Audit: State IT System Vulnerable To Security Breaches | Eastern NC Now

A newly released state audit has revealed shortcomings in the state government information technology system that could compromise security.

ENCNow
    Publisher's note: The author of this post is Barry Smith, who is an associate editor for the Carolina Journal, John Hood Publisher.

Auditor cites potential security gaps, praises CIO for working to address vulnerabilities


    RALEIGH     A newly released state audit has revealed shortcomings in the state government information technology system that could compromise security.

    "There have not been breaches," State Auditor Beth Wood said. "There have been a lot of instances where people were trying to get in." Wood added that the state took too much time reacting to the vulnerabilities.

    "The state's [chief information officer's] office doesn't have a plan for risk management," Wood said. "You really don't have them setting performance metrics to make sure our data can't be breached."

    The auditor's office recommends that the state CIO direct the department's Enterprise Security and Risk Management Office to adopt a comprehensive and well-documented risk management framework. It also recommends the CIO direct ESRMO to establish and post performance measures on the department's website as required by law.

    Other recommendations request the state CIO to direct:

  • the risk management office to begin annual assessments of each agency and each vendor to determine compliance with state security standards;
  • the risk management office to complete a comprehensive strategy for agencies to conduct security assessments and communicated that strategy to all agencies;
  • personnel to address and resolve immediately vulnerabilities detected during scans of systems within established deadlines.

    The auditor's office also suggests that the General Assembly consider modernizing the state's IT security law.

    Wood said that the state CIO has no authority over a lot of local organizations with information systems that are tied into the state's system. Those include local school systems connected to the state Department of Public Instruction's system, local clerks of court offices linked with the state Administrative Office of the Courts, and county agencies tied into the Department of Health and Human Services.

    The lack of sufficient safeguards puts state and personal information at risk, Wood said. That includes Social Security numbers, bank accounts, medical information, criminal records, and tax information, she said.

    "There is a lot of our private personal stuff that could be used to either steal money or steal our identities," Wood said.

    Keith Werner, state chief information officer, generally agreed with the auditor's findings and recommendations. In an eight-page letter to Wood, Werner laid out measures his office is taking or will take to address the shortcomings of the state IT system.

    Werner noted that many of the issues began at a time the IT system was divided among a host of state agencies. Last year, the General Assembly established a Cabinet-level Department of Information Technology in an attempt to centralize IT efforts and modernization.

    Wood said she was pleased with Werner's response.

    "The new CIO is very appreciative of the work," Wood said. "He was on to some of this before our audit started. ... This is good news for me as a taxpayer."
Go Back


Leave a Guest Comment

Your Name or Alias
Your Email Address ( your email address will not be published )
Enter Your Comment ( text only please )




Missouri Attorney General And Democrat Candidate For Governor Calls Obama's Directive To Schools "Wrong" Statewide, Government, State and Federal Online Driver License Renewal Hits Major Milestone


HbAD0

Latest State and Federal

Cheryl Hines. Dennis Quaid. Nicki Minaj. All became associated with the Trump administration. What happened next?
A federal grand jury in North Carolina has indicted former FBI Director James Comey on two charges related to making threats against President Donald Trump.
Their goal was simple: to put a Planned Parenthood in every mailbox in America.
Treasury officials allege these groups pose as humanitarian entities while covertly siphoning donations to Hamas.
President Donald Trump has publicly floated regime change and other aggressive actions toward Cuba.
With a new roadside plaque unveiled in Ellerbe on April 23, legendary wrestler and local resident André René Roussimoff is finally getting the formal recognition fans believe he deserves.
Following a string of attacks, critics are calling for denaturalizations. It's not that simple.
The solution is not to legalize the problem; it is to enforce the law consistently and deter future illegal immigration.
The teachers union is pushing to cancel school on May 1 as Chicago public schools continue to report dismal student proficiency rates.

HbAD1

Mission accomplished on sending inspiration from the dark side of the moon.
Two years ago, new media brought President Trump back to the White House. What happened?
Victims’ advocates, prosecutors, law enforcement officials, and families impacted by violent crime gathered Tuesday at the North Carolina State Archives building in Raleigh to recognize National Crime Victims’ Rights Week and honor those affected by crime across North Carolina.
The POLITICO poll found that almost half of respondents think Hollywood players should "be less vocal with their political beliefs."
"They help cultivate a radical hate America agenda, and we can't afford that same toxic ideology in America's War Department.”

HbAD2

 
 
Back to Top