Auditor General mini logo    Summary

Report Number:

2006-018

Report Title:

Florida Atlantic University - SCT Banner System Payroll Module

Report Period:

02/2005 - 05/2005

Release Date:

08/31/2005


Florida Atlantic University is a public university with multiple campuses in south Florida.  The University uses the SCT Banner enterprise resource planning (ERP) software for both its human resource management and financial management applications.  SCT Banner operates in an Internet-based environment supported by the Information Resource Management (IRM) department at the University. IRM is organizationally placed under the Associate Provost and Chief Information Officer and is located within the computing center at the main campus in Boca Raton. 

Our audit focused on evaluating selected application controls related to the SCT Banner System Payroll Module, as implemented by the University, and selected general controls within the overall information technology (IT) environment applicable to the University for the period February 2005 through May 2005.  We also evaluated University actions taken in response to selected IT-related deficiencies noted in audit report No. 2004-013.

As described below, we noted deficiencies in certain controls related to the University’s functions and practices. 

Finding No. 1:     The University had not developed an entitywide security program to ensure that exposures and vulnerabilities of IT resources had been sufficiently assessed by management and addressed through enforced user and system security controls.   Additionally, during our field work, the University had not established a security management structure with a central figure (Information Security Manager or similar function) assigned the responsibility of overseeing the security program.

Finding No. 2:    Deficiencies were noted in the University’s access security controls within the SCT Banner application environment.

Finding No. 3:    Improvements were needed in certain security controls within the overall operations of the application and the supporting network environment at the University.  


The University provided responses to our preliminary and tentative findings. This letter is included in its entirety at the end of this report.