JEFFERSON CITY, Mo. -- A state audit released Monday identified several problems with the computer system security of the Missouri Department of Transportation.
Auditors warned that MoDOT's computer system is "susceptible to threats and vulnerabilities including unauthorized use and disclosure of data." The audit also found that the transportation department has not implemented a disaster recovery plan for its network, which auditors warn means that there is no way to guarantee that MoDOT's computers could be quickly restored.
A MoDOT spokesman said Monday the department's computer system is secure and that the department's network security team is reviewing the audits findings and suggested changes.
"We have a very safe and very secure set up that is continually monitored," spokesman Jeff Briggs said. "However, we appreciate the auditor's review, and it pointed out some practices that are worth reviewing. You can always improve."
The audit's recommendations include creating a written, approved disaster recovery plan and establishing written policies for assessing and dealing with risks to the computer system. The review also suggested the transportation department develop a system to close inactive network accounts.
Auditors found that 263 former department employees still had computer network access, 630 accounts had never been accessed and 483 had not been accessed in more than a year.
Briggs said simply the existence of a network account didn't pose an imminent security threat because the former employees would still have needed to get access to a MoDOT computer and the right password.
He said the transportation department will regularly review existing network accounts and is studying how to set up a system in which network access is automatically terminated when an employee leaves the department.
Auditors also suggested that MoDOT start conducting regular background checks of employees in sensitive positions. Currently, the department screens new hires, those that transfer into certain sensitive positions and new contractors.
Earlier this year, MoDOT established an information systems security team to evaluate the department's computer system security.
Connect with the Southeast Missourian Newsroom:
For corrections to this story or other insights for the editor, click here. To submit a letter to the editor, click here. To learn about the Southeast Missourian’s AI Policy, click here.