Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Internal Audit topic

No spam. Unsubscribe anytime.

Audit committee sets priorities: targeted cybersecurity controls review and benefits audit proposed

PORT WASHINGTON UNION FREE SCHOOL DISTRICT Audit Committee · April 15, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The committee received an update from internal auditor Dimitri Vantelestas on student data management work and cybersecurity monitoring tied to the NIST framework. Members agreed to recommend a targeted review of cybersecurity standard operating procedures as a separate engagement and to propose an internal audit of active and retiree benefits to the board.

Dimitri Vantelestas, the district’s internal auditor, updated the Audit Committee on ongoing work and proposed cycles. He said the student data management audit (registration, attendance, grades and eligibility) is in fieldwork and that a report will be ready for management in May and for committee review in June.

“We do plan to have the report for review with the management team by May,” Dimitri said, describing interviews, document requests, and planned testing of data migrations and grade-change controls.

On cybersecurity, Dimitri summarized monitoring aligned with the NIST Cybersecurity Framework and reminded the committee of a 2021–22 NIST gap analysis. He offered two options: a full NIST re‑gap analysis (comprehensive, higher cost) or a separate targeted engagement to assess the design of documented procedures and controls (a lower-cost, focused engagement). Committee members favored the targeted SOP/control design review in the near term, as a pragmatic step to memorialize procedures and improve operating effectiveness, with a full NIST gap re‑analysis to be considered later.

Committee members also reviewed audit-cycle history and risk ratings. Given prior coverage and current risk assessment, members agreed that the next included internal audit to propose to the board should be a benefits audit covering active and retiree benefits and related payroll/Medicaid/retiree-reimbursement processes; retiree benefits were last reviewed in 2021. Chair Julie Epstein asked Dimitri to provide an estimated cost for the cybersecurity SOP review by May 5 so the committee can present a complete recommendation to the board.