OFFICE OF AUDITS & ADVISORY SERVICES SUNGARD TREASURY MANAGEMENT SYSTEM CONTRACT COMPLIANCE FINAL AUDIT REPORT
|
|
|
- Ferdinand Wilson
- 10 years ago
- Views:
Transcription
1 County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES SUNGARD TREASURY MANAGEMENT SYSTEM CONTRACT COMPLIANCE FINAL AUDIT REPORT Chief of Audits: Juan R. Perez Senior Audit Manager: Lynne Prizzia, CISA, CRISC Senior Auditor: Mady Cheng, CPA, CIA, CISA, MSBA Auditor I: Wasim Akand, MPA Report No. A October 2013
2 Intentionally Left Blank
3
4 INTRODUCTION Audit Objective Background Audit Scope & Limitations The Office of Audits & Advisory Services (OAAS) completed an audit of the SunGard Treasury Management System Contract. The objective of the audit was to evaluate compliance with contract terms and conditions. In June 2009, the County s Treasurer-Tax Collector (TTC) entered into a software licensing and services agreement ( Contract ) with SunGard AvantGard LLC (SunGard). According to the Contract, TTC acquired a software license for SunGard s AvantGard Quantum treasury management system (AvantGard) and outsourced the related information technology (IT) hosting services to SunGard for five years. The IT hosting services include the monitoring, management, and maintenance of the hardware and software, networking infrastructure, disaster recovery plan, and system upgrades for three application environments (i.e., Production, Test, and Disaster Recovery). TTC users can remotely access the AvantGard application supported by the SunGard data centers. The scope of the audit included TTC s Contract with SunGard, as described in the Background section. Specifically, the audit focused on the following two areas from July 2011 to August 2013: SunGard s IT security, as applicable to TTC s data. SunGard s disaster recovery (DR) plan for TTC s data and related IT hosting services. This audit was conducted in conformance with the International Standards for the Professional Practice of Internal Auditing prescribed by the Institute of Internal Auditors as required by California Government Code, Section Methodology OAAS performed the audit using the following methods: Interviewed TTC management and requested supporting documents to verify whether TTC had performed a review of SunGard s Statements on Standards for Attestation Engagements #16 (SSAE 16) audit report. Reviewed SunGard s most current SSAE 16 audit report available (i.e., for fiscal year ending September 2012) and related documents to identify significant IT security issues and to determine whether SunGard had remediated reported issues. Interviewed TTC management and requested supporting documents to verify whether: SunGard had developed a DR plan customized to TTC s IT environment. SunGard had tested the DR plan at least annually, as required in the contract. 1
5 AUDIT RESULTS TTC had received and reviewed SunGard s DR test results annually. Any significant DR issues had been remediated. Summary Within the scope of the audit, OAAS noted that the contractor did not comply with certain contract terms and conditions and TTC could strengthen its monitoring effort to ensure contract compliance. Finding I: Contract Monitoring of IT Hosting Services Should be Strengthened There was no evidence that TTC had monitored SunGard s IT hosting service contract to ensure proper system security. According to TTC s previous Accounting Manager, she received SunGard s SSAE 16 audit report every year. However, there was no evidence that TTC had performed a review of the audit report upon receipt. Conducted by SunGard s auditor, the SSAE 16 audit provides assurance on the design and operating effectiveness of SunGard s IT general controls. Without a timely review of the SSAE 16 audit report, TTC might be unaware of SunGard s IT security issues and the resulting impact to TTC s data. Consequently, corrective actions to remediate reported issues might be delayed or not take place, adversely affecting the availability, confidentiality, and integrity of TTC s data. County policies state that each County department is responsible for monitoring its contracts and protecting its data, including the following: The County s Board of Supervisors Policy #A-81, Procurement of Contract Services, specifies that the department head has overall contract administration responsibility for the contract awarded. Specifically, the department head shall be responsible for the overall performance of the contract, including contract monitoring. The County s Administrative Policy # , County Contracting, states that individual departments are responsible for life-cycle administration of their contracts up to and including final contract close-out. The County s Administrative Policy # , County Information Systems Management and Use, states that County departments are responsible for managing department information systems resources in a manner that maximizes service to its customers while maintaining network security. The County s Board of Supervisors Policy #A-111, Data/Information and Information Systems, specifies that designated County departments are responsible for managing and protecting County data/information. Also, the Board directs County departments to implement adequate physical security controls to protect County data/information from unauthorized access, distribution, disruption and accidental loss. During audit fieldwork, TTC management stated that they have recently designated a staff for contract monitoring and planned to develop a contract monitoring process and related checklists and templates. 2
6 Recommendation: Finding II: TTC should develop and implement a process to ensure timely and effective monitoring of the IT hosting service contract, including a review of the contractor s annual SSAE 16 audit report. In particular, if the SSAE 16 audit report identifies any significant security issues, TTC should follow up with the contractor to understand the impact to TTC s data and ensure timely remediation of any issues. Disaster Recovery Plan Not Documented or Tested Prior to this audit, SunGard utilized a standardized DR plan for TTC, without tailoring the plan to TTC s data and IT environment. Additionally, TTC had not requested SunGard to perform any DR testing specific to TTC s data until the end of audit fieldwork. According to the Contract, SunGard will maintain DR plans for the IT hosting services and TTC s data, DR plans will be tested at least annually, and DR test results made available for TTC s review upon request. Without a DR plan customized for TTC s data and IT environment, SunGard and TTC will not be able to test the DR plan. Without testing the DR plan, TTC cannot assess the adequacy and effectiveness of the DR plan. As a result, TTC s data may potentially be unrecoverable or unavailable for an extended period of time, should computer equipment fail or a disaster occur. Recommendation: 1. TTC should request that SunGard develop a DR plan that is up-todate with adequate details and customized for TTC s data and IT environment. 2. TTC should work with SunGard to test the DR plan as soon as possible to ensure that the DR process can be executed successfully with satisfactory results and any significant issues remediated. 3. For future IT service provider contracts, TTC should: Require the contractor to have an approved and tested DR plan. Require the contractor to perform DR tests on TTC s data, at least annually. Review the contractor s DR test results to identify any significant issues. Ensure any significant DR issues are satisfactorily remediated. 3
7 DEPARTMENT S RESPONSE 4
8 5
9 6
OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Lynne Prizzia, CISA, CRISC Senior Auditor:
OFFICE OF AUDITS & ADVISORY SERVICES SHAREPOINT SECURITY AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES SHAREPOINT SECURITY AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Senior Audit Manager: Lynne Prizzia, CISA, CRISC Senior
OFFICE OF AUDITS & ADVISORY SERVICES ACCOUNTS PAYABLE VENDOR MASTER FILE AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES ACCOUNTS PAYABLE VENDOR MASTER FILE AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Senior Audit Manager: Lynne Prizzia,
OFFICE OF AUDITS & ADVISORY SERVICES IT DISASTER RECOVERY AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES IT DISASTER RECOVERY AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Lynne Prizzia, CISA, CRISC Senior Auditor:
COMPUTER OPERATIONS - BACKUP AND RESTORATION
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES COMPUTER OPERATIONS - BACKUP AND RESTORATION FINAL AUDIT REPORT Chief of Audits: Julie Nieminski, CPA, CIA, CFE, CISA, MPA
COMPUTER OPERATIONS AUDIT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES COMPUTER OPERATIONS AUDIT FINAL AUDIT REPORT Chief of Audits: James L. Pelletier, CIA, CICA IT Audit Manager: Lynne Prizzia,
OFFICE OF AUDITS & ADVISORY SERVICES BEHAVIORAL HEALTH SERVICES CONTRACT MONITORING AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES BEHAVIORAL HEALTH SERVICES CONTRACT MONITORING AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Laura R.
OFFICE OF AUDITS & ADVISORY SERVICES MOBILE DEVICE MANAGEMENT COUNTYWIDE AUDIT FINAL REPORT. County of San Diego Auditor and Controller
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES MOBILE DEVICE MANAGEMENT COUNTYWIDE AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Lynne Prizzia, CISA,
Comptroller of the Treasury Information Technology Division
Audit Report Comptroller of the Treasury Information Technology Division September 2006 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY This report and any related
Office of Public Affairs Business Process Audit Final Report
Office of Public Affairs Business Process Audit Final Report May 2012 Executive Summary We performed a business process audit of the procurement cards, office supplies purchases, small purchase orders
Maryland Transportation Authority
Audit Report Maryland Transportation Authority March 2014 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY This report and any related follow-up correspondence
SECURITY AND EXTERNAL SERVICE PROVIDERS
SECURITY AND EXTERNAL SERVICE PROVIDERS How to ensure regulatory compliance and manage risks with Service Organization Control (SOC) Reports Jorge Rey, CISA, CISM, CGEIT Director, Information Security
OUTSOURCING DUE DILIGENCE FORM
OUTSOURCING DUE DILIGENCE FORM SERVICE TO BE OUTSOURCED 1. Type of service to be outsourced: Accounting/Finance: Compliance Consulting: Legal Services: Administrative Functions: Information Technology:
Information Technology Internal Audit Report
Information Technology Internal Audit Report Report #2013-03 August 9, 2013 Table of Contents Page Executive Summary... 3 Background Information... 4 Background... 4 Audit Objectives... 4 Scope... 5 Testing
Significant Revisions to OMB Circular A-127. Section Revision to A-127 Purpose of Revision Section 1. Purpose
Significant Revisions to OMB Circular A-127 Section Revision to A-127 Purpose of Revision Section 1. Purpose Section 5. Definitions Section 6. Policy Section 7. Service Provider Requirements Section 8.
MICHIGAN AUDIT REPORT OFFICE OF THE AUDITOR GENERAL THOMAS H. MCTAVISH, C.P.A. AUDITOR GENERAL
MICHIGAN OFFICE OF THE AUDITOR GENERAL AUDIT REPORT THOMAS H. MCTAVISH, C.P.A. AUDITOR GENERAL The auditor general shall conduct post audits of financial transactions and accounts of the state and of all
CFPB Readiness Series: Compliant Vendor Management Overview
CFPB Readiness Series: Compliant Vendor Management Overview Legal Disclaimer This information is not intended to be legal advice and may not be used as legal advice. Legal advice must be tailored to the
NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL
NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL INDEPENDENT EVALUATION OF THE NATIONAL CREDIT UNION ADMINISTRATION S COMPLIANCE WITH THE FEDERAL INFORMATION SECURITY MANAGEMENT ACT (FISMA)
Information Technology Operational Audit DEPARTMENT OF STATE. Florida Voter Registration System (FVRS) Report No. 2016-002 July 2015
July 2015 Information Technology Operational Audit DEPARTMENT OF STATE Florida Voter Registration System (FVRS) Sherrill F. Norman, CPA Auditor General Secretary of State Section 20.10, Florida Statutes,
AUDITOR GENERAL WILLIAM O. MONROE, CPA
AUDITOR GENERAL WILLIAM O. MONROE, CPA HILLSBOROUGH COUNTY DISTRICT SCHOOL BOARD LAWSON FINANCIALS MODULE Information Technology Audit SUMMARY To support its financial management needs, the Hillsborough
Larry Laine, Deputy Land Commissioner and Chief Clerk. Annual Report on the Internal Audit Quality Assurance and Improvement Program
DATE: TO: FROM: SUBJECT: Larry Laine, Deputy Land Commissioner and Chief Clerk Tracey Hall, Deputy Commissioner of Internal Audit Annual Report on the Internal Audit The following report is presented in
Software Licenses Managing the Asset and Related Risks
AUDITOR GENERAL S REPORT ACTION REQUIRED Software Licenses Managing the Asset and Related Risks Date: February 4, 2015 To: From: Wards: Audit Committee Auditor General All Reference Number: SUMMARY The
Goodbye, SAS 70! Hello, SSAE 16!
Goodbye, SAS 70! Hello, SSAE 16! A Session to Provide Insight on the New Standard and What Service Providers and End-Users Need to Know January 3, 2012 Agenda Introduction Background on what was SAS 70
TITLE III INFORMATION SECURITY
H. R. 2458 48 (1) maximize the degree to which unclassified geographic information from various sources can be made electronically compatible and accessible; and (2) promote the development of interoperable
STATE OF NORTH CAROLINA
STATE OF NORTH CAROLINA PERFORMANCE AUDIT OFFICE OF INFORMATION TECHNOLOGY SERVICES STATE TERM CONTRACT FOR MICROCOMPUTERS AND PERIPHERALS JULY 2013 OFFICE OF THE STATE AUDITOR BETH A. WOOD, CPA STATE
DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES
APPENDIX 1 DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES March 2008 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1
Management Standards for Information Security Measures for the Central Government Computer Systems
Management Standards for Information Security Measures for the Central Government Computer Systems April 21, 2011 Established by the Information Security Policy Council Table of Contents Chapter 1.1 General...
Comptroller of Public Accounts Effectiveness of Internal Engagement May 1997
Table of Contents Comptroller of Public Accounts Effectiveness of Internal Engagement May 1997 Overall Conclusion...1 The Internal Audit Department Is Currently Effective in All Eight Criteria, But Could
INTERNAL AUDIT DIVISION CLERK OF THE CIRCUIT COURT
INTERNAL AUDIT DIVISION CLERK OF THE CIRCUIT COURT FOLLOW UP REVIEW TO AUDIT OF COURTROOM AUTOMATION Karleen F. De Blaker Clerk of the Circuit Court Ex officio County Auditor Robert W. Melton, CPA*, CIA,
Outsourcing and third party access
Outsourcing and third party access This document is part of the UCISA Information Security Toolkit providing guidance on the policies and processes needed to implement an organisational information security
EVALUATION REPORT. Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review. March 13, 2015 REPORT NUMBER 15-07
EVALUATION REPORT Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review March 13, 2015 REPORT NUMBER 15-07 EXECUTIVE SUMMARY Weaknesses Identified During the FY 2014
INFORMATION SECURITY California Maritime Academy
CSU The California State University Office of Audit and Advisory Services INFORMATION SECURITY California Maritime Academy Audit Report 14-54 April 8, 2015 Senior Director: Mike Caldera IT Audit Manager:
Financial Management Information System Centralized Operations
Audit Report Financial Management Information System Centralized Operations March 2003 This report and any related follow-up correspondence are available to the public. Alternate formats may also be requested
Union County. Electronic Records and Document Imaging Policy
Union County Electronic Records and Document Imaging Policy Adopted by the Union County Board of Commissioners December 2, 2013 1 Table of Contents 1. Purpose... 3 2. Responsible Parties... 3 3. Availability
Vendor Compliance Management Series: Performing an Effective Risk Assessment
Vendor Compliance Management Series: Performing an Effective Risk Assessment Legal Disclaimer This information is not intended to be legal advice and may not be used as legal advice. Legal advice must
SOUTH LAKELAND DISTRICT COUNCIL INTERNAL AUDIT FINAL REPORT IT 11-02. IT Backup, Recovery and Disaster Recovery Planning
SOUTH LAKELAND DISTRICT COUNCIL INTERNAL AUDIT FINAL REPORT IT 11-02 IT Backup, Recovery and Disaster Recovery Planning Executive Summary Introduction As part of the 2011/12 Audit Plan and following discussions
OVERALL RATING: PARTIALLY SATISFACTORY
INTERNAL AUDIT DIVISION REPORT 2016/059 Audit of the use of consultants and individual contractors in the United Nations Support Office in Somalia Overall results relating to the effective management of
MANAGEMENT AUDIT REPORT DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION
MANAGEMENT AUDIT REPORT OF DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION REPORT NO. 13-101 City of Albuquerque Office of Internal Audit
Office of the Auditor General Performance Audit Report. Statewide UNIX Security Controls Department of Technology, Management, and Budget
Office of the Auditor General Performance Audit Report Statewide UNIX Security Controls Department of Technology, Management, and Budget December 2015 State of Michigan Auditor General Doug A. Ringler,
Health and Human. Services. Commission. InternalAutht Division. Internal Audit Plan. Fiscal Year 2016
x Health and Human Services, Commission InternalAutht Division Internal Audit Plan Fiscal Year 2016 September 22, 2015 NicolE Guerrero, MBA, CIA, CGAP DiredQgof Internal Audit Chris Traylor Executive Commissioner
MICHIGAN AUDIT REPORT OFFICE OF THE AUDITOR GENERAL THOMAS H. MCTAVISH, C.P.A. AUDITOR GENERAL
MICHIGAN OFFICE OF THE AUDITOR GENERAL AUDIT REPORT THOMAS H. MCTAVISH, C.P.A. AUDITOR GENERAL The auditor general shall conduct post audits of financial transactions and accounts of the state and of all
Comptroller of Maryland Information Technology Division Annapolis Data Center Operations
Audit Report Comptroller of Maryland Information Technology Division Annapolis Data Center Operations March 2015 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY
2002-2003 GRAND JURY REPORT Advanced Life Support Ambulance Contract Riverside County
2002-2003 GRAND JURY REPORT Advanced Life Support Ambulance Contract Riverside County Background On September 14, 1995, the Board of Supervisors of Riverside County, State of California, enacted County
Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014
Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014 Summary of Request: The purpose, authority, and responsibility of the internal
CASH COUNT AND BANK RECONCILIATION AUDIT
City of San Diego AUDIT REPORT CASH COUNT AND BANK RECONCILIATION AUDIT KROLL REMEDIATION OF THE CITY S BANK RECONCILIATION PROCESS April 28, 2008 Internal Audit Eduardo Luna, CIA, CGFM, Internal Auditor
Office of Inspector General
Audit Report OIG-12-052 INFORMATION TECHNOLOGY: Financial Management Service Successfully Demonstrated Recovery Capability for Treasury Web Application Infrastructure May 11, 2012 Office of Inspector General
Office of the Register of Wills Baltimore County, Maryland
Audit Report Office of the Register of Wills Baltimore County, Maryland April 2002 This report and any related follow-up correspondence are available to the public. Alternate formats may also be requested
I S O I E C 2 7 0 0 2 2 0 1 3 I N F O R M A T I O N S E C U R I T Y A U D I T T O O L
15.1 ESTABLISH SECURITY AGREEMENTS WITH SUPPLIERS 15.1.1 EXPECT SUPPLIERS TO COMPLY WITH RISK MITIGATION AGREEMENTS Do you clarify the information security risks that exist whenever your suppliers have
Audit of Physical Security Management
Audit of Physical Security Management Natural Sciences and Engineering Research Council of Canada Social Sciences and Humanities Research Council Approved by the President on March 18, 2015 1 Her Majesty
