STUDENT FINANCIAL ASSISTANCE CLUSTER FINDINGSFINDING 2022-003 - Internal Control over Compliance (Repeat Finding 2021-003, 2020-001, 2019-002, 2018-003, 2017-002, 2015-002, 2014-008)ResponsesNSHE Overall response/context ?NSHE increased its dialogue amongst the three instances of the student informa...
STUDENT FINANCIAL ASSISTANCE CLUSTER FINDINGSFINDING 2022-003 - Internal Control over Compliance (Repeat Finding 2021-003, 2020-001, 2019-002, 2018-003, 2017-002, 2015-002, 2014-008)ResponsesNSHE Overall response/context ?NSHE increased its dialogue amongst the three instances of the student information system throughout fiscalyear 2022. The results of this robust dialogue led to additional controls to reduce related IT risks, enhancedmonitoring of activities, and targeted periodic reviews, highlighted in each instance?s response below. Theseenhanced techniques operating throughout the entire fiscal year ahead, should provide a stronger overall controlenvironment and lower associated risks.UNR ?? Detailed corrective action taken, including what will be done to avoid the identified issues inthe future, and when these measures will be in place;UNR has implemented controls to address the risk associated with the PeopleSoft Administrators(PSA?s) access to the production and development environments. The controls include:1. The University will remove the PSA role for the three individuals that are identified as not havingthe appropriate segregation of duties. The PSA role is still required of the University and will onlybe granted on a temporary basis when necessary and this access will be, documented, monitored,and deactivated upon completion of the required tasks.a) Approvals ? A PSA role is granted for task specific business needs and when the individualssecurity level does not permit the action to be performed. When justified, the PSA role isgranted by a security administrator.b) Documented ? When the PSA role is granted a notification is triggered to the Associate VicePresident, Planning, Budget and Analysis, the Registrar and the Director of AccountingOperations as to the role assignment and the person assigned.c) Monitored ? The activities performed are documented and monitored in a TeamDynamixticket.d) Deactivated ? The PSA system access is deactivated upon completion of the required activity.The deactivation is documented in the TeamDynamix ticketing system.2. The University will implement a quarterly User Access Review that identifies the incidences ofwhen the PSA role is granted and when the PSA login occurs and compares this to Team Dynamixto establish the activity. The activity can be compared to the system for validity. This will beperformed by the Registrar. 3. The University will continue to explore and research Change Control Systems as options tomonitor activities of the PSA?s.? How compliance and performance will be measured and documented for future audit,management and performance review.The PSA role will not be established for continuous periods of time. When the PSA role is temporarilygranted it is documented and tracked in Team Dynamix. This provides an audit trail of role access,timeframes of logins, and activities.? Who will be responsible and may be held accountable in the future if repeat or similarobservations are noted.The Associate Vice President, Planning, Budget and Analysis will monitor the compliance with thecorrective action plans and will implement new processes as needed to meet the needs of mitigatingthis risk and the system updates and changes.UNLV ?UNLV agrees with this finding.? Detailed corrective action taken, including what will be done to avoid the identified issues inthe future, and when these measures will be in place;UNLV understands the importance of adequate segregation of duties within the PeopleSoftenvironments and applications. The PeopleSoft Administrator (PSA) position that is the subject ofthe finding is responsible for the installation, configuration, upgrades, and troubleshooting of all theapplication environments. The PeopleSoft Administrators are not programmers/developers, andtheir access to the production environments is periodically required to perform the needed activitiesrequired to provide timely support of the application within the scope of their job duties.UNLV has implemented the following controls to mitigate the risks associated with the elevatedaccess required for the administrators to perform their required support activities.a. UNLV will remove the PeopleSoft Administrator role from all PSAs in productionenvironments.b. The PeopleSoft Administrator role will be assigned temporarily when elevated actions arerequired. The assignment will have the following requirements:i. Be limited in duration.ii. Document a justification detailing the need and actions to be performed.iii. Generate notification to the Director of Enterprise Applications.iv. Automatically be removed.v. It is reviewed as part of normal audit activities. c. UNLV will increase their reviews of access, activities, and assigned privileges to monthly forthe PeopleSoft Administrators.d. UNLV will continue researching and implementing other control methods to address thesegregation of duties while providing appropriate service and support.? How compliance and performance will be measured and documented for future audit,management and performance review.The PeopleSoft Administrator role will no longer be a persistent assignment to the PSA position.UNLV will perform monthly reviews of the access and activities to determine if the PeopleSoftAdministrators' current levels require further refinement. Additionally, UNLV will continue toresearch other control methods that will address the segregation of duties while providingappropriate service and support.? Who will be responsible and may be held accountable in the future if repeat or similarobservations are noted.The Director of Enterprise Applications will be responsible for reviewing the access needs of thePeopleSoft Administrators. The Director will complete the reviews and is also accountable if repeat orsimilar observations are noted. The Chief Information Security Officer will verify the reviews are permonthly audit practices.SCS ?? Detailed corrective action taken, including what will be done to avoid the identified issues inthe future, and when these measures will be in place;PeopleSoft Administrator (PSA) access to the Production and Development environments arereviewed on an ongoing basis. Due to the need to develop and perform program changes for all fiveshared-instance Institutions on a frequent basis it was determined that PSA access cannot be reducedany further. However, to address the segregation of duties risk the following compensating controlsare in place:(a) STAT for PeopleSoft ? Code control and internal modification tracking provides visibility over PSAactivities that are processed via this tool. These object changes are reviewed and approved by theDirector of Information and Application Services.(b) JIRA - Change control management and project tracking software. Change requests and projectsrelated to the PeopleSoft shared instance are tracked and approved. This would include user accessmodifications and system updates for example.(c) Security e-mail alerts ? The SCS security team are alerted via automated e-mails when user access(to include PSA roles) is changed.(d) User Access Reviews ? On an annual basis a user access review is performed incorporatingSCS/SA privileged users and all shared instance security coordinators SCS will implement the following additional control from FY22/23 going forward:(e) Splunk reporting and monitoring ? Reporting and trigger events developed incorporating PSAactivity ?anomalies?. For example, PSA after-hour logins reviewed and matched to plannedupdates/activities.(f) Periodic management reviews ? A formal review incorporating, and documenting PSA andassociated exception activities will take place. Where appropriate this will include approvals anddocumented rationale.SCS will continue to explore additional solutions to minimize the segregation of duties risk, especiallyas it relates to the monitoring of PSA activities.? How compliance and performance will be measured and documented for future audit,management and performance review.The periodic management review where appropriate will include documentation and approvals tosupport PSA activities that do not meet established criteria. This review will also document anyfollow-ups required as it relates to similar controls. For example, security e-mail alerts.? Who will be responsible and may be held accountable in the future if repeat or similarobservations are noted.SCS Director of Information and Application Services, SCS Security Group.