Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the It Security Audits topic

No spam. Unsubscribe anytime.

Post Audit: About half of small state and local entities failed key IT security controls; committee holds executive session, approves audits

Legislative Post Audit Committee · February 5, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Legislative Post Audit staff told the committee that, across 15 audits over two years, seven entities scored below 50% on IT security controls. The committee recessed to an executive session on the Board of Veterinary Examiners' IT security, then approved the presented audits as part of its consent calendar.

Alex Gard, principal IT auditor with the Legislative Post Audit division, told the Legislative Post Audit Committee that the two‑year summary of IT security work covering 15 audited entities shows mixed results: "the short answer is about half did and and half did not," he said, later adding that "7 of the 15 entities audited in the past 2 years did not substantially comply with applicable IT security standards and best practices."

The committee met in Room 546 South of the State House and first recessed into an executive session to discuss the IT security measures protecting the Board of Veterinary Examiners. Representative Sawyer moved that the open meeting be recessed for a closed executive meeting "pursuant to KSA 75 4 3 1 9 a to discuss matters relating to the security measures that protect the information systems of the Board of Veterinary Examiners," and the motion was seconded and adopted by voice vote. Chris (legislative staff) identified the people who could remain for that executive session, including Dr. Mark Olson, Jeff Maxon, John Godfrey and Legislative Post Audit staff members listed by name.

Gard framed the audit's purpose as checking whether state and local entities follow significant IT security controls and best practices. He said auditors evaluated roughly 50 control items across 10 control areas (awarding 0–3 points per item), converted totals to percentages, and assessed overall assurance ratings. The summary highlighted three recurring problem areas: vulnerability remediation (scanning and patching), continuity of operations and disaster recovery planning and testing, and incident response. Gard said many entities either performed incomplete or uncredentialed vulnerability scans or did not apply vendor patches; several maintained unsupported software versions. He also said many entities lacked tested disaster recovery plans and had management‑process weaknesses such as incomplete asset inventories, weak contract management and missing formal information security officer designations.

Gard described likely root causes as insufficient top‑management attention and oversight, inadequate staff and resources, and poor contractor administration. He said entities that invested in IT security staffing and resources tended to have better outcomes. The summary report does not make recommendations at the summary level; each audited entity received its own report with specific recommendations.

After the presentation, the committee considered its consent calendar. Kristen summarized the consent items, which included approval of draft minutes from the Jan. 21 and Jan. 28 meetings and acceptance of the IT security audits presented that day (including the Board of Veterinary Examiners audit discussed in executive session and the two‑year summary). No members objected and the consent calendar was adopted.

Members also discussed scheduling and audits still underway. Chris listed several audits in progress (K‑State/KU admissions, TANF and SNAP error rates, the fire marshal, industrial revenue bonds, K‑12 extracurricular and bilingual policies, the historic rehabilitation tax credit limited scope and a slate of IT security audits for 2026) and advised that the committee typically picks topics at its spring meeting (the first regularly scheduled meeting after first adjournment), historically held the day before veto session. Chris said a survey to all 165 legislators had produced about 14 responses after roughly two weeks.

Senator Tyson asked whether the committee had ever audited the CALIS system and whether a historical financial audit of that system was possible, noting reported problems. Chris responded that, to his knowledge, the office had not audited CALIS and cautioned that auditing legislative systems can raise conflict‑of‑interest concerns because the audit office is legislative staff; he said the office could work with revisors or follow committee preference if members wished to pursue it.

The committee adjourned after the business was completed; staff said members will be notified when the next meeting is scheduled, likely in late March.