Loading...
The URL can be used to link to this page
Your browser does not support the video tag.
Home
My WebLink
About
Audit Reports - Public - IT Risk Assessment Internal Audit - 3/16/2026
�1SECURANCE CONSULTING Advantagge nsight Communication Documents Interviews Risk � N • " ��', Scope System lisk Assessment Testing Procedures Internal Audit , . r Date: March 16, 2026 Securance Consulting Provided for: City of Glendale VERSION MANAGEMENT Version Date Approved Approved By Brief Description 1.0.0 March 16, 20265 Securance Draft Report 1.2.0 March 18, 2026 Securance Client edits FINAL April 30, 2026 Securance Final Report NOTE: For cybersecurity concerns, the individual risk scores/rankings for the systems, hardware, software, and/or processes assessed in this engagement have been removed from the public portion of this report. This report is intended solely for the management of the City of Glendale for its internal use and is not intended to,nor may,be relied upon by any other party(Third Party').Neither this deliverable nor Its contents may be distributed to, discussed with, or otherwise disclosed to any Third Party without the prior written permission of Securance Consulting. Securance Consulting accepts no liability or responsibility to any Third Party that gains access to this hired.©2026 Securance I.I.C. CONFIDENTIAL Securance Consulting Provided for: City of Glendale TABLE OF CONTENTS SECTION I: TECHNOLOGY RISK ASSESSMENT REPORT Risk-Based Planning ...................................................................................................................................................4 RiskAssessment Report..............................................................................................................................................6 RiskAssessment Participants .....................................................................................................................................9 Multi-Year IT Audit Plan.............................................................................................................................................12 ITRisk by Score.........................................................................................................................................................13 ITRisk by Category ...................................................................................................................................................15 SECTION II: SECURANCE VALUE SecuranceValue .......................................................................................................................................................17 CONFIDENTIAL Securance Consulting Provided for: City of Glendale RISK-BASED PLANNING Risk Assessment Risk assessment is the process of estimating risk associated with each auditable technology. Risk assessments are typically undertaken to focus attention on significant areas, to allocate scarce resources to the most important areas, and to help with prioritizing decisions such as frequency, intensity, and timing. The criteria used to assign risk scores are as follows: ID Risk Category Name and Definition 1 Corporate Reliance — To what extent does the organization rely on the application/technology? 2 Internal Customer Impact — What is the impact to internal users of the application/technology if the application/technology is taken offline? 3 External Customer Impact — What is the impact to external users of the application/technology if the application/technology is taken offline? 4 Financial Exposure — What is the financial impact to the organization if the application/technology is taken offline due to a breach or unmanaged administration? 5 Future Life — Is the application being replaced within the next two years? 6 Security Threat — What is the level and type of security threat associated with the application/technology? For example, a network perimeter device such as a firewall has a higher level of security threat associated with it than an internal file server. 7 Level of Admin Tasks — What is the level of technical administration required to maintain the application/technology in production? 8 Commercial vs Internally Developed — Is the application/technology a commercial product or one that was developed internally? 9 Prior Audit — When did the last audit of the application or IT process occur? 10 Recent Major Change — Was there a recent (i.e., within the last 6 months) major upgrade to the technology? If so, it may carry a greater risk than an application that has been implemented and stable for a longer period of time. CONFIDENTIAL Securance Consulting Provided for: City of Glendale This report is an opinion-based risk assessment. The scoring of auditable technologies is based on the opinions of the participants interviewed. In addition, the level of risk associated with each auditable technology is based on multiple factors. Risk scores alone may not be a sufficient basis for making an audit planning decision. It may be necessary to factor in the cost of carrying out the audit relative to the risk the organization is willing to assume. The general opinion, with respect to audit frequency, is that the riskier technologies should be assessed more frequently. This matrix is a guide that should be used in conjunction with a conditional audit frequency approach. Under a conditional frequency approach, all key technologies are monitored for signs of major changes. Examples of major changes include significant upgrades, reconfigurations, and/or the addition of a large number of users. Audit intensity should be determined by assessing staff qualification and the complexity of the technology. Generally, the more complex the technology, given the same level of staff skills, the more detailed the audit. Audit timing is another component to be considered during planning. Again, audit timing is heavily dependent upon resource availability. A variety of approaches have been used to determine when audits should be scheduled. Fixed-time audits are based on the assumption that there are set times that are best suited to conduct the audit, whereas random-timed audits are more unpredictable and may be used to motivate IT personnel to maintain their controls and procedures at reasonable levels. Audit frequency, intensity, timing, and resources are key components that should be considered when using the technology risk matrix. CONFIDENTIAL Securance Consulting Provided for: City of Glendale TECHNOLOGY RISK ASSESSMENT REPORT Introduction and Scope Securance Consulting has been engaged to perform an IT risk assessment of the auditable technologies and processes deployed and implemented to protect the City of Glendale's information assets. The objectives of the IT risk assessment were to: 1) better assess and understand the IT systems that store, process, or transmit organizational information, and 2) enable management to make well-informed decisions related to implementing risk management techniques and processes, including IT audits. Approach and Methodology The approach and methodology for performing the IT risk assessment included gaining an understanding of the City's diverse IT environment to identify auditable technologies and processes. Internal Audit selected applicable risk categories to assess each auditable technology/process against. Key personnel were interviewed independently to obtain risk ratings. Individual ratings were entered into a proprietary risk assessment engine for analysis. Technologies/processes were prioritized based on the following scale: • High Risk — score between 44 and 35 • Medium Risk — score between 34 and 31 • Low Risk— score of 30 or less The remaining sections of the report include: • Risk Assessment Participants • Multi-Year IT Audit Plan • IT Risk by Score • IT Risk by Category Items Considered But Excluded from Scope As part of the scoping process, Securance reviewed a number of additional items that had been identified by Internal Audit as CONFIDENTIAL AN Securance Consulting Provided for: City of Glendale potentially relevant to this engagement. After consulting with IT leadership and applicable staff, Securance determined that each item described below does not present a discrete, assessable control risk appropriate for inclusion in the current IT risk assessment cycle. The following summarizes each item and the rationale for its exclusion. Technology Vendor INI — Third-Party Staff Access The modern data platform initiative, which previously involved a significant number of INI contractor staff, has been discontinued under the new CIO. The INI vendor presence has since been reduced to a single staff member focused on business intelligence reporting. Given the material reduction in scope and personnel, the third-party access risk that originally prompted this item has substantially diminished and is no longer considered suitable for inclusion in the current assessment cycle. Unsanctioned IT Tool and Web Application Development The new CIO has halted all unsanctioned development initiatives and reoriented the department toward a formal "buy versus build" philosophy. Several development projects have been stopped, and a structured, procurement-focused approach is now in place. The control environment has changed in a meaningful way, and the risk of ungoverned development activity no longer exists in its prior form. City Has Outgrown MUNIS While MUNIS continues to serve its core functions, the platform performs poorly in areas such as recruiting and budgeting, prompting the City to procure supplemental solutions. A future ERP replacement is acknowledged as a likely long-term outcome; however, no formal initiative is currently underway. This topic represents a valid strategic technology risk but does not present a discrete, assessable control gap appropriate for the current assessment cycle. An ERP replacement planning review would be better suited as a future audit topic once a formal initiative is initiated. Senior MUNIS Administrator Retirement and Knowledge Continuity The City maintained two MUNIS administrators, and the retired administrator has since returned on a part-time basis to support continuity. This arrangement has adequately addressed the knowledge continuity concern that originally prompted this item. MUNIS Upgrades Breaking Functionality Standard MUNIS upgrade cycles have generally run without significant issue. The disruptions previously noted appear to have CONFIDENTIAL Securance Consulting Provided for: City of Glendale been largely associated with the platform's migration to Amazon Web Services, a one-time infrastructure event rather than a recurring pattern. With that migration complete, upgrade stability has improved and this item no longer represents a heightened, assessable risk for the current cycle. ThirdLine MUNIS User Access Review and Segregation of Duties Analysis IT leadership is fully supportive of engaging ThirdLine to conduct a user access review of MUNIS and identify segregation of duties violations. However, the decision to proceed rests with the Director of Budget and Finance. Rather than including this item in the current IT risk assessment, Securance recommends following up directly with that office to gauge interest and timeline. If authorized, a MUNIS access and segregation of duties review could serve as a valuable component of the multi-year IT audit plan. Software Implementation. The City has terminated its contract with ; however, affected departments have since reverted to previously used technologies in the interim. With the contract terminated, the immediate technology risk has been resolved, and this item is not applicable to the current assessment. CONFIDENTIAL Securance Consulting Provided for: City of Glendale Risk Assessment Participants The audit planning recommendations provided in the report are based on the results of the IT risk assessment analysis, our IT audit experience, and interviews of the following IT and business personnel: Name Job Title Department 1. Anne Sullivan HR Supervisor Human Resources 2. Arlene Chemello Deputy Chief Information Officer Information Technology 3. Brad Gresham Deputy Chief Information Officer Information Technology 4. Brendan McGuire Systems Analyst, Senior Information Technology 5. Brian Malinski Information Technology Supervisor Information Technology 6. Bryan Schmidt Information Technology Supervisor Information Technology 7. Cem Sahin Software Engineer, Senior Information Technology 8. Christian Polintan Deputy Chief Information Officer Information Technology 9. David Getz Systems Analyst, Senior Information Technology 10.David Melville Database Administrator, Senior Information Technology 11.Esmeralda Saldana Customer Service Manager Budget and Finance 12.Jake Devros Enterprise Cybersecurity Manager Information Technology 13.Jim Brown HR and RM Director Human Resources 14.Laura Hinson Administrative Support Supervisor Information Technology 15.Levi Gibson Budget and Finance Director Budget and Finance 16.Lis Cortes Fire Administration Supervisor Public Safety 17.Loretta Hadlock Police Communications Manager Public Safety 18.Michaelanne Acree Police Technical Services Administrator Public Safety 19.Paul Lopez Customer Service Manager Budget and Finance 20.Sheila Reddic Technology Services Manager Information Technology 21.Steve Martin Chief Information Officer Information Technology CONFIDENTIAL Securance Consulting Provided for: City of Glendale Name Job Title Department 22.Trevor Gifford Business Systems Analyst Information Technology Remainder of page left blank intentionally. CONFIDENTIAL Securance Consulting Provided for: City of Glendale SECURANCE VALUE Securance Consulting appreciates the opportunity to support the Office of Internal Audit in this engagement. We remain available to assist with any questions regarding this report and to support ongoing or future technology audits. Glendale CONFIDENTIAL �� SECURANCE CONSULTING Advnnroge rnvgnr 13916 Monroes Business Park, Suite 102 • Tampa, FL 33635 * 877.578.0215 www.securanceconsulting.com ® o