Information Technology

Board Oversight of Cybersecurity Risk Management at Vancouver Island University

Report cover showing Vancouver Island University campus
Date: 
August 2023

Across B.C., each university’s board of governors has a critical role in overseeing cybersecurity risk management. They review strategies to protect IT systems and personal data, and they hold university management accountable for those strategies.

This audit focused on the board of Vancouver Island University and its oversight of cybersecurity risk management at VIU. 

audit, report, auditor general, B.C., IT, cybersecurity, oversight, risk management

Managing Cybersecurity in the Telework Environment

cover page showing woman working at home with laptop computer
Date: 
March 2022

The number of B.C. government teleworkers grew 20-fold after the COVID-19 pandemic started​. Teleworking has many benefits but it can also pose increased risk to sensitive government data. Our audit focused on the Office of the Chief Information Officer's responsibility for cybersecurity risk management in the government telework environment. It looked at the OCIO's strategic activities, such as risk assessment, telework-related policies, data protection measures, and cybersecurity training and guidance. 
 

telework cybersecurity audit report ocio office of the chief information officer

Management of Medical Device Cybersecurity at the Provincial Health Services Authority

Date: 
February 2021

This audit examined whether the Provincial Health Services Authority (PHSA) is effectively managing medical device cybersecurity risk to protect patients.

IT medical device cybersecurity cyber security health information technology
News Release: 

The B.C. Government’s Internal Directory Account Management

Date: 
August 2019

In this audit, we looked at whether five selected ministries, and their related branches and agencies, had designed and implemented key controls for protecting government information and information assets from unauthorized access.

IDIR information security standard OCIO controls
News Release: 

Detection and Response to Cybersecurity Threats on BC Hydro’s Industrial Control Systems

Date: 
March 2019

In this audit, we looked at whether BC Hydro was effectively managing its cybersecurity risk by detecting, and responding to, cybersecurity incidents on its industrial control systems, which form an integral part of its electric power infrastructure.

ICS BC Hydro Cybersecurity power standards critical detection response

An Independent Audit of the Regional Transportation Management Centre's Cybersecurity Controls

Date: 
October 2017

The Ministry of Transportation and Infrastructure’s Regional Transportation Management Centre (RTMC) manages traffic flow at major bridges and roadways throughout the province. This audit looked to see if the RTMC had foundational cybersecurity controls in place. It didn’t assess the effectiveness of these controls.

transportation management cybersecurity controls regional transit infrastructure bridge tunnel
Report: 
News Release: 

Progress Audit: Integrated Case Management System

Date: 
February 2017

This progress audit looked at whether the Ministry of Social Development and Social Innovation has fairly and accurately represented its progress implementing the recommendations made in Integrated Case Management System, originally published in March 2015.

progress audit integrated case management system

Workstation Support Services Contract: An Audit of Due Diligence

Date: 
November 2016

This audit looked at whether the Ministry of Technology, Innovation and Citizens' Services and Health Shared Services BC completed appropriate due diligence when expanding government's 2004 agreement with the service provider to include the health authorities, and when extending the timeframe of the original agreement.

health computer workstation IT decision-making

Pages

Subscribe to RSS - Information Technology