De La Rosa questions audit findings on technical control weaknesses
De La Rosa asks about confidential weaknesses in system monitoring, unsupported systems, and firewalls identified in the comptroller's audit. DOE officials confirm changes have been made or are planned but decline to disclose specifics for security reasons. De La Rosa presses for status updates on each recommendation.
Okay, I want to move on to my other questions, but I am interested in hearing what steps since 2024, what changes you've made besides saying something different in the Chancellor's regulations and sending out more emails in Principles Digest is being done to do this
critical training that was identified in the Comptroller's report, the audit.
The audit also identified weaknesses in DOE's technical controls that were not disclosed publicly because they were confidential, correct?
Yes, that's right.
So is the DOE in a position today to share more information about those weaknesses and what it's done to remediate them?
I don't believe we're in the position to disclose.
I think part of the reason why that portion of the audit report was kept confidential is because there's information in there that could potentially jeopardize our information technology assets.
Security posture.
Like your mom's made a name last four of your social and first pet's name?
Something like that.
Something like that.
But what that means to me also,
I'll say the audit states the weaknesses involved system monitoring, unsupported systems, and firewalls, correct?
Yes, that's right.
And have any changes been made to your systems to improve system monitoring and firewalls and other unsupported systems?
I could defer to DIT on that, as far as I know that work is underway.
The answer is yes.
The changes have been made or we're talking about doing the work?
Both.
Tell me more.
I don't really want to go too far past what has already been disclosed with the areas.
And this is...
This is common practice in a security, the security side of an audit, that some of the information is not disclosed, disclosed publicly.
But it was disclosed to us, and to the extent that we said, yes, we agree, and could make the technical changes to improve security, we've either planned to do that or have done it.
So this, again, this is a report, I just...
From 2024, and they're in a confidential report, you just shared that there were specific recommendations made in the confidential report.
In those two years, in addition to whatever changes that you are implementing,
outside of the recommendations.
In those two years, have you implemented the recommendations made by the controller's report?
Sorry, can I just interject?
Please.
What is the 2024 date that you're referring to?
I have a report.
The data was from 2024 in the report.
I apologize.
So how many of those?
Yeah, so, Chair, please, thank you.
I'll try to parse this because I would like to be able to answer the question.
Yes, thank you.
But let's say there were five or six recommendations.
Without disclosing specifically what they were, I think it would be appropriate for us to look at those and provide back as much information as we can about the status of each one of those.
Yeah.
And I think, I mean, this is all part of a pattern, right?
I mean, everyone from the DOE.
And the council, I think we care a lot about the same things, but what we're interested in is the implementation of a policy that keeps our kids safe and keeps our kids learning.
So I want to turn over second round to...