Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Office Of State Auditor Audit topic
No spam. Unsubscribe anytime.
Legislative auditors find IT and asset-management gaps at Office of the State Auditor; state auditor outlines remediation plan
Summary
The Office of the Legislative Auditor (OLA) told the House State Government Finance Policy Committee on Feb. 20 that a performance audit of the Office of the State Auditor (OSA) found generally sound financial controls but multiple IT security and asset-management weaknesses that need remediation.
Get email alerts on the Office Of State Auditor Audit topic
No spam. Unsubscribe anytime.
The Office of the Legislative Auditor (OLA) told the House State Government Finance Policy Committee on Feb. 20 that a performance audit of the Office of the State Auditor (OSA) found generally sound financial controls but multiple IT security and asset-management weaknesses that need remediation.
The OLA’s deputy legislative auditor for the financial audit division, Lori Lyson, and IT audit director Mark Matheson presented the audit, saying the financial controls “generally had really, strong internal controls and followed legal criteria,” while the information-technology review identified seven IT-related findings and two asset-management findings that require action.
The nut graf: The OSA conducts audits of other state and local entities and holds sensitive statewide data, including materials tied to the single audit process. Auditors told the committee that the office’s role and the sensitivity of some datasets make strengthening IT and asset controls important even though the OSA is a relatively small operation and not required to participate in the statewide Minnesota IT Services program.
Most significant findings
- Financial controls: The OLA reported that OSA generally complied with significant financial requirements. The audit noted two asset-management weaknesses: six of 70 acquisitions tested during the scope period lacked assigned asset numbers and were not recorded in the OSA’s capital asset system; and the office had not completed a full physical inventory during the audit period. The auditors said the most recent partially completed physical inventory dated from February 2020 and recommended annual inventories and reconciliation of discrepancies.
- Asset examples and thresholds: The six unnumbered acquisitions included three desks, a mail sorter, a secure area network component and an audio-conferencing device. During the audit period the OSA reported approximately $21 million in payroll expenditures and about $3.3 million in nonpayroll expenditures. Auditors noted the OSA tracks any items costing $1,000 or more; Minnesota Management and Budget’s threshold for capital assets is $30,000 and the Department of Administration’s equipment threshold is $5,000. (These policy thresholds were discussed by OLA staff during the hearing.)
- IT security: Mark Matheson said auditors reviewed the information security program, inventory of IT hardware and software, security awareness training, identity and access management, physical security, logging and monitoring, and network protections. He said the OSA had implemented some best practices but that its control environment was “ad hoc” in places. The OLA listed gaps in documented policies and standards, infrequent risk assessments, lack of a vulnerability-tracking mechanism, outdated hardware and software, weaknesses in privileged-account authentication, and opportunities to improve logging and monitoring.
Quantitative details cited in the audit
- The OLA identified roughly 45 servers, network devices and printers that were more than 10 years old; a handful dated more than 20 years. - The audit period covered July 1, 2021, through Dec. 30, 2023. - Auditors said they found seven IT-related findings in total and two asset-management findings.
OSA response and remediation steps
State Auditor Julie Blaha, joined by operations director Matt Lindemann and new chief information officer Kathy Frazier, told the committee the office has already begun remediation. Blaha said the OSA had requested and received funding to hire IT staff in the last budget cycle and that the new positions reduced the need for additional funding to address the audit’s recommendations. "As a result, to implement these...findings, we will not need additional funding because this funding with the additional staff has put us in a good place," Blaha said.
Kathy Frazier, the OSA’s CIO, described specific actions: implementing two-factor authentication in the coming months; deploying managed detection/endpoint detection and response software last fall; hiring two additional IT staff since her arrival; contracting for planned penetration testing; and phasing out older infrastructure, including a plan to retire about seven servers during the current year. Frazier said she is developing a three-year technology roadmap that prioritizes security and shifts some workloads to cloud or software-as-a-service options to reduce local support burden.
Committee discussion and next steps
Members asked whether the OLA would follow up on the audit recommendations. OLA staff said the office has begun follow-up reviews of prior audit findings and typically performs follow-ups one to two years after an audit, depending on the finding. Representative Kelly M. (Rep. names as in transcript) and others urged clearer public tracking of remediation progress; OLA and OSA staff said the audit report includes the OSA’s response and that OLA will reassess implemented changes when it returns to constitutional-office reviews on its four-year rotation.
Several committee members—including Rep. Bonner, Rep. Kraft and Rep. Howard—emphasized that small agencies often lack IT staffing and that penetration testing and other advanced controls can be contracted if in-house capacity is limited. Audit staff said many recommendations align with commonly accepted frameworks such as NIST and the Center for Internet Security and that controls are prioritized in implementation groups so smaller offices can address foundational items first.
Why this matters locally
Because the state auditor’s office performs audits across government and stores data tied to statewide compliance efforts, the committee and auditors said strengthening asset-tracking and basic cyber hygiene reduces the risk that minor problems evolve into broader operational or security incidents. The OSA and OLA agreed to continue coordination; OLA will include the OSA in its follow-up schedule and OSA will report progress through its response channels and in future budget requests if additional resources are needed.
Ending
Committee Chair Nash thanked auditors and OSA officials and said the committee would invite the OSA back to present budget requests and an update on remediation. OLA and OSA representatives said they expected to track and report progress and that the next formal check will come through the OLA’s routine audit and any interim follow-up work.

