HomeMy WebLinkAboutCOM 0261.000 2020-2022 Maxinne Pacheco • •
-
Acting County Auditor14,c
•
Business Address
ef:: . t:P• 120 Pauahi Street
4TE oF'e►ra Suite 309
Hilo, Hawaii 96720
CCouttfu of Ittfilai %
OFFICE OF THE COUNTY AUDITOR
25 Aupuni Street Hilo, Hawaii 96720 • (808)961-8386 • Fax(808)961-8905
website:http:;ihawaiicounty.gov e-mail:countvauditora,hawaiicountv.gov ,
May 20, 2021 �a -
Honorable Maile Mederios David, Council Chair
and Members of the Hawaii County Council
Hawaii County Council
25 Aupuni Street
Hilo, Hawaii 96720
Dear Chair David and Council Members,
In accordance with generally accepted government auditing standards and the Hawaii
County Charter Section 3-18(d)(3), the Office of the County Auditor has a responsibility
to monitor and follow-up on audit recommendations to ensure that audit findings are
being addressed through appropriate corrective action and to aid us in planning future
audits.
We have completed our follow-up audit of the County of Hawaii Information Technology
Asset Management (Report No. 2015-01) dated November 12, 2015. The audit
objective was to determine if the Department of Information Technology implemented
the 2015 IT Asset Management recommendations. We tested eleven recommendations
and found that management took corrective action as follows:
Status of Recommendations:
Implemented In Process Not Implemented
4 6 1
Department has fully Department started or has Department has not begun
implemented the audit partially implemented the implementation of the
recommendation. audit recommendation. recommendation.
Currently, the Department of Information Technology (DIT) does not own or manage all
the County's IT assets. To fully meet best practices, IT asset management should be
centralized, DIT should own all IT assets, and use an IT asset management role. WI
Comm. N
Ref. To:
Hawaii County is an Equal Opportunity Provider and Employer MAY 2 4 2021
Ref. Date X11
These are key elements to successful management of IT assets and without these
elements, the County is at an increased risk of security concerns, system instability,
helpdesk, and County employee inefficiencies, as well as increased hardware and
software costs.
Management has generally agreed with the comments and the status of recommendations
in this report.
We would like to express our sincere appreciation and commend the Department of
Information Technology's leadership and staff for their continued efforts to improve
information technology asset management and for their assistance, cooperation, and
prompt feedback during the follow-up audit process.
If you have any questions or concerns about the status of recommendations discussed,
please feel free to contact me at 961-8386.
Respectfully,
Maxinne Pacheco
Acting County Auditor
cc: Mitchell D. Roth, Mayor
Lee Lord, Managing Director
Jon Henricks, County Clerk
Scott Uehara, Director, Department of Information Technology
Deanna Sako, Finance Director
Follow-up
Audit
Report County of Hawaii
Information Technology
Asset Management
May 20, 2021
1 WIRWIIIIII ' 141.111 ,
/' r:,�,- --•
Yi Vi 1 1'. ir ir. ---.:s_ 1 . ,
V t\
VOJ � l„ Hq�9'y ,t =
•
vi
County of Hawai`i '..
Office of the County
Auditor
Maxinne Pacheco
Acting County Auditor 41:1- ti--
/• Business Address
120 Pauahi Street
OF Nj: Suite 309
Hilo, Hawaii 96720
(i uttfvr f Pail i`Y
OFFICE OF THE COUNTY AUDITOR
25 Aupuni Street Hilo, Hawaii 96720 • (808)96/-8386 • Fax(808)961-8905
website:http://hawaiicountv.gor e-mail:cowvvauditorWlawaiicountr.gor
May 20, 2021
Honorable Maile Mederios David, Council Chair
and Members of the Hawaii County Council
Hawaii County Council
25 Aupuni Street
Hilo, Hawaii 96720
Dear Chair David and Council Members,
In accordance with generally accepted government auditing standards and the Hawaii
County Charter Section 3-18(d)(3), the Office of the County Auditor has a responsibility
to monitor and follow-up on audit recommendations to ensure that audit findings are
being addressed through appropriate corrective action and to aid us in planning future
audits.
We have completed our follow-up audit of the County of Hawaii Information Technology
Asset Management (Report No. 2015-01) dated November 12, 2015. The audit
objective was to determine if the Department of Information Technology implemented
the 2015 IT Asset Management recommendations. We tested eleven recommendations
and found that management took corrective action as follows:
Status of Recommendations:
Implemented In Process Not Implemented
4 6 1
Department has fully Department started or has Department has not begun
implemented the audit partially implemented the implementation of the
recommendation. audit recommendation. recommendation.
Currently, the Department of Information Technology (DIT) does not own or manage all
the County's IT assets. To fully meet best practices, IT asset management should be
centralized, DIT should own all IT assets, and use an IT asset management role.
Hawaii County is an Equal Opportunity Provider and Employer
These are key elements to successful management of IT assets and without these
elements, the County is at an increased risk of security concerns, system instability,
helpdesk, and County employee inefficiencies, as well as increased hardware and
software costs.
Management has generally agreed with the comments and the status of recommendations
in this report.
We would like to express our sincere appreciation and commend the Department of
Information Technology's leadership and staff for their continued efforts to improve
information technology asset management and for their assistance, cooperation, and
prompt feedback during the follow-up audit process.
If you have any questions or concerns about the status of recommendations discussed,
please feel free to contact me at 961-8386.
Respectfully,
Maxinne Pacheco
Acting County Auditor
cc: Mitchell D. Roth, Mayor
Lee Lord, Managing Director
Jon Henricks, County Clerk
Scott Uehara, Director, Department of Information Technology
Deanna Sako, Finance Director
Report Highlights May 20, 2021
County of Hawaii Information Technology
Asset Management Follow-Up
Original Audit Follow-Up Audit
What we found In November of 2015, the Office of the County Auditor
Two key elements of IT asset management issued the audit of the County of Hawaii Information
are the centralization of the IT function and Technology Asset Management and made eleven
the use of an IT asset management role. recommendations.
Without these two elements, the County is at
an increased risk of security concerns, system Management generally agreed with the comments
instability, and helpdesk inefficiencies. and status of recommendations.
What we recommended Objective
We identified the following recommendations To determine if the Department of Information
for management to meet best practices: Technology implemented the 2015 IT asset
1. DIT should own all IT assets. Furthermore, management recommendations.
an IT asset management role should be
established to manage the County's IT Status of Recommendations
assets including: We tested eleven recommendations and found that
• Developing a financial forecast of management took corrective action as follows:
hardware and software upgrades and
replacements; • Implemented: 4
• Maintaining an approved software list • In Process: 6
for standardization; • Not Implemented: 1
• Identifying re-deployable IT assets;
• Continuing to evaluate leasing as an Hardware & Software Lifecycle Management
option; • Upgrades & Replacements: (1) In Process
• Maintaining a listing of IT assets and
• Purchase Request & Approval:
the assigned users in a centralized (1) In Process and (1) Implemented
database; • Redeployment of Assets: (1) In Process
• Centrally receiving and accepting all • Leasing: (1) Implemented
IT assets; Hardware & Software Inventory Management
• Reconciling IT assets in the IT asset
management inventory; and • Centralized Management System:
Ensuring the disposal of IT assets (1) Implemented and (1) In Process
• • Receiving & Accepting: (1) In Process
occurs in a secured manner.
2. The County should address gaps in formal • Annual Physical Inventory: (1) Not Implemented
written policies and procedures over IT Hardware & Software Security
practices.
• Secured Disposal: (1) In Process and (1) Implemented
This audit was conducted in accordance with generally accepted government auditing standards.
Table of Contents
Status of Recommendations 1
Hardware and Software Lifecycle Management
1. Upgrades and Replacements 1
2. Purchase Request and Approval 3
3. Redeployment of Assets 4
4. Leasing 5
Hardware and Software Inventory Management
5. Centralized Management System 6
6. Receiving and Accepting 8
7. Annual Physical Inventory 9
Hardware and Software Security
8. Secured Disposal 10
Audit Objective 11
Audit Scope and Methodology 11
Conclusion 13
Department Response 14
Status of Recommendations
Recommendation Auditee Action Status
Hardware and Software Lifecycle Management
1. Upgrades and Replacements
We recommend that DIT In September 2019, DIT developed a plan In Process
establish an IT asset manager Ito deploy 310 computers and/or laptops.
position to manage the County's Due to the COVID-19 pandemic,
IT assets and implement a plan deployment is ongoing.
to develop a one through five-
year financial forecast of In November 2020, we discussed the
hardware and software upgrades status of recommendations with the
replacements for each of the
and
current and incomingDIT Director. We
departments by analyzing the worked with the incoming administration
historical information on the Ito provide a written response to be
County's IT environment, current included in this report.
trends, and future needs. We reviewed the supplemental budget
While the County has requests and found the IT asset manager
implemented several procedures position was not established. In January
to better manage IT assets, to 2021 , the new DIT Director stated in his
fully meet industry best practices new role he has discretion to realign
and improve the process of duties to close gaps in certain processes
upgrading and replacing by dividing up work between DIT
computers and laptops, the IT sections. He further affirmed he has a
asset manager should goal of developing a five-year hardware
implement a plan to take and software upgrade and replacement
ownership of all IT assets. schedule to address this audit
recommendation.
Additionally, in July 2020, we reviewed a
contract authorizing the development of an
IT Strategic Plan and Roadmap with the
State of Hawaii, Office of Enterprise
Technology and the United States
Department of Defense, Office of
Homeland Security.
of Recommendations 1
IT Asset Management Follow-up Audit Status �
DIT attended a series of workshops to
learn:
• IT Strategy
o Assess the current state of IT and
compare it to the desired future
state;
o Create a roadmap of IT initiatives
that will bring IT to the level needed
to achieve its goals and fulfill its
role to support business objectives;
and
o Establish a strategic roadmap for
the next 2-3 years.
• Information Security
• Disaster Recovery Planning
To fully meet best practices, management
should prioritize establishing an IT asset
manager or equivalent to manage all
County-owned IT assets and develop a
one through five-year financial forecast of
upgrades and replacements for each of
the departments by analyzing the historical
information on the County's IT
environment, current trends, and future
needs as part of their IT Strategic Plan and
Roadmap.
I, II
IT Asset Management Follow-up Audit Status of Recommendations 12
2. Purchase Request and
Approval
We recommend DIT implement We reviewed 137 approved and In Process
a policy to maintain an approved disapproved software listings and found
software listing and DIT has a process of maintaining an
communicate the risks to the approved software listing and
departments. The policy should communicates the risk in their Hawaii
include an annual review of the County Security Handbook that provides
listing to ensure that software guidance on, 'What you need to know to
listed is still relevant and does stay safe while computing, and help
not pose a security concern to protect the County's IT assets."
the County. A review process
should be implemented to To fully meet best practices, DIT should
respond to requests for software address current software approval
titles that are not currently in the processes including an annual review in
supported software listing. DIT Employee Policies.
We also recommend DIT We reviewed DIT Employee Policies' Implemented
update the County-Issued Electronic Resources Policy(March 2020)
Technology Device policy to prohibiting:
include prohibiting users from
installing non-supported • "Engaging in disruptive or
software and adding un- malicious activities such as
n
unauthorized software, hardware,
approved devices to the County
network. or data modification."
• "Installing or downloading software
not approved and/or licensed to
the County."
IT Asset Management Follow-up Audit Status of Recommendations 13
3. Redeployment of Assets
We recommend that once the We reviewed 426 equipment transfer In Process
IT asset manager position has records and found DIT partially meets best
been established, DIT should practices because they:
implement a process to identify
redeployable assets and to • Identify and tag usable hardware and
establish County-wide formal software through department transfers
written redeployment procedures and helpdesk ticket requests.
to retrieve computers and
software licenses that were • Redeploy local or cloud-based
installed on computers that were software licenses (Microsoft/Adobe)
replaced or idle for an extended when computers become inoperable,
period of time. The or user separates from the County.
redeployment of computers and
software licenses is often cost- • Identify computers and laptops that
effective, minimizes could be redeployed because of
unnecessary purchases, County-wide computer upgrade and
reduces over purchasing of replacement initiatives.
assets and reduces data security • Track equipment on loan with an
risks. In/Out log.
Items ta• •ed for rede•lo ment To fully meet best practices, DIT should
trgi•AI,m address current redeployment processes
r o if including establishing a County-wide formal
•a written redeployment procedures to retrieve
A
' .ilk_ computers and software licenses that were
2;4 ,�*
= installed on computers that were replaced
or idle for an extended period of time in DIT
4•,
== ,fEmployee Policies.
E
In January 2021, the new DIT Director
... _ stated they will redeploy usable IT assets
Figure within the three to five-year warranty
Photo courtesy period.
Office of the County Auditor
IT Asset Management Follow-up Audit Status of Recommendations 14
4. Leasing
We recommend DIT continue We verified a contract authorizing a five- Implemented
to evaluate leasing as an option year lease for 310 computers and/or
to procure computers and laptops.
software licenses for the
County. We also reviewed yearly subscriptions for
software licenses for:
• Adobe VIP (Value Incentive
Program)
• Adobe Sign
• Microsoft
• ESRI (software mapping)
IT Asset Management Follow-up Audit Status of Recommendations 15
Hardware and Software Inventory Management
5. Centralized Management
System
We recommend DIT track users We observed Lansweeper, an automated Implemented
in a centralized database. Not software program used to monitor asset
tracking users in a centralized data information, network security,
database may increase the software updates, and patches for:
County's security exposure since
DIT may not be able to determine • 1 ,408 users
if computers are in use or locate
•
assets. In addition, DIT may 1,449 devices
have difficulty holding employees • Flagging computers/devices not
accountable for the protection of
seen in the network in the last
assets and inappropriate 30/60/90 days
activities. Unused computers are
candidates for redeployment and • Flagging users' access upon
may unnecessarily consume separation from the County every
software licenses. From a two weeks
software compliance perspective,
software end-user licensing • Flagging and redeploying local or
agreements can be tied to users cloud-based software licenses
instead of computers, and DIT (Microsoft/Adobe) when
may not be able to determine the computers become inoperable, or
appropriate license counts user separates from the County
without knowing the assigned
users. • Blocking at-risk devices from the
network
The fixed assets inventory
system is not accessible to DIT • Pushing out security updates and
and the automated network and patches
software inventory system is not
• Reporting discrepancies to
used to track the user.
department IT liaisons
• Restricting most user's
administrative rights.
IT Asset Management Follow-up Audit Status of Recommendations 16
Therefore, we recommend that We observed DIT staff using In Process
once the IT asset manager Lansweeper to track asset data
position is established, DIT information for over 1400 users and
should implement a plan to devices connecting to the network to
identify a centralized database ensure the network is safe.
that has the ability to track users
whether it is the fixed assets To fully meet best practices, the IT asset
inventory system, the automated manager should implement County-wide
network and software inventory written procedures to centrally track
system, or another IT asset users for all IT assets in applicable DIT
management inventory system. Employee Policies and/or IT Strategic
After a product has been Plan and Roadmap.
identified, the IT asset manager
should implement County-wide
written procedures to centrally
track users for all IT assets.
IT Asset Management Follow-up Audit Status of Recommendations 17
6. Receiving and Accepting
We recommend DIT implement DIT centrally receives and accepts most In Process
a plan to centrally receive and IT assets only during County-wide
accept all IT assets to ensure computer upgrade and replacement
DIT is aware of new computers initiatives/Refresh (January 2015 and
or software before they are
introduced into the County 2020).
environment.
DIT is aware of new computers and
software because they:
• Coordinate County-wide computer
update and replacement
initiatives/Refresh.
• Restrict most user's administrative
rights.
• Require users to submit a helpdesk
ticket for hardware/software
installation and/or configuration to
the network.
• Require users to submit a Custom
Technology Request Form for all
other non-price term agreement
equipment and software requests.
To fully meet best practices, DIT should
implement a plan to centrally receive and
accept all IT assets and/or address
current receiving and accepting
processes to ensure DIT is aware of new
computers or software before they are
introduced into the County environment
in DIT Employee Policies.
IT Asset Management Follow-up Audit Status of Recommendations 18
7. Annual Physical Inventory
We recommend DIT periodically We corroborated with DIT staff and Not
reconcile IT assets listed on the reviewed the County's inventory records Implemented
Fixed Asset Detail Report with and found DIT performs physical inventory
the automated network and of only their departments IT assets.
software inventory system to
ensure all IT assets are properly
recorded and included in the To fully meet best practices, DIT should
annual physical inventory. Any conduct periodic County-wide physical
discrepancies should be inventory to ensure all IT assets are
investigated ted and resolved
properly recorded and included in the
immediately. annual physical inventory.
IT Asset Management Follow-up Audit Status of Recommendations 19
Hardware and Software Security
8. Secured Disposal
We understand that the Director We reviewed the DIT Employee Policies In Process
of IT plans to issue a memo with Electronic Data Storage Destruction
the "Electronic Records Policy(March 2020) and found the policy
Destruction Policy for Computer was periodically reviewed but not updated
and Electronic Media" to the accordingly.
Department heads and managers
requiring the transfer of all To fully meet best practices, DIT should
obsolete hard drives to DIT for address the transfer of all obsolete hard
destruction. We recommend the drives to DIT for destruction including
County review this policy at least annual review process in DIT Employee
annually and update accordingly. Policies.
We also understand that the We verified additional physical security Implemented
current computer deployment controls to safeguard IT assets and media
location is temporary. However, from loss or theft, specifically we:
if DIT continues to use the facility,
we recommend that additional • Observed security camera system
physical security controls be and safeguarding practices in
implemented to safeguard IT place at Schultz Siding office and
assets and media from loss or baseyard.
theft.
• Reviewed 82 disposal records and
three police reports to confirm
Manual Hard Drive Crusher there were no redeployed items in
DIT's custody that were stolen.
• Compared Equipment Disposal
,,
-
3 Forms to Certificates of Disposal
10 I and found no exceptions.
\,
'-.gr
• Observed manual hard drive
crusher used to destroy obsolete
. ` " hard drives and media tapes at
`'- secured location.
Figure 2
Photo courtesy
Office of the County Auditor 1
IT Asset Management Follow-up Audit Status of Recommendations 110
Audit Objective
The objective of this follow-up audit was to determine if the Department of Information
Technology implemented the 2015 IT asset management recommendations.
Audit Scope and Methodology
To verify the Department of Information Technology implemented the IT asset
management recommendations, we:
• Corroborated information with appropriate staff to follow-up on the responses to
audit recommendations
• Performed tests of controls
• Reviewed applicable source documents:
o Inventory Procedures Manual dated 1-1-83
o DIT Employee Policies dated 12-31-16, revised 7-1-17, and 3-23-2020
• Electronic Resources Policy
• Password Policy
• E-Mail Retention Policy
• Electronic Data Storage Destruction Policy
• Mobile Device Policy
• Social Media Policy
o Memorandum of Understanding for the County of Hawaii Department of
Information Technology's Strategic Plan and Roadmap 6-18-2020
o Statement of Work: IT Strategy, Information Security, and Disaster
Recovery Planning Workshops for County of Hawaii
o Windows Upgrade and Deployment Strategies dated 9-11-19
o Project Data Criteria dated 10-2-19
o Information Technology Information Security Handbook
o Standard Operating Procedures for County Devices
o Approved/disapproved software listings
o Loaner equipment In/Out logs
o Inventory records including department transfers and disposals
o 2015 - 2019 Price Term Agreements for Computer Equipment
o Supplemental Budget Requests
o Council Resolutions and Communications
o Other as needed information from December 2015 to January 2021
• Conducted site visits to verify monitoring, redeployment, and safeguarding
practices at Waiakea Office Plaza and Schultz Siding Office.
IT Asset Management Follow-up Audit Audit Objective, Scope and Methodology 111
The scope of the audit was limited to departments that the Department of Information
Technology supports. The audit excluded the Department of Water Supply, Police
Department, Office of Housing and Community Development, Office of the Prosecuting
Attorney, and the Office of Aging.
We conducted this performance audit in accordance with generally accepted government
auditing standards. Those standards require that we plan and perform the audit to
obtain sufficient, appropriate evidence to provide reasonable basis for our findings and
conclusions based on our audit objectives. We believe that the evidence obtained
provides a reasonable basis for our findings s and conclusions based on our audit 9
objectives.
IT Asset Management Follow-up Audit Audit Objective, Scope and Methodology 1 12
Conclusion
We sincerely thank the Department of Information Technology's leadership and staff for
their cooperation during our follow-up work and for their efforts in working toward
implementing and partially implementing most IT asset management recommendations,
such as:
r Lifecycle management for hardware and software upgrades and replacements
Purchase request and approval
o maintaining approved software listing and communicating the risks to
departments
o updating County-Issued Technology Devise policy prohibiting users from
installing non-supported software and adding un-approved devices to the
County network
r Redeployment of assets
r Evaluating leasing as an option to procure computers and software licenses
r Tracking users in a centralized database
r Centrally receiving and accepting all IT assets to ensure DIT is aware of new
computers or software before they are introduced into the County environment
r Secure disposal
o Annual review of secured disposal policy
o Additional physical security controls to safeguard IT assets from loss or
theft.
Opportunities exist to fully meet best practices, such as DIT should:
r Centralize the IT asset management function
r Own all IT assets and establish an IT asset management role
o Develop a one through five-year financial forecast of upgrades and
replacements for each of the departments by analyzing the historical
information on the County's IT environment, current trends, and future
needs.
r Conduct periodic physical inventory to ensure all County IT assets are properly
recorded and included in the annual physical inventory.
r Address gaps in Employee Policies to address:
o Current software approval processes including annual review
o Current redeployment processes including the retrieval of computers and
software licenses that were installed on computers that were replaced or idle
for an extended period of time.
o Implement County-wide written procedures to centrally track users for all
IT assets
o Centrally receive and accept all IT assets and/or current receiving and
accepting processes, and
o Transfer of all obsolete hard drives to DIT for destruction including an annual
review process.
IT Asset Management Follow-up Audit Conclusion 113
Department Response
OF„'
Mitchell D.Roth ° y :; Scott Uehara
Mayor ; � " �/ Director
' '44. �N
OF ;0' ,
Lee Lord
Managing Director of jbathat•` t
Department of Information Technology
1990 Kinoole Street,Suite 105•Hilo,Hawaii 96720
(808)932-2960•Fax(808)961-8089
May 18, 2021
Acting County Auditor
Maxinne Pacheco
25 Aupuni Street
Hilo, Hawaii 96720
To Maxinne Pacheco:
You will find the Department of Information and Technology's response letter to the Hawaii
County Audit for 2021.
or concerns,please feel free to contact me.
there be anyquestions
Should
Sincerely,
C�y
Scott Uehara
Department of Information Technology, Director
1990 Kinoole Street, Suite#105
Hilo,HI 96720
#808-932-2975
Scott.Uehara@hawaiicounty.gov
County of Hawaii is an Equal Opportunity Provider and Employer
IT Asset Management Follow-up Audit Department Response 114
Hardware and Software Lifecycle Management
1. Upgrades and Replacements (Status: In Process)
Recommendation: Recommended that DIT establish an if asset manager position to manage the
County's IT assets and implement a plan to develop a one through five year financial forecast of
hardware and software upgrades and replacements for each of the departments by analyzing
the
historical information on the County's IT environment, current trends and future needs.
While the County has implemented several procedures to better manage IT assets, to fully meet
industry best practices and improve the process of upgrading and replacing computers and
laptops, the IT asset manager should implement a plan to take ownership of all IT assets.
Response: An IT asset management position was recommended in the November 12, 2015 audit
and is being recommended again in the November 30, 2020 audit. In the November 12, 2015
audit report, management of hardware and software lifecycle, inventory, financial and security
procedures were compared against the Best Practices Library published by the International
Association of Information Technology Asset Managers.
Managing Information Technology assets across the County is an important issue that must be
addressed. In order to manage the overall life cycle of these assets, the finances, inventory, and
contractual/risk management responsibilities are required. The IT Asset Manager (ITAM) will
have many different roles to play. They will be not only short term,but long-term goals. The
position will also introduce best practices that provide value to the County as a whole. The
simplest way to summarize the importance of this role is with the saying, "If you are not
managing your technology, you are not managing your business."By Dr. Barbara Rembiesa.
While DIT moves towards investigating the ITAM position, questions still need to be answered,
such as:
• Will the ITAM be financially responsible for missing assets, when this position does not
have total physical accountability for assets?
• As technology moves forward with mobile technology, how will asset control account for
equipment which are routinely moving?
• Will inventory auditing be conducted in tandem or asynchronous from yearly and
administrative audits?
2. Purchase Request and Approval (Status: In Process)
Recommendation: Recommended that DIT implement a policy to maintain an approved software
listing and communicate the risks to the departments. The policy should include an annual
review of the listing to ensure that software listed is still relevant and does not pose a security
concern to the County. A review process should be implemented to respond to requests for
software titles that are not currently in the supported software listing.
Response: DIT does manage a list of approved and unapproved software listing. It is agreed that
a policy should be created to address baseline standards for the review process of software.
County of Hawaii is an Equal Opportunity Provider and Employer.
IT Asset Management Follow-up Audit Department Response 115
3. Redeployment of Assets (Status: In Process)
Recommendation: Was recommended that once the IT asset manager position has been
established, DIT should implement a process to identify redeployable assets and to establish
County-wide formal written redeployment procedures to retrieve computers and software
licenses that were installed on computers that were replaced or idle for an extended period of
time. The redeployment of computers and software licenses is often cost effective, minimizes
unnecessary purchases, reduces over purchasing of assets and reduces data security risks.
Response: DIT continues efforts to utilize assets capable of supporting user requirements and
aligning with established security requirements. The Coronavirus pandemic required DIT to
quickly adjust to work reassignments and this caused some assets to fall out of compliance for
redeployment.
4. Leasing
Recommendation: Recommended that DIT continue to evaluate leasing as an option to procure
computers and software licenses for the County.
Response: Agree with recommendation and implementation of leasing.
5. Centralized Management System (Status: In Process)
Recommendation: Recommended that DIT track users in a centralized database. Not tracking
users in a centralized database may increase the County's security exposure since DIT may not
be able to determine if computers are in use or locate assets. In addition, DIT may have difficulty
holding employees accountable for the protection of assets and inappropriate activities. Unused
computers are candidates for redeployment and may unnecessarily consume software licenses.
From a software compliance perspective, software end-user licensing agreements can be tied to
users instead of computers, and DIT may not be able to determine the appropriate license counts
without knowing the assigned users. The fixed assets inventory system is not accessible to DIT
and the automated network and software inventory system is not used to track the user.
Therefore, we recommend that once the IT asset manager position is established, DIT should
implement a plan to identify a centralized database that has the ability to track users whether it is
the fixed assets inventory system, the automated network and software inventory system, or
another IT asset management inventory system. After a product has been identified, the IT asset
manager should implement County-wide written procedures to centrally track users for all IT
assets.
Response: The majority of software licenses have been migrated from device assignments to
being assigned to users. User tracking will need to account for all device and license types as
some employees have stationary assets in their office environment, and also have mobile assets
which will require additional tracking of the asset and software associated.
To aide DIT in tracking users, we need assistance from all County departments to timely notify
DIT of employee changes.
County of Hawaii is an Equal Opportunity Provider and Employer.
IT Asset Management Follow-up Audit Department Response 06
6. Receiving and Accepting (Status: In Process)
Recommendation: Recommended that DIT implement a plan to centrally receive and accept all
IT assets to ensure DIT is aware of new computers or software before they are introduced into
the County environment.
Response: DIT will work on a policy and process with the Finance department to accurately
account for all computer purchases to ensure that all assets will be centrally received. To move
forward with this recommendation, DIT will need a warehouse or location to physically store
assets while waiting for configuration and deployment.
7. Annual Physical Inventory (Status: Not Implemented)
Recommendation: Recommended that DIT periodically reconcile IT assets listed on the Fixed
Asset Detail Report with the automated network and software inventory system to ensure all IT
assets are properly recorded and included in the annual physical inventory. Any discrepancies
should be investigated and resolved immediately.
•
Response: The Coronavirus pandemic has introduced new challenges to inventory assets as many
devices have remained off, and thusly automated network scans have not been fully successful
with ascertaining if assets are still in place. Without additional staff, dedicated to asset
management, this will remain on ongoing issue.
8. Secured Disposal (Status: In Process)
Recommendation: We understand that the Director of IT plans to issue a memo with the
"Electronic Records Destruction Policy for Computer and Electronic Media" to the Department
heads and managers requiring the transfer of all obsolete hard drives to DIT for destruction.
Recommend the County review this policy at least annually and update accordingly. We also
understand that the current computer deployment location is temporary. However, if DIT
continues to use the facility, we recommend that additional physical security controls be
implemented to safeguard IT assets and media from loss or theft.
Response: We will request a secured facility and container to ensure assets and media are
safeguarded from theft and/or loss. As a County, a review and agreement must be congruent on
a record retention policy to include electronic documents and media.
County of Hawaii is an Equal Opportunity Provider and Employer.
IT Asset Management Follow-up Audit Department Response 117