The Register Citizen (Torrington, CT)

DMV officials: Security issues resolved

- By Christine Stuart

HARTFORD — It’s no secret the Department of Motor Vehicles struggled to implement a new computer and licensing system, but the department recently told the Auditors of Public Accounts that they’ve fixed those problems.

The problems were mostly related to security, stemming from the installati­on of a more than $26million computer system that spanned all or part of the tenure of at least four DMV commission­ers. The DMV’s current commission­er, Sibongile Magubane, wasn’t appointed until April 2019, months after the audit was completed.

The DMV contracted with Science Applicatio­ns Internatio­nal Corporatio­n in 2009 to develop the Connecticu­t Integrated Vehicle and Licensing System. SAIC later assigned the contract to 3M Corporatio­n, which worked on the project until 2016 when the DMV terminated the contract.

The new system was part of a larger plan to modernize DMV operations to improve the department’s overall business and administra­tive processes, but the Auditors of Public Accounts found several problems with the way that plan was implemente­d.

From overly optimistic project milestones to project management turnover, and the vendor’s lack of understand­ing of the complexity and scope of the project, it appears that it got off to a bad start, according to the auditors.

One of the problems highlighte­d by the auditors in a report released last week involved password security for employees who worked on the system.

At the time the auditors were testing the password policy, only 125 of 800 DMV employees had user accounts with the stricter password policy.

“This policy has been addressed. An industryst­andard password policy has been implemente­d,” the DMV stated.

The DMV also failed to maintain the level of user access to certain accounts.

“DMV lacks control over inappropri­ate access levels being issued to and removed from users,” the auditors found. “The department lacks the ability to determine when users are added to or removed from groups, or even enabled and disabled.”

The department said that issue has been addressed.

The auditors also found that new accounts can be created without detection.

“Additional­ly, intruders typically create backdoor accounts, and some malware is specifical­ly programmed for that purpose,” the auditors warned.

The DMV said both problems have been addressed.

“This finding has been addressed. A procedure has been completed regarding the configurat­ion of new, promoted/demoted, and terminated employees. The procedure also addresses the monitoring of audit log reports,” the DMV said in response to the audit.

But the auditors have been unable to test the new policy.

“DMV recently provided our office with a report displaying disabled accounts, but it did not include all of the required tracking functional­ity. We will test the policy during our next audit,” the auditors stated in the report.

Without much detail due to security concerns, the auditors also pointed out the problems with password protection.

The auditors recommende­d the DMV take steps to properly implement secure authentica­tion controls.

“This finding is currently being addressed, with a project plan in place to ensure appropriat­e password encryption standards are implemente­d by 2021,” the DMV stated.

The auditors found that the department does not have documentat­ion of a personnel security policy and procedure. That means there’s a risk that the related security controls and control enhancemen­ts may not be effectivel­y implemente­d. The auditors said the DMV had not prioritize­d it.

“This finding is currently being addressed, with a plan in place to create written policy & procedures regarding personnel access with a target completion in December 2019,” the DMV stated.

The system also fails to disable inactive accounts, which may allow some users unnecessar­y access to the system. DMV uses Microsoft to manage user accounts, which is not configured to automatica­lly disable user accounts after a defined period of inactivity.

The DMV again said the finding “has been addressed. Dormant accounts are monitored and deactivate­d when necessary.”

The auditors also found that between Jan. 1, 2015, and Jan. 18, 2017, there were 58 instances in which an employee was terminated but the user account had not been deactivate­d at the time of testing on Jan. 19, 2017.

“This finding has been addressed. A procedure has been implemente­d to disable terminated employee accounts within one business day,” the DMV stated.

The new policies the DMV said it implemente­d might be tested as part of the DMV’s regular audit, but that has yet to be determined.

 ?? Erik Trautmann / Hearst Connecticu­t Media ?? The state Department of Motor Vehicles said it has addressed security issues raised in an auditor’s report released last week.
Erik Trautmann / Hearst Connecticu­t Media The state Department of Motor Vehicles said it has addressed security issues raised in an auditor’s report released last week.

Newspapers in English

Newspapers from United States