Skip to Content

Audit: State agency lacks basic cybersecurity safeguards

KTVZ

The Oregon Department of Administrative Services lacks basic cybersecurity safeguards, according to an audit report released Wednesday by Secretary of State Bev Clarno.

“The security of Oregon’s data is a serious issue,” Clarno said. “DAS should take immediate action to address the findings outlined in this report.”

Auditors concluded the agency does not have a security management program that identifies necessary actions to ensure systems are appropriately secure and lacks basic foundational cybersecurity safeguards.

This is due in large part to a fragmented organizational and governance structure, as well as numerous legacy applications within various business units.

Additionally, they said, the DAS CIO (chief information officer) role lacks appropriate functional authority and staffing to carry out its official responsibilities and ensure consistent controls across these units. As a result, DAS systems and data may be at risk for unauthorized use, disclosure, or modification.

Read the full audit on the Secretary of State website.

Article Topic Follows: News

Jump to comments ↓

KTVZ News Team

BE PART OF THE CONVERSATION

KTVZ NewsChannel 21 is committed to providing a forum for civil and constructive conversation.

Please keep your comments respectful and relevant. You can review our Community Guidelines by clicking here

If you would like to share a story idea, please submit it here.

Skip to content