Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Audit Cybersecurity topic

No spam. Unsubscribe anytime.

Audit committee flags purchasing and personnel paperwork issues; district says cybersecurity and disaster plans are in place

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The board’s audit committee reported minor findings in purchasing and personnel processing and circulated a corrective-action plan; the district also received a regional information-center review of cybersecurity and disaster-recovery practices and said core data are cloud-hosted.

The audit committee updated the Binghamton board on a recent internal audit and on information-technology reviews during the Sept. 16 meeting.

The committee said the internal audit focused on purchasing practices and processing of bills and personnel paperwork. Findings were described as relatively minor — examples included procurement and payment items such as gifts charged to incorrect funds at recognition events and personnel-form processing mistakes attributed in part to turnover in the personnel office — and the committee circulated a corrective-action plan that identifies process fixes, staff training needs and timelines for remediation.

Committee members also summarized a review by the Regional Information Center (RIC) that examined cybersecurity practices and the district’s disaster-recovery plan. RIC found that district data are largely cloud-hosted (the committee said much of the data reside in Amazon’s cloud services); the committee reported the district is “in good shape” for disaster recovery and has steps to strengthen procedures. The audit committee said more detailed reports will be circulated and that the board will vote to accept the internal-audit report at the October meeting.

The board did not take immediate corrective action at the meeting; the committee recommended staff training, procedural reminders and implementation of the corrective-action plan, and said the external audit and the proposed corrective steps will come back to the board for formal acceptance.