State comptroller reviews Eastchester school district IT

Facebook
Twitter
LinkedIn
Email
Print

ALBANY – District officials in the Eastchester Union Free School District officials did not establish adequate controls over user accounts to help prevent unauthorized use, access and loss nor did they establish an adequate IT contingency plan, according to an audit by the state comptroller’s office.

Sensitive IT control weaknesses were also communicated confidentially to officials.

Officials did not:

  • Develop comprehensive procedures for managing network and financial application user accounts nor did they periodically review all network user accounts and permissions to determine if they needed to be disabled. As a result, auditors identified the following unneeded network user accounts:
  • 181 for students no longer in the district. These students left the district between June 2020 and August 2021.
  • Six former employees, two former board members and two former interns. These users left District employment between 2016 and 2021.
  • Adopt a comprehensive IT contingency plan to minimize the risk of data loss or prevent a serious interruption of services.

Recommendations includes developing written procedures for managing network and financial application user accounts; developing, adopting, distributing and periodically reviewing and testing a comprehensive IT contingency plan.

District officials agreed with our findings and indicated they are initiating corrective action.