2023-034: Evaluate Separation of Duty Conflicts within the Case Management System Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services has not performed nor documented a conflicting access review for its case management system to identify the combination of roles that could pose a separation of duties conflict and ensure compensating controls are in place to mitigate risks arising from those conflicts. Social Services uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid Cluster, Child Care and Development Fund Cluster, SNAP Cluster, TANF, and Low-Income Household Energy Assistance (LIHEA) federal grant programs. Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. The Security Standard, Section 8.1 AC-5, requires the agency to separate duties of individuals as necessary, document separation of duties of individuals, and define information system access authorization to support the separation of duties. Social Services, in collaboration with its service provider, has documented role-based security access. However, due to lack of management oversight, the documentation did not include a review of conflicting role access and Social Services has not properly updated the documentation even though the case management system has undergone multiple changes and upgrades since its initial release over ten years ago. By not performing and documenting a conflicting access review, Social Services does not know which combinations of roles pose a separation of duties conflict and could potentially create opportunities for users to exploit vulnerabilities in the case management system. Social Services should perform and document a conflicting access review for the case management system to identify the combinations of roles that could pose separation of duties conflicts and ensure compensating controls are in place to mitigate risks arising from those conflicts. Additionally, Social Services should update the role-based security access documentation to reflect all system changes from prior case management system related releases. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-034: Evaluate Separation of Duty Conflicts within the Case Management System Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services has not performed nor documented a conflicting access review for its case management system to identify the combination of roles that could pose a separation of duties conflict and ensure compensating controls are in place to mitigate risks arising from those conflicts. Social Services uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid Cluster, Child Care and Development Fund Cluster, SNAP Cluster, TANF, and Low-Income Household Energy Assistance (LIHEA) federal grant programs. Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. The Security Standard, Section 8.1 AC-5, requires the agency to separate duties of individuals as necessary, document separation of duties of individuals, and define information system access authorization to support the separation of duties. Social Services, in collaboration with its service provider, has documented role-based security access. However, due to lack of management oversight, the documentation did not include a review of conflicting role access and Social Services has not properly updated the documentation even though the case management system has undergone multiple changes and upgrades since its initial release over ten years ago. By not performing and documenting a conflicting access review, Social Services does not know which combinations of roles pose a separation of duties conflict and could potentially create opportunities for users to exploit vulnerabilities in the case management system. Social Services should perform and document a conflicting access review for the case management system to identify the combinations of roles that could pose separation of duties conflicts and ensure compensating controls are in place to mitigate risks arising from those conflicts. Additionally, Social Services should update the role-based security access documentation to reflect all system changes from prior case management system related releases. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-034: Evaluate Separation of Duty Conflicts within the Case Management System Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services has not performed nor documented a conflicting access review for its case management system to identify the combination of roles that could pose a separation of duties conflict and ensure compensating controls are in place to mitigate risks arising from those conflicts. Social Services uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid Cluster, Child Care and Development Fund Cluster, SNAP Cluster, TANF, and Low-Income Household Energy Assistance (LIHEA) federal grant programs. Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. The Security Standard, Section 8.1 AC-5, requires the agency to separate duties of individuals as necessary, document separation of duties of individuals, and define information system access authorization to support the separation of duties. Social Services, in collaboration with its service provider, has documented role-based security access. However, due to lack of management oversight, the documentation did not include a review of conflicting role access and Social Services has not properly updated the documentation even though the case management system has undergone multiple changes and upgrades since its initial release over ten years ago. By not performing and documenting a conflicting access review, Social Services does not know which combinations of roles pose a separation of duties conflict and could potentially create opportunities for users to exploit vulnerabilities in the case management system. Social Services should perform and document a conflicting access review for the case management system to identify the combinations of roles that could pose separation of duties conflicts and ensure compensating controls are in place to mitigate risks arising from those conflicts. Additionally, Social Services should update the role-based security access documentation to reflect all system changes from prior case management system related releases. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-035: Perform Annual Review of Case Management System Access Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services did not perform the required annual access review for its case management system during fiscal year 2023. Social Services uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid Cluster, Child Care and Development Fund Cluster, SNAP Cluster, TANF, and LIHEA federal grant programs. Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. The Security Standard, Section 8.1 AC-2(j), requires the agency to review accounts for compliance with account management on an annual basis. Additionally, Social Services’ policies and procedures require an annual review of user accounts to verify access privileges of active employees for every role-based access system and this review must be completed within 364 days of the last completion of access review. The annual access review for the case management system was not performed during fiscal year 2023 due to staff turnover. By not performing this annual access review, Social Services increases the risk of improper or unnecessary access to sensitive systems, which could result in a breach in data security. Social Services should perform an annual access review of user accounts for the case management system as required by the Security Standard and the agency’s policies and procedures. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-035: Perform Annual Review of Case Management System Access Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services did not perform the required annual access review for its case management system during fiscal year 2023. Social Services uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid Cluster, Child Care and Development Fund Cluster, SNAP Cluster, TANF, and LIHEA federal grant programs. Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. The Security Standard, Section 8.1 AC-2(j), requires the agency to review accounts for compliance with account management on an annual basis. Additionally, Social Services’ policies and procedures require an annual review of user accounts to verify access privileges of active employees for every role-based access system and this review must be completed within 364 days of the last completion of access review. The annual access review for the case management system was not performed during fiscal year 2023 due to staff turnover. By not performing this annual access review, Social Services increases the risk of improper or unnecessary access to sensitive systems, which could result in a breach in data security. Social Services should perform an annual access review of user accounts for the case management system as required by the Security Standard and the agency’s policies and procedures. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-035: Perform Annual Review of Case Management System Access Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services did not perform the required annual access review for its case management system during fiscal year 2023. Social Services uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid Cluster, Child Care and Development Fund Cluster, SNAP Cluster, TANF, and LIHEA federal grant programs. Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. The Security Standard, Section 8.1 AC-2(j), requires the agency to review accounts for compliance with account management on an annual basis. Additionally, Social Services’ policies and procedures require an annual review of user accounts to verify access privileges of active employees for every role-based access system and this review must be completed within 364 days of the last completion of access review. The annual access review for the case management system was not performed during fiscal year 2023 due to staff turnover. By not performing this annual access review, Social Services increases the risk of improper or unnecessary access to sensitive systems, which could result in a breach in data security. Social Services should perform an annual access review of user accounts for the case management system as required by the Security Standard and the agency’s policies and procedures. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-036: Perform Annual System Access Reviews Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services has not performed an annual access review for two of three user groups of the claims processing module of the Medicaid management system since June 2022. Medical Assistance Services completed an annual access review of Medical Assistance Services’ employees but did not perform an annual review of the Social Services’ and contractors’ user groups. The Social Services and contractor user groups represent almost ninety percent of the total users of the system. The Security Standard, Section 8.1 AC-2, requires the agency to review accounts for compliance with account management requirements on an annual basis. Medical Assistance Services encountered issues after the implementation of the Medicaid management system including lack of staff and budgetary constraints, causing management to defer the review process. By not reviewing access on an annual basis, Medical Assistance Services cannot verify that each user’s access is appropriate based on job functions; does not violate the principles of least privilege or separation of duties; and is configured appropriately. Lack of an annual access review increases the risk that a user retains inappropriate access, which could lead to unauthorized access to sensitive information. Medical Assistance Services should perform an annual review of Social Services’ and contractors’ access to identify unnecessary access due to terminations or changes in responsibilities. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-036: Perform Annual System Access Reviews Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services has not performed an annual access review for two of three user groups of the claims processing module of the Medicaid management system since June 2022. Medical Assistance Services completed an annual access review of Medical Assistance Services’ employees but did not perform an annual review of the Social Services’ and contractors’ user groups. The Social Services and contractor user groups represent almost ninety percent of the total users of the system. The Security Standard, Section 8.1 AC-2, requires the agency to review accounts for compliance with account management requirements on an annual basis. Medical Assistance Services encountered issues after the implementation of the Medicaid management system including lack of staff and budgetary constraints, causing management to defer the review process. By not reviewing access on an annual basis, Medical Assistance Services cannot verify that each user’s access is appropriate based on job functions; does not violate the principles of least privilege or separation of duties; and is configured appropriately. Lack of an annual access review increases the risk that a user retains inappropriate access, which could lead to unauthorized access to sensitive information. Medical Assistance Services should perform an annual review of Social Services’ and contractors’ access to identify unnecessary access due to terminations or changes in responsibilities. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-036: Perform Annual System Access Reviews Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services has not performed an annual access review for two of three user groups of the claims processing module of the Medicaid management system since June 2022. Medical Assistance Services completed an annual access review of Medical Assistance Services’ employees but did not perform an annual review of the Social Services’ and contractors’ user groups. The Social Services and contractor user groups represent almost ninety percent of the total users of the system. The Security Standard, Section 8.1 AC-2, requires the agency to review accounts for compliance with account management requirements on an annual basis. Medical Assistance Services encountered issues after the implementation of the Medicaid management system including lack of staff and budgetary constraints, causing management to defer the review process. By not reviewing access on an annual basis, Medical Assistance Services cannot verify that each user’s access is appropriate based on job functions; does not violate the principles of least privilege or separation of duties; and is configured appropriately. Lack of an annual access review increases the risk that a user retains inappropriate access, which could lead to unauthorized access to sensitive information. Medical Assistance Services should perform an annual review of Social Services’ and contractors’ access to identify unnecessary access due to terminations or changes in responsibilities. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-043: Monitor Internal Controls to Ensure Timely Removal of System Access Applicable to: Department of Social Services Prior Year Finding Number: 2022-059; 2021-038;2021-027;2020-025;2019-027;2018-042 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to implement internal controls to monitor the timely removal of system access. The Security Standard, Section PS-4, requires the organization to disable information system access within 24 hours of employment termination. In prior audits, we identified instances where Social Services did not remove separated employee access in accordance with the Security Standard. In response to the prior audit recommendations, Social Services formed an agency-wide working group to determine the exact processes needed to implement the internal controls necessary to address the audit recommendations. Additionally, Social Services’ ISRM function and the Division of Human Resources (Human Resources) have worked together to discuss implementing new reporting and interface processes between its internal human resources system and the Commonwealth’s human resources system. However, because of the extent of its corrective actions, Social Services was not able to implement all of them by the end of fiscal year 2023. Social Services administers numerous public assistance programs that collect personally identifiable information and other protected information from beneficiaries. Social Services places its data and reputation at risk by not removing access timely. Additionally, Social Services could incur potential financial liabilities should its information become compromised. Therefore, Social Services should continue its corrective action efforts to implement internal controls to monitor the timely removal of system access. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-043: Monitor Internal Controls to Ensure Timely Removal of System Access Applicable to: Department of Social Services Prior Year Finding Number: 2022-059; 2021-038;2021-027;2020-025;2019-027;2018-042 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to implement internal controls to monitor the timely removal of system access. The Security Standard, Section PS-4, requires the organization to disable information system access within 24 hours of employment termination. In prior audits, we identified instances where Social Services did not remove separated employee access in accordance with the Security Standard. In response to the prior audit recommendations, Social Services formed an agency-wide working group to determine the exact processes needed to implement the internal controls necessary to address the audit recommendations. Additionally, Social Services’ ISRM function and the Division of Human Resources (Human Resources) have worked together to discuss implementing new reporting and interface processes between its internal human resources system and the Commonwealth’s human resources system. However, because of the extent of its corrective actions, Social Services was not able to implement all of them by the end of fiscal year 2023. Social Services administers numerous public assistance programs that collect personally identifiable information and other protected information from beneficiaries. Social Services places its data and reputation at risk by not removing access timely. Additionally, Social Services could incur potential financial liabilities should its information become compromised. Therefore, Social Services should continue its corrective action efforts to implement internal controls to monitor the timely removal of system access. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-043: Monitor Internal Controls to Ensure Timely Removal of System Access Applicable to: Department of Social Services Prior Year Finding Number: 2022-059; 2021-038;2021-027;2020-025;2019-027;2018-042 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to implement internal controls to monitor the timely removal of system access. The Security Standard, Section PS-4, requires the organization to disable information system access within 24 hours of employment termination. In prior audits, we identified instances where Social Services did not remove separated employee access in accordance with the Security Standard. In response to the prior audit recommendations, Social Services formed an agency-wide working group to determine the exact processes needed to implement the internal controls necessary to address the audit recommendations. Additionally, Social Services’ ISRM function and the Division of Human Resources (Human Resources) have worked together to discuss implementing new reporting and interface processes between its internal human resources system and the Commonwealth’s human resources system. However, because of the extent of its corrective actions, Social Services was not able to implement all of them by the end of fiscal year 2023. Social Services administers numerous public assistance programs that collect personally identifiable information and other protected information from beneficiaries. Social Services places its data and reputation at risk by not removing access timely. Additionally, Social Services could incur potential financial liabilities should its information become compromised. Therefore, Social Services should continue its corrective action efforts to implement internal controls to monitor the timely removal of system access. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-049: Continue Improving IT Change and Configuration Management Process Applicable to: Department of Social Services Prior Year Finding Number: 2022-052; 2021-049; 2020-044; 2019-038 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to improve its IT change and configuration management process to align with the Security Standard. Change management is a key control to evaluate, approve, and verify configuration changes to security components. Two weaknesses remain since our last review, which we communicated to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Social Services’ Change Management Process Guide details the process Social Services follows to manage changes, but does not include all the required elements, which contributed to the weaknesses remaining. Additionally, the change request form does not have the necessary fields to document the required elements. Not aligning IT change management processes with the Security Standard increases the risk of a data breach or unauthorized access to confidential and mission-critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. Social Services should resolve the remaining two weaknesses discussed in the communication marked FOIAE in accordance with the Security Standard. Continuing to improve Social Services’ IT change and configuration management process will decrease the risk of unauthorized modifications to sensitive systems and help maintain the confidentiality, integrity, and availability of sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-049: Continue Improving IT Change and Configuration Management Process Applicable to: Department of Social Services Prior Year Finding Number: 2022-052; 2021-049; 2020-044; 2019-038 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to improve its IT change and configuration management process to align with the Security Standard. Change management is a key control to evaluate, approve, and verify configuration changes to security components. Two weaknesses remain since our last review, which we communicated to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Social Services’ Change Management Process Guide details the process Social Services follows to manage changes, but does not include all the required elements, which contributed to the weaknesses remaining. Additionally, the change request form does not have the necessary fields to document the required elements. Not aligning IT change management processes with the Security Standard increases the risk of a data breach or unauthorized access to confidential and mission-critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. Social Services should resolve the remaining two weaknesses discussed in the communication marked FOIAE in accordance with the Security Standard. Continuing to improve Social Services’ IT change and configuration management process will decrease the risk of unauthorized modifications to sensitive systems and help maintain the confidentiality, integrity, and availability of sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-049: Continue Improving IT Change and Configuration Management Process Applicable to: Department of Social Services Prior Year Finding Number: 2022-052; 2021-049; 2020-044; 2019-038 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to improve its IT change and configuration management process to align with the Security Standard. Change management is a key control to evaluate, approve, and verify configuration changes to security components. Two weaknesses remain since our last review, which we communicated to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Social Services’ Change Management Process Guide details the process Social Services follows to manage changes, but does not include all the required elements, which contributed to the weaknesses remaining. Additionally, the change request form does not have the necessary fields to document the required elements. Not aligning IT change management processes with the Security Standard increases the risk of a data breach or unauthorized access to confidential and mission-critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. Social Services should resolve the remaining two weaknesses discussed in the communication marked FOIAE in accordance with the Security Standard. Continuing to improve Social Services’ IT change and configuration management process will decrease the risk of unauthorized modifications to sensitive systems and help maintain the confidentiality, integrity, and availability of sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-051: Improve Change Control Process Applicable to: Virginia Employment Commission Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management ALPT or Cluster Name and ALN: Unemployment Insurance (UI) - 17.225 Federal Award Number and Year: UI210F2300 - 2023 Name of Federal Agency: U.S. Department of Labor Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 The Commission does not define whether certain types of changes are exempt from certain elements of its information technology (IT) change control process. As a result, the Commission does not consistently follow its Configuration Management Policy and Procedures (Configuration Management Policy) and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). Specifically, the following weaknesses exist: The Commission does not perform an explicit evaluation of change requests from a security perspective, commonly referred to as a security impact analysis, for changes to some of its systems and applications. For all 50 changes we selected for review, the Commission could not provide evidence that it performed a security impact analysis. The Configuration Management Policy requires the Commission’s Information Security Officer (ISO) or designee to perform a security impact analysis for proposed changes, document the findings, and attach the documentation to the change request. Additionally, the Security Standard requires the Commission to approve or deny change requests with explicit consideration for security impact analyses. Without conducting and documenting a security impact analysis for each requested change, the Commission may not detect and prevent changes that could compromise the security of the IT environment (Configuration Management Policy Section 3.b Security Impact Analysis; Security Standard Sections CM-3 Configuration Change Control and CM-4 Security Impact Analysis). The Commission did not perform pre-implementation testing for 34 out of 50 changes sampled (68%). The Configuration Management Policy requires the Commission to test, validate, and document changes to the information system before implementing the changes on the operational system. Without performing pre-implementation testing to validate a change, the Commission increases the risk that a change may compromise security of the IT environment without being detected and prevented (Configuration Management Policy Section 2.a.9 Configuration Change Control; Security Standard Section CM-3 Configuration Change Control). The Commission not documenting whether specific types of changes are exempt from certain aspects of its formal change management process or should follow a different process caused it not to consistently perform pre-implementation testing. Additionally, the Commission did not enforce its Configuration Management Policy, which also led to it not formally documenting a security impact analysis for each change. The Commission should define and formally document the different change types and whether the type of change is exempt from aspects of its formal change management process. Additionally, the Commission should conduct and document its analysis of security impacts for each change request prior to approval and implementation to the production IT environment. These actions will help ensure the confidentiality, integrity, and availability of sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-051: Improve Change Control Process Applicable to: Virginia Employment Commission Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management ALPT or Cluster Name and ALN: Unemployment Insurance (UI) - 17.225 Federal Award Number and Year: UI210F2300 - 2023 Name of Federal Agency: U.S. Department of Labor Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 The Commission does not define whether certain types of changes are exempt from certain elements of its information technology (IT) change control process. As a result, the Commission does not consistently follow its Configuration Management Policy and Procedures (Configuration Management Policy) and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). Specifically, the following weaknesses exist: The Commission does not perform an explicit evaluation of change requests from a security perspective, commonly referred to as a security impact analysis, for changes to some of its systems and applications. For all 50 changes we selected for review, the Commission could not provide evidence that it performed a security impact analysis. The Configuration Management Policy requires the Commission’s Information Security Officer (ISO) or designee to perform a security impact analysis for proposed changes, document the findings, and attach the documentation to the change request. Additionally, the Security Standard requires the Commission to approve or deny change requests with explicit consideration for security impact analyses. Without conducting and documenting a security impact analysis for each requested change, the Commission may not detect and prevent changes that could compromise the security of the IT environment (Configuration Management Policy Section 3.b Security Impact Analysis; Security Standard Sections CM-3 Configuration Change Control and CM-4 Security Impact Analysis). The Commission did not perform pre-implementation testing for 34 out of 50 changes sampled (68%). The Configuration Management Policy requires the Commission to test, validate, and document changes to the information system before implementing the changes on the operational system. Without performing pre-implementation testing to validate a change, the Commission increases the risk that a change may compromise security of the IT environment without being detected and prevented (Configuration Management Policy Section 2.a.9 Configuration Change Control; Security Standard Section CM-3 Configuration Change Control). The Commission not documenting whether specific types of changes are exempt from certain aspects of its formal change management process or should follow a different process caused it not to consistently perform pre-implementation testing. Additionally, the Commission did not enforce its Configuration Management Policy, which also led to it not formally documenting a security impact analysis for each change. The Commission should define and formally document the different change types and whether the type of change is exempt from aspects of its formal change management process. Additionally, the Commission should conduct and document its analysis of security impacts for each change request prior to approval and implementation to the production IT environment. These actions will help ensure the confidentiality, integrity, and availability of sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-056: Conduct Information Technology Security Audits Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services does not conduct a comprehensive IT security audit on each sensitive system at least once every three years that assesses whether IT security controls are adequate and effective. Specifically, Social Services has not conducted an IT security audit in the last three years over 29 of the 70 sensitive systems (41%) due for an IT security audit. The Security Standard, Section 7, requires that each IT system classified as a sensitive system undergo an IT security audit as required by and in accordance with the current version of the IT Audit Standard. The IT Audit Standard, Section 1.4, requires that IT systems containing sensitive data, or systems with an assessed sensitivity of high on any of the criteria of confidentiality, integrity, or availability, shall receive an IT security audit at least once every three years. Additionally, the IT Audit Standard, Section 2.2, requires that the IT security auditor shall use criteria that, at a minimum, assesses the effectiveness of the system controls and measures compliance with the applicable requirements of the Security Standard. Social Services does not have an internal audit function but does employ an IT Audit Manager. However, any audits conducted by the IT Audit Manager cannot be peer reviewed due to Social Services not having an internal audit function or Chief Audit Executive, and thus, these audits do not meet Government Auditing Standards requirements. Therefore, Social Services procures an external auditor to complete all the required IT Security Audits using funds allocated from the Virginia General Assembly, as well as funds allocated to Information Technology Services. Social Services tasks the IT Audit Manager with coordinating the audits and tracking Social Services’ remediation of audit findings. However, the IT Audit Manager relies on the collaboration of the business divisions, Information Technology Services, and Information Security Risk Management, as well as the oversight of the Executive Team to effectively schedule and conduct the audits. Social Services did not perform the IT security audits in accordance with the Security Standard because of a lack of governance over IT security. Without conducting full IT security audits that cover all applicable Security Standard requirements for each sensitive system every three years, Social Services increases the risk that IT staff will not detect and mitigate existing weaknesses. Malicious parties taking advantage of continued weaknesses could compromise sensitive and confidential data. Further, such security incidents could lead to mission-critical systems being unavailable. Social Services should evaluate potential options and develop a formal process for conducting IT audits over each sensitive system at least once every three years that tests the effectiveness of the IT security controls and compliance with Security Standard requirements. Social Services should then complete the planned IT security audits and implement adequate governance processes to ensure it is meeting the Security Standard requirements. Compliance with the IT Audit Standard will help to ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-056: Conduct Information Technology Security Audits Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services does not conduct a comprehensive IT security audit on each sensitive system at least once every three years that assesses whether IT security controls are adequate and effective. Specifically, Social Services has not conducted an IT security audit in the last three years over 29 of the 70 sensitive systems (41%) due for an IT security audit. The Security Standard, Section 7, requires that each IT system classified as a sensitive system undergo an IT security audit as required by and in accordance with the current version of the IT Audit Standard. The IT Audit Standard, Section 1.4, requires that IT systems containing sensitive data, or systems with an assessed sensitivity of high on any of the criteria of confidentiality, integrity, or availability, shall receive an IT security audit at least once every three years. Additionally, the IT Audit Standard, Section 2.2, requires that the IT security auditor shall use criteria that, at a minimum, assesses the effectiveness of the system controls and measures compliance with the applicable requirements of the Security Standard. Social Services does not have an internal audit function but does employ an IT Audit Manager. However, any audits conducted by the IT Audit Manager cannot be peer reviewed due to Social Services not having an internal audit function or Chief Audit Executive, and thus, these audits do not meet Government Auditing Standards requirements. Therefore, Social Services procures an external auditor to complete all the required IT Security Audits using funds allocated from the Virginia General Assembly, as well as funds allocated to Information Technology Services. Social Services tasks the IT Audit Manager with coordinating the audits and tracking Social Services’ remediation of audit findings. However, the IT Audit Manager relies on the collaboration of the business divisions, Information Technology Services, and Information Security Risk Management, as well as the oversight of the Executive Team to effectively schedule and conduct the audits. Social Services did not perform the IT security audits in accordance with the Security Standard because of a lack of governance over IT security. Without conducting full IT security audits that cover all applicable Security Standard requirements for each sensitive system every three years, Social Services increases the risk that IT staff will not detect and mitigate existing weaknesses. Malicious parties taking advantage of continued weaknesses could compromise sensitive and confidential data. Further, such security incidents could lead to mission-critical systems being unavailable. Social Services should evaluate potential options and develop a formal process for conducting IT audits over each sensitive system at least once every three years that tests the effectiveness of the IT security controls and compliance with Security Standard requirements. Social Services should then complete the planned IT security audits and implement adequate governance processes to ensure it is meeting the Security Standard requirements. Compliance with the IT Audit Standard will help to ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-056: Conduct Information Technology Security Audits Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services does not conduct a comprehensive IT security audit on each sensitive system at least once every three years that assesses whether IT security controls are adequate and effective. Specifically, Social Services has not conducted an IT security audit in the last three years over 29 of the 70 sensitive systems (41%) due for an IT security audit. The Security Standard, Section 7, requires that each IT system classified as a sensitive system undergo an IT security audit as required by and in accordance with the current version of the IT Audit Standard. The IT Audit Standard, Section 1.4, requires that IT systems containing sensitive data, or systems with an assessed sensitivity of high on any of the criteria of confidentiality, integrity, or availability, shall receive an IT security audit at least once every three years. Additionally, the IT Audit Standard, Section 2.2, requires that the IT security auditor shall use criteria that, at a minimum, assesses the effectiveness of the system controls and measures compliance with the applicable requirements of the Security Standard. Social Services does not have an internal audit function but does employ an IT Audit Manager. However, any audits conducted by the IT Audit Manager cannot be peer reviewed due to Social Services not having an internal audit function or Chief Audit Executive, and thus, these audits do not meet Government Auditing Standards requirements. Therefore, Social Services procures an external auditor to complete all the required IT Security Audits using funds allocated from the Virginia General Assembly, as well as funds allocated to Information Technology Services. Social Services tasks the IT Audit Manager with coordinating the audits and tracking Social Services’ remediation of audit findings. However, the IT Audit Manager relies on the collaboration of the business divisions, Information Technology Services, and Information Security Risk Management, as well as the oversight of the Executive Team to effectively schedule and conduct the audits. Social Services did not perform the IT security audits in accordance with the Security Standard because of a lack of governance over IT security. Without conducting full IT security audits that cover all applicable Security Standard requirements for each sensitive system every three years, Social Services increases the risk that IT staff will not detect and mitigate existing weaknesses. Malicious parties taking advantage of continued weaknesses could compromise sensitive and confidential data. Further, such security incidents could lead to mission-critical systems being unavailable. Social Services should evaluate potential options and develop a formal process for conducting IT audits over each sensitive system at least once every three years that tests the effectiveness of the IT security controls and compliance with Security Standard requirements. Social Services should then complete the planned IT security audits and implement adequate governance processes to ensure it is meeting the Security Standard requirements. Compliance with the IT Audit Standard will help to ensure the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-058: Upgrade End-of-Life Technology Applicable to: Department of Social Services Prior Year Finding Number: 2022-060 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services uses end-of-life (EOL) technologies in its IT environment and maintains technologies that support mission-essential data on IT systems running software that its vendors no longer support. We communicated internal control weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard prohibits agencies from using software that is EOL and which the vendor no longer supports to reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Social Services does not assign an individual or team with the responsibility to track EOL software dates and does not have a formal process to ensure that it upgrades software versions prior to the EOL date, which caused the EOL software to remain in the environment. Using EOL technologies increases the risk of successful cyberattack, exploit, and data breach by malicious parties. Further, vendors do not offer operational and technical support for EOL or end-of-support technology, which affects data availability by increasing the difficulty of restoring system functionality if a technical failure occurs. Social Services should dedicate the necessary resources to evaluate and implement the internal controls and recommendations discussed in the communication marked FOIAE in accordance with the Security Standard. Dedicating the necessary resources to minimize the use of EOL technologies will help to ensure that Social Services secures its IT environment and systems to protect its sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-058: Upgrade End-of-Life Technology Applicable to: Department of Social Services Prior Year Finding Number: 2022-060 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services uses end-of-life (EOL) technologies in its IT environment and maintains technologies that support mission-essential data on IT systems running software that its vendors no longer support. We communicated internal control weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard prohibits agencies from using software that is EOL and which the vendor no longer supports to reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Social Services does not assign an individual or team with the responsibility to track EOL software dates and does not have a formal process to ensure that it upgrades software versions prior to the EOL date, which caused the EOL software to remain in the environment. Using EOL technologies increases the risk of successful cyberattack, exploit, and data breach by malicious parties. Further, vendors do not offer operational and technical support for EOL or end-of-support technology, which affects data availability by increasing the difficulty of restoring system functionality if a technical failure occurs. Social Services should dedicate the necessary resources to evaluate and implement the internal controls and recommendations discussed in the communication marked FOIAE in accordance with the Security Standard. Dedicating the necessary resources to minimize the use of EOL technologies will help to ensure that Social Services secures its IT environment and systems to protect its sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-058: Upgrade End-of-Life Technology Applicable to: Department of Social Services Prior Year Finding Number: 2022-060 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services uses end-of-life (EOL) technologies in its IT environment and maintains technologies that support mission-essential data on IT systems running software that its vendors no longer support. We communicated internal control weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard prohibits agencies from using software that is EOL and which the vendor no longer supports to reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Social Services does not assign an individual or team with the responsibility to track EOL software dates and does not have a formal process to ensure that it upgrades software versions prior to the EOL date, which caused the EOL software to remain in the environment. Using EOL technologies increases the risk of successful cyberattack, exploit, and data breach by malicious parties. Further, vendors do not offer operational and technical support for EOL or end-of-support technology, which affects data availability by increasing the difficulty of restoring system functionality if a technical failure occurs. Social Services should dedicate the necessary resources to evaluate and implement the internal controls and recommendations discussed in the communication marked FOIAE in accordance with the Security Standard. Dedicating the necessary resources to minimize the use of EOL technologies will help to ensure that Social Services secures its IT environment and systems to protect its sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-061: Improve Vulnerability Management Process Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Child and Adult Care Food Program (CACFP) - 10.558; Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Educational Stabilization Fund (ESF) - 84.425 Federal Award Number and Year: Various - 2023 Name of Federal Agency: U.S. Department of Agriculture; U.S. Department of Education; U.S. Department of the Treasury Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not consistently remediate vulnerabilities in its information technology (IT) environment within the timeframe required by agency policy and the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). VITA and Education share the responsibility for the remediation of legitimate vulnerabilities and Education does not consistently remediate vulnerabilities that are its responsibility. We communicated the weaknesses and recommendations to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. Both Education’s Information Security Policy Manual and the Security Standard require Education to remediate legitimate vulnerabilities within 90 days in accordance with an organizational assessment of risk. Without remediating vulnerabilities within the required timeframe, Education increases the risk of unauthorized access to the IT environment. Education follows a vulnerability management process; however, some extensive and time-consuming elements of the process caused delays in remediation efforts. Education should improve its vulnerability management process to remediate vulnerabilities within the timeline required by the Security Standard and its Information Security Policy Manual. By remediating vulnerabilities timely, Education will reduce data security risks for sensitive and mission-critical systems and better protect the confidentiality, integrity, and availability of the data processed by those systems. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-066: Continue Developing Record Retention Requirements and Processes for Electronic Records Applicable to: Department of Social Services Prior Year Finding Number: 2022-064; 2021-047; 2020-041; 2019-049; 2018-054 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to operate without an adequate data retention process that ensures consistent compliance with retention requirements for its case management system and adherence to federal regulations and the Code of Virginia. Specifically, Social Services does not have data retention policies and procedures that define its requirements and processes to consistently ensure data retention compliance and destruction. Social Services’ case management system stores several types of federal benefit program records with varying retention requirements supporting ten programs and services, such as Medicaid, TANF, and the Supplemental Nutrition Assistance Program (SNAP). Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. Since fiscal year 2019, Social Services gathered retention requirements from the business divisions that support the federal programs and services. In fiscal year 2022, Social Services finalized and documented policies with retention requirements for the data sets handled by each of the ten programs and services supported by its case management system. However, Social Services has not developed, documented, and implemented procedures and processes to operationalize the records retention policies for each of the programs and services to ensure consistent retention and destruction of records in compliance with regulations and laws. Title 45 CFR § 155.1210, governs record retention for Medicaid and requires state agencies to maintain records for ten years. Additionally, the Virginia Public Records Act outlined in § 42.1-91 of the Code of Virginia makes an agency responsible for ensuring that it preserves, maintains, and makes accessible public records throughout their lifecycle, including converting and migrating electronic records as often as necessary so that information is not lost due to hardware, software, or media obsolescence or deterioration. Furthermore, the Virginia Public Records Act in § 42.1-86.1 of the Code of Virginia details requirements for the disposition of records including that records created after July 1, 2006, and authorized to be destroyed or discarded, must be discarded in a timely manner and in accordance with the provisions of Chapter 7 of the Virginia Public Records Act. Records that contain identifying information as defined by subsection C of § 18.2-186.3 of the Code of Virginia shall be destroyed within six months of the expiration of the records retention period. Finally, the Security Standard requires agencies to implement backup and restoration plans that address the retention of the data in accordance with the records retention policy for every IT system identified as sensitive relative to availability (Security Standard, Section CP-9-COV Information System Backup). Without implementing records retention requirements, Social Services increases the risk of a data or privacy breach. Additionally, destroying documents that should be available for business processes or audit, or keeping data longer than stated, could expose Social Services to fines, penalties, or other legal consequences. Further, Social Services may not be able to ensure that backup and restoration efforts will provide mission essential information according to recovery times. Finally, Social Services spends additional resources to maintain, back up, and protect information that no longer serves a business purpose. Social Services determined that the retention requirements for all ten programs and services supported by its case management system are not feasible as a single release due to the risk and complexity of the project, as well as changes to federal requirements, since its initial analysis. Therefore, Social Services plans to use a phased delivery approach including multiple releases, beginning with Release 1 in February 2024. Further, Social Services is working on a revised timeline to complete each additional phase for the remaining releases. Social Services should continue to develop and implement records retention procedures that define its requirements and processes to ensure that consistent records retention processes can be operationalized across business divisions to comply with applicable with laws and regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-066: Continue Developing Record Retention Requirements and Processes for Electronic Records Applicable to: Department of Social Services Prior Year Finding Number: 2022-064; 2021-047; 2020-041; 2019-049; 2018-054 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to operate without an adequate data retention process that ensures consistent compliance with retention requirements for its case management system and adherence to federal regulations and the Code of Virginia. Specifically, Social Services does not have data retention policies and procedures that define its requirements and processes to consistently ensure data retention compliance and destruction. Social Services’ case management system stores several types of federal benefit program records with varying retention requirements supporting ten programs and services, such as Medicaid, TANF, and the Supplemental Nutrition Assistance Program (SNAP). Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. Since fiscal year 2019, Social Services gathered retention requirements from the business divisions that support the federal programs and services. In fiscal year 2022, Social Services finalized and documented policies with retention requirements for the data sets handled by each of the ten programs and services supported by its case management system. However, Social Services has not developed, documented, and implemented procedures and processes to operationalize the records retention policies for each of the programs and services to ensure consistent retention and destruction of records in compliance with regulations and laws. Title 45 CFR § 155.1210, governs record retention for Medicaid and requires state agencies to maintain records for ten years. Additionally, the Virginia Public Records Act outlined in § 42.1-91 of the Code of Virginia makes an agency responsible for ensuring that it preserves, maintains, and makes accessible public records throughout their lifecycle, including converting and migrating electronic records as often as necessary so that information is not lost due to hardware, software, or media obsolescence or deterioration. Furthermore, the Virginia Public Records Act in § 42.1-86.1 of the Code of Virginia details requirements for the disposition of records including that records created after July 1, 2006, and authorized to be destroyed or discarded, must be discarded in a timely manner and in accordance with the provisions of Chapter 7 of the Virginia Public Records Act. Records that contain identifying information as defined by subsection C of § 18.2-186.3 of the Code of Virginia shall be destroyed within six months of the expiration of the records retention period. Finally, the Security Standard requires agencies to implement backup and restoration plans that address the retention of the data in accordance with the records retention policy for every IT system identified as sensitive relative to availability (Security Standard, Section CP-9-COV Information System Backup). Without implementing records retention requirements, Social Services increases the risk of a data or privacy breach. Additionally, destroying documents that should be available for business processes or audit, or keeping data longer than stated, could expose Social Services to fines, penalties, or other legal consequences. Further, Social Services may not be able to ensure that backup and restoration efforts will provide mission essential information according to recovery times. Finally, Social Services spends additional resources to maintain, back up, and protect information that no longer serves a business purpose. Social Services determined that the retention requirements for all ten programs and services supported by its case management system are not feasible as a single release due to the risk and complexity of the project, as well as changes to federal requirements, since its initial analysis. Therefore, Social Services plans to use a phased delivery approach including multiple releases, beginning with Release 1 in February 2024. Further, Social Services is working on a revised timeline to complete each additional phase for the remaining releases. Social Services should continue to develop and implement records retention procedures that define its requirements and processes to ensure that consistent records retention processes can be operationalized across business divisions to comply with applicable with laws and regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.