Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Education It Security topic
No spam. Unsubscribe anytime.
Audit finds gaps in school accounting IT access controls across 20 districts; recommends KSDE templates and local fixes
Summary
A Legislative Post Audit of 20 school districts found none had adequate IT access controls across account‑management, identity‑management and user‑limits categories; auditors recommended KSDE provide templates and districts implement stronger practices, including multi‑factor authentication and documented account change procedures.
Get email alerts on the Education It Security topic
No spam. Unsubscribe anytime.
Mori, who supervised an audit for Legislative Post Audit, told the committee that auditors reviewed IT access controls for accounting systems in 20 school districts selected by size and geography and found that none of the districts had adequate controls across all three evaluated categories (account management, identity management and user‑limits).
Auditors identified 12 specific controls drawn from state and national best practices. In account management, only one district had adequate formal procedures and timely documentation for account creation and deprovisioning. In identity management, four districts had adequate practices across all controls; while most districts used unique user IDs and password rules, fewer than half required multi‑factor authentication. Districts performed better on user‑limits (segregation of duties, approval for high‑dollar purchases), with 11 of 20 meeting all five controls in that category.
Mori said few districts had adequate written policies documenting access-control expectations. Auditors warned that inadequate controls increase the risk of unauthorized access, ransomware, phishing, or fraudulent modification of financial records. The report recommended KSDE develop templates and resources and recommended that districts implement the identified practices. Both KSDE and the districts agreed to take steps to implement the recommendations, Mori said.
Committee members thanked the audit team and indicated follow-up work may take time; the committee did not take formal legislative action during the hearing.

