T HE C ITY A UDITOR C OLORADO S PRINGS, C OLORADO 12 05 City Cash Receipts Audit Report Some parts of this public document have been redacted in an effort to minimize the opportunity for control

More information

Division of Insurance Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014

Division of Insurance Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014 Official Audit Report Issued March 6, 2015 Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014 State House Room 230 Boston, MA 02133 [email protected] www.mass.gov/auditor

More information

EL PASO COUNTY SHERIFF S OFFICE POLICY AND PROCEDURE MANUAL

EL PASO COUNTY SHERIFF S OFFICE POLICY AND PROCEDURE MANUAL EL PASO COUNTY SHERIFF S OFFICE POLICY AND PROCEDURE MANUAL Effective Date: 03/12/15 Supersedes: 02/21/07 Approval: Number: 318 Subject: ATTENDANCE RECORDS Reference: FLSA Standard: Chapter: III Reevaluation

More information

GENERAL ORDER DISTRICT OF COLUMBIA I. BACKGROUND

GENERAL ORDER DISTRICT OF COLUMBIA I. BACKGROUND GENERAL ORDER DISTRICT OF COLUMBIA Subject CJIS Security Topic Series Number SPT 302 12 Effective Date March 28, 2014 Related to: GO-SPT-302.08 (Metropolitan Police Department (MPD) Wide Area Network)

More information

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES APPENDIX 1 DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES March 2008 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1

More information

BACKUP & RESTORATION PROCEDURE

BACKUP & RESTORATION PROCEDURE BACKUP & RESTORATION PROCEDURE KING SAUD UNIVERSITY DEANSHIP OF ETRANSACTIONS & COMMUNICATION VERSION 1.1 INTERNAL USE ONLY PREPARED BY REVIEWED BY APPROVED BY ALTAMASH SAYED NASSER A. AMMAR DR. MOHAMMED

More information

Information Security Operational Procedures Banner Student Information System Security Policy

Information Security Operational Procedures Banner Student Information System Security Policy Policy No: 803 Area: Information Technology Services Adopted: 8/6/2012 Information Security Operational Procedures Banner Student Information System Security Policy INTRODUCTION This document provides

More information

System Security Plan University of Texas Health Science Center School of Public Health

System Security Plan University of Texas Health Science Center School of Public Health System Security Plan University of Texas Health Science Center School of Public Health Note: This is simply a template for a NIH System Security Plan. You will need to complete, or add content, to many

More information