MassHire Department of Career Services - Finding 5

The MassHire Department of Career Services did not perform a business impact analysis or risk assessment to classify its information systems.

Table of Contents

Overview

MDCS management revealed to us in interviews that they did not perform a business impact analysis or risk assessment to classify their information systems. Information systems should be classified as low, medium, high, or critical, depending on the use of the system and the information it contains.

Without a business impact analysis or risk assessment to classify information systems, the criticality of systems will not be assessed based on the sensitivity of the information stored within them. If vital systems are not classified correctly, then they cannot be protected correctly, whether from cybersecurity threats, natural disasters, or fraud. As a result, MDCS could face challenges in planning for these potential disruptions and may not be able to prioritize information technology (IT) resources effectively in the event of an emergency.

Authoritative Guidance

EOTSS’s Asset Management Standard IS.004 states,

6.6.2   Commonwealth Agencies and Offices must conduct a business impact analysis or a risk assessment to determine information system classifications for their information assets.

Reasons for Issue

MDCS management stated that they have classified the information system but have yet to document it anywhere or conduct a business impact analysis or risk assessment corresponding to it. Additionally, the system has not been reclassified in 5 to 10 years because there have not been any significant changes. MDCS management stated that they do conduct risk assessments, but that these are related to fiscal areas and not IT systems.

Recommendations

  1. MDCS management should implement a policy to periodically conduct a business impact analysis or risk assessment in order to classify its information systems.
  2. MDCS should review these classifications at least annually or anytime a significant system change occurs.

Auditee’s Response

See response 4. MDCS will continue to partner with EOLWD to implement the required recommendations to ensure full compliance. This will include a related business impact analysis and risk assessment.

Auditor’s Reply

Based on its response, MDCS is taking measures to address our concerns regarding this matter.

Date published: May 27, 2025

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback