Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Internal Audit Information Security topic
No spam. Unsubscribe anytime.
TAHC audit subcommittee approves information-resources audit and updated internal audit charter
Summary
The Texas Animal Health Commission (TAHC) audit subcommittee approved an internal audit of information resources and adopted an updated internal audit charter at a Feb. 25, 2025 meeting.
Get email alerts on the Internal Audit Information Security topic
No spam. Unsubscribe anytime.
The Texas Animal Health Commission (TAHC) audit subcommittee approved an internal audit of information resources and adopted an updated internal audit charter at a Feb. 25, 2025 meeting.
The internal audit, presented by Rufus Mundy, found that the agency has implemented security controls but lacks documented, formal risk-assessment processes and has not formally designated an information security officer (ISO). The subcommittee voted to accept the audit report and to approve revisions to the internal audit charter that align the agency’s audit function with Institute of Internal Auditors professional standards.
The audit presentation said the review focused on compliance with Texas Administrative Code, chapter 202 (TAC 202), which sets minimum information security and cybersecurity responsibilities for state agencies. Mundy told the committee that the agency has controls for approving access to information resources, protecting data and monitoring systems, and that contract terms for file services appear to comply with TAC 202. "There is a system in place," Mundy said, "but the system is not documented." He told the subcommittee there is no evidence a designated ISO has been formally appointed and that ISO duties have been performed by the agency’s IT director.
Mundy recommended the agency review TAC 202 and implement controls to ensure continued compliance, including designating an ISO separate from the IT director. A subcommittee member asked whether the recommendation should be worded specifically to direct the agency to designate an ISO separate from the IT director; Mundy answered that the agency should review the relevant provisions of TAC 202 to determine the appropriate designation and role definitions.
Separately, the subcommittee reviewed and approved an updated internal audit charter. Mundy said the charter was revised to reflect changes in the Institute of Internal Auditors' standards in February 2025 and to spell out the internal audit function’s purpose, responsibilities and required principles such as integrity, objectivity, confidentiality, planning and reporting. He said the charter requires formal authorization by the commission and signatures by the subcommittee chair, the agency executive director and the general counsel.
Votes at a glance
- Approval of Nov. 12, 2024 meeting minutes — motion approved by voice vote; tally not specified (quorum recorded as two members present, one absent). - Approval of the internal audit of information resources (audit report referencing TAC 202) — motion approved by voice vote; tally not specified (quorum recorded as two members present, one absent). - Approval of updated internal audit charter (aligned with Institute of Internal Auditors standards) — motion approved by voice vote; tally not specified (quorum recorded as two members present, one absent). - Motion to adjourn — approved by voice vote; tally not specified (quorum recorded as two members present, one absent).
The meeting record shows two subcommittee members present with one member absent. The audit presentation noted the agency lacked a documented formal risk assessment and that some ISO responsibilities were being carried out by the IT director; the audit recommended separating those duties and documenting roles and periodic reviews to identify vulnerabilities. The charter changes are intended to bring the internal audit function into alignment with the IIA professional practice framework and the Texas Internal Audit Act (Government Code, chapter 2102), as described in the presentation.
No public comments were received at the meeting; the committee adjourned after approving the motions.

