DiscoverThe Rundown with Kansas Legislative Division of Post AuditInformation Systems: Reviewing Specific IT Security Controls Across State Agencies and School Districts [July 2023]
Information Systems: Reviewing Specific IT Security Controls Across State Agencies and School Districts [July 2023]

Information Systems: Reviewing Specific IT Security Controls Across State Agencies and School Districts [July 2023]

Update: 2023-07-06
Share

Description

This audit determined whether selected state agencies and school districts adequately complied with certain IT security standards and best practices. State agencies must follow state IT security standards to protect sensitive information against data loss and theft. Local entities are not required to follow the state's policies. 

9 of 15 entities we audited did not substantively comply with IT standards and best practices in at least 2 of 3 subject areas we evaluated. Specifically, 8 of 15 entities did not substantively comply with selected security awareness training controls. 10 of 15 entities did not substantively comply with selected account security controls. Lastly, 8 of 15 did not substantively comply with selected incident response controls. The findings demonstrate a poor "tone at the top" at many entities--meaning lack of top management oversight and supervision.

Comments 
In Channel
loading
Download from Google Play
Download from App Store
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Information Systems: Reviewing Specific IT Security Controls Across State Agencies and School Districts [July 2023]

Information Systems: Reviewing Specific IT Security Controls Across State Agencies and School Districts [July 2023]

Legislative Post Audit