Audit: State IT System Vulnerable To Security Breaches | Eastern NC Now

A newly released state audit has revealed shortcomings in the state government information technology system that could compromise security.

ENCNow
    Publisher's note: The author of this post is Barry Smith, who is an associate editor for the Carolina Journal, John Hood Publisher.

Auditor cites potential security gaps, praises CIO for working to address vulnerabilities


    RALEIGH     A newly released state audit has revealed shortcomings in the state government information technology system that could compromise security.

    "There have not been breaches," State Auditor Beth Wood said. "There have been a lot of instances where people were trying to get in." Wood added that the state took too much time reacting to the vulnerabilities.

    "The state's [chief information officer's] office doesn't have a plan for risk management," Wood said. "You really don't have them setting performance metrics to make sure our data can't be breached."

    The auditor's office recommends that the state CIO direct the department's Enterprise Security and Risk Management Office to adopt a comprehensive and well-documented risk management framework. It also recommends the CIO direct ESRMO to establish and post performance measures on the department's website as required by law.

    Other recommendations request the state CIO to direct:

  • the risk management office to begin annual assessments of each agency and each vendor to determine compliance with state security standards;
  • the risk management office to complete a comprehensive strategy for agencies to conduct security assessments and communicated that strategy to all agencies;
  • personnel to address and resolve immediately vulnerabilities detected during scans of systems within established deadlines.

    The auditor's office also suggests that the General Assembly consider modernizing the state's IT security law.

    Wood said that the state CIO has no authority over a lot of local organizations with information systems that are tied into the state's system. Those include local school systems connected to the state Department of Public Instruction's system, local clerks of court offices linked with the state Administrative Office of the Courts, and county agencies tied into the Department of Health and Human Services.

    The lack of sufficient safeguards puts state and personal information at risk, Wood said. That includes Social Security numbers, bank accounts, medical information, criminal records, and tax information, she said.

    "There is a lot of our private personal stuff that could be used to either steal money or steal our identities," Wood said.

    Keith Werner, state chief information officer, generally agreed with the auditor's findings and recommendations. In an eight-page letter to Wood, Werner laid out measures his office is taking or will take to address the shortcomings of the state IT system.

    Werner noted that many of the issues began at a time the IT system was divided among a host of state agencies. Last year, the General Assembly established a Cabinet-level Department of Information Technology in an attempt to centralize IT efforts and modernization.

    Wood said she was pleased with Werner's response.

    "The new CIO is very appreciative of the work," Wood said. "He was on to some of this before our audit started. ... This is good news for me as a taxpayer."
Go Back


Leave a Guest Comment

Your Name or Alias
Your Email Address ( your email address will not be published )
Enter Your Comment ( text only please )




Missouri Attorney General And Democrat Candidate For Governor Calls Obama's Directive To Schools "Wrong" Statewide, Government, State and Federal Online Driver License Renewal Hits Major Milestone


HbAD0

Latest State and Federal

Tax Day is a week away, and the reports are in: North Carolinians are winning big with record-setting tax returns thanks to President Trump and Republicans' Working Families Tax Cuts.
“It is a trust fund, a piece of the American economy for every child that they will be able to take out when they are 18.”
For most of her life, Zofia Cheeseman built her life and schedule around being a gymnast until a health scare forced her to look at her life off the mat.
"We could very well end up having a friendly takeover of Cuba."
You can't make this up. If you turned this script into Hollywood, they'd say it's too on the nose.
"Alaska native" firms, most often in Virginia, were paid $45 billion in Pentagon contracts thanks to DEI law.

HbAD1

Small cities rarely make headlines. Their struggles - fiscal mismanagement, leadership vacuums, the slow erosion of public trust - play out in school gymnasiums and wood-paneled council chambers, witnessed by a handful of residents and largely ignored by the world outside.
"Go that way and get down ... there has been a shooting ... there are people dead over here."
Former provost Chris Clemens has dropped his open meetings and public records lawsuit against the University of North Carolina at Chapel Hill.
How the Minnesota Senate race became a purity test for the far Left
America is great because for many decades her immigrants came from a similar cultural background that bore a heavy Christian influence.
After years in the limelight for his combative style both with Democrats and his fellow Republicans, Crenshaw's future now unsure.
Conservatives don't always engage with the broader culture. We're going to change that.
A heavy security presence remains in downtown Austin after a chaotic shooting spree early Sunday morning left two victims dead and 14 others injured.

HbAD2

 
 
Back to Top