DiscoverThe Rundown with Kansas Legislative Division of Post Audit3 Year Summary of Security Controls in Selected State and Local Entities (2020-2022) [December 2022]
3 Year Summary of Security Controls in Selected State and Local Entities (2020-2022) [December 2022]

3 Year Summary of Security Controls in Selected State and Local Entities (2020-2022) [December 2022]

Update: 2022-12-12
Share

Description

We completed 21 audits on 16 agencies and 4 school districts between CY 2020 and 2022 (1 entity was audited twice during this time period). This summary report shows 10 of the 21 entities did not substantially comply with applicable IT security standards and best practices. Entities struggled with properly scanning and patching their computers. Entities also had compliance problems because they did not create, maintain, or test incident response plans or continuity of operations plans. Other significant issues included poor security awareness training or failed social engineering tests. Almost half the entities had significant management, contract, or policy-related weaknesses. Additional security weaknesses included inadequate account security controls, poor encryption, back up, or destruction processes of sensitive data. We also noted several entities had inadequate network boundary protection or had poor access or environmental controls for their data centers. Lastly, we identified significant security issues within agencies’ specific IT systems. The findings in this report are similar to those in previous summary IT reports. The main reasons for compliance problems across the 20 entities included insufficient top management attention and inadequate resources.

Comments 
In Channel
loading
Download from Google Play
Download from App Store
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

3 Year Summary of Security Controls in Selected State and Local Entities (2020-2022) [December 2022]

3 Year Summary of Security Controls in Selected State and Local Entities (2020-2022) [December 2022]