E-12E1(NSUARB) RIR-1 to RIR-41
11 passages
esulting in a risk to implemented an access align with the rate of EfficiencyOne related to unauthorized access to PI. review process, we turnover for personnel and noted that the review is frequency of permissions only performed once chan...
AI summary The text discusses concerns related to unauthorized access to personal information (PI) by EfficiencyOne, highlighting a lack of timely removal of access permissions following personnel turnover. It notes that access reviews are conducted annually and that one sampled departure was not handled promptly.
NSUARB IR-11, Attachment 1, Page 7 of 25 Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.2 Vulnerability While Efficiency...
AI summary EfficiencyOne acknowledges the importance of vulnerability scanning and internal assessments but currently relies on an external consultant for these tasks due to a lack of in-house capabilities. The finding has been remediated with no remaining gaps or recommendations.
rest and associated encryption keys are adequately protected. Management response N/A © 2022 KPMG LLP, an Ontario limited liability partnership and a member firm of the KPMG global organization of independent member firms affiliated with K...
AI summary The document contains a section discussing the protection of rest and associated encryption keys, with a management response listed as N/A. It includes a copyright notice from KPMG LLP and a filing date of April 29, 2022, related to the NSUARB IR-11 proceeding.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.5 Security monitoring While EfficiencyOne leverages system health and Par...
AI summary The review identifies a partial remediation of security monitoring gaps in EfficiencyOne's hosted IT environment, noting that security monitoring does not extend to non-cloud systems hosted by the third-party provider. It recommends expanding security monitoring capabilities to more comprehensively cover all systems.
noted that there is no comprehensively cover the security information and cloud environments and event management offer timely alerting for (SIEM) solution in place suspicious activity to aggregate and detected within these correlate event...
AI summary The text highlights the absence of a comprehensive security information and event management (SIEM) solution in place to aggregate and correlate event logs from various components in EfficiencyOne’s cloud environments, which is necessary to detect and alert on suspicious activity in a timely manner.
security personnel in real-time. Management acknowledges KPMG's recommendation. EfficiencyOne intends to conduct a pilot to evaluate Microsoft Sentinel and in coordination with our web Management response services provide Arrivals & Depart...
AI summary EfficiencyOne plans to conduct a pilot to evaluate Microsoft Sentinel in coordination with web services, including AWS GuardDuty, starting in Q3 2022, following a recommendation from KPMG.
environments. noted that there is no monthly change review compensating control for process where the development and segregation of duties for implementation of website changes is not EfficiencyOne's feasible, which includes websites. ret...
AI summary The text discusses concerns regarding the lack of a compensating control process for website changes at EfficiencyOne, specifically noting the absence of a monthly change review and segregation of duties. It also mentions that retroactively reviewing technical evidence of changes is not feasible.
NSUARB IR-11, Attachment 1, Page 12 of 25 Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.8 Security of service While it...
AI summary A residual finding from the NSUARB IR-11 review highlights a low-risk issue where a service account with access to the corporate data warehouse exists, granting access to personal information through an embedded Excel macro. This was identified as a security concern at EfficiencyOne, though it is not standard practice.
rporate data warehouse with access to PI corporate data through an embedded Excel macro. warehouse Management response N/A Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk lev...
AI summary This chunk discusses a finding related to the redaction of social insurance numbers in EfficiencyOne's corporate data warehouse. The concern is that the current method does not fully render the numbers irrecoverable, although physical security safeguards are in place for paper forms.
personal information all the locations of the data records being retained subject’s PI to ensure after a specific period of timely deletion. time or after a customer requests to be forgotten. Management is consulting with legal counsel to...
AI summary The document discusses the management of personal information, specifically focusing on the retention and deletion of data, and mentions that Management is consulting with legal counsel to determine an appropriate approach for handling consent withdrawal procedures related to EfficiencyOne.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe PIO-6 Unapproved We noted that an administrative user had ‘The Remediated N...
AI summary A review identified the installation of the TOR browser by IT administrators at EfficiencyOne, which could potentially obfuscate network traffic. The recommendation is for EfficiencyOne to investigate and ensure that TOR connections are not technically possible and to review restrictions on unauthorized software installation.