Management asked: "What are the biggest threats to the district and are we adequately addressing these threats?"
Context
The school district required an enterprise risk assessment to determine high-risk areas/processes
Based on the risk assessment results, we prioritized the highest risk areas within our audit plan, which included IT general controls and cybersecurity
Conducted an internal audit of IT general controls and cybersecurity processes and identified areas for cybersecurity posture improvements
Our Approach
Risk Assessment
Determined the residual risk ratings for key processes by considering the school district's inherent risks (i.e., types of risks and likelihood of occurrence) and the potential impact to the school districts if these risks materialized, after considering the mitigating internal controls (i.e., control effectiveness)
Based on the residual risk ratings, the internal audit plan was developed for the subsequent three-year period, prioritizing the highest risk areas including cybersecurity
Internal Audit Process
Conducted detailed corroborative interviews of key IT and cybersecurity stakeholders to gain an understanding of the current state of implemented controls and identify potential control gaps
Performed substantive testing and data analysis of key IT general and cybersecurity controls to determine the sufficiency of design and operating effectiveness of implemented controls
Reported on the potential risks and impacts of identified IT and cybersecurity deficiencies, utilizing specific and measurable attributes to best estimate the impacts in an actionable format
Provided recommended corrective action plans to jumpstart the remediation process for the identified vulnerabilities
Customer Impact
Received detailed summary of internal audit results, including recommendations to improve the overall security of the school district
Technology staff able to coordinate immediately with Elliott Davis and respond to critical findings
Utilizing the internal audit results, the school district improved the security controls surrounding its critical computer systems and information resources to mitigate the impacts of internal and external cybersecurity threats
We Can Help
For more information on this and other topics, contact a member of our team.
The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.
download the white paper
contact our team
contact our team
contact our team.
relatedinsights
CISA’s Microsoft 365 alert is a wake-up call: Are cloud misconfigurations exposing your organization to risk?
CISA warns that Microsoft 365 misconfigurations are driving real-world cyberattacks. Learn how cloud security evaluations uncover hidden risk before incidents occur.
Article
April 22, 2026
The One Big Beautiful Bill’s impact on meals and entertainment: What business owners need to know
The OBBBA changes meal & entertainment deductions starting in the 2026 tax year. Most employer-provided meals will no longer qualify for deductions with a few specific exceptions. Explore next steps for employers.
Article
February 12, 2026
Understanding the importance of SOC for blockchain: A comprehensive guide
Elliott Davis team provides a guide for SOC 2 compliance with blockchain technology, ensuring security and compliance, enhancing trust, data protection, and competitive advantage through robust controls.
December 12, 2024
The impact of AI on business: A sector-by-sector guide – Article 4
AI is transforming industries by enhancing efficiency, decision-making, and innovation across sectors like healthcare, finance, manufacturing, and retail. As businesses adapt to AI-driven advancements, they must navigate challenges like data privacy and ethical considerations while leveraging AI’s potential to drive growth and competitive advantage.
Article
September 19, 2024
Helping a private school benchmark compensation for its staff
A leading private school sought Elliott Davis's help to ensure staff compensation aligned with market standards to attract and retain top talent. By analyzing job descriptions and market data, leadership gained insights to make informed adjustments, improving employee satisfaction and competitive positioning.
July 12, 2024
Microsoft® Power BI™ best practices: Lessons learned – business guidelines for Power BI adoption
Struggling to build a data-driven culture? Learn best practices for adopting BI in your organization, from data governance to user support. Our Power BI experts share key insights to help you succeed.