Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Audit topic

No spam. Unsubscribe anytime.

Legislative audit committee releases public cybersecurity audit of OIT, finds documentation gaps and partial implementation

Legislative Audit Committee
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Legislative Audit Committee released a January 2026 public audit of the Governor’s Office of Information Technology finding 12 audit findings and 85 recommendations; OIT leaders acknowledged documentation shortfalls and pledged reorganizations and monthly meetings with auditors to close remaining items.

The Legislative Audit Committee on January 15 released a public audit of the Governor’s Office of Information Technology (OIT) that found gaps in governance, documentation and training across the state’s information‑technology program.

The Office of the State Auditor (OSA) told the committee the follow‑up audit identified 12 findings and 85 recommendations related to cybersecurity resilience. OSA said OIT agreed with 18 recommendations, partially agreed with 30 and disagreed with 37. "We have to verify it with supporting evidence and documentation," OSA Chief IT Auditor Matt Devlin said during the presentation.

OIT Executive Director David Edinger acknowledged the agency fell short of expectations in documenting its remediation work. He told the committee OIT mobilized "hundreds of employees and thousands of work hours," but that the agency's submissions lacked the evidence OSA required to confirm full implementation. "We missed the ball on that documentation piece," Edinger said.

OSA recounted that the original 2023 resiliency audit produced 77 recommendations. In OSA's 2024 follow‑up it found 71 of those recommendations remained open; the 2025 follow‑up audit assessed OIT's implementation status as of June 30, 2025. OSA noted that where OIT reported broad implementation, auditors often found only partial implementation because OIT did not provide sufficient meeting notes, approvals, or other documentation.

The audit highlighted several governance issues, including: incomplete coordination with state agencies on a new tiered system for prioritizing consolidated systems; standard operating procedures for publishing and enforcing the Colorado Information Security Policies (CISPs) lacking approval dates or clear effective/enforcement distinctions; inconsistent glossary and terminology changes (such as replacing the term "business owner" with "agency"); and technical standards that appeared as "expired" or "retired" on OIT's public site while a tracking spreadsheet listed new standards not posted publicly.

On training and awareness, OSA said OIT did not implement May 2023 recommendations to provide role‑based security training to agency staff and OIT IT directors and could not produce documentation showing completion of training and acceptable‑use policy attestations or documentation of sanctions for noncompliance.

Devlin said the report includes 10 specific recommendations to improve OIT governance and internal control processes, including better audit tracking, clearer SOPs for policy changes, documenting agency coordination on system prioritization, and publishing minimum baseline security standards such as session timeout and backup frequency requirements.

OIT leaders told the committee they have taken steps to address shortcomings. Edinger said OIT has arranged monthly meetings with OSA starting next month and will consider organizational changes to clarify responsibility and increase resources dedicated to audit remediation. "We are confident we were confident that we had fully implemented nearly all of the recommendations," Edinger said, "but we were in a vacuum when it came to proving that to OSA." Katie Shakin, OIT’s interim chief technology officer, told members the agency identified 18 "life‑impacting" systems as a highest priority under a new five‑tier prioritization approach.

Committee members repeatedly pressed both OSA and OIT on whether the main gap was documentation or substantive technical work, and on timelines the legislature should expect for follow‑up. Representative Johnson asked whether updates could be provided "preferably before the end of this regular session" if the discrepancies were primarily documentation issues. Several members said they want clearer benchmarks and accountability for remediation work.

The committee approved release of the public report at the meeting. The agenda then moved to a confidential portion of the audit; a motion to go into executive session under Colorado law to discuss the confidential report was moved and seconded, but the provided transcript ends before a recorded vote on the executive session motion.

What’s next: OIT told the committee it believes six of eight remaining high‑priority recommendations are fully implemented and the remaining two were targeted for completion within 30 days of the Jan. 15 presentation. OSA recommended OIT finalize SOPs, clarify policy enforcement dates, publish technical standards promptly, and document agency coordination and training completion. The committee indicated it will continue oversight and requested follow‑up updates.

Sources: Office of the State Auditor presentation to the Legislative Audit Committee; statements by David Edinger and OIT staff at the Jan. 15 committee meeting.