FinePrint

Audit · Maple Grove, Minnesota · April 17, 2018

Maple Grove Police audit

Two pages. Every section ends “was found to be compliant.” The auditor is the consortium that sells the department its software.

0

Meets

7

Partial

1

Fails

10

Missing

of 18 practices this document could address

LOGIS is a consortium of Minnesota cities that supplies their IT. In 2018 its security specialist wrote a two-page executive summary of Maple Grove’s two squad-car plate readers. The policy “was found to be compliant.” The audit trail “was sampled” with no sample size or result. The retention setting was checked on the admin panel. The ALPR administrator “demonstrated how they created” the public log reports. The summary concludes the department uses the system “as an effective law enforcement tool for the purpose of combating auto theft.”

No data was pulled. No query was tested. No number appears anywhere except the count of cameras. It is the template most of Minnesota’s 68 filed audits follow, and LOGIS has never recorded a finding against a member.

Document

Practice by practice

What the document says, or does not say, on each practice in the Standard. Practices this kind of document has no business addressing are marked n/a. These marks are evidence for a jurisdiction’s grade; the document itself gets no score.

Stage 1

Decide

Stage 2

Acquire

Partial

2.2Published use policy before deployment

Policy 428 was reviewed and “found to be compliant.” Its contents are not described and it is not attached.

Stage 3

Deploy

Missing

3.1Purpose limitation in writing

The stated purpose, auto theft, appears in the conclusion, not in any test.

Partial

3.2Scope limits

Two mobile units, no fixed cameras. Scope stated by inventory.

Missing

3.3Signage and notice

No check of public notice or the BCA list.

Stage 4

Use

Partial

4.1Logged justification for every query

“The Vigilant ALPR system also contains a robust audit trail which was sampled.” No sample size, no result, no exceptions noted or denied.

Stage 5

Share

Partial

5.1No sharing without a published policy

Sharing “is conducted through inter-agency requests” reviewed by a captain. No request was examined.

Stage 6

Retain

Partial

6.1Shortest retention that serves the stated purpose

The admin panel setting was checked for 60 days or less. No data was queried to confirm.

Stage 7

Audit

Fails

7.1Independent audit on a schedule

The auditor is the department’s own IT consortium. Staff demonstrated reports instead of the auditor querying the system. Zero findings, no sample sizes, no exceptions.

Partial

7.2Logs available to the oversight body

The auditor saw what the administrator showed.

Partial

7.3Annual public report with counts

Public log reports exist; the administrator demonstrated creating them.

Stage 8

Retire

What to take from it

This is the receipt the statute’s audit clause produces when nothing defines the audit. Compare it to the Paul Bunyan report and the difference is not the auditor’s conclusion. It is whether anyone looked.