The Information Technology (IT) Audit group of the OIG conducts independent audits of SEPTA’s IT systems and processes. This includes assessing SEPTA’s ability to protect its information assets and ensure data integrity, confidentiality, and availability. IT audits use best practice benchmarks for compliance with cybersecurity frameworks and guidance from federal regulators. The OIG is committed to continuous improvement. This means that the IT audit process is ongoing and not just a one-time event. The goal is to identify areas for improvement and implement changes to enhance SEPTA’s IT operations and cybersecurity posture.

Because IT Audit reports may contain sensitive details about security vulnerabilities and areas of risk, they are not published here. Below is a list of the completed IT audits, in accordance with the annual Audit Plan.

OIG #TitleDateDateComments
IT-23-04Public-Facing Internet Servers and Services AuditJun 20242024-06-01Action Plan in response to 6 OIG recommendations in progress.
IT-23-02Enterprise Application Suite ReviewMar 20242024-03-01No recommendations were made.
IT-24-01Cloud-Based Human Resources Management Software Suite AuditNov 20242024-11-12Action Plan in response to 3 OIG recommendations in progress.
IT-24-02File Transfer Services AuditDec 20242024-12-01Action Plan in response to 2 OIG recommendations in progress.
IT-24-03Third Party and Vendor Management AuditDec 20242024-12-01Action Plan in response to 2 OIG recommendations in progress.
A-22-06Identity and Access Management SystemMar 20232023-03-01Action Plan in response to 8 OIG recommendations in progress.
A-22-07Communications and Signals AuditJun 20232023-06-01Action Plan in response to 5 OIG recommendations in progress.
A-22-12Security Operations Center AuditJun 20232023-06-01Action Plan in response to 5 OIG recommendations in progress.
A-22-11Enterprise Application UpgradesMay 20232023-05-01Action Plan in response to 6 OIG recommendations in progress.
IT-23-01Information, Communication, and Collaboration Software SuiteDec 20232023-12-01Action Plan in response to 7 OIG recommendations in progress.
IT-23-03Physical AccessOct 20232023-10-01Action Plan in response to 4 OIG recommendations in progress.