Expands the main menu

Breadcrumb

Audit Reports

Jul
13
2015
Report Number:
IT-AR-15-007
Report Type:
Audit Reports
Category: Technology

Software Inventory Management – Greater Boston District

Background 

Software management provides processes for managing inventories, license agreements, and monitoring software assets. Effective software management allows organizations to maintain an accurate software inventory to improve accountability, security, and compliance. Reliable software inventories are necessary to effectively test, evaluate, monitor, and manage information system controls. 

 

The U.S. Postal Service Office of Inspector General’s Information Technology Security Risk Model identified the Greater Boston District as the highest risk for security events in fiscal year 2014. Having an inventory of authorized and unauthorized software ranks second on the list of the 20 most critical security controls in the industry. To respond effectively to emerging threats and detect unauthorized software, the Postal Service must manage and monitor its software inventories.

 

 Our objective was to evaluate the effectiveness of the Postal Service’s software inventory management practices in the Greater Boston District. What The OIG Found Effective software management practices are not in place to adequately protect and safeguard information resources in the Greater Boston District. Specifically, there are no clearly defined policies and procedures for the software inventory management process including: roles and responsibilities, systems to maintain software inventories, and instructions for detecting and removing unauthorized software. In addition, there is no accurate inventory of software installed at facilities in the Greater Boston District. We identified 186 instances of unauthorized software products on 31 of the 161 computers we reviewed. 

 

This occurred because headquarters management has not issued to districts detailed guidance related to the software inventory management process. Current systems the Postal Service uses to manage its enterprise-wide software inventory are not effective and are fragmented across the organization. Without an accurate inventory of software assets, the Greater Boston District may be using unsecure versions of software, purchasing unnecessary licenses, or violating software license agreements. 

 

What The OIG Recommended 

 

We recommended the Postal Service update its software inventory management process, identify software to add to its approved listing, and require district information technology personnel to follow approved software processes prior to software installation. We also recommended management establish an automated process to reconcile software inventories and coordinate with district staff to remove unauthorized software.

Report Recommendations

# Recommendation Status Value Initial Management Response USPS Proposed Resolution OIG Response Final Resolution
1

R - 1 -- Update policies to provide specific roles and responsibilities for managing the software inventory process, and provide instructions for detecting and removing unauthorized software to all districts.

Closed $0 Agree
2

R - 2 -- Develop a process for identifying software products that should be added to the Infrastructure Toolkit and document any deviations.

Closed $0 Agree
3

R - 3 -- Require district Information Technology personnel to access and review the Infrastructure Toolkit listing of all approved software products and follow the Technology Initiative Prioritization Assessment process prior to software installation.

Closed $0 Agree
4

R - 4 -- Establish an automated process to reconcile the enterprise-wide inventory and detect unauthorized software on the network.

Closed $0 Agree
5

R - 5 -- Remove unauthorized software identified on the Greater Boston District network.

Closed $0 Agree
6

R - 6 -- Revise Handbook AS-805, Information Security, to clarify software inventory policies pertaining to Engineering systems connected to the Postal Service’s Mail Processing Equipment/Mail Handling Equipment private network and the Managed Network Services.

Closed $0 Disagree