HomeCybersecurityM10473Evidence
Topic/Matter Intersection

Topic:"Cybersecurity" in M10473

Matter: E-ENS-R-22 EfficiencyOne 2023-2025 Demand Side Management (DSM) Plan Application
11 passages 1 document

Cybersecurity across all matters →

E-12E1(NSUARB) RIR-1 to RIR-41 11 passages
Section 54
esulting in a risk to implemented an access align with the rate of EfficiencyOne related to unauthorized access to PI. review process, we turnover for personnel and noted that the review is frequency of permissions only performed once chan...

AI summary The text discusses concerns related to unauthorized access to personal information (PI) by EfficiencyOne, highlighting a lack of timely removal of access permissions following personnel turnover. It notes that access reviews are conducted annually and that one sampled departure was not handled promptly.

Section 56
NSUARB IR-11, Attachment 1, Page 7 of 25 Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.2 Vulnerability While Efficiency...

AI summary EfficiencyOne acknowledges the importance of vulnerability scanning and internal assessments but currently relies on an external consultant for these tasks due to a lack of in-house capabilities. The finding has been remediated with no remaining gaps or recommendations.

Section 58
rest and associated encryption keys are adequately protected. Management response N/A © 2022 KPMG LLP, an Ontario limited liability partnership and a member firm of the KPMG global organization of independent member firms affiliated with K...

AI summary The document contains a section discussing the protection of rest and associated encryption keys, with a management response listed as N/A. It includes a copyright notice from KPMG LLP and a filing date of April 29, 2022, related to the NSUARB IR-11 proceeding.

Section 63
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.5 Security monitoring While EfficiencyOne leverages system health and Par...

AI summary The review identifies a partial remediation of security monitoring gaps in EfficiencyOne's hosted IT environment, noting that security monitoring does not extend to non-cloud systems hosted by the third-party provider. It recommends expanding security monitoring capabilities to more comprehensively cover all systems.

Section 64
noted that there is no comprehensively cover the security information and cloud environments and event management offer timely alerting for (SIEM) solution in place suspicious activity to aggregate and detected within these correlate event...

AI summary The text highlights the absence of a comprehensive security information and event management (SIEM) solution in place to aggregate and correlate event logs from various components in EfficiencyOne’s cloud environments, which is necessary to detect and alert on suspicious activity in a timely manner.

Section 66
security personnel in real-time. Management acknowledges KPMG's recommendation. EfficiencyOne intends to conduct a pilot to evaluate Microsoft Sentinel and in coordination with our web Management response services provide Arrivals & Depart...

AI summary EfficiencyOne plans to conduct a pilot to evaluate Microsoft Sentinel in coordination with web services, including AWS GuardDuty, starting in Q3 2022, following a recommendation from KPMG.

Section 69
environments. noted that there is no monthly change review compensating control for process where the development and segregation of duties for implementation of website changes is not EfficiencyOne's feasible, which includes websites. ret...

AI summary The text discusses concerns regarding the lack of a compensating control process for website changes at EfficiencyOne, specifically noting the absence of a monthly change review and segregation of duties. It also mentions that retroactively reviewing technical evidence of changes is not feasible.

Section 77
NSUARB IR-11, Attachment 1, Page 12 of 25 Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.8 Security of service While it...

AI summary A residual finding from the NSUARB IR-11 review highlights a low-risk issue where a service account with access to the corporate data warehouse exists, granting access to personal information through an embedded Excel macro. This was identified as a security concern at EfficiencyOne, though it is not standard practice.

Section 78
rporate data warehouse with access to PI corporate data through an embedded Excel macro. warehouse Management response N/A Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk lev...

AI summary This chunk discusses a finding related to the redaction of social insurance numbers in EfficiencyOne's corporate data warehouse. The concern is that the current method does not fully render the numbers irrecoverable, although physical security safeguards are in place for paper forms.

Section 94
personal information all the locations of the data records being retained subject’s PI to ensure after a specific period of timely deletion. time or after a customer requests to be forgotten. Management is consulting with legal counsel to...

AI summary The document discusses the management of personal information, specifically focusing on the retention and deletion of data, and mentions that Management is consulting with legal counsel to determine an appropriate approach for handling consent withdrawal procedures related to EfficiencyOne.

Section 99
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe PIO-6 Unapproved We noted that an administrative user had ‘The Remediated N...

AI summary A review identified the installation of the TOR browser by IT administrators at EfficiencyOne, which could potentially obfuscate network traffic. The recommendation is for EfficiencyOne to investigate and ensure that TOR connections are not technically possible and to review restrictions on unauthorized software installation.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →