Audit Objective
Determine whether Bainbridge-Guilford Central School District (District) officials adequately managed network user accounts.
Key Findings
District officials:
- Did not adequately manage network user accounts. We identified 66 unneeded user accounts including 52 generic accounts and 14 former employees’ accounts.
- Adequately managed network administrative permissions.
Sensitive information technology (IT) control weaknesses were communicated confidentially to officials.
Key Recommendations
- Disable former employees’ network user accounts as soon as they leave District employment.
- Periodically evaluate existing network user accounts, including generic accounts and disable any deemed unneeded.
District officials agreed with our recommendations and indicated they planned to initiate corrective action.