Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Jis It Audit topic

No spam. Unsubscribe anytime.

IT audit flags change-management risk at Justice Integration Services; committee hears remediation suggestions

2158980 · January 24, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Consultants from Fraser and Dieter presented an IT audit of Justice Integration Services (JIS), identifying a high-risk change-management finding, three medium security-area findings and two low-priority items; staff described operational constraints and proposed mitigating controls.

External consultants Fraser and Dieter presented the results of an information-systems audit of Justice Integration Services and told the Audit Committee the review found gaps in change management, logical access, application security, information security and business continuity.

Brandon Sherman, national management partner at Fraser and Dieter, opened the presentation and said the consultants focused on IT general controls for systems JIS operates and supports. “We were engaged to do an IT audit over the Justice Integration Services department,” Sherman said.

Tanner Hazouri, a Fraser and Dieter consultant, summarized the findings: one high-risk item, three medium-risk items and two low-risk items. The high-risk finding relates to change management for code and system changes affecting applications used across multiple Metro departments; consultants said that in some cases a single developer could both make and promote changes into production without an automated segregation control in place. Hazouri said the committee’s concern is heightened because JIS provides shared services to many judiciary and public-safety applications (the audit cited CJIS, GEMS and TVS among the systems supported).

JIS staff described the current development workflow and staffing limitations. Nick Key, assistant director for JIS, said the development process includes a separate development environment, promotion to test, business-analyst testing and customer testing before production; database changes are promoted by DBAs. Key noted the JIS shop is small: “It’s really a staff of about 5 at the moment,” he said, and that full segregation of duties would be difficult to achieve without additional staffing.

Consultants recommended practical mitigations such as running back-end audit logs and monthly reviews of promotions to production, pairing production promotions with development notes and source-control records, and risk-ranking change activity to prioritize oversight. Hazouri noted that the team did test samples of actual changes and found standard approvals and testing documented for many of the sampled items, even though documentation and systematic controls were inconsistent across the whole environment.

Committee members raised operational implications, including whether changes could affect data used for judiciary operations. Members also discussed access to the NCIC federal database for judges and magistrates; consultants and JIS staff said NCIC access is restricted by federal rules and that some counties host data in secure environments other than Metro’s current setup. Key said Metro does not currently have NCIC access and that requirements for certification and secure hosting are stringent.

The consultants characterized many of the findings as common for smaller development shops and emphasized that remedies can range from low-cost compensating controls (regular audit reviews) to staffing or system-configuration changes if the committee prioritizes systematic segregation. The committee thanked the consultants; no formal vote was required to receive the audit presentation.