Information Technology Update
Audit Committee June 5, 2019
1
Audit Committee PRESENTATION REVISED
Information Technology Update Audit Committee June 5, 2019 1 - - PowerPoint PPT Presentation
Audit Committee PRESENTATION REVISED Information Technology Update Audit Committee June 5, 2019 1 Audit Committee PRESENTATION REVISED Agenda 01 02 03 04 Agenda Agenda Agenda Agenda AMI Audit Discussion of Data Security 2.0
Audit Committee June 5, 2019
1
Audit Committee PRESENTATION REVISED
01 02 03 04
Agenda
AMI Audit Presented by Abbot, Stringham & Lynch.
Agenda
General IT Audit Results
Agenda
Discussion of responses to Cybersecurity RFI
Agenda
Data Security 2.0
Audit Committee PRESENTATION REVISED
3
Audit Committee PRESENTATION REVISED
aslcpa.com | @aslcpasv
Silicon Valley Clean Energy Authority Agreed-upon Procedures Report on AMI (Covered) Data Privacy and Security For the Period through December 31, 2018
Audit Committee PRESENTATION REVISED
1. Abbott, Stringham & Lynch, CPAs (ASL) – Introduction of Firm and Team
12-08-045
3. Overall Report Findings – Steve Carter, CPA 4. IT Discussion – Chris White and Steve Nessen 5. Q & A
Audit Committee PRESENTATION REVISED
Automated Meter Infrastructure (AMI) audit required by CPUC triennially
Regulatory
AMI specific IT controls related to the acquisition, storage and processing of AMI related data General IT controls (such as patch management, IT governance, backup- recovery)
Focus
Audit Committee PRESENTATION REVISED
Audit Committee PRESENTATION REVISED
Audit Committee PRESENTATION REVISED
Audit Committee PRESENTATION REVISED
10
password settings match organizational policy
reviewed to ensure appropriate security and audit logging are enabled
appropriate documentation (SOC-2, independent security assessment) provided to SVCE.
Audit Committee PRESENTATION REVISED
11
Audit Committee PRESENTATION REVISED
12
Audit Committee PRESENTATION REVISED
cybercriminals
in place:
engineering testing
Audit Committee PRESENTATION REVISED
perspective of any internal user (malicious or
facilities and systems. Focus on regulatory and agency compliance.
system access
function (Asset Classification)
Audit Committee PRESENTATION REVISED
controls for i.s., hosts and networks
and is essential component of overall security plan
Audit Committee PRESENTATION REVISED
Category Initial Assessment 3/19/2019 Rescan Assessment 5/19/2019 Cleaned Total Critical Severity Vulnerabilities 33 8 25 Total High Severity Vulnerabilities 89 50 39 Total Medium Severity Vulnerabilities 160 51 109 Total Low Severity Vulnerabilities 9 10 +1 Total Vulnerabilities 290 119 171
Audit Committee PRESENTATION REVISED
17
could allow dictionary attacks that would bypass alarms
Blue = Remediated Black = Work in Progress
Audit Committee PRESENTATION REVISED
18
Audit Committee PRESENTATION REVISED
19
industry streamlining
Audit Committee PRESENTATION REVISED
20
funding for IT security
Audit Committee PRESENTATION REVISED
21
Audit Committee PRESENTATION REVISED
22
machine and remove
lifecycle.
Audit Committee PRESENTATION REVISED
23
Policy
develop mitigation plan
Audit Committee PRESENTATION REVISED
24
Audit Committee PRESENTATION REVISED