-
3
pages
-
English
-
Documents
Description
ffLEGISLATIVE AUDIT DIVISION Tori Hunthausen, Legislative Auditor Deputy Legislative Auditors:Monica Huyg, Legal Counsel James Gillett Angie Grove MEMORANDUM TO: Legislative Audit Committee Members FROM: Kent Rice, Information Systems Audit Manager DATE: June 2009 CC: Janet R. Kelly, Director, Department of Administration Dick Clark, Chief Information Officer RE: Follow-up IS Audit (09SP-19): State Web Server Security Audit (org. 08DP-02), Department of Administration INTRODUCTION We presented our information systems audit on State Web Server Security at the Department of Administration to the Legislative Audit Committee in January 2008. The report contains two recommendations relating to: Web server and web server application security, responsibilities and policy Rogue server detection We requested and received information from Department of Administration (DOA) personnel regarding progress toward implementation of the report recommendations. This memorandum summarizes DOA’s response and our follow-up work. BACKGROUND A web server is a computer running software (applications) to provide services to other computers and their users. Web server and web server application weaknesses potentially allow a user to gain unauthorized access to website programming or agency data. Additionally, web servers could potentially be put into production without state authorization. Without proper controls, unauthorized access ...
-
Publié par
-
Langue
English