Lax security left employees’ data vulnerable
The Atlanta Journal-Constitution
An audit of state government’s accounting office found lax computer security that left thousands of state employees’ personal information vulnerable to theft by hackers.
No evidence was found that personal and financial information was stolen, according to the audit, released last week. But the report noted that weaknesses in the system allowed investigators to “gain full access to servers, databases and information.”
The review of the State Accounting Office’s information systems “revealed significant deficiencies in the protection of sensitive information and critical computer systems,” the Department of Audits and Accounts’ report says.
State Accounting Office officials did not return repeated messages for comment on the audit. The agency has already addressed many of the problems, however, according to its written response to the audit’s results.
Russell Hinton, the state auditor, said Wednesday while no evidence of fraud or loss of data was found, “we found some fairly significant control issues that [the Georgia Technology Authority] and the State Accounting Office are in the process of addressing.”
But John Thorton, director of the audit department’s state government division, said his team continues to review whether the security deficiencies led to improper spending.
“Anytime someone could access the system who was not authorized to do so, it increases the risk that some unauthorized transactions could have occurred,” Thorton said. “Work is still ongoing.”
The State Accounting Office manages the human resources systems for 185 state agencies and colleges through the PeopleSoft Financials and PeopleSoft Human Capital Management programs. Those systems provide accounting, purchasing, labor distribution, asset management, human resources, personnel administration and payroll processes to the majority of state government. The Georgia Technology Authority provides tech support for the systems.
The audit examined 15 areas and found that three were “high” risk areas, meaning “an immediate risk, directly impacting the confidentiality, integrity or availability of systems,” the report says. The rating also means the agency might not know if its system were attacked.
Five more areas were rated as “medium” risks, which could affect confidentiality and integrity of the system. The final seven areas were rated as low risks.
The high-risk problems largely involved inadequate encryption of confidential information, passwords or access keys. Some former employees and retirees from the State Accounting Office improperly retained access to internal systems; employees were often able to access information beyond their clearance level; and passwords were sometimes set to default or not changed according to policies.
While the report found serious security issues, one computer security expert said the real story is how common these types of deficiencies are. Detmar Straub, a professor of computer information systems at Georgia State University, said in an e-mail that “these deficiencies are not that unusual. Many, many organizations have lax security. Both public and private sector organizations suffer in this regard.”
The problem, Straub said, is that many organizations see information security as a “overhead and thus a drain on organizational resources.” Few organizational leaders, he wrote, “appreciate the true value of information security, or better put, the balancing of risk, costs, productivity and security measures.”
Inside ajc.com
Atlanta day trip getaways

Escape from the grind using our list of destinations that require only a tank of gas and a sense of adventure.
Essence of music

Music industry veteran Sylvia Rhone and Kelly Rowland were honored at the Essence Black Women in Music event.
Lady in red

Actress Minka Kelly is among the celebrities who walked the Heart Truth red dress fashion show in New York.
Pass the Haterade

Forbes' list of most disliked athletes is out, and Atlantans will find a familiar face tied for No. 1.
Is that really Lindsay?

Lindsay Lohan arrived at amfAR's annual kickoff to Fashion Week looking not so fresh-faced.
V-Day with the Angels

Victoria's Secret Angels celebrate Valentine's Day while showing off some the lingerie store's goods.
Services » Find the right people for the job
From our news partners
- Gallery: Week in photos
- Charlotte to attempt new world record for most people dressed as Waldo
- Necklace flushed down toilet returned months later
- Hold the mystery meat; military food gets upgrade
- Westboro Baptist Church to stage anti-gay protest at Powell boys' funeral
- Family of girl killed by dogs awarded $20K
- Nevada gaming revenues increase 2.8 percent in 2011; Strip figures up 5.1 percent
- Teen stabs grandmother over 90 times, wanted to upset uncle
- 20 most anticipated movies for 2012
- Social Security: Valentine's Day reminder of benefits
