"We tested five of the 11 state IT security standards at five selected agencies, and found close to 350 instances – out of 1,035 security standard components tested – in which these agencies are not in full compliance," said an audit released on Monday from the Washington State Auditor's Office.
New performance audit out: Is the state's IT security posture strong enough to prevent hacking and other attacks? http://t.co/rQNfsrdfLu
— WA State Auditor (@WaStateAuditor) 15 декабря 2014
Three areas were deemed most concerning by the report, for which auditors ran a number of application security tests to find out whether the agencies' applications were vulnerable to an attack. Applications security, data security and operations management were subject to the most instances of noncompliance with the state's IT standards, which the document said "closely align with leading practices," but are in practice not being met in a large number of cases.
Examples of noncompliance included a lack of documentation for application changes, inadequate use of encryption and failure to send backup data to an offsite location.