Variaciones sostenidas ±0.6'¼ Variaciones súbitas ±1.0Hertz
TENSIONES MAXIMAS Y MINIMAS (VOLTIOS)
6.13 Verificación de Tableros de Distribución
State information security experts and auditors have identified critical weaknesses in ASDB’s IT environment. These weaknesses have persisted for several years. In 2009, ASDB engaged ADOA’s Information Security group to assess ASDB’s information technology environment. The resulting report identified several gaps between the existing state of ASDB’s IT environment and best practices and made recommendations for how ASDB should address the deficiencies. The report also found that ASDB’s IT department had received little strategic direction or oversight from ASDB management.
Although ASDB has made some efforts to address the weaknesses ADOA identified, auditors found that critical IT weaknesses still exist. Specifically, auditors found that ASDB’s IT security controls are weak, its disaster recovery planning is inadequate, its data backup strategy is flawed, and it has no data classification process to help ensure that the information it maintains is sufficiently protected. ASDB officials stated that the IT department lacks the
Although the Arizona State Schools for the Deaf and the Blind (ASDB) has made some improvements to its information technology (IT) practices since the Arizona Department of
Administration (ADOA) assessed those practices in 2009, several additional improvements are needed to help ensure that student and school information is properly safeguarded. Specifically, auditors found that continued weaknesses have led to critical
vulnerabilities in several IT areas. These include IT security management, disaster recovery, and data backup. ASDB should first prioritize and then correct these IT weaknesses to minimize the impact these vulnerabilities and security threats could have on its operations.
staff and resources necessary to address all of ASDB’s IT issues and needs. As a consequence, it has not prioritized addressing the recommendations made in ADOA’s report, which has contributed to the lack of progress in addressing and resolving weaknesses. In October 2011, the department had turnover in a key position when ASDB’s IT Director left. At that time, the existing IT security specialist was made the interim IT Director but also retained his responsibilities for security. As of June 2012, ASDB had still not appointed a permanent IT Director.
IT security controls are weak—
ASDB’s controls over IT security are weak, and its systems are susceptible to attack. According to IT standards and best practices, effective security management helps protect IT assets and minimizes the impact that security vulnerabilities and incidents could have on IT operations. Security monitoring is also essential to help ASDB comply with federal laws and regulations designed to protect sensitive information, financial aid records, and health information. Despite the critical importance of effective IT security management, auditors found weaknesses in several key areas, including ASDB’s efforts to assess risk and monitor its systems, secure its networks from attacks, and deploy updates and patches on computers and servers. Specifically:•
Failure to assess risk and adequately monitor systems—ASDB’s IT Department does not perform regular risk assessments or security reviews of ASDB’s IT environment, which can cause ASDB to be unaware of potential threats that may exist within its IT environment. For example, threats such as potential loss of data, unauthorized access to systems, and disruption of services, can be identified through an effective risk assessment process. Risk assessments are also used to help determine the controls needed to reduce the risk associated with those types of threats. IT standards and best practices state that critical business applications, computer installations, networks, and systems should be subject to risk analysis on a regular basis.In addition, ASDB’s monitoring activities are insufficient. Although ASDB has several software applications for logging information about the status, performance, and utilization of servers and networks, it does not have specific procedures or responsibilities defined for who should review events or how it uses and follows up on the information it collects. Further, ASDB does not perform any logging or monitoring of its network to identify specific events, such as intrusions or attacks. As a result, network security scans performed by auditors found that ASDB had not detected an attack on a computer at the Phoenix Day School for the Deaf (see textbox). IT standards and best practices state that a logging and monitoring function will enable the early prevention and/or detection and subsequent timely reporting of unusual and/or abnormal activities.
t
Hacker attack and virus were undetected
ASDB did not identify a computer at the Phoenix Day School for the Deaf that had already been hacked by an unknown attacker. The computer also contained a persistent virus infection, and an unauthorized backdoor account had been created—an account that allows a hacker access to the system. ASDB became aware of this issue only after auditors brought it to ASDB’s attention, after which ASDB acted to remove the computer from its network and repair it.
Source: Network security scans performed and analyzed by Auditor General staff. Auditors found weaknesses
in several key areas, including ASDB’s efforts to assess risk and monitor its systems, secure its networks from attacks, and deploy updates and patches on computers and servers.
•
Inadequate network controls—ASDB’s IT network does not have adequate controls to secure it from outside attacks. According to IT standards and best practices, organizations should implement security techniques and management procedures to control access to and information available within its computer networks. Auditors found, however, that ASDB, in an effort to utilize assistive technology for some of its students, configured one part of its network using outdated controls that are known to be susceptible to attack. As a result, auditors were able to compromise these controls and obtain unauthorized access to the school’s network. This access provided auditors with the ability to identify and take advantage of additional vulnerabilities (see textbox).•
Poor patch and vulnerability management—ASDB lacks an effective process for deploying updates on computers and servers and is running some critical systems on outdated software. Hardware and software vendors periodically issue updates, or patches, to their products to correct security vulnerabilities and other bugs and to improve usability and performance. The process of reviewing updates, establishing a plan to apply them, and applying them as appropriate is called patch management. Failure to apply updates in a timely manner may leave systems susceptible to known vulnerabilities. Auditors’ scan of ASDB’s network identified numerous critical vulnerabilities on computers and servers because updates had not been applied to these devices. Through further test work, auditors were able to exploit some of these vulnerabilities and gain unauthorized access to sensitive information as discussed above. IT standards and best practices indicate that organizations should have a systematic, accountable, and documented process for managing exposure to vulnerabilities through the timely deployment of patches.In addition, auditors found that ASDB has critical systems running on versions of software that are no longer fully supported by the vendor. Security risks are higher when systems are using unsupported software because the vendor will no longer release patches or updates to their software to address potential vulnerabilities. As a result, vulnerabilities are not corrected and may be more likely to be exploited.