Audit Objective
Determine whether Peekskill City School District (District) officials adequately managed and monitored network user accounts.
Key Findings
District officials did not adequately manage and monitor network user accounts. In addition to sensitive information technology (IT) control weaknesses which we communicated confidentially to officials, we found District officials should have:
- Disabled 133 of the District’s 821 network user accounts. These accounts consisted of 56 individual and 77 generic unneeded network user accounts, one of which was last logged on in January 2012.
- Ensured all users using IT resources received periodic IT awareness training.
Key Recommendations
- Periodically review enabled network user accounts and ensure that unneeded user accounts are immediately disabled.
- Provide periodic IT security awareness training to all users who use IT resources.
District officials agreed with our recommendations and indicated they will take corrective action.