The file sharing (RAS) server was not updated with the security patch for Operating System since 25 June 2014 and the network uses private ip. In addition, the remote desktop was disabled. Therefore, the unauthorised person cannot have access to the SCBT application in the production line. In addition, the requestor had to request to access to the server room which was approved by IT Manager and Fastcheque Supervisor.
The responsible staff were not aware on how to keep the security patch on file sharing server updated.
The responsible staff were not aware on hoe to prepare the evidence for security patch update on Operating System and Database.