2 CFR 200 › § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
100,090
Across all audits in database
Showing Page
768 of 2002
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCEIN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCE
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCEIN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCE
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCEIN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCE
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCEIN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCE
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: AEL
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not m...

FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards.   According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: AEL
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provide...

FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-024 Fish and Wildlife Cluster, ALN 15.605, 15.611, and 15.626, Activities Allowed or Unallowed; Allowable Costs/Cost Principles; and Matching, Level of Effort, and Earmarking - Inappropriate Telecommunication Expenditures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster were incurred for fish and wildlife activities. We review...

FINDING 2023-024 Fish and Wildlife Cluster, ALN 15.605, 15.611, and 15.626, Activities Allowed or Unallowed; Allowable Costs/Cost Principles; and Matching, Level of Effort, and Earmarking - Inappropriate Telecommunication Expenditures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster were incurred for fish and wildlife activities. We reviewed 1 sampled telecommunication transaction related to 196 employees. We sampled 20 of those employees and noted 2 (10%) employees did not work on fish and wildlife activities. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing the federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Also, Subpart E of federal regulation 2 CFR 200 requires costs charged to federal programs be necessary and reasonable for the administration of the federal award and be in accordance with the relative benefits received by the program. In addition, federal regulation 2 CFR 200.306 requires costs used for matching be allowable costs to the federal award. Cause DNR informed us because of an oversight error, it did not timely identify these employees to be removed from the monthly telecommunication bill. Effect DNR charged the Fish and Wildlife Cluster for telecommunication expenditures related to employees who worked on non-fish and wildlife activities. The federal grantor agency could issue sanctions or disallowances related to noncompliance. Known Questioned Costs None. Recommendation We recommend DNR ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster are incurred for fish and wildlife activities. Management Views DNR agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-024 Fish and Wildlife Cluster, ALN 15.605, 15.611, and 15.626, Activities Allowed or Unallowed; Allowable Costs/Cost Principles; and Matching, Level of Effort, and Earmarking - Inappropriate Telecommunication Expenditures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster were incurred for fish and wildlife activities. We review...

FINDING 2023-024 Fish and Wildlife Cluster, ALN 15.605, 15.611, and 15.626, Activities Allowed or Unallowed; Allowable Costs/Cost Principles; and Matching, Level of Effort, and Earmarking - Inappropriate Telecommunication Expenditures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster were incurred for fish and wildlife activities. We reviewed 1 sampled telecommunication transaction related to 196 employees. We sampled 20 of those employees and noted 2 (10%) employees did not work on fish and wildlife activities. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing the federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Also, Subpart E of federal regulation 2 CFR 200 requires costs charged to federal programs be necessary and reasonable for the administration of the federal award and be in accordance with the relative benefits received by the program. In addition, federal regulation 2 CFR 200.306 requires costs used for matching be allowable costs to the federal award. Cause DNR informed us because of an oversight error, it did not timely identify these employees to be removed from the monthly telecommunication bill. Effect DNR charged the Fish and Wildlife Cluster for telecommunication expenditures related to employees who worked on non-fish and wildlife activities. The federal grantor agency could issue sanctions or disallowances related to noncompliance. Known Questioned Costs None. Recommendation We recommend DNR ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster are incurred for fish and wildlife activities. Management Views DNR agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-024 Fish and Wildlife Cluster, ALN 15.605, 15.611, and 15.626, Activities Allowed or Unallowed; Allowable Costs/Cost Principles; and Matching, Level of Effort, and Earmarking - Inappropriate Telecommunication Expenditures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster were incurred for fish and wildlife activities. We review...

FINDING 2023-024 Fish and Wildlife Cluster, ALN 15.605, 15.611, and 15.626, Activities Allowed or Unallowed; Allowable Costs/Cost Principles; and Matching, Level of Effort, and Earmarking - Inappropriate Telecommunication Expenditures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster were incurred for fish and wildlife activities. We reviewed 1 sampled telecommunication transaction related to 196 employees. We sampled 20 of those employees and noted 2 (10%) employees did not work on fish and wildlife activities. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing the federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Also, Subpart E of federal regulation 2 CFR 200 requires costs charged to federal programs be necessary and reasonable for the administration of the federal award and be in accordance with the relative benefits received by the program. In addition, federal regulation 2 CFR 200.306 requires costs used for matching be allowable costs to the federal award. Cause DNR informed us because of an oversight error, it did not timely identify these employees to be removed from the monthly telecommunication bill. Effect DNR charged the Fish and Wildlife Cluster for telecommunication expenditures related to employees who worked on non-fish and wildlife activities. The federal grantor agency could issue sanctions or disallowances related to noncompliance. Known Questioned Costs None. Recommendation We recommend DNR ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster are incurred for fish and wildlife activities. Management Views DNR agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-024 Fish and Wildlife Cluster, ALN 15.605, 15.611, and 15.626, Activities Allowed or Unallowed; Allowable Costs/Cost Principles; and Matching, Level of Effort, and Earmarking - Inappropriate Telecommunication Expenditures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster were incurred for fish and wildlife activities. We review...

FINDING 2023-024 Fish and Wildlife Cluster, ALN 15.605, 15.611, and 15.626, Activities Allowed or Unallowed; Allowable Costs/Cost Principles; and Matching, Level of Effort, and Earmarking - Inappropriate Telecommunication Expenditures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster were incurred for fish and wildlife activities. We reviewed 1 sampled telecommunication transaction related to 196 employees. We sampled 20 of those employees and noted 2 (10%) employees did not work on fish and wildlife activities. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing the federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Also, Subpart E of federal regulation 2 CFR 200 requires costs charged to federal programs be necessary and reasonable for the administration of the federal award and be in accordance with the relative benefits received by the program. In addition, federal regulation 2 CFR 200.306 requires costs used for matching be allowable costs to the federal award. Cause DNR informed us because of an oversight error, it did not timely identify these employees to be removed from the monthly telecommunication bill. Effect DNR charged the Fish and Wildlife Cluster for telecommunication expenditures related to employees who worked on non-fish and wildlife activities. The federal grantor agency could issue sanctions or disallowances related to noncompliance. Known Questioned Costs None. Recommendation We recommend DNR ensure that telecommunication expenditures charged to the Fish and Wildlife Cluster are incurred for fish and wildlife activities. Management Views DNR agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: M
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: M
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABH
FINDING 2023-026 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - Grant Reimbursement Approval Procedures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Environment, Great Lakes, and Energy (EGLE) did not review and approve drinking water and clean water grant reimbursement requests for 1 of 8 sampled payments to ensure the requests are reasonabl...

FINDING 2023-026 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - Grant Reimbursement Approval Procedures See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Environment, Great Lakes, and Energy (EGLE) did not review and approve drinking water and clean water grant reimbursement requests for 1 of 8 sampled payments to ensure the requests are reasonable and appropriate. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal awards. Also, Subpart E of federal regulation 2 CFR 200 requires costs charged to federal programs be necessary and reasonable for the administration of the federal award and be in accordance with the relative benefits received by the program.   Cause EGLE informed us it determined instances where for a singular grant, it did not follow the established process for reviewing and approving reimbursement requests. Effect EGLE could potentially reimburse for ineligible project expenditures. The federal grantor agency could issue sanctions or disallowances related to noncompliance. Known Questioned Costs None. Recommendation We recommend EGLE review and approve drinking water and clean water grant reimbursement requests to ensure the requests are reasonable and appropriate. Management Views EGLE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABH
FINDING 2023-027 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - Insufficient Respite Payment Controls See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not have sufficient controls in place to prevent or detect and correct payment errors made to respite grant recipients. We noted MDHHS did not review and approve respite grant payments subsequent to input...

FINDING 2023-027 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - Insufficient Respite Payment Controls See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not have sufficient controls in place to prevent or detect and correct payment errors made to respite grant recipients. We noted MDHHS did not review and approve respite grant payments subsequent to input into the Medical Services Administration Manual Payment System. Our review disclosed MDHHS issued duplicated payments to two recipients. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Also, Subpart E of federal regulation 2 CFR 200 requires costs charged to federal programs be necessary and reasonable for the administration of the federal award and be in accordance with the relative benefits received by the program. Cause MDHHS informed us limited staff resources contributed to the lack of reviews and approvals of the respite grant payments. Effect The deficiencies could potentially result in improper payments to recipients. The federal grantor agency could issue sanctions or disallowances related to noncompliance. Known Questioned Costs None. Recommendation We recommend MDHHS improve its controls to prevent or detect and correct payment errors made to respite grant recipients. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: L
FINDING 2023-030 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Reporting - Workfront Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition DTMB did not fully establish effective security management and access controls over Workfront. DTMB program staff utilize Workfront to collect and prepare all CSLFRF data reported to the U.S. Department of the Treasury. We noted: a. DTMB did not maintain documentation to support it...

FINDING 2023-030 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Reporting - Workfront Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition DTMB did not fully establish effective security management and access controls over Workfront. DTMB program staff utilize Workfront to collect and prepare all CSLFRF data reported to the U.S. Department of the Treasury. We noted: a. DTMB did not maintain documentation to support it approved the system role for all 9 sampled Workfront users. b. DTMB did not review all privileged accounts on a semiannual basis for Workfront users. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts. Cause DTMB's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to Workfront. Known Questioned Costs None. Recommendation We recommend DTMB fully establish effective security management and access controls over Workfront. Management Views DTMB agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: L
FINDING 2023-031 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Reporting - Workfront Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition DTMB did not fully implement an effective change management process over Workfront. We sampled 4 Workfront change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective...

FINDING 2023-031 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Reporting - Workfront Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition DTMB did not fully implement an effective change management process over Workfront. We sampled 4 Workfront change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause DTMB informed us the development team met with program management to discuss the necessary system changes to resolve the identified issues, but it did not maintain documentation of these meetings. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Workfront. As a result, an increased risk exists that DTMB cannot ensure Workfront is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend DTMB fully implement an effective change management process over Workfront. Management Views DTMB agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABM
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABGMN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABEGN
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not m...

FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards.   According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABEGN
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provide...

FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABEGN
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not m...

FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards.   According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABEGN
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provide...

FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABEGN
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not m...

FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards.   According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABEGN
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provide...

FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABG
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

« 1 766 767 769 770 2002 »