Loading...
HomeMy WebLinkAboutCOM 0261.000 2020-2022 Maxinne Pacheco • • - Acting County Auditor14,c • Business Address ef:: . t:P• 120 Pauahi Street 4TE oF'e►ra Suite 309 Hilo, Hawaii 96720 CCouttfu of Ittfilai % OFFICE OF THE COUNTY AUDITOR 25 Aupuni Street Hilo, Hawaii 96720 • (808)961-8386 • Fax(808)961-8905 website:http:;ihawaiicounty.gov e-mail:countvauditora,hawaiicountv.gov , May 20, 2021 �a - Honorable Maile Mederios David, Council Chair and Members of the Hawaii County Council Hawaii County Council 25 Aupuni Street Hilo, Hawaii 96720 Dear Chair David and Council Members, In accordance with generally accepted government auditing standards and the Hawaii County Charter Section 3-18(d)(3), the Office of the County Auditor has a responsibility to monitor and follow-up on audit recommendations to ensure that audit findings are being addressed through appropriate corrective action and to aid us in planning future audits. We have completed our follow-up audit of the County of Hawaii Information Technology Asset Management (Report No. 2015-01) dated November 12, 2015. The audit objective was to determine if the Department of Information Technology implemented the 2015 IT Asset Management recommendations. We tested eleven recommendations and found that management took corrective action as follows: Status of Recommendations: Implemented In Process Not Implemented 4 6 1 Department has fully Department started or has Department has not begun implemented the audit partially implemented the implementation of the recommendation. audit recommendation. recommendation. Currently, the Department of Information Technology (DIT) does not own or manage all the County's IT assets. To fully meet best practices, IT asset management should be centralized, DIT should own all IT assets, and use an IT asset management role. WI Comm. N Ref. To: Hawaii County is an Equal Opportunity Provider and Employer MAY 2 4 2021 Ref. Date X11 These are key elements to successful management of IT assets and without these elements, the County is at an increased risk of security concerns, system instability, helpdesk, and County employee inefficiencies, as well as increased hardware and software costs. Management has generally agreed with the comments and the status of recommendations in this report. We would like to express our sincere appreciation and commend the Department of Information Technology's leadership and staff for their continued efforts to improve information technology asset management and for their assistance, cooperation, and prompt feedback during the follow-up audit process. If you have any questions or concerns about the status of recommendations discussed, please feel free to contact me at 961-8386. Respectfully, Maxinne Pacheco Acting County Auditor cc: Mitchell D. Roth, Mayor Lee Lord, Managing Director Jon Henricks, County Clerk Scott Uehara, Director, Department of Information Technology Deanna Sako, Finance Director Follow-up Audit Report County of Hawaii Information Technology Asset Management May 20, 2021 1 WIRWIIIIII ' 141.111 , /' r:,�,- --• Yi Vi 1 1'. ir ir. ---.:s_ 1 . , V t\ VOJ � l„ Hq�9'y ,t = • vi County of Hawai`i '.. Office of the County Auditor Maxinne Pacheco Acting County Auditor 41:1- ti-- /• Business Address 120 Pauahi Street OF Nj: Suite 309 Hilo, Hawaii 96720 (i uttfvr f Pail i`Y OFFICE OF THE COUNTY AUDITOR 25 Aupuni Street Hilo, Hawaii 96720 • (808)96/-8386 • Fax(808)961-8905 website:http://hawaiicountv.gor e-mail:cowvvauditorWlawaiicountr.gor May 20, 2021 Honorable Maile Mederios David, Council Chair and Members of the Hawaii County Council Hawaii County Council 25 Aupuni Street Hilo, Hawaii 96720 Dear Chair David and Council Members, In accordance with generally accepted government auditing standards and the Hawaii County Charter Section 3-18(d)(3), the Office of the County Auditor has a responsibility to monitor and follow-up on audit recommendations to ensure that audit findings are being addressed through appropriate corrective action and to aid us in planning future audits. We have completed our follow-up audit of the County of Hawaii Information Technology Asset Management (Report No. 2015-01) dated November 12, 2015. The audit objective was to determine if the Department of Information Technology implemented the 2015 IT Asset Management recommendations. We tested eleven recommendations and found that management took corrective action as follows: Status of Recommendations: Implemented In Process Not Implemented 4 6 1 Department has fully Department started or has Department has not begun implemented the audit partially implemented the implementation of the recommendation. audit recommendation. recommendation. Currently, the Department of Information Technology (DIT) does not own or manage all the County's IT assets. To fully meet best practices, IT asset management should be centralized, DIT should own all IT assets, and use an IT asset management role. Hawaii County is an Equal Opportunity Provider and Employer These are key elements to successful management of IT assets and without these elements, the County is at an increased risk of security concerns, system instability, helpdesk, and County employee inefficiencies, as well as increased hardware and software costs. Management has generally agreed with the comments and the status of recommendations in this report. We would like to express our sincere appreciation and commend the Department of Information Technology's leadership and staff for their continued efforts to improve information technology asset management and for their assistance, cooperation, and prompt feedback during the follow-up audit process. If you have any questions or concerns about the status of recommendations discussed, please feel free to contact me at 961-8386. Respectfully, Maxinne Pacheco Acting County Auditor cc: Mitchell D. Roth, Mayor Lee Lord, Managing Director Jon Henricks, County Clerk Scott Uehara, Director, Department of Information Technology Deanna Sako, Finance Director Report Highlights May 20, 2021 County of Hawaii Information Technology Asset Management Follow-Up Original Audit Follow-Up Audit What we found In November of 2015, the Office of the County Auditor Two key elements of IT asset management issued the audit of the County of Hawaii Information are the centralization of the IT function and Technology Asset Management and made eleven the use of an IT asset management role. recommendations. Without these two elements, the County is at an increased risk of security concerns, system Management generally agreed with the comments instability, and helpdesk inefficiencies. and status of recommendations. What we recommended Objective We identified the following recommendations To determine if the Department of Information for management to meet best practices: Technology implemented the 2015 IT asset 1. DIT should own all IT assets. Furthermore, management recommendations. an IT asset management role should be established to manage the County's IT Status of Recommendations assets including: We tested eleven recommendations and found that • Developing a financial forecast of management took corrective action as follows: hardware and software upgrades and replacements; • Implemented: 4 • Maintaining an approved software list • In Process: 6 for standardization; • Not Implemented: 1 • Identifying re-deployable IT assets; • Continuing to evaluate leasing as an Hardware & Software Lifecycle Management option; • Upgrades & Replacements: (1) In Process • Maintaining a listing of IT assets and • Purchase Request & Approval: the assigned users in a centralized (1) In Process and (1) Implemented database; • Redeployment of Assets: (1) In Process • Centrally receiving and accepting all • Leasing: (1) Implemented IT assets; Hardware & Software Inventory Management • Reconciling IT assets in the IT asset management inventory; and • Centralized Management System: Ensuring the disposal of IT assets (1) Implemented and (1) In Process • • Receiving & Accepting: (1) In Process occurs in a secured manner. 2. The County should address gaps in formal • Annual Physical Inventory: (1) Not Implemented written policies and procedures over IT Hardware & Software Security practices. • Secured Disposal: (1) In Process and (1) Implemented This audit was conducted in accordance with generally accepted government auditing standards. Table of Contents Status of Recommendations 1 Hardware and Software Lifecycle Management 1. Upgrades and Replacements 1 2. Purchase Request and Approval 3 3. Redeployment of Assets 4 4. Leasing 5 Hardware and Software Inventory Management 5. Centralized Management System 6 6. Receiving and Accepting 8 7. Annual Physical Inventory 9 Hardware and Software Security 8. Secured Disposal 10 Audit Objective 11 Audit Scope and Methodology 11 Conclusion 13 Department Response 14 Status of Recommendations Recommendation Auditee Action Status Hardware and Software Lifecycle Management 1. Upgrades and Replacements We recommend that DIT In September 2019, DIT developed a plan In Process establish an IT asset manager Ito deploy 310 computers and/or laptops. position to manage the County's Due to the COVID-19 pandemic, IT assets and implement a plan deployment is ongoing. to develop a one through five- year financial forecast of In November 2020, we discussed the hardware and software upgrades status of recommendations with the replacements for each of the and current and incomingDIT Director. We departments by analyzing the worked with the incoming administration historical information on the Ito provide a written response to be County's IT environment, current included in this report. trends, and future needs. We reviewed the supplemental budget While the County has requests and found the IT asset manager implemented several procedures position was not established. In January to better manage IT assets, to 2021 , the new DIT Director stated in his fully meet industry best practices new role he has discretion to realign and improve the process of duties to close gaps in certain processes upgrading and replacing by dividing up work between DIT computers and laptops, the IT sections. He further affirmed he has a asset manager should goal of developing a five-year hardware implement a plan to take and software upgrade and replacement ownership of all IT assets. schedule to address this audit recommendation. Additionally, in July 2020, we reviewed a contract authorizing the development of an IT Strategic Plan and Roadmap with the State of Hawaii, Office of Enterprise Technology and the United States Department of Defense, Office of Homeland Security. of Recommendations 1 IT Asset Management Follow-up Audit Status � DIT attended a series of workshops to learn: • IT Strategy o Assess the current state of IT and compare it to the desired future state; o Create a roadmap of IT initiatives that will bring IT to the level needed to achieve its goals and fulfill its role to support business objectives; and o Establish a strategic roadmap for the next 2-3 years. • Information Security • Disaster Recovery Planning To fully meet best practices, management should prioritize establishing an IT asset manager or equivalent to manage all County-owned IT assets and develop a one through five-year financial forecast of upgrades and replacements for each of the departments by analyzing the historical information on the County's IT environment, current trends, and future needs as part of their IT Strategic Plan and Roadmap. I, II IT Asset Management Follow-up Audit Status of Recommendations 12 2. Purchase Request and Approval We recommend DIT implement We reviewed 137 approved and In Process a policy to maintain an approved disapproved software listings and found software listing and DIT has a process of maintaining an communicate the risks to the approved software listing and departments. The policy should communicates the risk in their Hawaii include an annual review of the County Security Handbook that provides listing to ensure that software guidance on, 'What you need to know to listed is still relevant and does stay safe while computing, and help not pose a security concern to protect the County's IT assets." the County. A review process should be implemented to To fully meet best practices, DIT should respond to requests for software address current software approval titles that are not currently in the processes including an annual review in supported software listing. DIT Employee Policies. We also recommend DIT We reviewed DIT Employee Policies' Implemented update the County-Issued Electronic Resources Policy(March 2020) Technology Device policy to prohibiting: include prohibiting users from installing non-supported • "Engaging in disruptive or software and adding un- malicious activities such as n unauthorized software, hardware, approved devices to the County network. or data modification." • "Installing or downloading software not approved and/or licensed to the County." IT Asset Management Follow-up Audit Status of Recommendations 13 3. Redeployment of Assets We recommend that once the We reviewed 426 equipment transfer In Process IT asset manager position has records and found DIT partially meets best been established, DIT should practices because they: implement a process to identify redeployable assets and to • Identify and tag usable hardware and establish County-wide formal software through department transfers written redeployment procedures and helpdesk ticket requests. to retrieve computers and software licenses that were • Redeploy local or cloud-based installed on computers that were software licenses (Microsoft/Adobe) replaced or idle for an extended when computers become inoperable, period of time. The or user separates from the County. redeployment of computers and software licenses is often cost- • Identify computers and laptops that effective, minimizes could be redeployed because of unnecessary purchases, County-wide computer upgrade and reduces over purchasing of replacement initiatives. assets and reduces data security • Track equipment on loan with an risks. In/Out log. Items ta• •ed for rede•lo ment To fully meet best practices, DIT should trgi•AI,m address current redeployment processes r o if including establishing a County-wide formal •a written redeployment procedures to retrieve A ' .ilk_ computers and software licenses that were 2;4 ,�* = installed on computers that were replaced or idle for an extended period of time in DIT 4•, == ,fEmployee Policies. E In January 2021, the new DIT Director ... _ stated they will redeploy usable IT assets Figure within the three to five-year warranty Photo courtesy period. Office of the County Auditor IT Asset Management Follow-up Audit Status of Recommendations 14 4. Leasing We recommend DIT continue We verified a contract authorizing a five- Implemented to evaluate leasing as an option year lease for 310 computers and/or to procure computers and laptops. software licenses for the County. We also reviewed yearly subscriptions for software licenses for: • Adobe VIP (Value Incentive Program) • Adobe Sign • Microsoft • ESRI (software mapping) IT Asset Management Follow-up Audit Status of Recommendations 15 Hardware and Software Inventory Management 5. Centralized Management System We recommend DIT track users We observed Lansweeper, an automated Implemented in a centralized database. Not software program used to monitor asset tracking users in a centralized data information, network security, database may increase the software updates, and patches for: County's security exposure since DIT may not be able to determine • 1 ,408 users if computers are in use or locate • assets. In addition, DIT may 1,449 devices have difficulty holding employees • Flagging computers/devices not accountable for the protection of seen in the network in the last assets and inappropriate 30/60/90 days activities. Unused computers are candidates for redeployment and • Flagging users' access upon may unnecessarily consume separation from the County every software licenses. From a two weeks software compliance perspective, software end-user licensing • Flagging and redeploying local or agreements can be tied to users cloud-based software licenses instead of computers, and DIT (Microsoft/Adobe) when may not be able to determine the computers become inoperable, or appropriate license counts user separates from the County without knowing the assigned users. • Blocking at-risk devices from the network The fixed assets inventory system is not accessible to DIT • Pushing out security updates and and the automated network and patches software inventory system is not • Reporting discrepancies to used to track the user. department IT liaisons • Restricting most user's administrative rights. IT Asset Management Follow-up Audit Status of Recommendations 16 Therefore, we recommend that We observed DIT staff using In Process once the IT asset manager Lansweeper to track asset data position is established, DIT information for over 1400 users and should implement a plan to devices connecting to the network to identify a centralized database ensure the network is safe. that has the ability to track users whether it is the fixed assets To fully meet best practices, the IT asset inventory system, the automated manager should implement County-wide network and software inventory written procedures to centrally track system, or another IT asset users for all IT assets in applicable DIT management inventory system. Employee Policies and/or IT Strategic After a product has been Plan and Roadmap. identified, the IT asset manager should implement County-wide written procedures to centrally track users for all IT assets. IT Asset Management Follow-up Audit Status of Recommendations 17 6. Receiving and Accepting We recommend DIT implement DIT centrally receives and accepts most In Process a plan to centrally receive and IT assets only during County-wide accept all IT assets to ensure computer upgrade and replacement DIT is aware of new computers initiatives/Refresh (January 2015 and or software before they are introduced into the County 2020). environment. DIT is aware of new computers and software because they: • Coordinate County-wide computer update and replacement initiatives/Refresh. • Restrict most user's administrative rights. • Require users to submit a helpdesk ticket for hardware/software installation and/or configuration to the network. • Require users to submit a Custom Technology Request Form for all other non-price term agreement equipment and software requests. To fully meet best practices, DIT should implement a plan to centrally receive and accept all IT assets and/or address current receiving and accepting processes to ensure DIT is aware of new computers or software before they are introduced into the County environment in DIT Employee Policies. IT Asset Management Follow-up Audit Status of Recommendations 18 7. Annual Physical Inventory We recommend DIT periodically We corroborated with DIT staff and Not reconcile IT assets listed on the reviewed the County's inventory records Implemented Fixed Asset Detail Report with and found DIT performs physical inventory the automated network and of only their departments IT assets. software inventory system to ensure all IT assets are properly recorded and included in the To fully meet best practices, DIT should annual physical inventory. Any conduct periodic County-wide physical discrepancies should be inventory to ensure all IT assets are investigated ted and resolved properly recorded and included in the immediately. annual physical inventory. IT Asset Management Follow-up Audit Status of Recommendations 19 Hardware and Software Security 8. Secured Disposal We understand that the Director We reviewed the DIT Employee Policies In Process of IT plans to issue a memo with Electronic Data Storage Destruction the "Electronic Records Policy(March 2020) and found the policy Destruction Policy for Computer was periodically reviewed but not updated and Electronic Media" to the accordingly. Department heads and managers requiring the transfer of all To fully meet best practices, DIT should obsolete hard drives to DIT for address the transfer of all obsolete hard destruction. We recommend the drives to DIT for destruction including County review this policy at least annual review process in DIT Employee annually and update accordingly. Policies. We also understand that the We verified additional physical security Implemented current computer deployment controls to safeguard IT assets and media location is temporary. However, from loss or theft, specifically we: if DIT continues to use the facility, we recommend that additional • Observed security camera system physical security controls be and safeguarding practices in implemented to safeguard IT place at Schultz Siding office and assets and media from loss or baseyard. theft. • Reviewed 82 disposal records and three police reports to confirm Manual Hard Drive Crusher there were no redeployed items in DIT's custody that were stolen. • Compared Equipment Disposal ,, - 3 Forms to Certificates of Disposal 10 I and found no exceptions. \, '-.gr • Observed manual hard drive crusher used to destroy obsolete . ` " hard drives and media tapes at `'- secured location. Figure 2 Photo courtesy Office of the County Auditor 1 IT Asset Management Follow-up Audit Status of Recommendations 110 Audit Objective The objective of this follow-up audit was to determine if the Department of Information Technology implemented the 2015 IT asset management recommendations. Audit Scope and Methodology To verify the Department of Information Technology implemented the IT asset management recommendations, we: • Corroborated information with appropriate staff to follow-up on the responses to audit recommendations • Performed tests of controls • Reviewed applicable source documents: o Inventory Procedures Manual dated 1-1-83 o DIT Employee Policies dated 12-31-16, revised 7-1-17, and 3-23-2020 • Electronic Resources Policy • Password Policy • E-Mail Retention Policy • Electronic Data Storage Destruction Policy • Mobile Device Policy • Social Media Policy o Memorandum of Understanding for the County of Hawaii Department of Information Technology's Strategic Plan and Roadmap 6-18-2020 o Statement of Work: IT Strategy, Information Security, and Disaster Recovery Planning Workshops for County of Hawaii o Windows Upgrade and Deployment Strategies dated 9-11-19 o Project Data Criteria dated 10-2-19 o Information Technology Information Security Handbook o Standard Operating Procedures for County Devices o Approved/disapproved software listings o Loaner equipment In/Out logs o Inventory records including department transfers and disposals o 2015 - 2019 Price Term Agreements for Computer Equipment o Supplemental Budget Requests o Council Resolutions and Communications o Other as needed information from December 2015 to January 2021 • Conducted site visits to verify monitoring, redeployment, and safeguarding practices at Waiakea Office Plaza and Schultz Siding Office. IT Asset Management Follow-up Audit Audit Objective, Scope and Methodology 111 The scope of the audit was limited to departments that the Department of Information Technology supports. The audit excluded the Department of Water Supply, Police Department, Office of Housing and Community Development, Office of the Prosecuting Attorney, and the Office of Aging. We conducted this performance audit in accordance with generally accepted government auditing standards. Those standards require that we plan and perform the audit to obtain sufficient, appropriate evidence to provide reasonable basis for our findings and conclusions based on our audit objectives. We believe that the evidence obtained provides a reasonable basis for our findings s and conclusions based on our audit 9 objectives. IT Asset Management Follow-up Audit Audit Objective, Scope and Methodology 1 12 Conclusion We sincerely thank the Department of Information Technology's leadership and staff for their cooperation during our follow-up work and for their efforts in working toward implementing and partially implementing most IT asset management recommendations, such as: r Lifecycle management for hardware and software upgrades and replacements Purchase request and approval o maintaining approved software listing and communicating the risks to departments o updating County-Issued Technology Devise policy prohibiting users from installing non-supported software and adding un-approved devices to the County network r Redeployment of assets r Evaluating leasing as an option to procure computers and software licenses r Tracking users in a centralized database r Centrally receiving and accepting all IT assets to ensure DIT is aware of new computers or software before they are introduced into the County environment r Secure disposal o Annual review of secured disposal policy o Additional physical security controls to safeguard IT assets from loss or theft. Opportunities exist to fully meet best practices, such as DIT should: r Centralize the IT asset management function r Own all IT assets and establish an IT asset management role o Develop a one through five-year financial forecast of upgrades and replacements for each of the departments by analyzing the historical information on the County's IT environment, current trends, and future needs. r Conduct periodic physical inventory to ensure all County IT assets are properly recorded and included in the annual physical inventory. r Address gaps in Employee Policies to address: o Current software approval processes including annual review o Current redeployment processes including the retrieval of computers and software licenses that were installed on computers that were replaced or idle for an extended period of time. o Implement County-wide written procedures to centrally track users for all IT assets o Centrally receive and accept all IT assets and/or current receiving and accepting processes, and o Transfer of all obsolete hard drives to DIT for destruction including an annual review process. IT Asset Management Follow-up Audit Conclusion 113 Department Response OF„' Mitchell D.Roth ° y :; Scott Uehara Mayor ; � " �/ Director ' '44. �N OF ;0' , Lee Lord Managing Director of jbathat•` t Department of Information Technology 1990 Kinoole Street,Suite 105•Hilo,Hawaii 96720 (808)932-2960•Fax(808)961-8089 May 18, 2021 Acting County Auditor Maxinne Pacheco 25 Aupuni Street Hilo, Hawaii 96720 To Maxinne Pacheco: You will find the Department of Information and Technology's response letter to the Hawaii County Audit for 2021. or concerns,please feel free to contact me. there be anyquestions Should Sincerely, C�y Scott Uehara Department of Information Technology, Director 1990 Kinoole Street, Suite#105 Hilo,HI 96720 #808-932-2975 Scott.Uehara@hawaiicounty.gov County of Hawaii is an Equal Opportunity Provider and Employer IT Asset Management Follow-up Audit Department Response 114 Hardware and Software Lifecycle Management 1. Upgrades and Replacements (Status: In Process) Recommendation: Recommended that DIT establish an if asset manager position to manage the County's IT assets and implement a plan to develop a one through five year financial forecast of hardware and software upgrades and replacements for each of the departments by analyzing the historical information on the County's IT environment, current trends and future needs. While the County has implemented several procedures to better manage IT assets, to fully meet industry best practices and improve the process of upgrading and replacing computers and laptops, the IT asset manager should implement a plan to take ownership of all IT assets. Response: An IT asset management position was recommended in the November 12, 2015 audit and is being recommended again in the November 30, 2020 audit. In the November 12, 2015 audit report, management of hardware and software lifecycle, inventory, financial and security procedures were compared against the Best Practices Library published by the International Association of Information Technology Asset Managers. Managing Information Technology assets across the County is an important issue that must be addressed. In order to manage the overall life cycle of these assets, the finances, inventory, and contractual/risk management responsibilities are required. The IT Asset Manager (ITAM) will have many different roles to play. They will be not only short term,but long-term goals. The position will also introduce best practices that provide value to the County as a whole. The simplest way to summarize the importance of this role is with the saying, "If you are not managing your technology, you are not managing your business."By Dr. Barbara Rembiesa. While DIT moves towards investigating the ITAM position, questions still need to be answered, such as: • Will the ITAM be financially responsible for missing assets, when this position does not have total physical accountability for assets? • As technology moves forward with mobile technology, how will asset control account for equipment which are routinely moving? • Will inventory auditing be conducted in tandem or asynchronous from yearly and administrative audits? 2. Purchase Request and Approval (Status: In Process) Recommendation: Recommended that DIT implement a policy to maintain an approved software listing and communicate the risks to the departments. The policy should include an annual review of the listing to ensure that software listed is still relevant and does not pose a security concern to the County. A review process should be implemented to respond to requests for software titles that are not currently in the supported software listing. Response: DIT does manage a list of approved and unapproved software listing. It is agreed that a policy should be created to address baseline standards for the review process of software. County of Hawaii is an Equal Opportunity Provider and Employer. IT Asset Management Follow-up Audit Department Response 115 3. Redeployment of Assets (Status: In Process) Recommendation: Was recommended that once the IT asset manager position has been established, DIT should implement a process to identify redeployable assets and to establish County-wide formal written redeployment procedures to retrieve computers and software licenses that were installed on computers that were replaced or idle for an extended period of time. The redeployment of computers and software licenses is often cost effective, minimizes unnecessary purchases, reduces over purchasing of assets and reduces data security risks. Response: DIT continues efforts to utilize assets capable of supporting user requirements and aligning with established security requirements. The Coronavirus pandemic required DIT to quickly adjust to work reassignments and this caused some assets to fall out of compliance for redeployment. 4. Leasing Recommendation: Recommended that DIT continue to evaluate leasing as an option to procure computers and software licenses for the County. Response: Agree with recommendation and implementation of leasing. 5. Centralized Management System (Status: In Process) Recommendation: Recommended that DIT track users in a centralized database. Not tracking users in a centralized database may increase the County's security exposure since DIT may not be able to determine if computers are in use or locate assets. In addition, DIT may have difficulty holding employees accountable for the protection of assets and inappropriate activities. Unused computers are candidates for redeployment and may unnecessarily consume software licenses. From a software compliance perspective, software end-user licensing agreements can be tied to users instead of computers, and DIT may not be able to determine the appropriate license counts without knowing the assigned users. The fixed assets inventory system is not accessible to DIT and the automated network and software inventory system is not used to track the user. Therefore, we recommend that once the IT asset manager position is established, DIT should implement a plan to identify a centralized database that has the ability to track users whether it is the fixed assets inventory system, the automated network and software inventory system, or another IT asset management inventory system. After a product has been identified, the IT asset manager should implement County-wide written procedures to centrally track users for all IT assets. Response: The majority of software licenses have been migrated from device assignments to being assigned to users. User tracking will need to account for all device and license types as some employees have stationary assets in their office environment, and also have mobile assets which will require additional tracking of the asset and software associated. To aide DIT in tracking users, we need assistance from all County departments to timely notify DIT of employee changes. County of Hawaii is an Equal Opportunity Provider and Employer. IT Asset Management Follow-up Audit Department Response 06 6. Receiving and Accepting (Status: In Process) Recommendation: Recommended that DIT implement a plan to centrally receive and accept all IT assets to ensure DIT is aware of new computers or software before they are introduced into the County environment. Response: DIT will work on a policy and process with the Finance department to accurately account for all computer purchases to ensure that all assets will be centrally received. To move forward with this recommendation, DIT will need a warehouse or location to physically store assets while waiting for configuration and deployment. 7. Annual Physical Inventory (Status: Not Implemented) Recommendation: Recommended that DIT periodically reconcile IT assets listed on the Fixed Asset Detail Report with the automated network and software inventory system to ensure all IT assets are properly recorded and included in the annual physical inventory. Any discrepancies should be investigated and resolved immediately. • Response: The Coronavirus pandemic has introduced new challenges to inventory assets as many devices have remained off, and thusly automated network scans have not been fully successful with ascertaining if assets are still in place. Without additional staff, dedicated to asset management, this will remain on ongoing issue. 8. Secured Disposal (Status: In Process) Recommendation: We understand that the Director of IT plans to issue a memo with the "Electronic Records Destruction Policy for Computer and Electronic Media" to the Department heads and managers requiring the transfer of all obsolete hard drives to DIT for destruction. Recommend the County review this policy at least annually and update accordingly. We also understand that the current computer deployment location is temporary. However, if DIT continues to use the facility, we recommend that additional physical security controls be implemented to safeguard IT assets and media from loss or theft. Response: We will request a secured facility and container to ensure assets and media are safeguarded from theft and/or loss. As a County, a review and agreement must be congruent on a record retention policy to include electronic documents and media. County of Hawaii is an Equal Opportunity Provider and Employer. IT Asset Management Follow-up Audit Department Response 117