Performance Audit Reports

State Information resources managed by the Centre of Registers

December 6, 2021

2021-12-09

National Audit Office: The Centre of Registers should pay more attention to data security and availability when managing public information resources

Picture for National Audit Office: The Centre of Registers should pay more attention to data security and availability when managing public information resourcesThe National Audit Office carried out an audit of the management of state information resources in the Centre of Registers, which revealed the opportunities for improvement of processes for development, supervision, service and maintenance of these resources. During the audit, it was analysed whether the processes for the management of state information resources comply with the requirements of legislation and international good practice recommendations. 

The audit found that the Centre of Registers does not always ensure the availability of managed state information resources. In 6 (out of 8) of critical public information resources the time of inactivity in some months in 2020 exceeded the limit of 8 hours allowed. 

The smooth use of state information resources may also be hampered by the unintended replacement of more than half (55 %) of staff performing important IT functions. If these employees were to leave the Centre of Registers or take long-term leave, urgent measures would have to be taken to avoid disrupting the operation of the systems. 

“The audit also found that the Centre of Registers did not follow some of the mandatory security requirements for information resources: for three years, almost half of all (11 out of 21) state information resources have not been subject to safety conformity assessments. Improvement of the management of state information resources managed by the Centre in accordance with the recommendations of IT good practice would ensure the availability of critical state information resources, sufficient high-speed and data security", — says Deputy Auditor General Živilė Kindurytė. 

The National Audit Office notes that the Centre of Registers takes measures to implement the State’s strategic expectations in the areas assigned to the entity. The Centre actually applies IT good practice recommendations in its management of IT processes and achieves its objectives to a large extent. In addition, it takes steps to bring IT processes to a higher level of capacity: improves IT processes and provides for measures for the implementation of recommendations. 

The Centre of Registers is the main manager of 25 critical state information resources. Among the information resources managed by the Centre are also such vital ones for the performance of state functions as the Electronic Information System for Health Services and Cooperation Infrastructure (E-Health), Real estate and legal entities registers, etc. These data are used by state institutions, municipalities, notaries, bailiffs, other legal and natural persons. Therefore, failures in these systems lead to disruptions in the provision of health services, the validation of transactions and the provision of other services. The Centre of Registers has to ensure that state information resources are managed in such a way that the data contained therein are reliable, secure and conveniently accessible to state and municipal institutions and bodies, businesses and the public. 

Following the audit, the National Audit Office issued recommendations on how to improve the management processes of state information resources. Proper implementation of the recommendations will contribute to the implementation of good practices in IT management, thus ensuring high availability of critical state information resources and data security.