Corrective Action Plans

Browse how organizations respond to audit findings

Total CAPs
59,974
In database
Filtered Results
9,411
Matching current filters
Showing Page
138 of 377
25 per page

Filters

Clear
Active filters: § 200.303
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Corrective Action Planned: DSS Information Security and Risk Management security awareness and training assets will develop role based training for system administrat...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Corrective Action Planned: DSS Information Security and Risk Management security awareness and training assets will develop role based training for system administrators and data custodians. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Corrective Action Planned: DSS has contracted external IT auditors to perform IT audits once...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Corrective Action Planned: DSS has contracted external IT auditors to perform IT audits once every three years on an ongoing rotating basis in accordance with yellow book audit standards. Estimated Completion Date: 12/15/2025
Responsible Contact Person(s): Mike Jones, Chief Information Officer Steve Hanoka, Information Security Officer Corrective Action Planned: Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked acco...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Steve Hanoka, Information Security Officer Corrective Action Planned: Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked according to SEC530 resolution standards. Goal is to ensure that all vulnerabilities are remediated within the SLA or have approved exceptions by May 30, 2025. In addition, DMAS has gained guidance from VITA on acceptable alternatives to penetration testing and are tracking completion. Estimated Completion Date: 5/30/2025
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Fede...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Kavansa Gardner, IT Manager Corrective Action Planned: DSS performed an annual access review of user accounts for the system. As of December 20, 2024, the DSS projected completion date for the 2024 system Annual Review was December 31, 2024. The IT Manager is waiting f...
Responsible Contact Person(s): Kavansa Gardner, IT Manager Corrective Action Planned: DSS performed an annual access review of user accounts for the system. As of December 20, 2024, the DSS projected completion date for the 2024 system Annual Review was December 31, 2024. The IT Manager is waiting for eight more FIPs to submit screenshots of roles that have been removed or changed. The IT Manager has been in contact with all noncompliant agencies and has meetings scheduled to ensure all necessary documentation is obtained prior to the cutoff point. DSS will be reviewing final documents to certify the accuracy of the review before deadline. Estimated Completion Date: 1/31/2025
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Kavansa Gardner, IT Manager Corrective Action Planned: DSS will perform and document a conflicting access review for the management system to identify the combinations of roles that could pose separation of duties conflicts an...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Kavansa Gardner, IT Manager Corrective Action Planned: DSS will perform and document a conflicting access review for the management system to identify the combinations of roles that could pose separation of duties conflicts and ensure compensating controls are in place to mitigate risks arising from those conflicts. Additionally, DSS will work with the vendor to update the role-based security access documentation to reflect all system changes from prior case management system related releases when there are proposed changes to the roles matrix. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determine...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2026
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Dwayne Sneade, Director of Cybersecurity Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Dwayne Sneade, Director of Cybersecurity Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Sam Owusu, IT Risk Manager of Information Security & Risk Management Corrective Action Plann...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Sam Owusu, IT Risk Manager of Information Security & Risk Management Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2026
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federa...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 4/30/2025
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: 1. The requirements in the IT Security Governance or general requirements in SEC 530 are going to be addressed as part of the IT Security Planning and IT Security Program Management Policies and Pr...
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: 1. The requirements in the IT Security Governance or general requirements in SEC 530 are going to be addressed as part of the IT Security Planning and IT Security Program Management Policies and Procedures which are targeted to be complete by February 28, 2025. In addition, as part of this effort DMAS will publicize and communicate to system owners those control families which will have general / organizational procedures and which will require system specific procedures. 2. Access Management policies and procedures are in place. As part of annual SSP reviews DMAS is now verifying compliance or issues found 3. All SSPs are current and under SEC530 4. Incident Response Policies and Procedures exist 5. Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked according to SEC530 resolution standards. Goal is to ensure that all vulnerabilities are remediated within the SLA or have approved exceptions by May 30, 2025. In addition, DMAS has gained guidance from VITA on acceptable alternatives to penetration testing and are tracking completion. 6. Comprehensive third-party Management procedures are being developed and will be implemented by March 31, 2025. 7. Security Training is up to date and compliant Estimated Completion Date: 5/31/2025
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: Third-party Management that will cover ensuring all deliverables required are part of a procedure and work instruction. In addition, to specifically address the points in the finding, ISO will ensure...
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: Third-party Management that will cover ensuring all deliverables required are part of a procedure and work instruction. In addition, to specifically address the points in the finding, ISO will ensure that the work instructions cover obtaining a confirmation on the geographic location of sensitive data monthly and vulnerability scan results at least every 90 days.  During this procedure implementation, ISO will also work to specifically obtain these deliverables from the vendor in question.  Estimated Completion Date: 3/31/2025
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: Language has been added to the Conduent contract renewal for option years 1 and 2 to require the SOC 1 Type II. The renewal is in the process of being reviewed and executed to go into effect July 1, 2025...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: Language has been added to the Conduent contract renewal for option years 1 and 2 to require the SOC 1 Type II. The renewal is in the process of being reviewed and executed to go into effect July 1, 2025. Language added to contract renewal: Contractor Internal Controls Reports The Contractor shall provide the Department, at a minimum; annual, unredacted reports from its independent external auditor on the effectiveness of the Contractor’s internal controls conducted in accordance with the AICPA Statement on Standards for Attestation Engagements. If the reports disclose deficiencies in internal controls, the Contractor shall include management’s corrective action plans to remediate the deficiency. The Contractor shall provide the following reports: · SOC 1 Type 2 Report that reports on the controls at the service organization which are relevant to the user entities’ internal control over financial reporting · SOC 2 Type 2 Report covering all five Trust Services Criteria (Security, Availability, Processing Integrity, Privacy and Confidentiality) The contractor shall provide the Department with these internal control reports within 30 days of the report’s issue date. Reports shall cover a period of 12 months beginning from the end date of the prior audit period with the first report covering a period of 12 months from the execution date of this contract. The contractor shall provide unredacted SOC 1 Type 2 and/or SOC 2 Type 2 reports as described above for any subservice organizations which provide a service to the Contractor that may impact the Department’s financial, program operations, or data security as determined by the Department. Estimated Completion Date: 7/1/2026
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additio...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additionally, DSS will create a systems modification request to correct errors that are identified as occurring as a result of inaccurate programming in the data modification phase of federal report creation. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Ida Witherspoon, Chief Financial Officer Corrective Action Planned: Send periodic e-mail reminders to program staff responsible for submitting FFATA data to the Federal Reporting Unit for submission to the federal government. Estimated Completion Date: 3/15/2025
Responsible Contact Person(s): Ida Witherspoon, Chief Financial Officer Corrective Action Planned: Send periodic e-mail reminders to program staff responsible for submitting FFATA data to the Federal Reporting Unit for submission to the federal government. Estimated Completion Date: 3/15/2025
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additio...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additionally, DSS will create a systems modification request to correct errors that are identified as occurring as a result of inaccurate programming in the data modification phase of federal report creation. Benefit Program is working with appropriate parties to resolve outstanding errors. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Sherika Charity, Director of Financial Aid Lisa Boyko, Associate Director of Financial Aid Corrective Action Planned: Step 1: Develop a timeline to review information system Access for college financial aid staff and non-financial aid staff with financial aid access. ...
Responsible Contact Person(s): Sherika Charity, Director of Financial Aid Lisa Boyko, Associate Director of Financial Aid Corrective Action Planned: Step 1: Develop a timeline to review information system Access for college financial aid staff and non-financial aid staff with financial aid access. This will include the Director of Financial Aid and the Associate Director of Financial Aid Information Systems who will set scheduled meetings to conduct periodic reviews of the information system Access each semester using a designated report. Step 2: The Associate Director of Financial Aid Information Systems will create a repository to store the designated reports, which will be accessible by the Director of Financial Aid. Step 3: The Director of Financial Aid and the Associate Director of Financial Aid Information Systems will review access. If changes are needed, the appropriate IT forms will be submitted to have staff members access updated appropriately. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Paul Cormal, Chief Technology Officer Diane Carnohan, Chief Information Security Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE unde...
Responsible Contact Person(s): Paul Cormal, Chief Technology Officer Diane Carnohan, Chief Information Security Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 9/30/2025
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: DSS has 15 plus applications that are in active oversight, IT Business Administration is in receipt of the required SOC 2, Type 2 reports. However, additional requirements to capture the SOC 1, Type 2 ...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: DSS has 15 plus applications that are in active oversight, IT Business Administration is in receipt of the required SOC 2, Type 2 reports. However, additional requirements to capture the SOC 1, Type 2 reports has not yet been accomplished. Estimated Completion Date: 12/31/2025
Context: The School Corporation had one vendor which exceeded the simplified acquisition threshold which was selected for testing. The School Corporation was unable to provide any supporting documentation for the procurement process required under School Corporation policy. The sample item amount...
Context: The School Corporation had one vendor which exceeded the simplified acquisition threshold which was selected for testing. The School Corporation was unable to provide any supporting documentation for the procurement process required under School Corporation policy. The sample item amount dispersed was $160,827 for food purchases in FY 2023. Additionally, the School Corporation did not have any support to show the vendor was not disbarred or suspended. Contact Person Responsible for Corrective Action: Steve Boulanger, Food Service Director Contact Phone Number: 765-240-2372 Views of Responsible Official: We concur with the finding. Description of Corrective Action Plan: As of October 2024, our Food Service Director has been running vendors through the SAM.gov website, printing the results, and filing them for audit purposes. Anticipated Completion Date: 10/01/2024
Context: We noted that for two claims in a sample of four, the Food Service Director prepared the reimbursement claim without a secondary, documented review to ensure the accuracy of the reimbursement claim. Additionally, the number of meals claimed on two of the four claims sampled did not agree...
Context: We noted that for two claims in a sample of four, the Food Service Director prepared the reimbursement claim without a secondary, documented review to ensure the accuracy of the reimbursement claim. Additionally, the number of meals claimed on two of the four claims sampled did not agree to the supporting meal system reports. There was a gross overstatement of meals claimed of $349 and a gross understatement of meals claimed of $161 resulting in a net over reimbursement amount of $188. Contact Person Responsible for Corrective Action: Steve Boulanger, Food Service Director Contact Phone Number: 765-240-2372 Views of Responsible Official: We concur with the finding. Description of Corrective Action Plan: As of February 2024, the Food Service Director prepares the claim for reimbursement, and the Corporation Treasurer double checks all numbers and signs the claim. Anticipated Completion Date: 02/01/2024
View Audit 345211 Questioned Costs: $1
Context: During testing over controls for eligibility, we noted there was no formal, secondary review for the applications entered in the food service software determining eligibility. Additionally, there was no documented annual review by School Corporation personnel of the income eligibility guide...
Context: During testing over controls for eligibility, we noted there was no formal, secondary review for the applications entered in the food service software determining eligibility. Additionally, there was no documented annual review by School Corporation personnel of the income eligibility guidelines used by the food service software. Contact Person Responsible for Corrective Action: Steve Boulanger, Food Service Director Contact Phone Number: 765-240-2372 Views of Responsible Official: We concur with the finding. Description of Corrective Action Plan: As of February 2024, our new Food Service Director has implemented a second check of all applications by the High School ECA Treasurer. Additionally, the Food Service Director will print the USDA income parameters after July 1st, compare it to the income guidelines in our nutrition software, and have the High School ECA Treasurer double check the numbers as well. Both employees will sign off on the form, and it will be filed for audit purposes. Anticipated Completion Date: 07/01/2025
Finding Number: 2024-001 Condition: Controls were not sufficient to establish written policies and procedures surrounding procured contracts and to ensure that the history of procurement decisions were documented, as required by 2 CFR 200. Context - Institute's Management did not maintain adequate...
Finding Number: 2024-001 Condition: Controls were not sufficient to establish written policies and procedures surrounding procured contracts and to ensure that the history of procurement decisions were documented, as required by 2 CFR 200. Context - Institute's Management did not maintain adequate records for three of the four noncompetitive contracts, including details on procurement history. Additionally, for contracts under both the Research and Development Cluster and the ELC contract, management failed to provide evidence of suspension and debarment checks for contractors before entering into transactions. However, there was no evidence of contractors being suspended or debarred, and no questioned costs were identified. Planned Corrective Action: Management agrees with the recommendation and will review the relevant guidance to ensure compliance. Necessary revisions will be made to the existing procurement policies and procedures in a timely manner to ensure that procurement decisions are documented, as required by 2 CFR Part 200. Contact person responsible for corrective action: Lavenia Bell, Accounting; Teresa Martinez, Senior Post Award Coordinator; Mariela Romo, Administrator Anticipated Completion Date: 8/31/2025
Child Nutrition Cluster – Assistance Listing No. 10.553, 10.555 and 10.559 Recommendation: We recommend the District retain all direct certification reports from the State and for the District to review applications submitted electronically through food service system to determine correct eligibili...
Child Nutrition Cluster – Assistance Listing No. 10.553, 10.555 and 10.559 Recommendation: We recommend the District retain all direct certification reports from the State and for the District to review applications submitted electronically through food service system to determine correct eligibility determination is made. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action planned in response to finding: Direct Cert files received from the State starting in August 2024 will be kept on the Food Service Google drive. Names of the contact persons responsible for corrective action: Wesley Haselhorst and Dawn Koshio Planned completion date for corrective action plan: June 30, 2025
FINDING 2024-006 Finding Subject: Special Education – Procurement Summary of Finding: There was no control in place, such as an oversight, review, or approval process, to ensure that contractors or subrecipients were not suspended, debarred, or otherwise excluded from receiving federal funds for the...
FINDING 2024-006 Finding Subject: Special Education – Procurement Summary of Finding: There was no control in place, such as an oversight, review, or approval process, to ensure that contractors or subrecipients were not suspended, debarred, or otherwise excluded from receiving federal funds for the Special Education program. Contact Person Responsible for Corrective Action: Danica Houze Contact Phone Number and Email Address: 812-274-8103 dhouze@madison.k12.in.us Views of Responsible Officials: We concur with the finding. Description of Corrective Action Plan: The CFO will monitor encumbrance reports on a regular basis. When federal procurements exceeding $25,000 are encumbered, we will have vendors submit a Suspended and Debarment Certification with their contract agreement when federal dollars are being encumbered. If we are unable to obtain a certification in this manner, alternate procedures such as checking the SAM.gov website will be utilized and the appropriate documentation supporting this review will be retained Anticipated Completion Date: 6/30/2025
« 1 136 137 139 140 377 »