Organization: | Office of the State Auditor |
---|---|
Date published: | November 8, 2024 |
Executive Summary
In accordance with Section 12 of Chapter 11 of the Massachusetts General Laws, the Office of the State Auditor has conducted a performance audit of the Executive Office of Technology Services and Security (EOTSS), as well as 22 other executive branch agencies, state colleges and universities, and regional transit authorities. This audit covers the period July 1, 2021 through April 30, 2023 and includes the following agencies:
Executive Branch Agencies | State Colleges and Universities | Regional Transit Authorities |
---|---|---|
Executive Office of Technology Services and Security (EOTSS) | Framingham State University (FSU) | Cape Ann Transportation Authority (CATA) |
Bureau of the State House (BSH) | Holyoke Community College (HCC) | Cape Cod Regional Transit Authority (CCRTA) |
Civil Service Commission (CSC) | Massachusetts Bay Community College (MBCC) | Martha’s Vineyard Regional Transit Authority (VTA) |
Department of Labor Standards (DLS) | Massasoit Community College (MCC) | Nantucket Regional Transit Authority (NRTA) |
Department of Mental Health (DMH) | North Shore Community College (NSCC) | |
Department of Public Health (DPH) | Northern Essex Community College (NECC) | |
Department of Revenue (DOR) | Westfield State University (WSU) | |
Massachusetts Department of Transportation (MassDOT) | ||
Group Insurance Commission (GIC) | ||
Massachusetts Parole Board (MPB) | ||
Registry of Motor Vehicles (RMV) | ||
State 911 Department (911) |
The purpose of our audit was to determine whether EOTSS and the above executive branch agencies, state colleges and universities, and regional transit authorities ensured that their employees completed cybersecurity awareness training in accordance with Sections 6.2.3 and 6.2.4 of EOTSS’s Information Security Risk Management Standard IS.010.
Below is a summary of our findings, the effects of those finds, and our recommendations, with links to each page listed.
Finding 1 | EOTSS did not ensure that all of its employees completed cybersecurity awareness training. |
Effect | If EOTSS does not ensure that all of its employees complete cybersecurity awareness training, then EOTSS may expose itself to an increased risk of cybersecurity attacks and financial and/or reputational losses. |
Recommendations |
|
Finding 2 | CSC, DLS, DMH, DPH, DOR, MassDOT, GIC, MPB, and RMV did not ensure that all of their employees completed cybersecurity awareness training. |
Effect | If executive branch agencies do not ensure that all of their employees complete cybersecurity awareness training, then they may expose themselves to an increased risk of cybersecurity attacks and financial and/or reputational losses. |
Recommendation |
|
Finding 3 | Seven state colleges and universities did not ensure that all of their employees completed cybersecurity awareness training. |
Effect | If state colleges and universities do not ensure that all of their employees complete cybersecurity awareness training, then they may expose themselves to an increased risk of cybersecurity attacks and financial and/or reputational losses. |
Recommendations |
|
Finding 4 | CATA, CCRTA, and VTA did not ensure that all of their employees completed cybersecurity awareness training. |
Effect | If regional transit authorities do not ensure that all of their employees complete cybersecurity awareness training, then they may expose themselves to an increased risk of cybersecurity attacks and financial and/or reputational losses. |
Recommendations |
|
Table of Contents
Downloads
Contact
Phone
Online
Fax
Address
Room 230
Boston, MA 02133