Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the It Audit topic

No spam. Unsubscribe anytime.

City auditor says IT disaster‑recovery plan implemented but business‑impact analysis still pending

Baltimore City Board of Estimates · June 3, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The city auditor told the Board of Estimates that two of four prior IT audit findings are fully implemented while two remain partially implemented; officials said BCIT has completed a disaster‑recovery plan, compiled an application inventory of more than 500 apps and aims to finish critical‑system testing by September 2026.

The Baltimore City auditor presented a biennial performance‑audit follow‑up on information‑technology controls Tuesday, reporting that two of four prior recommendations were fully implemented and two were only partially completed. "We had four follow‑up findings. Two were implemented and two were partially implemented," City Auditor Josh Pash said.

Audits found that the city now has a documented disaster‑recovery plan and an updated administrative manual, both of which auditors counted as completed. But the audit found the city has not yet finished a citywide business‑impact analysis that would identify which agency applications are critical and require prioritized recovery. "They are still working with agencies to determine the critical applications by the agencies and they have not completed the business impact analysis," Pash said.

The auditor recommended continued work to establish governance, testing schedules and roles for disaster recovery. Director TJ Mayotte, speaking for BCIT, said the department compiled an inventory of more than 500 applications and is downgrading some apps after agency consultation. "Once that review process is complete, the application inventory will be done, and we expect that to be done by June," he said.

Mayotte described a tiered testing approach: tabletop exercises already completed, category 1 and 2 application testing underway, and plans to complete Category 0 (critical infrastructure and apps) testing by September 2026. He added the city has improved authentication and backup protections for administrative accounts. "For our critical accounts, we have several ways to authenticate…critical systems and accounts are vaulted, essentially, double protected," Mayotte said.

Board members tied the follow‑up to the city’s single‑audit material weakness over IT security and asked whether the remaining recommendations would address that finding. Pash noted the single audit covers broader citywide controls and said completing the disaster‑recovery plan and business‑impact analysis would help, but additional steps remain. Comptroller Bill Henry pressed for specific disaster scenarios and whether testing covered environmental impacts and server damage; Pash and Mayotte described flooding and remote‑work recovery as examples.

The board noted the item and auditors said they will return as part of the 2027 annual audit to track progress on the outstanding business‑impact analysis and testing schedules.

The item was presented, discussed at length, and noted by the board; no formal ordinance or spending decision was taken during the presentation.