N-1Non-Confidential Work Order 7/30/2010
6 passages
4.6.Changes that may require increased Security (Physical and Electronic) There is little security in the NSP version of Opsym. There is no requirement for a user ID or password to gain access to the application. The data can be delegated...
AI summary The NSP version of Opsym lacks basic security measures like user authentication and access controls, allowing unrestricted data access. Recommendations include implementing user restrictions and regular backups to enhance security and ensure audit availability.
4.7.Top Issues with the Application The following have been identified as the priority issues with the application or its environment. - Opsym does not accurately model NSPI's electrical system, in particular, the various transmission cons...
AI summary The application faces critical issues: Opsym's inability to model transmission constraints, lack of a relational database, security vulnerabilities, reliance on Excel spreadsheets, network dependency, and limited support. These flaws hinder accurate modeling, data retrieval, system reliability, and compliance with ISO requirements.
8.1.APPENDIX A - SECURITY CONTROLS BASELINE CHECKLIST The purpose of the following questions is to provide a basic example of the type of questions that should be asked concerning Security (physical and electronic) for the systems identifi...
AI summary This appendix provides a baseline checklist of security control questions for systems identified in the Technology Asset Review (TAR). The checklist is not a comprehensive risk assessment but aims to identify existing or ongoing security measures, with responses categorized as Yes, In progress, or No.
NO = Does not exist QUESTION YES IP NO Is the current system configurations documented, including links to other systems? X Does application adhere to password lifetime policy of 30 days? X Do logical access controls restrict users to auth...
AI summary The document presents a series of questions related to information security and system management practices, focusing on areas such as password policies, access controls, security patches, intrusion detection, and physical security measures. These questions are part of an evaluation process for a Nova Scotia Power IT system.
QUESTION YES IP NO Does management regularly review the list of persons with physical access to sensitive facilities? X 8.2. APPENDIX B - CONTINUITY RISK MITIGATION CHECKLIST
AI summary The document includes a table and an appendix titled 'Continuity Risk Mitigation Checklist' under section 8.2. The table asks whether management regularly reviews the list of persons with physical access to sensitive facilities, with a 'YES' marked.
8.4. APPENDIX D – SEVERITY RATINGS Using the Keys described on the next two pages please rate the "IMPACT" to your business of the loss of or loss of control over the Information Asset Group identified above and the "PROBABILITY" of this r...
AI summary Appendix D outlines a severity rating process requiring stakeholders to assess the impact on their business from losing or losing control over information assets, and the probability of such risks occurring. The appendix serves as a tool for risk evaluation within a regulatory proceeding context.