Audit: State IT System Vulnerable To Security Breaches | Eastern North Carolina Now

    Publisher's note: The author of this post is Barry Smith, who is an associate editor for the Carolina Journal, John Hood Publisher.

Auditor cites potential security gaps, praises CIO for working to address vulnerabilities


    RALEIGH     A newly released state audit has revealed shortcomings in the state government information technology system that could compromise security.

    "There have not been breaches," State Auditor Beth Wood said. "There have been a lot of instances where people were trying to get in." Wood added that the state took too much time reacting to the vulnerabilities.

    "The state's [chief information officer's] office doesn't have a plan for risk management," Wood said. "You really don't have them setting performance metrics to make sure our data can't be breached."

    The auditor's office recommends that the state CIO direct the department's Enterprise Security and Risk Management Office to adopt a comprehensive and well-documented risk management framework. It also recommends the CIO direct ESRMO to establish and post performance measures on the department's website as required by law.

    Other recommendations request the state CIO to direct:

  • the risk management office to begin annual assessments of each agency and each vendor to determine compliance with state security standards;
  • the risk management office to complete a comprehensive strategy for agencies to conduct security assessments and communicated that strategy to all agencies;
  • personnel to address and resolve immediately vulnerabilities detected during scans of systems within established deadlines.

    The auditor's office also suggests that the General Assembly consider modernizing the state's IT security law.

    Wood said that the state CIO has no authority over a lot of local organizations with information systems that are tied into the state's system. Those include local school systems connected to the state Department of Public Instruction's system, local clerks of court offices linked with the state Administrative Office of the Courts, and county agencies tied into the Department of Health and Human Services.

    The lack of sufficient safeguards puts state and personal information at risk, Wood said. That includes Social Security numbers, bank accounts, medical information, criminal records, and tax information, she said.

    "There is a lot of our private personal stuff that could be used to either steal money or steal our identities," Wood said.

    Keith Werner, state chief information officer, generally agreed with the auditor's findings and recommendations. In an eight-page letter to Wood, Werner laid out measures his office is taking or will take to address the shortcomings of the state IT system.

    Werner noted that many of the issues began at a time the IT system was divided among a host of state agencies. Last year, the General Assembly established a Cabinet-level Department of Information Technology in an attempt to centralize IT efforts and modernization.

    Wood said she was pleased with Werner's response.

    "The new CIO is very appreciative of the work," Wood said. "He was on to some of this before our audit started. ... This is good news for me as a taxpayer."
Go Back


Leave a Guest Comment

Your Name or Alias
Your Email Address ( your email address will not be published)
Enter Your Comment ( no code or urls allowed, text only please )




Missouri Attorney General And Democrat Candidate For Governor Calls Obama's Directive To Schools "Wrong" Statewide, Government, State and Federal Online Driver License Renewal Hits Major Milestone


HbAD0

Latest State and Federal

House Judiciary Chair Jim Jordan (R-OH) is looking into whether GoFundMe and Eventbrite cooperated with federal law enforcement during their investigation into the financial transactions of supporters of former President Donald Trump.
Far-left Rep. Alexandria Ocasio-Cortez (D-NY) was mocked online late on Monday after video of her yelling at pro-Palestinian activists went viral.
Daily Wire Editor Emeritus Ben Shapiro, along with hosts Matt Walsh, Andrew Klavan, and company co-founder Jeremy Boreing discussed the state of the 2024 presidential election before President Joe Biden gave his State of the Union address on Thursday.
Former U.N. Ambassador Nikki Haley said this week that the criminal trials against former President Donald Trump should happen before the upcoming elections.
Vice President Kamala Harris ignored recommendations while attorney general of California to investigate an alleged pyramid scheme at a company linked to her husband, according to documents obtained by The New York Post.
'The entire value add of Hunter Biden to our business was his family name and his access to his father, Vice President Joe Biden'
Robert F. Kennedy Jr. announced on Tuesday that he has selected Nicole Shanahan to be his vice presidential running mate as he continues to run as an Independent after dropping out of the Democratic Party’s presidential primary late last year.
The campaign for former President Donald Trump released a statement Saturday afternoon condemning the White House’s declaration of Easter Sunday as “Transgender Day of Visibility.”

HbAD1

On Tuesday, another Republican announced that he plans to retire early from the House, a decision that would further diminish a narrow GOP majority in the lower chamber.
"President Trump is moved by the invitation to join NYPD Officer Jonathan Diller’s family... "
Arkansas Republican Governor Sarah Sanders said on Tuesday that the state would ban the use of “X” on driver’s licenses and that state IDs must identify the individual as either male or female, according to an announcement first shared with The Daily Wire.
The State Board of Elections and local district attorneys argue that a recent change in North Carolina election should prompt a federal court to throw out a lawsuit from felon voting advocates.
A former Boeing employee who raised safety concerns related to the company’s aircraft production was found dead this week.
Pro-life advocates slammed a decision on Friday from pharmacy giants Walgreens and CVS to begin selling abortion pills.
Rep. Eric Swalwell (D-CA) used up his time during a Tuesday hearing on Capitol Hill to lay out a case against former President Donald Trump — and then appeared to get frustrated when the witness, Special Counsel Robert Hur, refused to help him do it.
The state Supreme Court will decide in the months ahead whether the family of a man who suffered a violation of his speedy-trial constitutional right can seek money damages against the state.

HbAD2

 
Back to Top