Audit Objective
Determine whether Nyack Union Free School District (District) officials adequately managed and monitored network user accounts.
Key Findings
District officials did not ensure that network user accounts were adequately managed and monitored. Officials did not:
- Monitor compliance with the District’s computer acceptable use policy.
- Maintain a current authorized user list.
Sensitive information technology (IT) control weaknesses were communicated confidentially in a separate letter to officials.
Key Recommendations
- Monitor compliance with the computer acceptable use policy.
- Develop written procedures for managing system access that include periodically reviewing user access and disabling unnecessary network user accounts.
District officials agreed with our recommendations and indicated they will take and have taken corrective action.