Boulder Politics

BVSD Board of Education · Document

Signed Final Management Letter.pdf (202 KB)

Regular Meeting, December 9, 2025 · item 9.5: Annual Comprehensive Financial Report (ACFR) · 1 page

Open the original file

This is the text extracted from the file, without its layout, tables, or images. Use the original for anything that matters.

CliftonLarsonAllen LLP CLAconnect.com

Management Boulder Valley School District Boulder, Colorado In planning and performing our audit of the financial statements of Boulder valley School District (the District) as of and for the year ended June 30, 2025, in accordance with auditing standards generally accepted in the United States of America, we considered the entity’s internal control over financial reporting (internal control) as a basis for designing audit procedures that are appropriate in the circumstances for the purpose of expressing our opinion on the financial statements, but not for the purpose of expressing an opinion on the effectiveness of the entity’s internal control. Accordingly, we do not express an opinion on the effectiveness of the entity’s internal control. However, during our audit we became aware of deficiencies in internal control other than significant deficiencies and material weaknesses and other matters that are opportunities to strengthen your internal control and improve the efficiency of your operations. Our comments and suggestions regarding those matters are summarized below. This letter does not affect our report on the financial statements dated December 2, 2025. During our review of the District’s IT environment, we noted several operating systems that are either out of service or nearing end-of-support, including CentOS 7, Ubuntu 18.04, Windows 10, Windows Server 2012, and Windows Server 2016. Unsupported systems increase the risk of security vulnerabilities and operational disruptions. The District should develop and implement a formal plan to address these risks by:       

Upgrading to supported versions of operating systems. Implementing automated monitoring for timely detection of issues. Isolating unsupported systems using network segmentation or VLANs to reduce exposure. Restricting access to essential personnel with strong authentication controls. Performing regular backups of critical data on unsupported systems. Establishing a phased replacement strategy aligned with strategic initiatives, including budgeting and training. Applying compensating controls such as intrusion detection, enhanced firewall rules, endpoint protection, and vulnerability scanning.

We will review the status of these comments during our next audit engagement. We have already discussed many of these comments and suggestions with various entity personnel, and we will be pleased to discuss them in further detail at your convenience, to perform any additional study of these matters, or to assist you in implementing the recommendations. This communication is intended solely for the information and use of management and others within the entity, and is not intended to be, and should not be, used by anyone other than these specified parties.

CliftonLarsonAllen LLP Denver, Colorado December 2, 2025 CLA (CliftonLarsonAllen LLP) is an independent network member of CLA Global. See CLAglobal.com/disclaimer.