19.01.2015 Views

Commonwealth of Virginia Single Audit Report for the Year Ended ...

Commonwealth of Virginia Single Audit Report for the Year Ended ...

Commonwealth of Virginia Single Audit Report for the Year Ended ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

11-13: Improve Micros<strong>of</strong>t SQL Server Security<br />

Applicable to: Department <strong>of</strong> Transportation<br />

The <strong>Virginia</strong> Department <strong>of</strong> Transportation (Transportation) does not manage its Micros<strong>of</strong>t<br />

SQL Server 2000 databases to minimize <strong>the</strong> risk <strong>of</strong> malicious or unapproved modification <strong>of</strong> data. A<br />

system <strong>of</strong> internal controls should include capabilities to prevent and detect certain actions to<br />

mission critical and confidential data. Some <strong>of</strong> <strong>the</strong>se controls are recommended by industry best<br />

practices and o<strong>the</strong>rs are necessary to compensate <strong>for</strong> o<strong>the</strong>r weaknesses in an IT environment.<br />

Since our observations include descriptions <strong>of</strong> security mechanisms, which are exempt from<br />

public disclosure by <strong>the</strong> Code <strong>of</strong> <strong>Virginia</strong>, management received a separate document containing a<br />

detailed description <strong>of</strong> our observations. While Transportation had planned to upgrade its legacy<br />

MS SQL Server 2000 environment to address several risks, <strong>the</strong>se plans were delayed due to shifting<br />

priorities and resource limitations. It should be noted that delaying <strong>the</strong>se upgrades limits<br />

Transportation’s ability to adequately safeguard data and establish a proper system <strong>of</strong> internal<br />

controls over <strong>the</strong>se serves.<br />

We recommend that Transportation dedicate <strong>the</strong> necessary resources to execute its plans to<br />

upgrade <strong>the</strong> legacy Micros<strong>of</strong>t SQL Server 2000 databases. At a minimum, Transportation should<br />

consider establishing controls <strong>for</strong> <strong>the</strong> weaknesses previously communicated. We also encourage<br />

Transportation to run Micros<strong>of</strong>t Baseline Security Analyzer periodically to ensure compliance with<br />

best practices, and to document any decisions and compensating controls <strong>for</strong> those instances when<br />

Transportation needs to deviate from best practices.<br />

Management Plan <strong>for</strong> Corrective Action <strong>for</strong> Department <strong>of</strong> Transportation<br />

• SQL Server 2000 databases will be migrated to SQL Server 2008<br />

• SQL Server 2005 and 2008 instances will be reconfigured to provide appropriate<br />

alerts<br />

• The Micros<strong>of</strong>t Baseline Security Analyzer will be used to review <strong>the</strong> security<br />

configuration <strong>of</strong> <strong>the</strong> production SQL Server servers. MBSA reviews a significant<br />

number <strong>of</strong> items, <strong>of</strong> which some may not be actionable in <strong>the</strong> VDOT environment.<br />

MBSA will be run on a periodic basis, an assessment will be made as to which<br />

recommendations should be implemented, and <strong>the</strong>n <strong>the</strong> action taken and date<br />

completed will be documented. MBSA review and action will be done on <strong>the</strong><br />

identified database server. A schedule <strong>for</strong> MBSA review and action <strong>for</strong> <strong>the</strong><br />

remaining production SQL Server databases will be created.<br />

Responsible Party: Pam Tauer, IT Systems Engineering Manager<br />

Estimated Completion Date: Server migration will occur by December 2012, remaining<br />

items will be addressed by April 1, 2012.<br />

25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!