Performance Audit Reports

General and Creation Control of Information Systems of the Ministry of Foreign Affairs

January 31, 2013

2013-02-14

More reliable safeguards required for the information system of the Ministry of Foreign Affairs

Picture for More reliable safeguards required for the information system of the Ministry of Foreign Affairs

The Ministry of Foreign Affairs (MFA) uses information systems which, among other things, process personal data and classified information marked as restricted. In view of the importance of the data processed in the systems, the National Audit Office conducted an audit of the information systems of the MFA and analysed whether they are properly managed.

“The Ministry of Foreign Affairs has achieved considerable progress in the management of its information systems, however, there are areas where the management still needs improvement. It is particularly important that in the event of unforeseen situations the ministry is able to ensure information security and business continuity”, said Auditor General Giedre Švedienė.

The audit revealed certain deficiencies in the management and security of the information systems of the ministry. For example, there is no clear description of the current e-data flows, the IT management lacks a stronger connection between business processes and information technologies, no authorised persons of data management have been appointed, there is a lack of control of personal data processing. The auditors found that the management of restricted classified information at the MFA is not sufficiently secure. Documents which regulate handling of such information have not been reviewed and updated.

The ministry is insufficiently prepared to ensure continuity of information systems in case of emergency or unforeseen situations because the Information Systems Continuity Management Plan has not been tested, the Plan does not provide for priorities of the recovery of information systems, no persons responsible for maintenance of IT equipment have been appointed, data backup procedures have not been described. So in the event of an unforeseen or emergency situation, the operation of the information systems of the MFA may be disrupted and the information may be irreversibly lost.

The information system of the MFA has been upgraded since 2008. However, given the fact that this process takes several years, a detailed plan is needed on the stages of this process. The information system specification has not been updated since 1998, therefore there is an increasing risk that the functions of the upgraded information system will not meet the demands of the ministry which have already changed during such a long period and so the goal of the upgrading will not be achieved.

The National Audit Office provided recommendations to the Ministry of Foreign Affairs on how to improve the management of the information systems and to better ensure the security of the information at the ministry. The ministry started implementing some of these recommendations already during the audit.