Audit Objective
Did Lawrence Union Free School District (District) officials adequately manage network user accounts and provide IT security awareness training to staff?
Audit Period
July 1, 2024 – April 28, 2026
Understanding the Audit Area
School officials are responsible for effectively managing network user accounts and providing periodic IT security awareness training to staff. Together, these measures strengthen a district’s IT control environment by helping prevent unauthorized access; protecting personal, private, sensitive information (PPSI)1 and critical systems; reducing the risk of operational disruptions and supporting the continuity of a district’s operations. Effective IT governance also helps safeguard public resources and promote accountability, transparency and public trust.
As of March 26, 2025, the District had 494 enabled nonstudent network user accounts on one domain, and as of April 24, 2025, it had 175 enabled nonstudent network user accounts on a second domain.
Audit Summary
Although District training records support that officials generally provided IT security awareness training to staff we reviewed, officials did not adequately manage all nonstudent network user accounts. As a result, officials cannot be assured that District IT systems are secured and protected against unauthorized use.
District officials did not have written policies or procedures for user account management. We identified 250 unneeded user accounts which District officials should have disabled or removed, including 162 accounts of former employees, third-party providers and consultants, and 88 service accounts. Additionally, officials could not provide documentation demonstrating IT security awareness training was completed for one employee of the 10 employee records we reviewed.
The report includes five recommendations that, if implemented, will improve the District’s management of network user accounts, strengthen cybersecurity governance and internal controls and better protect District information systems from unauthorized access and misuse. District officials generally agreed with our recommendations and have initiated, or indicated they planned to initiate corrective action.
This audit was conducted pursuant to Article V, Section 1 of the State Constitution and the Office of the New York State Comptroller’s (OSC’s) authority as set forth in Article 3 of the New York State General Municipal Law (GML). The audit’s methodology and standards are included in Appendix C.
A written corrective action plan (CAP) that addresses the findings and recommendations in this report must be prepared and provided to OSC within 90 days, pursuant to Section 35 of GML, Section 2116-a (3)(c) of the New York State Education Law and Section 170.12 of the Regulations of the Commissioner of Education. To the extent practicable, implementation of the CAP must begin by the end of the next fiscal year. For more information on preparing and filing the CAP, please refer to the OSC brochure, Responding to an OSC Audit Report, which was provided with the draft audit report. The CAP should be posted on the District’s website for public review.
1 PPSI is any information to which unauthorized access, disclosure, modification, destruction or use – or disruption of access or use – could have or cause a severe impact on critical functions, employees, customers, third parties or other individuals or entities.