• No results found

Specific observations and recommendations that were discussed with campus management are presented in detail below.

N/A
N/A
Protected

Academic year: 2021

Share "Specific observations and recommendations that were discussed with campus management are presented in detail below."

Copied!
14
0
0

Loading.... (view fulltext now)

Full text

(1)
(2)

INFORMATION SECURITY

California State University, San Bernardino

Audit Report 14-55

March 18, 2015

(3)

EXECUTIVE SUMMARY

OBJECTIVE

The objectives of the audit were to ascertain the effectiveness of existing policies and procedures related to the administration of information security and to determine the adequacy of controls over the related processes; to evaluate adherence to the Integrated California State University Administrative Manual (ICSUAM) information security policy, or where appropriate to an industry-accepted standard; and to ensure compliance with relevant governmental regulations, Trustee policy, Office of the Chancellor directives, and campus procedures.

CONCLUSION

Based upon the results of the work performed within the scope of the audit, the operational and administrative controls for information security activities as of December 5, 2014, taken as a whole, were not sufficient to meet the objectives of this audit. In general, the audit revealed that the campus information security function did not have adequate oversight of and

participation from the various decentralized information technology support units on campus. Some issues were identified with security of the centrally administered campus network. Other issues identified in this audit were related to the decentralized computing

environments, which were not consistently following the same information security standards as the campus information technology services department.

In addition, we found that some observations identified in our 2013 Sensitive Data audit were still in the process of being remediated. Specifically, we found that some information security projects, such as the periodic inventory and assessment of sensitive data and the periodic review of all systems and applications with protected data, had been initiated but not completely implemented as of the time of our review.

The issues identified suggest that attention is needed in the decentralized operations to ensure that the campus information security program operates in conformance with existing policy and to a level necessary to meet management expectations. Although many issues listed below represent opportunities to improve the process and methodologies used to administer the information security program at California State University, San Bernardino (CSUSB), effective implementation will require a campuswide commitment.

(4)

OBSERVATIONS, RECOMMENDATIONS, AND RESPONSES

1. INFORMATION SECURITY OVERSIGHT

OBSERVATION

The campus information security office did not have a process to track and report

decentralized computing departments’ compliance with campus information security policies and procedures. This is a repeat finding from the 2013 Sensitive Data audit.

We noted that the campus is in the process of implementing an annual risk assessment for all departments on campus, which will require each department to identify sensitive data maintained in paper and electronic format, submit details on controls in place to protect the data, and certify that the department is in compliance with CSU and CSUSB information security policies and procedures, such as performing an annual review over user access privileges for all systems and applications with protected data. The information will be reviewed by the information security office to ensure all sensitive data is accounted for and appropriately secured.

Inadequate monitoring and enforcement of campuswide policies and standards limits the campus’ ability to direct a comprehensive information security program and increases the campus’ exposure to security breaches and inappropriate use of computing resources.

RECOMMENDATION

We recommend that the campus complete the implementation process to track and report decentralized computing departments’ compliance with campus information security policies and procedures.

MANAGEMENT RESPONSE

We concur. Our action plan is to complete the implementation process to track and report decentralized computing departments’ compliance with campus information security policies and procedures. The anticipated completion date is September 11, 2015.

2. INFORMATION SECURITY GOVERNANCE

OBSERVATION

(5)

Our technical analysis of the network traffic and devices revealed that:

 Many of the decentralized systems on campus, to which the information security office did not have administrative access, contained numerous vulnerabilities that had not been detected.

 Baseline security standards for the administration of decentralized servers and desktops had not been formally developed and implemented, and the information security office’s recommended practices for implementing secure servers were not being implemented. The inability to identify and monitor all campus IT resources and the lack of baseline server security standards increases the risk of misconfigured systems and may leave the campus vulnerable to both internal and external attacks that could slow or bring down the network.

RECOMMENDATION

We recommend that the campus:

a. Reconfigure all computer devices into a single network directory hierarchy to provide effective equipment management, oversight, compliance, and monitoring of campus computing equipment.

b. Develop baseline security standards for security of servers and desktop systems and ensure automated adherence to the baseline standard through domain group policies.

MANAGEMENT RESPONSE

We concur. Our action plan is to:

a. Reconfigure all computer devices into a single network directory hierarchy to provide effective equipment management, oversight, compliance, and monitoring of campus computing equipment.

b. Develop baseline security standards for security of servers and desktop systems and ensure automated adherence to the baseline standard through domain group policies. The anticipated completion date is September 11, 2015.

3. INVENTORY OF PROTECTED DATA

OBSERVATION

(6)

We found that the campus had performed an inventory and assessment of sensitive data maintained electronically, but the assessment did not include paper documents or data maintained by faculty, staff, and auxiliary employees.

Inadequate accountability and protection of sensitive information increases the risk of loss and increases campus exposure to inadvertent disclosure of personal data.

RECOMMENDATION

We recommend that the campus conduct a campuswide inventory of all protected data maintained in paper and electronic format and conduct a security assessment to ensure the data is adequately protected.

MANAGEMENT RESPONSE

We concur. Our action plan is to conduct a campuswide inventory of all protected data maintained in paper and electronic format and conduct a security assessment to ensure the data is adequately protected. The anticipated completion date is September 11, 2015.

4. VULNERABILITY MANAGEMENT

OBSERVATION

The campus did not perform periodic credentialed vulnerability scans of all high-risk servers, applications, and desktops connected to the campus network.

We found that the campus performed credentialed vulnerability scans of new servers and applications before they are placed in production; however, those scans were only performed for Internet-facing devices. Additionally, there was no process in place to perform periodic vulnerability scans of desktop computers.

Our technical analysis identified numerous vulnerabilities on servers, applications, and workstations, and some servers were running obsolete versions of operating systems for which the vendor no longer provided security updates.

Inadequate identification and correction of vulnerabilities in a timely manner may lead to a breach of network security and a loss of confidential information.

RECOMMENDATION

We recommend that the campus:

a. Perform periodic credentialed vulnerability scans of all high-risk servers, applications, and desktops connected to the campus network and address identified vulnerabilities in a timely manner.

(7)

MANAGEMENT RESPONSE

We concur. Our action plan is to:

a. Perform periodic credentialed vulnerability scans of all high-risk servers, applications, and desktops connected to the campus network and address identified vulnerabilities in a timely manner.

b. Remove or update the servers running obsolete and unsupported operating systems from the network.

The anticipated completion date is September 11, 2015.

5. DESKTOP SOFTWARE MANAGEMENT

OBSERVATION

The campus did not always remove obsolete versions of software and unauthorized software that did not support university business from desktop computers and did not always update browser software.

Inadequate updating of browser software and removal of vulnerable software products and unauthorized software may lead to compromise and potential loss of protected confidential information or inappropriate access to systems.

RECOMMENDATION

We recommend that the campus implement measures to remove unnecessary software and ensure software used on all computers is authorized.

MANAGEMENT RESPONSE

We concur. Our action plan is to implement measures to remove unnecessary software and ensure software used on all computers is authorized. The anticipated completion date is September 11, 2015.

6. WEB APPLICATION DEVELOPMENT

OBSERVATION

Application development and change management was not adequate to ensure accountability for authorized deployment of web development projects.

(8)

 The campus did not have a formal policy to govern system development practices.

 Management approval was not required before projects were placed into production.

 Security criteria and testing procedures were not always documented.

 User acceptance testing was not always documented.

 Developers had the capability to make changes to production versions without authorization.

The campus had a development standard in place; however, the standard did not specifically address security requirements unique to web development. The campus information security office recommended that developers follow security standards set by the Open Web

Application Security Project and the Web Application Security Consortium, but these standards had not been incorporated into the web development lifecycle to ensure security standards were built into the web systems.

The lack of proper software change management and testing procedures increases the risk of unauthorized changes to software, software failure, and security vulnerabilities that could inappropriately expose sensitive data.

RECOMMENDATION

We recommend that the campus:

a. Develop a formal policy to govern system development practices that details security requirements.

b. Require management approval for all web application development before placing projects into production.

c. Document security criteria and testing procedures. d. Document user acceptance testing.

e. Restrict developers’ ability to modify production web applications without prior management approval.

MANAGEMENT RESPONSE

We concur. Our action plan is to:

a. Develop a formal policy to govern system development practices that details security requirements.

(9)

c. Document security criteria and testing procedures. d. Document user acceptance testing.

e. Restrict developers’ ability to modify production web applications without prior management approval.

The anticipated completion date is September 11, 2015.

7. DESKTOP SECURITY MANAGEMENT

OBSERVATION

The campus allowed users to have administrative access to their workstations, which allows disabling of some security controls and installation of unauthorized software.

Administrative level privileges that allow users to disable security controls and install unauthorized applications may violate California State University (CSU) policy and/or expose the campus network to other vulnerabilities.

RECOMMENDATION

We recommend that the campus eliminate administrative access to workstations unless it is specifically approved.

MANAGEMENT RESPONSE

We concur. Our action plan is to eliminate administrative access to workstations unless it is specifically approved. The anticipated completion date is September 11, 2015.

8. INCIDENT REPORTING

OBSERVATION

The process for reporting lost or stolen computers to the information security office needed improvement.

Specifically, we found that the users did not notify the information security office when a computer was lost or stolen, as required by campus procedures, so it could investigate whether sensitive information was present on the computers and whether further action was required. We selected a sample of 15 computers reported as lost or stolen from 2012 to 2014 and found that none of them had been reported to the information security office for

investigation.

(10)

RECOMMENDATION

We recommend that the campus enforce existing procedures to ensure the information security office is notified when computers are lost or stolen.

MANAGEMENT RESPONSE

We concur. Our action plan is to enforce existing procedures to ensure the information security office is notified when computers are lost or stolen. This objective is complete.

9. REVIEW OF SECURITY EVENT LOGS

OBSERVATION

The campus did not have formal procedures for reviewing security event logs of operating systems, servers, and applications.

We noted that the analysis of audit and security event logs were generally informal, undocumented, and performed on an ad-hoc basis, unless formal periodic reviews were required by outside regulation such as the Health Insurance Portability and Accountability Act. Inadequate review of security logs increases the risk that malicious activity could go

undetected or viruses or other malicious code could be embedded within the campus network and its resources, which could lead to confidential information being breached and not

reported.

RECOMMENDATION

We recommend that the campus develop formal procedures for reviewing security event logs of operating systems, servers and applications.

MANAGEMENT RESPONSE

We concur. Our action plan is to develop formal procedures for reviewing security event logs of operating systems, servers, and applications. The anticipated completion date is

September 11, 2015.

10. USER ACCESS PRIVILEGES

OBSERVATION

The process for requesting access to PeopleSoft required improvement.

(11)

The ISO stated that the campus is in the process of remediating this issue with the implementation of an Enterprise Workflow Management system that will streamline the process for people needing access to PeopleSoft modules.

Inadequate administration of user accounts increases the risk of inappropriate access.

RECOMMENDATION

We recommend that the campus ensure that desired security roles are consistently documented on the online information access request forms.

MANAGEMENT RESPONSE

(12)

GENERAL INFORMATION

BACKGROUND

The CSU Information Security Policy, dated April 19, 2010, states that the Board of Trustees of the CSU is responsible for protecting the confidentiality, integrity, and availability of CSU

information assets. Unauthorized modification, deletion, or disclosure of information assets can compromise the mission of the CSU, violate individual privacy rights, and possibly constitute a criminal act. It is the collective responsibility of all users to ensure confidentiality of information that the CSU must protect from unauthorized access; integrity and availability of information stored on or processed by CSU information systems; and compliance with applicable laws, regulations, and CSU/campus policies governing information security and privacy protection. It further states that the CSU Information Security Policy shall apply to the following:

 All campuses.

 Central and departmentally managed campus information assets.

 All users employed by campuses or any other person with access to campus information assets.

 All categories of information, regardless of the medium in which the information asset is held or transmitted (e.g., physical or electronic).

 Information technology facilities, applications, hardware systems, and network resources owned or managed by the CSU.

Auxiliaries, external businesses, and organizations that use campus information assets must also operate those assets in conformity with the CSU Information Security Policy.

The CSU Information Security Policy directs the campus president to appoint an information security officer (ISO) and assign responsibility and authority for administering the information security function.

Information security at CSU campuses covers a broad range of sensitive data that requires protection to be in compliance with numerous state and federal regulations. Campuses collect social security numbers for employee personnel and for student financial aid tax reporting, which is regulated by federal and state law. Other forms of data include student grades and academic records that must be protected under federal privacy laws.

In addition, CSU campuses that have student health centers, psychological counseling centers, and pharmacies may also have medical and prescription records that must be protected under federal health privacy laws.

(13)

At the CSUSB campus, information security is administered by the ISO, who reports to the chief information officer/vice president of information technology services. CSUSB also has an information technology governance committee and information security and emerging technologies committee in place that provide oversight and guidance to the campus on information security issues. Additionally, there are several decentralized IT groups that do not report directly to the campus IT department. As a result, the campus has created IT working groups with other campus departments to helpguide compliance with established CSU and CSUSB information security policies, standards, and procedures.

SCOPE

Our audit and evaluation included the audit tests we considered necessary in determining whether operational, and administrative controls are in place and operative. The audit focused on procedures in effect from August 11, 2014, through September 12, 2014.

Specifically, we reviewed and tested:

 The activities and measures undertaken to protect the confidentiality, integrity, and access and availability of information.

 Processes for identifying confidential, private, or sensitive information; authorizing access; securing information; detecting security breaches; and evaluating security incident reporting and response.

 Measures to limit collection of information, control access to data and assure that individuals with access to data do not utilize the data for unauthorized purposes.

 Encryption of data in storage and transmission.

 Physical and logical security measures for all data repositories.

We also retained outside contractors to perform a technical security assessment that included running diagnostic software designed to identify improper configuration of selected systems, servers, and network devices. The purpose of the technical security assessment was to determine the effectiveness of technology and security controls governing the confidentiality, integrity, and availability of selected campus assets. Specifically, this configuration testing included assessment of the following technologies: selected operating systems, border firewall settings, network traffic analysis, vulnerability scanning, and website vulnerability assessment. As a result of changing conditions and the degree of compliance with procedures, the

effectiveness of controls changes over time. Specific limitations that may hinder the effectiveness of an otherwise adequate system of controls include, but are not limited to, resource constraints, faulty judgments, unintentional errors, circumvention by collusion, and management overrides. Establishing controls that would prevent all these limitations would not be cost-effective; moreover, an audit may not always detect these limitations.

(14)

testing approach was designed to provide a view of the security technologies used to protect only key computing resources. In addition, selected emerging technologies were not included in the scope of this review.

CRITERIA

Our audit was based upon standards as set forth in CSU Board of Trustee policies; Office of the Chancellor policies, letters, and directives; campus procedures; and other sound administrative practices. This audit was conducted in conformance with the Institute of Internal Auditors’

International Standards for the Professional Practice of Internal Auditing.

This review emphasized, but was not limited to, compliance with:

ICSUAM §8000, Information Security

ICSUAM §7000, Identity Management

Government Code §11549.3

International Standards Organization 27001, Information Security Management System

Standard

AUDIT TEAM

References

Related documents

The goal of this paper is to provide a theoretical analysis – for the case of continuous variables – of why and when single-variable models can be more effective in binary choice

– Business & Industry (B&I) Loan Guarantee Program – Rural Energy for America (REAP).. – Revolving Loan Fund (RLF) Programs – Value-Added Producer

A training manual was drawn up to serve as a practical tool to be used by Deputy Head teachers in charge of discipline in their daily tasks (MINEDUC, 2008).This study sought to

Any increase in flow (including both increased loadings and no increased loadings) from industrial treatment works where no change in wastewater service area or discharge type

Delaying the intervention reduces the strategic complementarity from a market recovery, but at the same time allows selling pressure to build up which increases the average quality

Using Survey Data and HEC-RAS Modeling to Assess a Riffle- Using Survey Data and HEC-RAS Modeling to Assess a Riffle- Remediation Structure on the Big River, Bonne Terre, Missouri

The diabetes care assistance system aims to facilitate diabetic patient side on managing daily self-monitoring activities and care manager side in a health service center on

PET-NECK – a multi-centre randomized phase III controlled trial (RCT) comparing PETCT guided active surveillance with planned neck dissection (ND) for locally advanced (N2 /N3)