An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to theCIO?