West Canada Valley Central School District – Access to the Student Information System (2016M-96)

Issued Date
July 08, 2016

Purpose of Audit

The purpose of our audit was to examine information technology (IT) access controls over personal, private and sensitive information (PPSI) in the District’s student information system (SIS) for the period July 1, 2014 through January 31, 2016.

Background

The West Canada Valley Central School District is located in the Towns of Fairfield, Herkimer, Manheim, Newport, Norway and Schuyler in Herkimer County and the Town of Deerfield in Oneida County. The District, which operates two schools with 679 students, is governed by an elected seven-member Board of Education. Budgeted appropriations for the 2015-16 fiscal year totaled approximately $16 million.

Key Findings

  • Twenty-nine users without grade change responsibilities had been granted permission to change certain grades in the SIS.
  • Permissions and accounts were not properly assigned or maintained in accordance with employees’ job responsibilities and changing employment status.
  • Unnecessary accounts could be used to inappropriately access the SIS

Key Recommendations

  • Communicate the Student Grading Information Systems policy to all District employees and provide training as needed to clarify roles and responsibilities.
  • Evaluate permissions currently granted to each SIS user, including MORIC employees, and remove any permissions deemed unnecessary.
  • Evaluate all existing SIS user accounts and remove any accounts deemed unnecessary.