2 CFR 200 › § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
100,114
Across all audits in database
Showing Page
876 of 2003
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: B
FINDING 2023-002 Subject: COVID-19 - Education Stabilization Fund - Allowable Costs/Cost Principles Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Number: 84.425U Federal Award Number and Year (or Other Identifying Number): S425U210013 Pass-Through Entity: Central Indiana Educational Service Center Compliance Requirement: Allowable Costs/Cost Principles Audit Findings: Material Weakness, Other Matters Condition and Context The...

FINDING 2023-002 Subject: COVID-19 - Education Stabilization Fund - Allowable Costs/Cost Principles Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Number: 84.425U Federal Award Number and Year (or Other Identifying Number): S425U210013 Pass-Through Entity: Central Indiana Educational Service Center Compliance Requirement: Allowable Costs/Cost Principles Audit Findings: Material Weakness, Other Matters Condition and Context The School Corporation was the subrecipient of an Explore, Engage, Experience (3E) Grant from the Central Indiana Educational Service Center (CIESC). Per the award letter received from the CIESC, the School Corporation was allocated $200,000 to hire a district coordinator for 3E initiatives. As only one reimbursement covering the period of August 1, 2022 to September 30, 2022, was requested from the CIESC for the 3E grant, all expenditures associated with the grant were selected for testing to verify the expenditures were in conformance with the applicable cost principles. Expenditures totaling $41,193, were for the salary of the grant lead and a secondary salary. No time and effort documentation was maintained to support the salary amounts charged to the program. As a result, these expenditures were determined not to be in conformance with the applicable cost principles and were considered questioned costs. The lack of internal controls and noncompliance were isolated to the 3E Grant expenditures noted above. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: . . . (g) Be adequately documented. . . ." 2 CFR 200.430(i) states in part: "Standards for Documentation of Personnel Expenses (1) Charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must: (i) Be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (ii) Be incorporated into the official records of the non-Federal entity; (iii) Reasonably reflect the total activity for which the employee is compensated by the non-Federal entity, not exceeding 100% of compensated activities . . . (vii) Support the distribution of the employee's salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities which are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. . . ." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, costs were not adequately supported by personnel records. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs Known questioned costs of $41,193 were identified, as detailed in the Condition and Context. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure costs adequately documented. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: N
FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings:...

FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Other Matters Condition and Context Construction contracts in excess of $2,000 financed by federal assistance funds must pay wages not less than those established for the locality of the project (prevailing wage rates) by the Department of Labor (DOL) to its laborers and mechanics. Nonfederal entities are to include in its construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with these requirements and the DOL regulations. This would include a requirement to submit a copy of the payroll and statement of compliance to the entity for each week in which contract work was performed. The School Corporation had not designed, nor implemented a system of internal controls to ensure that construction contracts in excess of $2,000 paid from federal grant funds included a prevailing wage rate clause and that a copy of the payroll was submitted for each week in which contract work was performed. Two construction projects were paid for from the Elementary and Secondary School Emergency Relief Fund grant funds during the audit period. Both contracts were tested. Both contracts contained the required prevailing wage rate clause; however, a copy of the payroll was not submitted for either contract for any week in which work was performed. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) The Agency head shall cause or require the contracting officer to insert in full in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the acts listed in § 5.1, the following clauses. . . (1) Minimum wages. (i) All laborers and mechanics employed or working upon the site of the work (or under the United States Housing Act of 1937 or under the Housing Act of 1949 in the construction or development of the project), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . . (3) Payrolls and basic records. . . . (ii) (A) The contractor shall submit weekly for each week in which any contract work is performed a copy of all payrolls to the (write in name of appropriate federal agency) if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the payrolls to the applicant, sponsor, or owner, as the case may be, for transmission to the (write in name of agency). The payrolls submitted shall set out accurately and completely all of the information required to be maintained under 29 CFR 5.5(a)(3)(i), except that full social security numbers and home addresses shall not be included on weekly transmittals. Instead the payrolls shall only need to include an individually identifying number for each employee (e.g., the last four digits of the employee's social security number). The required weekly payroll information may be submitted in any form desired. Optional Form WH-347 is available for this purpose from the Wage and Hour Division Web site at http://www.dol.gov/esa/whd/forms/wh347instr.htm or its successor site. The prime contractor is responsible for the submission of copies of payrolls by all subcontractors. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non- Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, certified payrolls were not obtained by the School Corporation. Noncompliance with the grant agreement and the compliance requirement could result in the loss of future federal funds to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a system of internal controls and ensure certified payrolls are obtained as required for all contracts. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: N
FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings:...

FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Other Matters Condition and Context Construction contracts in excess of $2,000 financed by federal assistance funds must pay wages not less than those established for the locality of the project (prevailing wage rates) by the Department of Labor (DOL) to its laborers and mechanics. Nonfederal entities are to include in its construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with these requirements and the DOL regulations. This would include a requirement to submit a copy of the payroll and statement of compliance to the entity for each week in which contract work was performed. The School Corporation had not designed, nor implemented a system of internal controls to ensure that construction contracts in excess of $2,000 paid from federal grant funds included a prevailing wage rate clause and that a copy of the payroll was submitted for each week in which contract work was performed. Two construction projects were paid for from the Elementary and Secondary School Emergency Relief Fund grant funds during the audit period. Both contracts were tested. Both contracts contained the required prevailing wage rate clause; however, a copy of the payroll was not submitted for either contract for any week in which work was performed. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) The Agency head shall cause or require the contracting officer to insert in full in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the acts listed in § 5.1, the following clauses. . . (1) Minimum wages. (i) All laborers and mechanics employed or working upon the site of the work (or under the United States Housing Act of 1937 or under the Housing Act of 1949 in the construction or development of the project), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . . (3) Payrolls and basic records. . . . (ii) (A) The contractor shall submit weekly for each week in which any contract work is performed a copy of all payrolls to the (write in name of appropriate federal agency) if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the payrolls to the applicant, sponsor, or owner, as the case may be, for transmission to the (write in name of agency). The payrolls submitted shall set out accurately and completely all of the information required to be maintained under 29 CFR 5.5(a)(3)(i), except that full social security numbers and home addresses shall not be included on weekly transmittals. Instead the payrolls shall only need to include an individually identifying number for each employee (e.g., the last four digits of the employee's social security number). The required weekly payroll information may be submitted in any form desired. Optional Form WH-347 is available for this purpose from the Wage and Hour Division Web site at http://www.dol.gov/esa/whd/forms/wh347instr.htm or its successor site. The prime contractor is responsible for the submission of copies of payrolls by all subcontractors. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non- Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, certified payrolls were not obtained by the School Corporation. Noncompliance with the grant agreement and the compliance requirement could result in the loss of future federal funds to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a system of internal controls and ensure certified payrolls are obtained as required for all contracts. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: N
FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings:...

FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Other Matters Condition and Context Construction contracts in excess of $2,000 financed by federal assistance funds must pay wages not less than those established for the locality of the project (prevailing wage rates) by the Department of Labor (DOL) to its laborers and mechanics. Nonfederal entities are to include in its construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with these requirements and the DOL regulations. This would include a requirement to submit a copy of the payroll and statement of compliance to the entity for each week in which contract work was performed. The School Corporation had not designed, nor implemented a system of internal controls to ensure that construction contracts in excess of $2,000 paid from federal grant funds included a prevailing wage rate clause and that a copy of the payroll was submitted for each week in which contract work was performed. Two construction projects were paid for from the Elementary and Secondary School Emergency Relief Fund grant funds during the audit period. Both contracts were tested. Both contracts contained the required prevailing wage rate clause; however, a copy of the payroll was not submitted for either contract for any week in which work was performed. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) The Agency head shall cause or require the contracting officer to insert in full in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the acts listed in § 5.1, the following clauses. . . (1) Minimum wages. (i) All laborers and mechanics employed or working upon the site of the work (or under the United States Housing Act of 1937 or under the Housing Act of 1949 in the construction or development of the project), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . . (3) Payrolls and basic records. . . . (ii) (A) The contractor shall submit weekly for each week in which any contract work is performed a copy of all payrolls to the (write in name of appropriate federal agency) if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the payrolls to the applicant, sponsor, or owner, as the case may be, for transmission to the (write in name of agency). The payrolls submitted shall set out accurately and completely all of the information required to be maintained under 29 CFR 5.5(a)(3)(i), except that full social security numbers and home addresses shall not be included on weekly transmittals. Instead the payrolls shall only need to include an individually identifying number for each employee (e.g., the last four digits of the employee's social security number). The required weekly payroll information may be submitted in any form desired. Optional Form WH-347 is available for this purpose from the Wage and Hour Division Web site at http://www.dol.gov/esa/whd/forms/wh347instr.htm or its successor site. The prime contractor is responsible for the submission of copies of payrolls by all subcontractors. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non- Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, certified payrolls were not obtained by the School Corporation. Noncompliance with the grant agreement and the compliance requirement could result in the loss of future federal funds to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a system of internal controls and ensure certified payrolls are obtained as required for all contracts. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: N
FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings:...

FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Other Matters Condition and Context Construction contracts in excess of $2,000 financed by federal assistance funds must pay wages not less than those established for the locality of the project (prevailing wage rates) by the Department of Labor (DOL) to its laborers and mechanics. Nonfederal entities are to include in its construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with these requirements and the DOL regulations. This would include a requirement to submit a copy of the payroll and statement of compliance to the entity for each week in which contract work was performed. The School Corporation had not designed, nor implemented a system of internal controls to ensure that construction contracts in excess of $2,000 paid from federal grant funds included a prevailing wage rate clause and that a copy of the payroll was submitted for each week in which contract work was performed. Two construction projects were paid for from the Elementary and Secondary School Emergency Relief Fund grant funds during the audit period. Both contracts were tested. Both contracts contained the required prevailing wage rate clause; however, a copy of the payroll was not submitted for either contract for any week in which work was performed. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) The Agency head shall cause or require the contracting officer to insert in full in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the acts listed in § 5.1, the following clauses. . . (1) Minimum wages. (i) All laborers and mechanics employed or working upon the site of the work (or under the United States Housing Act of 1937 or under the Housing Act of 1949 in the construction or development of the project), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . . (3) Payrolls and basic records. . . . (ii) (A) The contractor shall submit weekly for each week in which any contract work is performed a copy of all payrolls to the (write in name of appropriate federal agency) if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the payrolls to the applicant, sponsor, or owner, as the case may be, for transmission to the (write in name of agency). The payrolls submitted shall set out accurately and completely all of the information required to be maintained under 29 CFR 5.5(a)(3)(i), except that full social security numbers and home addresses shall not be included on weekly transmittals. Instead the payrolls shall only need to include an individually identifying number for each employee (e.g., the last four digits of the employee's social security number). The required weekly payroll information may be submitted in any form desired. Optional Form WH-347 is available for this purpose from the Wage and Hour Division Web site at http://www.dol.gov/esa/whd/forms/wh347instr.htm or its successor site. The prime contractor is responsible for the submission of copies of payrolls by all subcontractors. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non- Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, certified payrolls were not obtained by the School Corporation. Noncompliance with the grant agreement and the compliance requirement could result in the loss of future federal funds to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a system of internal controls and ensure certified payrolls are obtained as required for all contracts. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: N
FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings:...

FINDING 2023-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Other Matters Condition and Context Construction contracts in excess of $2,000 financed by federal assistance funds must pay wages not less than those established for the locality of the project (prevailing wage rates) by the Department of Labor (DOL) to its laborers and mechanics. Nonfederal entities are to include in its construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with these requirements and the DOL regulations. This would include a requirement to submit a copy of the payroll and statement of compliance to the entity for each week in which contract work was performed. The School Corporation had not designed, nor implemented a system of internal controls to ensure that construction contracts in excess of $2,000 paid from federal grant funds included a prevailing wage rate clause and that a copy of the payroll was submitted for each week in which contract work was performed. Two construction projects were paid for from the Elementary and Secondary School Emergency Relief Fund grant funds during the audit period. Both contracts were tested. Both contracts contained the required prevailing wage rate clause; however, a copy of the payroll was not submitted for either contract for any week in which work was performed. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) The Agency head shall cause or require the contracting officer to insert in full in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the acts listed in § 5.1, the following clauses. . . (1) Minimum wages. (i) All laborers and mechanics employed or working upon the site of the work (or under the United States Housing Act of 1937 or under the Housing Act of 1949 in the construction or development of the project), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . . (3) Payrolls and basic records. . . . (ii) (A) The contractor shall submit weekly for each week in which any contract work is performed a copy of all payrolls to the (write in name of appropriate federal agency) if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the payrolls to the applicant, sponsor, or owner, as the case may be, for transmission to the (write in name of agency). The payrolls submitted shall set out accurately and completely all of the information required to be maintained under 29 CFR 5.5(a)(3)(i), except that full social security numbers and home addresses shall not be included on weekly transmittals. Instead the payrolls shall only need to include an individually identifying number for each employee (e.g., the last four digits of the employee's social security number). The required weekly payroll information may be submitted in any form desired. Optional Form WH-347 is available for this purpose from the Wage and Hour Division Web site at http://www.dol.gov/esa/whd/forms/wh347instr.htm or its successor site. The prime contractor is responsible for the submission of copies of payrolls by all subcontractors. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non- Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, certified payrolls were not obtained by the School Corporation. Noncompliance with the grant agreement and the compliance requirement could result in the loss of future federal funds to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a system of internal controls and ensure certified payrolls are obtained as required for all contracts. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: L
FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not prop...

FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. The annual data reports were complied, prepared, and submitted by one employee without an oversight or review process in place to prevent, or detect and correct, errors. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place prior to filing required reports. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: L
FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not prop...

FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. The annual data reports were complied, prepared, and submitted by one employee without an oversight or review process in place to prevent, or detect and correct, errors. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place prior to filing required reports. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: L
FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not prop...

FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. The annual data reports were complied, prepared, and submitted by one employee without an oversight or review process in place to prevent, or detect and correct, errors. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place prior to filing required reports. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: L
FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not prop...

FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. The annual data reports were complied, prepared, and submitted by one employee without an oversight or review process in place to prevent, or detect and correct, errors. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place prior to filing required reports. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: L
FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not prop...

FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. The annual data reports were complied, prepared, and submitted by one employee without an oversight or review process in place to prevent, or detect and correct, errors. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place prior to filing required reports. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Batesville Community School Corporation
Compliance Requirement: L
FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not prop...

FINDING 2023-004 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. The annual data reports were complied, prepared, and submitted by one employee without an oversight or review process in place to prevent, or detect and correct, errors. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place prior to filing required reports. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2023-06-30
Global Community Charter School
Compliance Requirement: N
AL 84.425D – Elementary and Secondary School Emergency Relief Fund, U.S. Department of Education. Passed through New York State Education Department, Award Number 5891 Criteria: Requirements per 2 CFR Section 200.303 of the Uniform Guidance state that non-federal entities must establish and maintain effective internal control over federal awards to provide reasonable assurance that the nonfederal entity is managing the federal award in accordance with federal statutes, regulations, and terms and...

AL 84.425D – Elementary and Secondary School Emergency Relief Fund, U.S. Department of Education. Passed through New York State Education Department, Award Number 5891 Criteria: Requirements per 2 CFR Section 200.303 of the Uniform Guidance state that non-federal entities must establish and maintain effective internal control over federal awards to provide reasonable assurance that the nonfederal entity is managing the federal award in accordance with federal statutes, regulations, and terms and conditions of the awards received. Condition: Management had not established an adequate system of internal control over compliance with the relevant federal statutes, regulations, and terms and conditions of the federal awards as management’s internal control procedures did not cause the entity to comply with the Special Tests and Provisions related to Wage Rate Requirements under the Elementary and Secondary School Emergency Relief Fund. Cause: Management did not have adequate internal controls in place to identify and comply with Wage Rate Requirements established under 29 CFR Part 5. Effect or Potential Effect: Without appropriate internal controls over compliance, non-compliance could occur which the entity may not identify. Laborers and mechanics employed by contractors and subcontractors may not have been paid in accordance with local prevailing wage rates. We were not able to determine if the entity was in compliance with this compliance requirement as appropriate documentation was not requested from the applicable contractor. Questioned Costs: N/A Repeat Finding?: Yes, see finding 2022-001. Recommendation: Management should implement internal controls over Wage Rate Requirements to ensure compliance with applicable Federal statutes, regulations, and terms and conditions of the awards received. Views of Responsible Officials: We are in agreement with the finding. GCCS management will retain documentation to support proper operation of internal controls and compliance with applicable Federal statutes, regulations, Wage Rate Requirements, and other terms and conditions of awards received. Auditor’s Evaluation of the Views of Responsible Officials: Management’s response is appropriate to address the finding. If properly implemented, management’s response would include procedures to prevent reoccurrence in the future.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-010: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-024; 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Planning; Risk Assessment; Security Assessment and Authorization; System and...

2023-010: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-024; 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Planning; Risk Assessment; Security Assessment and Authorization; System and Services Acquisition ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services continues to address weaknesses in its IT general controls originally identified in a 2020 audit and confirmed in a 2023 audit covering the same IT general controls conducted by Medical Assistance Services’ Internal Audit division. The 2020 audit tested 100 controls required by the Security Standard and identified 71 individual control weaknesses grouped into ten findings. Internal Audit conducted an audit in 2023 of 105 controls based on the current Security Standard requirements and identified 61 individual control weaknesses, a 58 percent noncompliance rate. Medical Assistance Services addressed one finding in fiscal year 2022 and an additional two findings during fiscal year 2023, which Internal Audit’s review confirmed. However, Internal Audit issued one new finding to Medical Assistance Services in addition to the seven repeat findings, covering the following control areas: IT Security Governance Access Management System Security Plans IT Security Policies and Procedures Incident Response Penetration Testing and Vulnerability Assessments Third Party Vendor Management Security Awareness and Training (new) Noncompliance with the required security controls increases the risk for unauthorized access to mission-critical systems and data in addition to weakening the agency’s ability to respond to malicious attacks to its IT environment. Medical Assistance Services has experienced delays in addressing these findings due to ongoing staffing shortages, as well as lingering effects from organizational changes that affected some of its processes. Medical Assistance Services updated its corrective action plan for the seven repeat findings in June 2023, stating corrective actions are still ongoing with an estimated completion date of September 2023. Medical Assistance Services should prioritize and dedicate the necessary resources to ensure timely completion of its corrective action plans and to become compliant with the Security Standard. These actions will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-010: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-024; 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Planning; Risk Assessment; Security Assessment and Authorization; System and...

2023-010: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-024; 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Planning; Risk Assessment; Security Assessment and Authorization; System and Services Acquisition ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services continues to address weaknesses in its IT general controls originally identified in a 2020 audit and confirmed in a 2023 audit covering the same IT general controls conducted by Medical Assistance Services’ Internal Audit division. The 2020 audit tested 100 controls required by the Security Standard and identified 71 individual control weaknesses grouped into ten findings. Internal Audit conducted an audit in 2023 of 105 controls based on the current Security Standard requirements and identified 61 individual control weaknesses, a 58 percent noncompliance rate. Medical Assistance Services addressed one finding in fiscal year 2022 and an additional two findings during fiscal year 2023, which Internal Audit’s review confirmed. However, Internal Audit issued one new finding to Medical Assistance Services in addition to the seven repeat findings, covering the following control areas: IT Security Governance Access Management System Security Plans IT Security Policies and Procedures Incident Response Penetration Testing and Vulnerability Assessments Third Party Vendor Management Security Awareness and Training (new) Noncompliance with the required security controls increases the risk for unauthorized access to mission-critical systems and data in addition to weakening the agency’s ability to respond to malicious attacks to its IT environment. Medical Assistance Services has experienced delays in addressing these findings due to ongoing staffing shortages, as well as lingering effects from organizational changes that affected some of its processes. Medical Assistance Services updated its corrective action plan for the seven repeat findings in June 2023, stating corrective actions are still ongoing with an estimated completion date of September 2023. Medical Assistance Services should prioritize and dedicate the necessary resources to ensure timely completion of its corrective action plans and to become compliant with the Security Standard. These actions will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-010: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-024; 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Planning; Risk Assessment; Security Assessment and Authorization; System and...

2023-010: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-024; 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Planning; Risk Assessment; Security Assessment and Authorization; System and Services Acquisition ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services continues to address weaknesses in its IT general controls originally identified in a 2020 audit and confirmed in a 2023 audit covering the same IT general controls conducted by Medical Assistance Services’ Internal Audit division. The 2020 audit tested 100 controls required by the Security Standard and identified 71 individual control weaknesses grouped into ten findings. Internal Audit conducted an audit in 2023 of 105 controls based on the current Security Standard requirements and identified 61 individual control weaknesses, a 58 percent noncompliance rate. Medical Assistance Services addressed one finding in fiscal year 2022 and an additional two findings during fiscal year 2023, which Internal Audit’s review confirmed. However, Internal Audit issued one new finding to Medical Assistance Services in addition to the seven repeat findings, covering the following control areas: IT Security Governance Access Management System Security Plans IT Security Policies and Procedures Incident Response Penetration Testing and Vulnerability Assessments Third Party Vendor Management Security Awareness and Training (new) Noncompliance with the required security controls increases the risk for unauthorized access to mission-critical systems and data in addition to weakening the agency’s ability to respond to malicious attacks to its IT environment. Medical Assistance Services has experienced delays in addressing these findings due to ongoing staffing shortages, as well as lingering effects from organizational changes that affected some of its processes. Medical Assistance Services updated its corrective action plan for the seven repeat findings in June 2023, stating corrective actions are still ongoing with an estimated completion date of September 2023. Medical Assistance Services should prioritize and dedicate the necessary resources to ensure timely completion of its corrective action plans and to become compliant with the Security Standard. These actions will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-014: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U...

2023-014: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not have a formal and effective IT risk management program that aligns with the requirements in the Security Standard. As a result, Social Services does not complete various IT risk management documentation nor maintain an accurate list of sensitive systems. IT risk management documentation identifies the types of data stored and processed within its environment, the sensitivity classification of that data, potential risks and threats to the systems, and risk mitigating controls that Social Services should implement. Since we first issued this finding in 2018, Social Services has made progress to remediate the issues identified. However, Social Services continues to not comply with the following Security Standard requirements: Social Services does not verify and validate the data and system sensitivity ratings of its systems to ensure proper IT system sensitivity ratings. Social Services’ systems list includes 89 systems. Social Services classifies 77 of the 89 systems (87%) as sensitive systems based on the sensitive data handled by each system. Social Services classifies four of the 89 systems (4%) as nonsensitive systems. Social Services does not rate eight of the 89 systems (9%). However, five of the eight unrated systems transmit, process, or store sensitive data sets or support critical business processes and therefore, Social Services should consider these to be sensitive systems. The remaining three of the eight unrated systems do not transmit, process, or store sensitive data sets or support critical business processes and therefore, Social Services should consider these nonsensitive systems. The Security Standard defines sensitive systems as systems that transmit, process, or store sensitive data sets or support sensitive business processes. Without a process to maintain an updated sensitive systems list and verify and validate IT system and data sensitivity, Social Services increases the risk of not properly defining all sensitive systems within its IT environment. Failure to identify sensitive systems increases the likelihood of Social Services inadequately addressing risks, vulnerabilities, and remediation techniques necessary to protect sensitive IT systems and data. (Security Standard, Section 4.2.6 IT System and Data Sensitivity Classification) Social Services does not create or annually review risk assessments and system security plans (SSP) for every sensitive system. Social Services’ systems list indicates 77 systems classified as sensitive systems, and the systems list includes five additional systems without a sensitivity classification that process and store sensitive data and therefore should be classified as sensitive systems. Several of these systems have no or only partial risk assessment and SSP documentation. Specifically: Risk assessment documentation does not exist for 64 (78%) systems. Annual review documentation does not exist for 82 (100%) of the existing risk assessments. SSP documentation does not exist for 45 (55%) systems. Annual review documentation does not exist for 82 (100%) of the existing SSPs. The Security Standard requires the agency to conduct and document a risk assessment for each IT system classified as a sensitive system at least once every three years. The Security Standard also requires the agency to develop and distribute to appropriate organization-defined personnel a security plan for the information system. Without completing risk assessments and SSPs for all sensitive systems, Social Services may not appropriately secure its systems against known vulnerabilities that can affect the confidentiality, integrity, and availability of sensitive and mission-critical data. (Security Standard, Sections 6.2 Risk Assessment Requirements, RA-3 Risk Assessment and PL-2 System Security Plan). The Security Standard requires Social Services to review and update completed risk assessments annually or when changes occur that may impact the security state of the system, and to review and update each SSP on an annual basis or more frequently to address environmental changes. Without conducting an annual review and update of the risk assessment and SSP for each IT system classified as sensitive, Social Services may not adequately secure its sensitive systems against new vulnerabilities that can affect data confidentiality, integrity, and availability. (Security Standard, Sections RA-3 Risk Assessment and PL-2 System Security Plan) Social Services does not implement corrective actions to mitigate risks in its sensitive systems’ risk assessments. The Security Standard requires Social Services to prepare a report of each risk assessment that includes major findings and risk mitigation efforts (Security Standard, Section 6.2.3 Risk Assessment). While Social Services documents a list of risk remediation plans and a schedule within its risk assessments, Social Services does not have a process to establish effective corrective action plans to mitigate findings identified during the risk assessments. Without properly establishing and implementing corrective actions, Social Services opens its systems to possible risks and vulnerabilities that could compromise the agency’s sensitive information. Without documenting risk management information for all its sensitive systems and reviewing the documentation at least annually, Social Services may not consistently and effectively manage its IT risk management program. An effective IT risk management program is essential to help protect IT systems and data from potential risks. Specifically, Social Services cannot prioritize information security controls to implement or determine if proper information security controls are in place. Ineffective security controls could lead to a breach of data or unauthorized access to sensitive and confidential data. Social Services’ Information Security Risk Management (ISRM) oversees the risk management program on behalf of business owners and hired an IT Risk Manager in 2020. ISRM has prioritized completing risk assessments and SSPs for new systems; however, due to the magnitude of the project, ISRM has not yet completed the project. Additionally, the risk assessment requirements documented in the risk assessment policy and the risk assessment process documented in the risk assessment procedure do not align, which contributed to Social Services not consistently completing risk management documentation due to conflicting roles and responsibilities. Social Services should develop a plan and prioritize resources to complete risk management documentation for its sensitive systems and review those documents annually to validate that the information reflects the current environment. Additionally, Social Services should implement security controls to mitigate the risks and vulnerabilities identified in its risk assessments. Improving the IT risk management program will help to ensure the confidentiality, integrity, and availability of the agency’s sensitive systems and mission essential functions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-014: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U...

2023-014: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not have a formal and effective IT risk management program that aligns with the requirements in the Security Standard. As a result, Social Services does not complete various IT risk management documentation nor maintain an accurate list of sensitive systems. IT risk management documentation identifies the types of data stored and processed within its environment, the sensitivity classification of that data, potential risks and threats to the systems, and risk mitigating controls that Social Services should implement. Since we first issued this finding in 2018, Social Services has made progress to remediate the issues identified. However, Social Services continues to not comply with the following Security Standard requirements: Social Services does not verify and validate the data and system sensitivity ratings of its systems to ensure proper IT system sensitivity ratings. Social Services’ systems list includes 89 systems. Social Services classifies 77 of the 89 systems (87%) as sensitive systems based on the sensitive data handled by each system. Social Services classifies four of the 89 systems (4%) as nonsensitive systems. Social Services does not rate eight of the 89 systems (9%). However, five of the eight unrated systems transmit, process, or store sensitive data sets or support critical business processes and therefore, Social Services should consider these to be sensitive systems. The remaining three of the eight unrated systems do not transmit, process, or store sensitive data sets or support critical business processes and therefore, Social Services should consider these nonsensitive systems. The Security Standard defines sensitive systems as systems that transmit, process, or store sensitive data sets or support sensitive business processes. Without a process to maintain an updated sensitive systems list and verify and validate IT system and data sensitivity, Social Services increases the risk of not properly defining all sensitive systems within its IT environment. Failure to identify sensitive systems increases the likelihood of Social Services inadequately addressing risks, vulnerabilities, and remediation techniques necessary to protect sensitive IT systems and data. (Security Standard, Section 4.2.6 IT System and Data Sensitivity Classification) Social Services does not create or annually review risk assessments and system security plans (SSP) for every sensitive system. Social Services’ systems list indicates 77 systems classified as sensitive systems, and the systems list includes five additional systems without a sensitivity classification that process and store sensitive data and therefore should be classified as sensitive systems. Several of these systems have no or only partial risk assessment and SSP documentation. Specifically: Risk assessment documentation does not exist for 64 (78%) systems. Annual review documentation does not exist for 82 (100%) of the existing risk assessments. SSP documentation does not exist for 45 (55%) systems. Annual review documentation does not exist for 82 (100%) of the existing SSPs. The Security Standard requires the agency to conduct and document a risk assessment for each IT system classified as a sensitive system at least once every three years. The Security Standard also requires the agency to develop and distribute to appropriate organization-defined personnel a security plan for the information system. Without completing risk assessments and SSPs for all sensitive systems, Social Services may not appropriately secure its systems against known vulnerabilities that can affect the confidentiality, integrity, and availability of sensitive and mission-critical data. (Security Standard, Sections 6.2 Risk Assessment Requirements, RA-3 Risk Assessment and PL-2 System Security Plan). The Security Standard requires Social Services to review and update completed risk assessments annually or when changes occur that may impact the security state of the system, and to review and update each SSP on an annual basis or more frequently to address environmental changes. Without conducting an annual review and update of the risk assessment and SSP for each IT system classified as sensitive, Social Services may not adequately secure its sensitive systems against new vulnerabilities that can affect data confidentiality, integrity, and availability. (Security Standard, Sections RA-3 Risk Assessment and PL-2 System Security Plan) Social Services does not implement corrective actions to mitigate risks in its sensitive systems’ risk assessments. The Security Standard requires Social Services to prepare a report of each risk assessment that includes major findings and risk mitigation efforts (Security Standard, Section 6.2.3 Risk Assessment). While Social Services documents a list of risk remediation plans and a schedule within its risk assessments, Social Services does not have a process to establish effective corrective action plans to mitigate findings identified during the risk assessments. Without properly establishing and implementing corrective actions, Social Services opens its systems to possible risks and vulnerabilities that could compromise the agency’s sensitive information. Without documenting risk management information for all its sensitive systems and reviewing the documentation at least annually, Social Services may not consistently and effectively manage its IT risk management program. An effective IT risk management program is essential to help protect IT systems and data from potential risks. Specifically, Social Services cannot prioritize information security controls to implement or determine if proper information security controls are in place. Ineffective security controls could lead to a breach of data or unauthorized access to sensitive and confidential data. Social Services’ Information Security Risk Management (ISRM) oversees the risk management program on behalf of business owners and hired an IT Risk Manager in 2020. ISRM has prioritized completing risk assessments and SSPs for new systems; however, due to the magnitude of the project, ISRM has not yet completed the project. Additionally, the risk assessment requirements documented in the risk assessment policy and the risk assessment process documented in the risk assessment procedure do not align, which contributed to Social Services not consistently completing risk management documentation due to conflicting roles and responsibilities. Social Services should develop a plan and prioritize resources to complete risk management documentation for its sensitive systems and review those documents annually to validate that the information reflects the current environment. Additionally, Social Services should implement security controls to mitigate the risks and vulnerabilities identified in its risk assessments. Improving the IT risk management program will help to ensure the confidentiality, integrity, and availability of the agency’s sensitive systems and mission essential functions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-014: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U...

2023-014: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not have a formal and effective IT risk management program that aligns with the requirements in the Security Standard. As a result, Social Services does not complete various IT risk management documentation nor maintain an accurate list of sensitive systems. IT risk management documentation identifies the types of data stored and processed within its environment, the sensitivity classification of that data, potential risks and threats to the systems, and risk mitigating controls that Social Services should implement. Since we first issued this finding in 2018, Social Services has made progress to remediate the issues identified. However, Social Services continues to not comply with the following Security Standard requirements: Social Services does not verify and validate the data and system sensitivity ratings of its systems to ensure proper IT system sensitivity ratings. Social Services’ systems list includes 89 systems. Social Services classifies 77 of the 89 systems (87%) as sensitive systems based on the sensitive data handled by each system. Social Services classifies four of the 89 systems (4%) as nonsensitive systems. Social Services does not rate eight of the 89 systems (9%). However, five of the eight unrated systems transmit, process, or store sensitive data sets or support critical business processes and therefore, Social Services should consider these to be sensitive systems. The remaining three of the eight unrated systems do not transmit, process, or store sensitive data sets or support critical business processes and therefore, Social Services should consider these nonsensitive systems. The Security Standard defines sensitive systems as systems that transmit, process, or store sensitive data sets or support sensitive business processes. Without a process to maintain an updated sensitive systems list and verify and validate IT system and data sensitivity, Social Services increases the risk of not properly defining all sensitive systems within its IT environment. Failure to identify sensitive systems increases the likelihood of Social Services inadequately addressing risks, vulnerabilities, and remediation techniques necessary to protect sensitive IT systems and data. (Security Standard, Section 4.2.6 IT System and Data Sensitivity Classification) Social Services does not create or annually review risk assessments and system security plans (SSP) for every sensitive system. Social Services’ systems list indicates 77 systems classified as sensitive systems, and the systems list includes five additional systems without a sensitivity classification that process and store sensitive data and therefore should be classified as sensitive systems. Several of these systems have no or only partial risk assessment and SSP documentation. Specifically: Risk assessment documentation does not exist for 64 (78%) systems. Annual review documentation does not exist for 82 (100%) of the existing risk assessments. SSP documentation does not exist for 45 (55%) systems. Annual review documentation does not exist for 82 (100%) of the existing SSPs. The Security Standard requires the agency to conduct and document a risk assessment for each IT system classified as a sensitive system at least once every three years. The Security Standard also requires the agency to develop and distribute to appropriate organization-defined personnel a security plan for the information system. Without completing risk assessments and SSPs for all sensitive systems, Social Services may not appropriately secure its systems against known vulnerabilities that can affect the confidentiality, integrity, and availability of sensitive and mission-critical data. (Security Standard, Sections 6.2 Risk Assessment Requirements, RA-3 Risk Assessment and PL-2 System Security Plan). The Security Standard requires Social Services to review and update completed risk assessments annually or when changes occur that may impact the security state of the system, and to review and update each SSP on an annual basis or more frequently to address environmental changes. Without conducting an annual review and update of the risk assessment and SSP for each IT system classified as sensitive, Social Services may not adequately secure its sensitive systems against new vulnerabilities that can affect data confidentiality, integrity, and availability. (Security Standard, Sections RA-3 Risk Assessment and PL-2 System Security Plan) Social Services does not implement corrective actions to mitigate risks in its sensitive systems’ risk assessments. The Security Standard requires Social Services to prepare a report of each risk assessment that includes major findings and risk mitigation efforts (Security Standard, Section 6.2.3 Risk Assessment). While Social Services documents a list of risk remediation plans and a schedule within its risk assessments, Social Services does not have a process to establish effective corrective action plans to mitigate findings identified during the risk assessments. Without properly establishing and implementing corrective actions, Social Services opens its systems to possible risks and vulnerabilities that could compromise the agency’s sensitive information. Without documenting risk management information for all its sensitive systems and reviewing the documentation at least annually, Social Services may not consistently and effectively manage its IT risk management program. An effective IT risk management program is essential to help protect IT systems and data from potential risks. Specifically, Social Services cannot prioritize information security controls to implement or determine if proper information security controls are in place. Ineffective security controls could lead to a breach of data or unauthorized access to sensitive and confidential data. Social Services’ Information Security Risk Management (ISRM) oversees the risk management program on behalf of business owners and hired an IT Risk Manager in 2020. ISRM has prioritized completing risk assessments and SSPs for new systems; however, due to the magnitude of the project, ISRM has not yet completed the project. Additionally, the risk assessment requirements documented in the risk assessment policy and the risk assessment process documented in the risk assessment procedure do not align, which contributed to Social Services not consistently completing risk management documentation due to conflicting roles and responsibilities. Social Services should develop a plan and prioritize resources to complete risk management documentation for its sensitive systems and review those documents annually to validate that the information reflects the current environment. Additionally, Social Services should implement security controls to mitigate the risks and vulnerabilities identified in its risk assessments. Improving the IT risk management program will help to ensure the confidentiality, integrity, and availability of the agency’s sensitive systems and mission essential functions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-015: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2022-029; 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number an...

2023-015: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2022-029; 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not configure a sensitive web application in accordance with the Security Standard. Since the prior audit, Social Services has not remediated any of the previously identified weaknesses. We communicated the weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Lacking and insufficient procedures and processes to manage the web application contributed to the five weaknesses outlined in the separate FOIAE document. Additionally, Social Services prioritizing other projects also contributed to the weaknesses persisting. Not configuring web applications in accordance with the Security Standard increases the risk of successful cyberattack, exploit, and data breach by malicious parties. Social Services should dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Proper configuration of the web application will help Social Services to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-015: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2022-029; 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number an...

2023-015: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2022-029; 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not configure a sensitive web application in accordance with the Security Standard. Since the prior audit, Social Services has not remediated any of the previously identified weaknesses. We communicated the weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Lacking and insufficient procedures and processes to manage the web application contributed to the five weaknesses outlined in the separate FOIAE document. Additionally, Social Services prioritizing other projects also contributed to the weaknesses persisting. Not configuring web applications in accordance with the Security Standard increases the risk of successful cyberattack, exploit, and data breach by malicious parties. Social Services should dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Proper configuration of the web application will help Social Services to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-015: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2022-029; 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number an...

2023-015: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2022-029; 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not configure a sensitive web application in accordance with the Security Standard. Since the prior audit, Social Services has not remediated any of the previously identified weaknesses. We communicated the weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Lacking and insufficient procedures and processes to manage the web application contributed to the five weaknesses outlined in the separate FOIAE document. Additionally, Social Services prioritizing other projects also contributed to the weaknesses persisting. Not configuring web applications in accordance with the Security Standard increases the risk of successful cyberattack, exploit, and data breach by malicious parties. Social Services should dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Proper configuration of the web application will help Social Services to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 2...

2023-022: Improve IT Risk Management Program Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment; System and Services Acquisition ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education is missing certain elements within its IT risk management program to meet the requirements in the Commonwealth’s Security Standard. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires that Education review and update its risk assessment at least annually or when significant changes occur to the system or IT environment (Security Standard, Section 6.2 Risk Assessment). The Security Standard also requires that Education perform an initial risk analysis at project initiation for each external information system (Security Standard, Section SA-3-COV-1). Additionally, the Security Standard requires Education to develop a system security plan for the information system and conduct an annual review of the SSP (Security Standard, Section PL-2 System Security Plan). Without conducting and annually reviewing its risk management documentation, Education increases the risk that it may not properly secure its sensitive systems. An unexpected delay in implementing the planned risk management solution contributed to Education not consistently maintaining its risk management documentation. Education should complete the implementation of its new risk management solution. In addition, Education should conduct and annually review each element of its risk management documentation. This will help ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-027: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: 2022-022 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department...

2023-027: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: 2022-022 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services has an insufficient governance structure to manage and maintain its information security program in accordance with the Security Standard. Specifically, Social Services does not assess information security requirements for its IT projects and prioritize information security and information technology resources to ensure its information security program effectively protects sensitive Commonwealth data in accordance with the Security Standard. The Security Standard, Section 2.4.2, requires the agency head to maintain an information security program that is sufficient to protect the agency’s IT systems and to ensure the information security program is documented and effectively communicated. We communicated the control weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia due to its sensitivity and description of security controls. The control weaknesses described in the communication marked FOIAE are the result of Social Services not assessing information security requirements prior to project implementation and prioritizing information security within the IT environment. Social Services has hindered its ability to consistently and timely remediate findings from management recommendations issued throughout prior year audits and bring the information security program in compliance with the Security Standard by not dedicating the necessary IT resources to information security. Not prioritizing information technology resources to properly manage its information security program can result in a data breach or unauthorized access to confidential and mission-critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. Because of the scope of this matter and the magnitude of Social Services’ information system security responsibilities, we consider these weaknesses collectively to create a material weakness in internal controls over compliance. In July 2023, the Governor appointed a Chief Deputy Commissioner, who is responsible for overseeing Social Services’ information technology and security functions. Social Services should evaluate the most efficient and effective method to bring its IT and security program into compliance with the Security Standard. Social Services should also evaluate its IT resource levels to ensure sufficient resources are available and dedicated to prioritizing and implementing IT governance changes and address the control deficiencies discussed in the communication marked FOIAE. Implementing these recommendations will help to ensure Social Services protects the confidentiality, integrity, and availability of its sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-027: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: 2022-022 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department...

2023-027: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: 2022-022 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services has an insufficient governance structure to manage and maintain its information security program in accordance with the Security Standard. Specifically, Social Services does not assess information security requirements for its IT projects and prioritize information security and information technology resources to ensure its information security program effectively protects sensitive Commonwealth data in accordance with the Security Standard. The Security Standard, Section 2.4.2, requires the agency head to maintain an information security program that is sufficient to protect the agency’s IT systems and to ensure the information security program is documented and effectively communicated. We communicated the control weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia due to its sensitivity and description of security controls. The control weaknesses described in the communication marked FOIAE are the result of Social Services not assessing information security requirements prior to project implementation and prioritizing information security within the IT environment. Social Services has hindered its ability to consistently and timely remediate findings from management recommendations issued throughout prior year audits and bring the information security program in compliance with the Security Standard by not dedicating the necessary IT resources to information security. Not prioritizing information technology resources to properly manage its information security program can result in a data breach or unauthorized access to confidential and mission-critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. Because of the scope of this matter and the magnitude of Social Services’ information system security responsibilities, we consider these weaknesses collectively to create a material weakness in internal controls over compliance. In July 2023, the Governor appointed a Chief Deputy Commissioner, who is responsible for overseeing Social Services’ information technology and security functions. Social Services should evaluate the most efficient and effective method to bring its IT and security program into compliance with the Security Standard. Social Services should also evaluate its IT resource levels to ensure sufficient resources are available and dedicated to prioritizing and implementing IT governance changes and address the control deficiencies discussed in the communication marked FOIAE. Implementing these recommendations will help to ensure Social Services protects the confidentiality, integrity, and availability of its sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

FY End: 2023-06-30
Commonwealth of Virginia
Compliance Requirement: P
2023-027: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: 2022-022 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department...

2023-027: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: 2022-022 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services has an insufficient governance structure to manage and maintain its information security program in accordance with the Security Standard. Specifically, Social Services does not assess information security requirements for its IT projects and prioritize information security and information technology resources to ensure its information security program effectively protects sensitive Commonwealth data in accordance with the Security Standard. The Security Standard, Section 2.4.2, requires the agency head to maintain an information security program that is sufficient to protect the agency’s IT systems and to ensure the information security program is documented and effectively communicated. We communicated the control weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia due to its sensitivity and description of security controls. The control weaknesses described in the communication marked FOIAE are the result of Social Services not assessing information security requirements prior to project implementation and prioritizing information security within the IT environment. Social Services has hindered its ability to consistently and timely remediate findings from management recommendations issued throughout prior year audits and bring the information security program in compliance with the Security Standard by not dedicating the necessary IT resources to information security. Not prioritizing information technology resources to properly manage its information security program can result in a data breach or unauthorized access to confidential and mission-critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. Because of the scope of this matter and the magnitude of Social Services’ information system security responsibilities, we consider these weaknesses collectively to create a material weakness in internal controls over compliance. In July 2023, the Governor appointed a Chief Deputy Commissioner, who is responsible for overseeing Social Services’ information technology and security functions. Social Services should evaluate the most efficient and effective method to bring its IT and security program into compliance with the Security Standard. Social Services should also evaluate its IT resource levels to ensure sufficient resources are available and dedicated to prioritizing and implementing IT governance changes and address the control deficiencies discussed in the communication marked FOIAE. Implementing these recommendations will help to ensure Social Services protects the confidentiality, integrity, and availability of its sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.

« 1 874 875 877 878 2003 »