Audit Raises Concerns Over Administering ITS Security System Within DMV, House Republicans Say
This article was archived from the previous WordPress site. Formatting and media should be close, but may not match the original post perfectly.

HARTFORD – The audit of the Connecticut Integrated Vehicle and Licensing System, CIVLS, within the Department of Motor Vehicles today revealed ongoing problems of administering the information technology system, and renewed questions about addressing longstanding and troubling problems that have plagued the agency over recent years, State Rep. Laura Devlin of Fairfield, the Ranking House Member on the Transportation Committee, said.
The auditors highlighted 19 areas of concern. Another 14 involving security issues within the CIVLS were submitted to the DMV but omitted from the report.
“Significant security details regarding our audit of the information technology security of the DMV CIVIL system have been excluded from this report and provided to the management of the Department of Motor Vehicles,” according to the report.
“This report raises many questions including what steps need to be taken to fully address the ongoing problems at DMV. This has been going on for years and customer service has to be the priority,’’ Devlin said. “It is probably the one agency in all of state government in which virtually everyone or every family has to interact.’’
Devlin said perhaps the most critical issues may be ones that did not make it into the report that were pointed out by consultants.
The audit dates back to 2016 and was released today. Among the problems noted were:
- The report cites processing fees that should have been approved by supervisors but weren’t.
- DMV is not enforcing the proper use of passwords.
- The system was developed in a way that prevents DMV from using better security.
- The department does not disable access to the system for employees who have left state service or moved on to other jobs.
- 100 users hadn’t logged into the system in over 400 days, which indicates that these users likely still have access, even though they shouldn’t.