State -Wide Infor mation Syste ms Planning and Manage me nt
a r e port by
the Office of Program Evaluation & Government Accountability
INT E RIM RE PORT
DECEMBER
2005
OPEGA REVIEW
2005 the Office of Program Evaluation & Government - - PowerPoint PPT Presentation
OPEGA REVIEW INT E RIM RE PORT State -Wide Infor mation Syste ms Planning and Manage me nt DECEMBER a r e port by 2005 the Office of Program Evaluation & Government Accountability About the Re vie w Slide 2 OPEGA Interim
a r e port by
the Office of Program Evaluation & Government Accountability
INT E RIM RE PORT
DECEMBER
OPEGA REVIEW
OPEGA Interim Report: State-Wide Information Systems Management Slide 2
OPEGA Interim Report: State-Wide Information Systems Management Slide 3
OPE GA Se e ks to Answe r the Que stion…
OPEGA Interim Report: State-Wide Information Systems Management Slide 4
OPEGA Interim Report: State-Wide Information Systems Management Slide 5
OPEGA Interim Report: State-Wide Information Systems Management Slide 6
OPEGA Interim Report: State-Wide Information Systems Management Slide 7
Q4 ‘10 Q3 ‘10 Q1 ‘10 Q1 ‘10 Q3 ‘09 Q2 ‘09 Q1 ‘09 Q4 ‘08 Q3 ‘08 Q2 ‘08 Q1 ‘08 Q4 ‘07 Q3 ‘07 Q2 ‘07 Q1 ‘07 Q4 ‘06 Q3 ‘06 Q2 ‘06 Q1 ‘06 Q4 ‘05
Inhe r ite d c ur r e nt c onditions F r
e 2005 Ne w OIT Manage me nt te am hir e d Se pt ‘05 F ully imple me nte d E nte r pr ise Or ganization 2008 - 2010 OPE GA/ JWI Risk Asse ssme nt Se pt-Nov ‘05
independent IT “universes” with varying resources and priorities
planning & managing from an “enterprise” perspective
reorganization was beginning.
OPEGA Interim Report: State-Wide Information Systems Management Slide 8
Government/Quality Objectives What are we trying to ac hie ve ? Risks or Threats to Achievement What c o uld go wro ng? Ho w like ly is it? What’s the po te ntial impac t? Controls Ho w do we pre ve nt it, de te c t it o r re duc e its impac t?
Hig h Risk L
Risk
L ike lihood Impac t
Exposure What’s the like liho o d and impac t with c o ntro ls in plac e ?
OPEGA Interim Report: State-Wide Information Systems Management Slide 9
OPEGA Interim Report: State-Wide Information Systems Management Slide 10
OPEGA Interim Report: State-Wide Information Systems Management Slide 11
OPEGA Interim Report: State-Wide Information Systems Management Slide 12
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
Sunrise on Cobbossee Lake
Confidential and Proprietary
14
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
15
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
State of Maine / Results of OPEGA IS/IT Risk Assessment
Sunset on Cobbossee Lake
Confidential and Proprietary
17
State of Maine / Results of OPEGA IT Risk Assessment
OIT and agencies
Control Objectives for Information and Related Technologies (CobiT) standards
Confidential and Proprietary
18
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
Pemaquid Lighthouse
Confidential and Proprietary
20
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
21
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
In Camden Harbor
Confidential and Proprietary
23
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
24
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
At Harvey Pond
Confidential and Proprietary
26
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
27
with agency BCP’s strongly recommended
State of Maine / Results of OPEGA IT Risk Assessment
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
Mooselookmeguntic Lake
Confidential and Proprietary
29
for many network, WAN and stand alone computer systems
protection against hackers was noted as a positive in this assessment
security were noted
recommended actions
State of Maine / Results of OPEGA IT Risk Assessment High-Risk: Security
Confidential and Proprietary
30
State of Maine / Results of OPEGA IT Risk Assessment High-Risk: Project Management
adaptable to managing capital IT projects
methodology in place as a standard
projects as they will own the resulting system
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
At Small Falls
Confidential and Proprietary
32
State of Maine / Results of OPEGA IT Risk Assessment
integrated into procurement process
should be adopted and integrated into procurement process
industry standard for Project Managers
High-Risk: Project Management
Confidential and Proprietary
33
State of Maine / Results of OPEGA IT Risk Assessment
High-Risk: Procedures and Documentation
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
At Small Falls
Confidential and Proprietary
35
State of Maine / Results of OPEGA IT Risk Assessment
content standards which will ensure the completeness, identification and protection of documents
requirements for systems, policies and procedures
should be implemented for key IT documents
and approval of key plans and strategy documents should be immediately implemented High-Risk: Procedures and Documentation
Confidential and Proprietary
36
State of Maine / Results of OPEGA IT Risk Assessment Positives:
committed to providing quality IT services
begun to hold regular meetings
should serve as instructive examples
by many agencies
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
At Sand Pond
Confidential and Proprietary
38
State of Maine / Results of OPEGA IT Risk Assessment Positives:
sound practices are in use
daily, weekly and monthly basis
backup tapes
and VPN access to the network
Systems & relatively new hardware are in use
Confidential and Proprietary
39
State of Maine / Results of OPEGA IT Risk Assessment Summary:
service can be realized through IT consolidation
reasonably be expected to require between three to five years to fully realize the benefits
continuing IT management focus and strong support from business management within the State of Maine’s Executive Branch agencies
more process-driven IT environment with standardized service offerings
Confidential and Proprietary
40
State of Maine / Results of OPEGA IT Risk Assessment Summary:
IT consolidation
possible, with an internal IT audit staff or OPEGA
is the right thing to do
Maine can reap the benefits
Confidential and Proprietary
State of Maine / Results of OPEGA IT Risk Assessment
A Bright Sunrise for OIT
Confidential and Proprietary
State of Maine / Results of OPEGA IS/IT Risk Assessment Thank you for all your support … From your JWI IT Risk Assessment Team !!
OPEGA Interim Report: State-Wide Information Systems Management Slide 43
OPEGA Interim Report: State-Wide Information Systems Management Slide 44
Current level of overall risk exposure for State Information Systems and Technology is too high.
2 4 6 8 10 12 Number of Findings High Medium Low
Issues by Risk Severity & Number Found
High 7 Medium 11 Low 3
OPEGA Interim Report: State-Wide Information Systems Management Slide 45
Detailed Issues by IT Function
18% 10% 10% 5% 18% 19% 10% 10%
General Administrative Information Security Change Management Business Continuity Planning Operations Management Network OS, Database, and Application End-User Computing
JWI identified 21 issues involving 8 different IT functions.
OPEGA Interim Report: State-Wide Information Systems Management Slide 46
OPEGA Interim Report: State-Wide Information Systems Management Slide 47
and remedies for them were already in OIT’s Strategic plan.
responsibility will also be integrated into the Strategic Plan.
addressing issues within their area of responsibility in first quarter of 2006.
resource availability.
OPEGA Interim Report: State-Wide Information Systems Management Slide 48