The Oregon Secretary of State’s Office has released its audit of the state Liquor Control Commission’s cannabis regulation systems, identifying eight information-technology security issues and making 17 recommendations for addressing the program’s weaknesses.

The audit comes on the heels of a summit in the state held by U.S. Attorney Billy Williams with members of the industry to approach issues in the program identified by Williams, such as diversion of products out-of-state and to the illicit market.

What did the report identify as weaknesses?

  • “Data reliability issues with self-reported data in the Cannabis Tracking System (CTS) and an insufficient number of trained compliance inspectors inhibit OLCC’s ability to monitor the recreational marijuana program in Oregon.”
  • “OLCC should improve processes for ensuring the security and reliability of data in the CTS and the Marijuana Licensing System. In addition, better processes are needed to monitor vendors that host and support these applications.”
  • “OLCC has not implemented an effective IT security management program for the agency as a whole.”
  • “OLCC has not formally developed a disaster recovery plan and has not tested backup files to ensure they can be used to restore mission-critical applications and data.”

What are the agency’s recommendations?

  • “Develop and implement standards and protocols for on-site inspections and investigations.”­
  • “Evaluate the need and provide for an adequate number of trained OLCC inspectors commensurate with number of licensed marijuana businesses.”
  • “Perform risk-based on-site monitoring and inspections to ensure that licensees are reporting accurate information in the CTS and complying with applicable laws.”
  • “Develop and implement policies and procedures for effectively monitoring software of service vendors to ensure they are meeting security and hosting requirements defined in contracts and service level agreements.”
  • “Develop and implement reconciliation processes to ensure that data is appropriately transmitted by the Marijuana Licensing System (MLS) and received by the [CTS].”
  • “Establish processes for granting and reviewing access to the [MLS] and [CTS].”
  • “Implement change management processes in line with industry best practices, including measures that ensure test data remains segregated from the production environment.”
  • “Update and test OLCC’s information and security plan to ensure the plan reflects the agency’s current business and IT environment.”
  • “Establish a process to maintain an up-to-date inventory of authorized hardware and software allowed on OLCC’s network.”
  • “Develop and implement a configuration management process, including establishing configuration baselines, maintaining and up-to-date repository of configuration items, and monitoring configuration status changes to detect any unauthorized changes.”
  • “Develop and implement a process to scan for vulnerabilities on devices on network.”
  • “Develop and implement an effective antivirus solution on servers and workstations, and monitor to ensure all servers and workstations have an up-to-date antivirus solution.”
  • “Transition software off obsolete platforms. If that is not possible, ensure unsupported servers are appropriately segregated on the network.”
  • “Review physical access procedures to ensure access is appropriate, and require PINs to be periodically changed.”
  • “Develop and implement a process to remediate weaknesses identified in risk assessments and audits, and routinely evaluate and assess the agency’s security posture.”
  • “Develop a document an entity-wide disaster recovery plan.”
  • “Perform periodic tests of backups to ensure usability.”

 

Do you own a cannabis industry business? Create a listing in our directory and get discovered by new clients - Click Here
.

Tags: , | Categories: Cannabis Politics Recreational Cannabis News

Learn about cannabis businesses:

View the directory | Get featured here

  • TRIM Media House

    TRIM Media House is a full-service digital marketing agency with a heavy focus in visual content creation, website design, photography, and videography. If you are trying to navigate the digital arena when it comes to your brand, we would love to talk to you!

  • CannaSafe Solutions

    CannaSafe Solutions is the one-stop-shop for all the safety needs of your cannabis growhouse, dispensary, lab, or edibles manufacturing facility. We provide all of the safety equipment and apparel you need to protect your employees, your plants, and your business.

  • Steep Hill

    Steep Hill is the world's leading cannabis science and technology company with significant footprints in lab testing, research and development, licensing, genetics, and remote testing. No other company brings these sectors into one synergistic whole. With the goal to provide "best practices" in cannabis testing, we provide expert consulting services to legislators and regulators in many countries around the world. Steep Hill: Leading the Science of Cannabis. Globally.

  • LC Solutions Michigan PLLC

    LC Solutions offers clients timely accrual based bookkeeping, cost accounting strategies, planning, and consulting services. Our model supports an ongoing client relationship, helping to ensure accurate accounting records throughout the year. We are professional, patient, and creative in our approach. LC Solutions specializes 100% in serving Michigan’s Medical Cannabis industry.

  • 4blooms

    4blooms is San Diego’s first marijuana-specific marketing agency. The agency works with businesses involved in all aspects of the cannabis industry across the U.S., from growers to dispensaries to smoke shops. The team’s deep experience in web development, design and marketing makes 4blooms able to handle all aspects of business operations.

  • CO2Meter

    CO2Meter, Inc. is a Florida based business specializing in the design and manufacturing of gas detection and monitoring devices – mainly Carbon Dioxide. Our CO2 monitors satisfy the current fire code regulations necessary for all cannabis grow house and extraction facilities. Our business partners in agriculture, HVAC, science, safety, research, pharmaceuticals, beverage, and other fields find our devices to be highly accurate and cost effective.

  • HerbTools

    HerbTools is one of the largest online head shops specializing in all varieties of smoking accessories. Our bong shop has been distributing products worldwide at competitive rates since 2012. Customer service has always been our key priority and we ensure our products reach every customer in impeccable condition.

  • California Cannabis CPA

    California Cannabis CPA is the premiere CPA firm that helps individuals and companies working in the Cannabis Industry with all tax planning, compliance, preparation, savings, and peace of mind.

  • Ravenna Interactive

    Ravenna offers branding, websites, SEO and social marketing services designed to help grow your canna-business. With a foundation in strong communication and integrity we help our clients achieve their growth and digital marketing goals.

  • Tax Center & Accounting LLC

    Complete tax and accounting services for your cannabis business. We are a full-service Tax and Accounting firm dedicated to providing the highest quality of service and support to small and medium-sized businesses and individuals.

  • Moriconi Flowers Ltd.

    Moriconi Flowers Ltd. is a law firm dedicated to applying decades of legal expertise to the emerging commercial and medical cannabis and hemp markets in the United States and abroad. Building off of careers in commercial litigation, transactional debt instruments, oil and gas regulation, liquor licensing, insurance coverage, and catastrophic loss, the attorneys at Moriconi Flowers Ltd. routinely navigate regulated markets.

  • Wise Public Relations, Inc.

    We help our clients win by outsmarting and outmaneuvering the competition rather than outspending them. That’s our specialty. Through a strategic mix of marketing disciplines, all working together to create real momentum that give our clients a critical competitive advantage in the marketplace. MedMen, Cloudponics, Style & Stigma. We take great pride in the work we do and accountability for the opinions we shape. We have fun doing it. And we hope it shows.

Want a job in the cannabis industry?

Sign up to apply for unlimited jobs and get discovered by companies who are hiring

Post Your Resume View all jobs

Recent Job Postings

Subscribe for daily cannabis news, announcements, and business insights.

Stay informed about the latest cannabis industry news, policy progress, and business developments.