Determine whether Hicksville Union Free School District (District) officials established adequate controls for managing business office network user accounts to help prevent unauthorized computer use, access and loss.
District officials did not properly manage network user account controls to help maintain continuity of business office operations and prevent unauthorized computer use, access and loss. Officials also did not establish written procedures for granting, verifying, changing and disabling network user account access, including business office network user account access.
In addition, sensitive IT control weaknesses were confidentially communicated to District officials.
Establish written procedures for granting, verifying, changing and disabling business office network user account access.
District officials generally agreed with our recommendations and have initiated or indicated they plan to initiate corrective action. Appendix B includes our comment on an issue that was raised in the District’s response letter.