E-12E1(NSUARB) RIR-1 to RIR-41
13 passages
Remediation Summary The following table outlines the status of each observation and PIO, organized by risk level as noted in our follow-up review. Please refer to Appendix A for the risk classification level criteria used for each observat...
AI summary The document provides a remediation summary outlining the status of various observations and PIOs, organized by risk level. Several high and moderate risk items have been remediated, with some requiring additional actions or resulting in new PIOs.
Moderate Partially remediated 3.6 Segregation of duties for website developers Moderate Remediated + new PIO 3.7 Compliance monitoring for agents Low Remediated + new PIO 3.8 Security of service account credentials with access to the corpo...
AI summary The document outlines various risk ratings and remediation statuses for different process improvement opportunities, focusing on segregation of duties, compliance monitoring, security of credentials, and redaction of personal information. Some issues are partially remediated, while others remain unremediated.
ology system management and protection PIO Remediated PIO-3 Alignment to upcoming privacy breach notification requirements PIO Remediated PIO-4 No consent withdrawal procedure PIO Not remediated PIO-5 Use of multiple ticketing systems with...
AI summary The document outlines various privacy information officer (PIO) issues, including alignment with privacy breach notification requirements, lack of consent withdrawal procedures, use of multiple ticketing systems, unapproved software, outdated documentation, and insufficient safeguards in the privacy policy.
Partially remediated PIO-9 Lack of specificity in safeguards in the privacy policy PIO Remediated © 2022 KPMG LLP, an Ontario limited liability partnership and a member firm of the KPMG global organization of independent member firms affil...
AI summary The document outlines a follow-up review of privacy policies, highlighting gaps and recommendations identified during a 2018 privacy assessment by KPMG, as well as residual risks associated with these gaps.
diately manner where access upon termination of was terminated two personnel. business days after departure. Management agrees with the new moderate gap and recommendations identified by KPMG. Moving forward EfficiencyOne will be conductin...
AI summary Management agrees with KPMG's recommendations regarding account and access control reviews, which will be conducted quarterly starting in Q2, 2022. The document also references the termination of access two business days after personnel departure.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.4 Information security EfficiencyOne operates using a mix of formal and R...
AI summary EfficiencyOne's information security policies are a mix of formal and informal IT policies, which include a well-defined privacy policy but do not cover all domains of information security and are not consistently applied across the IT environment. The residual risk is medium, and recommendations include obtaining annual acknowledgments for the Privacy Policy.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.6 Segregation of While EfficiencyOne controls the flow of changes to Reme...
AI summary The review identified a medium risk issue regarding the lack of segregation of duties and monitoring for developers with access to both production and non-production environments at EfficiencyOne. The finding was remediated, but recommendations include establishing a monthly change review as part of continual improvement efforts.
EfficiencyOne's websites and ensure that they followed the change management process. Management acknowledges KPMG's new PIO. EfficiencyOne is currently refining its existing change and approval process to include a retroactive review Mana...
AI summary EfficiencyOne is refining its change and approval process to include a retroactive review of website change evidence relative to what had been approved, following KPMG's new PIO appointment.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.7 Compliance While EfficiencyOne captures the required consent Remediated...
AI summary EfficiencyOne has implemented measures to ensure compliance with privacy regulations, including obtaining consent and requiring agents to follow PIPEDA. However, there are gaps in routine assurance and monitoring of agents' compliance, which should be addressed through continual improvement efforts.
surance of or monitor the their understanding and EfficiencyOne should compliance of agents against these agreed-to commitment to consider promoting contractual requirements for the handling and compliance with privacy best practices to se...
AI summary The text discusses the need for EfficiencyOne to ensure compliance of agents with contractual requirements related to the handling and security of personal information (PI), including adherence to PIPEDA. It notes that some agent websites, such as those related to energy assessments, did not include privacy best practices or proper redirections.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe PIO-1 Potential for While we have not identified a specific instance Not re...
AI summary The review identifies a potential risk that EfficiencyOne may retain personal information (PI) longer than necessary, particularly if a data subject withdraws consent. There is no formal records retention and destruction schedule in place, and recommendations include establishing such a schedule and consulting with Nova Scotia Power.
handle data subject Spam Legislation ‘CASL’ form and the data subject requests to be forgotten. is no longer a direct consumer of EfficiencyOne services. For each applicable data subject’s case, EfficiencyOne should validate that at least...
AI summary EfficiencyOne is addressing data subject requests under CASL, particularly regarding the deletion of personal information. The company is consulting with legal counsel to determine appropriate records retention and destruction practices, ensuring compliance with data subject rights.
the low-income sector. In addition, NSTAR Gas and EGMA shall file all Annual Reports and Term Reports (and related documents) for this Three-Year Plans term, both on an individual and an aggregate basis. The Department will review the perf...
AI summary The text outlines requirements for NSTAR Gas and EGMA to file reports and update screening models as part of their compliance with the Three-Year Plans. It also discusses the Program Administrators' proposal to include energy savings from a Codes and Standards Compliance and Technical Support initiative in their Three-Year Plans.