2014-02-04
National Audit Office: there are many information systems at the Ministry of Agriculture but too little efficiency

The Ministry of Agriculture manages 32 information systems and registers where data, including personal data, is collected and processed. Of these, 24 ones are controlled, developed and upgraded by a state enterprise subordinate to the Ministry of Agriculture, the Agriculture Information and Rural Business Centre. The National Audit Office conducted an audit to assess the overall and development control of the information systems of the Ministry of Agriculture (MoA). “The audit found that the Ministry is failing to comply with legislative requirements when controlling and developing information resources, it does not have information on the development and maintenance costs of various registers and information. Also, a number of shortcomings in controlling security of information resources and electronic information were identified,” said Auditor General Giedrė Švedienė summing up the audit results.
The Ministry of Agriculture invests in information technology (IT) in accordance with the general strategy and objectives of the organisation; however, it has not been addressing strategic IT management issues so that the key demands of its business are connected to the opportunities provided by IT. It was also found that the MoA has no information architecture model of the information systems and registers managed thereby in place and no accurate information on the amount of its information resources. To be able to ensure efficient investment, coordination of the demands of activity and opportunities offered by IT should be strengthened by establishing an organisational structure (committee, commission or working group) consisting of business process managers and IT representatives of the Ministry of Agriculture, which should consider how IT should be used to enhance automation of IT business processes.
The auditors identified that 27 out of 32 information resources managed by the Ministry were developed in breach of legislative requirements and without mandatory documentation – provisions and specifications – in place, thus it is not possible to determine whether these resources are in line with business requirements and whether all functions required for the business have been introduced. The Ministry does not ensure compliance with the requirements for the security of information resources laid down in legislation and procedures approved by the Ministry, because data security regulations and documents implementing the security policy have been not approved for all information resources, so the security of e-information depends only on the awareness of IT staff. Also, no risk and security compliance assessments are carried out at the frequency established in legislation and for all systems managed by the Ministry, which results in failure to make sure whether appropriate and sufficient security measures have been chosen and to evaluate compliance with these measures.
In addition to other shortcomings in the processing of personal data, the audit also found that personal data of the Ministry of Agriculture is processed in 14 information systems and registers, however, not all purposes of the processing have been entered in the Register of Controllers of Personal Data. For these reasons, the Ministry fails to ensure control over the use of personal data and people are not able to know to what extent their data is processed.
To improve the management and ensure security of the information systems of the MoA, the National Audit Office recommended strengthening the strategic management of IT, establishing an information architecture model and eliminating non-compliance with legislation. During the audit, the Ministry implemented some of the recommendations on the efficiency of the use of funds allocated for the development and maintenance of information resources and approved a Methodology for determining the cost of developing and maintaining information resources and other services.