19.01.2015 Views

Commonwealth of Virginia Single Audit Report for the Year Ended ...

Commonwealth of Virginia Single Audit Report for the Year Ended ...

Commonwealth of Virginia Single Audit Report for the Year Ended ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

We recommend that DMV dedicate <strong>the</strong> necessary resources to implement controls that<br />

address <strong>the</strong> weaknesses noted above. Specifically, we recommend that DMV use automated controls<br />

on all its privileged accounts to reduce <strong>the</strong> risk <strong>of</strong> unauthorized access.<br />

We also recommend that DMV reviews <strong>the</strong> privileges granted to database roles to ensure<br />

appropriate access to data. Finally, we recommend that DMV log and review account activity to<br />

detect any fraudulent activity and <strong>the</strong> ability to trace unauthorized activity in <strong>the</strong> database<br />

management system and its tables. Someone outside <strong>the</strong> database administrator group should<br />

per<strong>for</strong>m <strong>the</strong>se reviews.<br />

Management Plan <strong>for</strong> Corrective Action <strong>for</strong> Department <strong>of</strong> Motor Vehicles #1<br />

DMV will dedicate <strong>the</strong> necessary resources to implement controls that address <strong>the</strong><br />

weaknesses identified.<br />

DMV will move towards using automated controls on its privileged accounts to<br />

reduce <strong>the</strong> risk <strong>of</strong> unauthorized access.<br />

Responsible Party: Douglas Mack, DMV IT Security Director (ISO) Dave Burhop,<br />

DMV Deputy Commissioner (CIO)<br />

Estimated Completion Date: August 31, 2012<br />

Management Plan <strong>for</strong> Corrective Action <strong>for</strong> Department <strong>of</strong> Motor Vehicles #2<br />

DMV will review <strong>the</strong> privileges granted to database roles to ensure appropriate<br />

access to data.<br />

Responsible Party: Douglas Mack, DMV IT Security Director (ISO) Dave Burhop,<br />

DMV Deputy Commissioner (CIO)<br />

Estimated Completion Date: August 31, 2012<br />

Management Plan <strong>for</strong> Corrective Action <strong>for</strong> Department <strong>of</strong> Motor Vehicles #3<br />

DMV will log and review account activity to detect any fraudulent activity and to<br />

have <strong>the</strong> ability to trace unauthorized activity in <strong>the</strong> database management system<br />

and its tables.<br />

DMV will have a person outside <strong>of</strong> <strong>the</strong> database administrator group to per<strong>for</strong>m <strong>the</strong><br />

reviews.<br />

Responsible Party: Douglas Mack, DMV IT Security Director (ISO)Dave Burhop,<br />

DMV Deputy Commissioner (CIO)<br />

Estimated Completion Date: August 31, 2012<br />

24

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!