19.01.2015 Views

Commonwealth of Virginia Single Audit Report for the Year Ended ...

Commonwealth of Virginia Single Audit Report for the Year Ended ...

Commonwealth of Virginia Single Audit Report for the Year Ended ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Responsible Party: Douglas Mack, DMV IT Security Director (ISO) Dave Burhop,<br />

DMV Deputy Commissioner (CIO)<br />

Estimated Completion Date: September 30, 2012<br />

Management Plan <strong>for</strong> Corrective Action <strong>for</strong> Department <strong>of</strong> Motor Vehicles #4<br />

The new DMV IT Security Policy will include a requirement <strong>for</strong> an annual review and<br />

assessment <strong>of</strong> <strong>the</strong> DMV IT Security Policy in light <strong>of</strong> new requirements or changes in<br />

internal/external requirements.<br />

The annual review and assessment will take place between July 1 and July 31 <strong>of</strong> each<br />

year.<br />

The new DMV IT Security Policy will also include a requirement <strong>for</strong> <strong>the</strong> DMV IT<br />

Security Director (ISO) to be aware <strong>of</strong> <strong>Commonwealth</strong> changes through active<br />

participation in <strong>Commonwealth</strong> IT security groups, etc., including <strong>the</strong> In<strong>for</strong>mation<br />

Security Officers Advisory Group.<br />

Responsible Party: Douglas Mack, DMV IT Security Director (ISO) Dave Burhop,<br />

DMV Deputy Commissioner (CIO)<br />

Estimated Completion Date: September 30, 2012<br />

Management Plan <strong>for</strong> Corrective Action <strong>for</strong> Department <strong>of</strong> Motor Vehicles #5<br />

DMV will correct <strong>the</strong> current situation identified in <strong>the</strong> previously referenced<br />

separate document containing a detailed description <strong>of</strong> <strong>the</strong> recommendations.<br />

DMV has taken <strong>the</strong> steps necessary to ensure that all but 11 employees have<br />

completed <strong>the</strong> required IT Security Awareness Training. Of those 11 employees, two<br />

are temporarily excused from <strong>the</strong> requirement due to being out on medical leave.<br />

The steps taken included <strong>the</strong> sanction <strong>of</strong> having one’s account disabled if <strong>the</strong> training<br />

was not completed by <strong>the</strong> specified deadline.<br />

The situation with contractors taking <strong>the</strong> training has not been resolved yet due to<br />

having incomplete in<strong>for</strong>mation. This will be addressed and followed up on.<br />

Responsible Party: Douglas Mack, DMV IT Security Director (ISO) Dave Burhop,<br />

DMV Deputy Commissioner (CIO)<br />

Estimated Completion Date:<br />

Employee Training – January 31, 2012Contractor<br />

Training – August 31, 2012<br />

17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!