Program Guide for Risk-based Compliance Monitoring and Enforcement Program. ERA-01 Rev. 1. NPCC Manager, Entity Risk Assessment
|
|
|
- Beryl Jackson
- 9 years ago
- Views:
Transcription
1 NPCC Entity Risk Assessment Program Guide for Risk-based Compliance Monitoring and Enforcement Program ERA-01 Rev. 1 Process Owner: NPCC Manager, Entity Risk Assessment Effective Date: 03/02/2015
2 Table of Contents 1. Introduction Purpose Roles and Responsibilities Procedure Risk Elements Inherent Risk Assessment (IRA) Internal Controls Evaluation (ICE) Entity Compliance Oversight Plan Glossary of Terms References Summary of Changes Periodic Review Date Review and Re-Approval Requirements This document will be reviewed every two years from the effective date, or as appropriate, for possible revision. The existing or revised document will be posted to the NPCC ERA website for NPCC registered entity reference. Northeast Power Coordinating Council, Inc. Page 1
3 1. Introduction The NERC (Risk-based CMEP) was developed through the Reliability Assurance Initiative (RAI). Risk-based compliance monitoring is intended to establish the type and frequency of Regional Entity compliance oversight based on the specific reliability risks posed by a registered entity. It is not practical, effective or sustainable to monitor all compliance issues to the same degree or treat all noncompliance in the same manner. A risk-based approach to compliance monitoring is based on a number of considerations, including risk factors, and registered entity management practices related to the detection, assessment, mitigation and reporting of noncompliance. A risk-based approach enables proper allocation of resources from both the Regional Entity and registered entity for compliance monitoring, and encourages registered entities to enhance internal controls, including those focused on the self-identification of noncompliance. In January 2015, the Northeast Power Coordinating Council, Inc. (NPCC) Entity Risk Assessment (ERA) Group was formed within the NPCC Compliance Department to support the (Risk-based CMEP). 2. Purpose The ERA Group is tasked with implementing the Risk-based Compliance Oversight Framework ( Framework ). This includes considering Risk Elements, conducting Inherent Risk Assessments (IRA) for all registered entities and Internal Controls Evaluation (ICE) for registered entities that volunteer for ICE. Northeast Power Coordinating Council, Inc. Page 2
4 The purpose of this ERA Program Document is to describe the NPCC roles and responsibilities, processes, and results, in order to ensure consistent, complete, and comprehensive implementation of the Risk-based CMEP Framework. 1 The ERA Group will develop the procedures, forms, templates, and necessary tools to conduct and document the results of IRA and the ICE. The ERA group will revise and maintain them as necessary to incorporate efficiencies and changes in guidance from the North American Electric Reliability Corporation (NERC). The scope, monitoring method and periodicity of compliance monitoring for each registered entity will be determined based on these tools and documentation. The ERA Group will develop outreach to industry, provide training support to the Electric Reliability Organization (ERO), and provide recommendations to related ERO or NPCC processes and documents to improve implementation and effectiveness of the Riskbased CMEP. These include, but are not limited to the annual NERC CMEP Implementation Plan, NPCC CMEP Implementation Plan, and NPCC Compliance Procedures. 1 This document is written for the mature ERA program state. Refer to ERA Implementation Plan for schedule, scope or priorities of process implementation and deliverables. Northeast Power Coordinating Council, Inc. Page 3
5 3. Roles and Responsibilities The ERA group is responsible for implementation, management and overall administration of the Entity Risk Assessment Program. The ERA group ensures that all NPCC ERA processes, tools, and evaluations adhere to Risk Management principles and practices and correlate to NERC guidance. These include the development of procedures, tools, and assignment of resources to conduct and document IRA and ICE, and Implementation Plan to prioritize and schedule ERA activities; scope, monitoring method and periodicity of compliance monitoring based on IRA and ICE results; creation and change management of registered entity Compliance Oversight Plans; interfacing with supporting NPCC groups and NERC; metrics demonstrating the impact of IRA and ICE in supporting Risk-based CMEP; outreach to industry; training support to the Electric Reliability Organization (ERO); review of Risk Elements/Focus Areas for inclusion in annual NERC/NPCC CMEP Implementation Plans; recommendations to improve ERO processes and tools for implementation and effectiveness of the Risk-based CMEP, including, but not limited to annual NERC CMEP Implementation Plan, NPCC CMEP Implementation Plan, and NPCC Compliance Procedures. The ERA group shall be knowledgeable in NERC processes, procedures, and guidance related to Risk-based CMEP as well as other risk management and internal controls governance processes (e.g. Enterprise Risk Management (ERM), COSO/CoCo/CoBIT models, SAC, SAS 55/78, GAGAS/Yellow Book, CGAP). Northeast Power Coordinating Council, Inc. Page 4
6 4. Procedure The Risk-based Framework focuses on identifying, prioritizing and addressing risks to the Bulk Electric System (BES), which enables NPCC to focus resources where they are most needed and effective. NPCC will tailor its approach to compliance monitoring (i.e., monitoring tools, frequency and depth of monitoring engagements) in accordance with guidance provided by NERC. The Basic Steps of the Framework are: Identify Continent-Wide Risks Identify Region-Wide Risks Perform Inherent Risk Assessment (IRA) Develop Scope of Monitoring Engagement (SoME) Perform voluntary/complimentary Internal Controls Evaluation (ICE) Summarize results of IRA and ICE into registered entity s Compliance Oversight Plan (COP) 4.1 Risk Elements Prioritization of Continent-wide and Region-wide risks based on the potential impact to reliability is identified annually as Risk Elements. These Risk Elements are reflected in the ERO Compliance Monitoring and Enforcement Program Implementation Plan (CMEP IP), and the NPCC CMEP IP (Appendix A3 to CMEP IP) The Focus Areas associated with each Risk Element are a list of NERC Reliability Standards and Requirements which require greatest attention for monitoring The ERA group considers these Focus Areas mandatory for audit engagements in the preliminary Scope of Monitoring Engagement (SoME). These Focus Areas will be coded into the preliminary SoME for each registered entity. 4.2 Inherent Risk Assessment (IRA) The NPCC ERA group will use an IRA form to assess the registered entities risks in various areas. The IRA results enable NPCC to determine risk-based areas of focus based on specific information about each registered entity s inherent risks to the BES The ERA group will document the in-house information they have available about the registered entity by filling out the information fields on the IRA form. In doing so, information gaps will be identified that challenge a complete and accurate completion of the IRA. Northeast Power Coordinating Council, Inc. Page 5
7 4.2.2 The ERA group will contact the registered entity and provide the IRA form listing the documentation that the ERA group possesses. The registered entity will be asked to provide missing and/or updated information to enable ERA group to perform the IRA as accurately as possible. The registered entity will be provided with secure method and file naming protocol to submit information to NPCC The ERA group will post the blank IRA form on the NPCC ERA webpage so that registered entities can see what information is used to perform their IRA. The registered entities may provide updated information which affects their risk profile should they choose to do so without waiting for NPCC to contact them (examples: acquisition of BES assets from another entity, or disposal of same; new owner of Special Protection System as of certain date; generator no longer a Blackstart unit, etc.) This fosters transparency and establishes real-time communication between the registered entity and NPCC so that the information used to conduct the IRA is complete, accurate and up-to-date Instructions for completion of the form and secure submittal of data will be provided on the NPCC ERA webpage Results of the IRA will be summarized and inputted to the registered entity s Compliance Oversight Plan Results of the IRA will be used by ERA group to develop the preliminary SoME NERC and NPCC Focus Areas are automatically included in preliminary audit scope These may be changed to alternate monitoring methods, or removed entirely based on results and basis of the registered entity s IRA Other exclusions or inclusions of NERC requirements to monitoring are made to the preliminary SoME, with supporting rationale by ERA group If there is no Internal Controls Evaluation (ICE), then this preliminary SoME represents the FINAL SoME describing the scope and monitoring methods for Compliance engagements for the registered entity If the registered entity is scheduled for an audit engagement, the items designated for audit in the FINAL SoME will be listed as Attachment 1 in the Audit Notification Letter sent to the registered entity in accordance with NPCC Compliance Procedures CP-02 and CP In general, the overall IRA process follows the flow diagram shown below: Northeast Power Coordinating Council, Inc. Page 6
8 4.2.9 If a registered entity volunteers for ICE, then the ERA group will work with the entity to review its schedule, resources, and registered entity s IRA (if any) and latest SoME, to determine when an ICE can be performed for further reduction or change in monitoring method and frequency. See Section 4.3, Internal Controls Evaluation Northeast Power Coordinating Council, Inc. Page 7
9 4.3 Internal Controls Evaluation (ICE) When developing specific monitoring plans for registered entities, NPCC will take into account information obtained through the processes outlined in the NERC Internal Control Evaluation (ICE) Guide. The ICE Guide describes the process for identifying key controls, testing their effectiveness and documenting the conclusions of the Internal Controls Evaluation. ICE is voluntary for registered entities and allows a further refinement of their Compliance Oversight Plans. NPCC will perform ICE based on the completed IRA and preliminary SoME for the registered entity If a registered entity volunteers for ICE, then an ICE worksheet will be developed for the registered entity based on the results of the registered entity s IRA (if available) or all the applicable requirements for the registered entity s registered function. NERC and NPCC Focus Areas will be flagged on the ICE worksheet. The registered entity may request a smaller subset of standards and requirements on which to provide their internal controls information for ICE The registered entity has the flexibility to choose the extent of ICE. As few, some, many or all of the registered entity s internal controls may be offered for evaluation. The registered entity s compliance monitoring schedule will be reviewed to determine the various phases of ICE An ICE Notification letter will be sent to the registered entity describing the ICE process and worksheet; composition of the NPCC ICE team; a proposed timeline for completion, review, and onsite evaluation/testing of the Internal Control Design; and how the results can benefit the registered entity If the registered entity has a scheduled audit: The ICE package should be sent approximately 5 6 months prior to the engagement to give the registered entity adequate time to complete the ICE worksheet. This would also allow the NPCC ICE Team time to review and schedule an onsite ICE evaluation to determine possible reduction in audit scope, and alternate monitoring methods. The near term goal of ICE is to determine possible scope reduction so that the FINAL audit scope may be determined and documented in the Audit Notification Letter sent in accordance with NPCC CP-02 or CP-03 for Onsite and Offsite audits If the ICE package cannot be sent with adequate time for the registered entity to complete it in its entirety, then priority should be given to completing the worksheet for those items designated as in the preliminary audit scope. Concentration on these items may allow the ICE Team to evaluate and remove items from audit scope prior to NPCC sending the Audit Notification Letter. This would provide greatest benefit to the registered entity and is considered phase 1 of the overall ICE Items on the ICE worksheet that were not part of audit scope can be completed later by the registered entity and/or evaluated later by the ICE Team for finalization of the SoME. This would be considered phase 2 of the ICE. Northeast Power Coordinating Council, Inc. Page 8
10 4.3.5 The ICE results will be summarized, changes in scope reduction and/or monitoring methods documented, and input to the registered entity s Compliance Oversight Plan In general, the overall ICE process follows the flow diagram shown below: Registered entities may elect not to participate in an ICE. In that case, NPCC will use the results of the registered entity s IRA and SoME to determine the appropriate compliance oversight strategy, including focus and tools within the determined scope. These results will be summarized and input to the registered entity s Compliance Oversight Plan. See para Northeast Power Coordinating Council, Inc. Page 9
11 4.4 Entity Compliance Oversight Plan Ultimately, NPCC will determine the type and frequency of the compliance monitoring tools (e.g., off-site or on-site audits, spot checks or guided self-certifications) that are warranted for a particular registered entity based on reliability risks The results of registered entity IRAs, and ICE will be summarized to determine the FINAL SoME, their monitoring method, and frequency or interval within a given implementation year. These summaries will be input to each registered entity s Compliance Oversight Plan Results of the IRAs and ICEs will be made available to the individual registered entities. Registered entities may request a discussion with NPCC regarding the results of the IRAs Change management of the registered entity s Compliance Oversight Plans is required periodically due to, but not limited to the following changes which could affect the Risk-based CMEP Framework Changes to a registered entity s IRA which require refreshing of the IRA Changes or additions to a registered entity s Internal Control Designs which require re-performance of ICE Changes to annual Risk Elements and Focus Areas by NERC and/or NPCC which require refreshing of IRA, SoME and ICE Retirement of standards, implementation of new standards, changes in Violation Risk Factors, new Information Attributes for IRA, new guidance for ICE. All require refreshing of applicable standards for registered functions, IRA, and ICE Other Risk Elements not identified by the above which may require ERA group to review for impact on existing and future IRA and ICE. Northeast Power Coordinating Council, Inc. Page 10
12 5. Glossary of Terms 5.1 Risk-based Compliance Oversight Framework The ERO Enterprise s Risk-based Compliance Oversight Framework (Framework) consists of processes that involve reviewing system-wide risk elements, an assessment of a registered entity s inherent risk, and, on a voluntary basis, an evaluation of a registered entity s internal controls prior to establishing a monitoring plan that is tailored to a particular entity or group of entities 5.2 Risk Elements A list of identified and prioritized continent-wide and regional risks to the reliability of the BPS resulting from the NERC Risk Elements Development Process described in the NERC Risk Elements Guide. These risks further identified the Reliability Standards and registration functional categories related to those risks and serve as Focus Areas in the annual NERC CMEP IP and Regional CMEP IP describing CMEP activities to be performed by the Regions. 5.3 Inherent Risk Assessment Regional Entities perform an Inherent Risk Assessment (IRA) of registered entities to identify areas of focus and the level of effort needed to monitor compliance with NERC Reliability Standards for a particular registered entity. The IRA is a review of potential risks posed by an individual registered entity to the reliability of the BPS. An IRA considers risk factors such as assets, systems, geography, interconnectivity, prior compliance history, and overall unique entity composition when determining the Compliance Oversight Plan for a registered entity. The IRA will be performed on a periodic basis, with the frequency based on a variety of factors, including, but not limited to, changes to a registered entity and significant changes or emergence of new reliability risks. 5.4 Internal Controls Evaluation An evaluation by the Regional Entity of a registered entity s Internal Controls for addressing risks applicable to the registered entity and for identifying, assessing and correcting noncompliance with Reliability Standards. The ICE is volunteered for by the registered entity to refine the list of monitored standards for future engagements. 5.5 CMEP Tools The CMEP Tools are the methods of monitoring (i.e., off-site or on-site audits, spot checks, or self-certifications) determined by the Regional Entities. Regional Entities will tailor compliance monitoring activities for registered entities in their footprint based on reliability risks. Reliability Coordinators, Balancing Authorities, and Transmission Operators are expected to remain on a three-year audit cycle. The determination of the appropriate CMEP tools will be adjusted, as needed, within a given implementation year. Northeast Power Coordinating Council, Inc. Page 11
13 6. References 6.1 Risk Elements Guide for Development of the 2015 CMEP IP, September 8, ERO Enterprise Inherent Risk Assessment Guide, October ERO Enterprise Internal Control Evaluation Guide October ERO Compliance Monitoring and Enforcement Implementation Plan, November 18, CMEP IP, Appendix A3 - Northeast Power Coordinating Council (NPCC) 2015 CMEP Implementation Plan for Entities within the U.S. 6.6 New Brunswick 2015 Annual Implementation Plan, Version 1, December 22, Memo of Understanding between the Independent Electricity System Operator (Ontario) and NERC and NPCC, November 29, Québec Reliability Standards Compliance Monitoring and Enforcement Program (QCMEP) 2015 Annual Implementation Plan, Version 1, April 1, 2015 (pending) 6.9 Memo of Understanding between Nova Scotia Power Incorporated and NPCC and NERC, May 9, 2010 Northeast Power Coordinating Council, Inc. Page 12
14 7. Summary of Changes Revision Reason for Change Approved By Date 0 None This is the original issue. Ben Eng/ Manager, Entity Risk Assessment 1 Revised Roles and Responsibilities section and editorial changes throughout the document 8. Periodic Review Date Ben Eng/ Manager, Entity Risk Assessment 03/02/15 03/26/15 Changes Necessary? (If Yes, provide Revision No. and Date) Performed By Date (03/26/17) Northeast Power Coordinating Council, Inc. Page 13
NPCC Implementation of the NERC Compliance Monitoring And Enforcement Program (CMEP)
Northeast Power Coordinating Council, Inc. NPCC Implementation of the NERC Compliance Monitoring And CP-01 Rev.2 The NERC Rules of Procedure and the Regional Delegation Agreement are the overriding documents
Appendix A3 - Northeast Power Coordinating Council (NPCC) 2016 CMEP Implementation Plan
Appendix A3 - Northeast Power Coordinating Council (NPCC) 2016 CMEP Implementation Plan This Appendix contains the CMEP Implementation Plan (IP) for the NPCC as required by the NERC Rules of Procedure.
2016 Business Plan and Budget. Texas Reliability Entity, Inc. Approved by Texas RE Board of Directors. Date: May 21, 2015
2016 Business Plan and Texas Reliability Entity, Inc. Approved by Texas RE Board of Directors Date: May 21, 2015 1 Table of Contents Table of Contents... 2 Introduction... 3 Section A 2016 Business Plan
A. Introduction. B. Requirements. Standard PER-005-1 System Personnel Training
A. Introduction 1. Title: System Personnel Training 2. Number: PER-005-1 3. Purpose: To ensure that System Operators performing real-time, reliability-related tasks on the North American Bulk Electric
North American Electric Reliability Corporation. Compliance Monitoring and Enforcement Program. December 19, 2008
116-390 Village Boulevard Princeton, New Jersey 08540-5721 North American Electric Reliability Corporation Compliance Monitoring and Enforcement Program December 19, 2008 APPENDIX 4C TO THE RULES OF PROCEDURE
Risk Management Services
Risk Management Services GridSME is proud to offer organizations a variety of risk management services, including the following: RISK ASSESSMENTS Strategic identification of enterprise risks & latent organizational
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page
ERCOT Design and Implementation of Internal Controls and benefits for NERC CMEP/RAI
ERCOT Design and Implementation of Internal Controls and benefits for NERC CMEP/RAI Matt Mereness, ERCOT Compliance Director August 2015 Anfield Summit Outline of discussion ERCOT Background Business Case
MEMORANDUM OF UNDERSTANDING THE INDEPENDENT ELECTRICITY SYSTEM OPERATOR THE NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION
MEMORANDUM OF UNDERSTANDING BETWEEN THE INDEPENDENT ELECTRICITY SYSTEM OPERATOR AND THE NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION AND THE NORTHEAST POWER COORDINATING COUNCIL, CROSS-BORDER REGIONAL
CIP-003-5 Cyber Security Security Management Controls
A. Introduction 1. Title: Cyber Security Security Management Controls 2. Number: CIP-003-5 3. Purpose: To specify consistent and sustainable security management controls that establish responsibility and
3. Purpose: To improve the reliability of the Bulk Electric System by requiring the reporting of events by Responsible Entities.
A. Introduction 1. Title: Event Reporting 2. Number: EOP-004-2 3. Purpose: To improve the reliability of the Bulk Electric System by requiring the reporting of events by Responsible Entities. 4. Applicability:
Re: NERC Notice of Penalty regarding Pacific Gas and Electric Company FERC Docket No. NP10-_-000
f April 28, 2010 Ms. Kimberly Bose Secretary Federal Energy Regulatory Commission 888 First Street, N.E. Washington, D.C. 20426 Re: NERC Notice of Penalty regarding Pacific Gas and Electric Company FERC
A&CS Assurance Review. Accounting Policy Division Rule Making Participation in Standard Setting. Report
A&CS Assurance Review Accounting Policy Division Rule Making Participation in Standard Setting Report April 2010 Table of Contents Background... 1 Engagement Objectives, Scope and Approach... 1 Overall
Regulatory Compliance Management for Energy and Utilities
Regulatory Compliance Management for Energy and Utilities The Energy and Utility (E&U) sector is transforming as enterprises are looking for ways to replace aging infrastructure and create clean, sustainable
PROCEDURE. Ontario Technical Feasibility Exception PUBLIC. Issue 0.2 IESO_PRO_0680
PROCEDURE PUBLIC IESO_PRO_0680 Ontario Technical Feasibility Exception Issue 0.2 This procedure provides guidance to TFE applicants on the Ontario-adapted NERC Technical Feasibility Exception process.
CIP-005-5 Cyber Security Electronic Security Perimeter(s)
A. Introduction 1. Title: Cyber Security Electronic Security Perimeter(s) 2. Number: CIP-005-5 3. Purpose: To manage electronic access to BES Cyber Systems by specifying a controlled Electronic Security
RE: PCAOB Rulemaking Docket Matter No. 041: Concept Release on Audit Quality Indicators
Office of the Secretary Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, DC 20006-2803 September 29, 2015 RE: PCAOB Rulemaking Docket Matter No. 041: Concept Release on Audit Quality
Internal Audit Manual
Internal Audit Manual Version 1.0 AUDIT AND EVALUATION SECTOR AUDIT AND ASSURANCE SERVICES BRANCH INDIAN AND NORTHERN AFFAIRS CANADA April 25, 2008 #933907 Acknowledgements The Institute of Internal Auditors
COSO Internal Control Integrated Framework (2013)
COSO Internal Control Integrated Framework (2013) The Committee of Sponsoring Organizations of the Treadway Commission (COSO) released its updated Internal Control Integrated Framework (2013 Framework)
Standard CIP 007 3a Cyber Security Systems Security Management
A. Introduction 1. Title: Cyber Security Systems Security Management 2. Number: CIP-007-3a 3. Purpose: Standard CIP-007-3 requires Responsible Entities to define methods, processes, and procedures for
Preface No changes of substance have been made in the Framework, Introduction or the IESs.
International Accounting Education Standards Board International Federation of Accountants 545 Fifth Avenue, 14th Floor New York, New York 10017 USA E-mail: [email protected] Website: http://www.ifac.org
Safety Management Program
Corrective Action Plan (CAP) Safety Management Program Submitted by TransCanada PipeLines Limited and its National Energy Board Regulated Subsidiaries to address non-compliant findings in the National
OF CPAB INSPECTION FINDINGS
PROTOCOL FOR AUDIT FIRM COMMUNICATION OF CPAB INSPECTION FINDINGS WITH AUDIT COMMITTEES CONSULTATION PAPER NOVEMBER 2013 The Canadian Public Accountability Board ( CPAB ) is requesting comments on the
John Keel, CPA State Auditor. An Audit Report on Inspections of Compounding Pharmacies at the Board of Pharmacy. August 2015 Report No.
John Keel, CPA State Auditor An Audit Report on Inspections of Compounding Pharmacies at the Board of Pharmacy Report No. 15-039 An Audit Report on Inspections of Compounding Pharmacies at the Board of
Privacy Management Program Toolkit Health Custodians Personal Health Information Act
Office of the Information and Privacy Commissioner for Nova Scotia Privacy Management Program Toolkit Health Custodians Personal Health Information Act Introduction: This toolkit was prepared by the Information
RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
Information Technology Project Oversight Framework
i This Page Intentionally Left Blank i Table of Contents SECTION 1: INTRODUCTION AND OVERVIEW...1 SECTION 2: PROJECT CLASSIFICATION FOR OVERSIGHT...7 SECTION 3: DEPARTMENT PROJECT MANAGEMENT REQUIREMENTS...11
Continuing Professional Development: A Program of Lifelong Learning and Continuing Development of Professional Competence
Education Committee IES 7 May 2004 International Education Standard for Professional Accountants 7 Continuing Professional Development: A Program of Lifelong Learning and Continuing Development of Professional
Implementation Plan for Version 5 CIP Cyber Security Standards
Implementation Plan for Version 5 CIP Cyber Security Standards April 10September 11, 2012 Prerequisite Approvals All Version 5 CIP Cyber Security Standards and the proposed additions, modifications, and
Framework for Cooperative Market Conduct Supervision in Canada
Framework for Cooperative Market Conduct Supervision in Canada November 2015 1 Purpose The Framework for Cooperative Market Conduct Supervision in Canada ( Cooperative Framework ) is intended to provide
Risk Management Framework
Risk Management Framework THIS PAGE INTENTIONALLY LEFT BLANK Foreword The South Australian Government Risk Management Policy Statement 2009 advocates that consistent and systematic application of risk
Audit-Ready SharePoint Applications
Audit-Ready SharePoint Applications Page 1 of 16 July 7, 2015 Table of Contents 1 Overview... 3 2 Company Background... 4 3 Audit-Ready SharePoint Applications... 4 3.1 Audit-Ready Compliance Dashboard...
MARKET CONDUCT ASSESSMENT REPORT
MARKET CONDUCT ASSESSMENT REPORT PART 1 STATUTORY ACCIDENT BENEFITS SCHEDULE (SABS) PART 2 RATE VERIFICATION PROCESS Phase 1 (2012) Financial Services Commission of Ontario (FSCO) Market Regulation Branch
Standard CIP 004 3a Cyber Security Personnel and Training
A. Introduction 1. Title: Cyber Security Personnel & Training 2. Number: CIP-004-3a 3. Purpose: Standard CIP-004-3 requires that personnel having authorized cyber or authorized unescorted physical access
BANK EXAMINERS MANUAL FOR AML/CFT RBS EXAMINATION
BANK EXAMINERS MANUAL FOR AML/CFT RBS EXAMINATION 1 Contents 1. EXAMINATION PROCEDURES ON SCOPING AND PLANNING 1..1 2. EXAMINATION PROCEDURES OF AML/CFT COMPLIANCE PROGRAM...3.. 3 3. OVERVIEW OF AML/CFT
122 FERC 61,040 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION. 18 CFR Part 40. [Docket No. RM06-22-000; Order No.
122 FERC 61,040 UNITED STATES OF AMERICA FEDERAL ENERGY REGULATORY COMMISSION 18 CFR Part 40 [Docket No. RM06-22-000; Order No. 706] Mandatory Reliability Standards for Critical Infrastructure Protection
North American Electric Reliability Corporation: Critical Infrastructure Protection, Version 5 (NERC-CIP V5)
Whitepaper North American Electric Reliability Corporation: Critical Infrastructure Protection, Version 5 (NERC-CIP V5) NERC-CIP Overview The North American Electric Reliability Corporation (NERC) is a
Loan Review: A Critical Element of Effective Portfolio Risk Management
Loan Review: A Critical Element of Effective Portfolio Risk Management By Donna Nails May 2010 This publication is made possible by the generous support of the Citi Foundation. Introduction All lending
4.1.1 Generator Owner 4.1.2 Transmission Owner that owns synchronous condenser(s)
A. Introduction 1. Title: Verification and Data Reporting of Generator Real and Reactive Power Capability and Synchronous Condenser Reactive Power Capability 2. Number: MOD-025-2 3. Purpose: To ensure
Program Overview. CDP is a registered certification designed and administered by Identity Management Institute (IMI).
Overview Certified in Data Protection (CDP) is a comprehensive global training and certification program which leverages international security standards and privacy laws to teach candidates on how to
CMS INFORMATION SECURITY (IS) CERTIFICATION & ACCREDITATION (C&A) PACKAGE GUIDE
Chief Information Officer Office of Information Services Centers for Medicare & Medicaid Services CMS INFORMATION SECURITY (IS) CERTIFICATION & ACCREDITATION (C&A) PACKAGE GUIDE August 25, 2009 Version
Transmission Function Employees Job Titles and Descriptions 18 C.F.R 358.7(f)(1)
Date of Last Change to the Provided Information August 27 th, 2015 Director, Transmission Operations The employee in this position is responsible for effectively managing the operation of FirstEnergy Utilities
[Project Name] Project Human-Resource Management Plan. [Sub-Project, phase, etc.] [Company] [Company Address]
[Company] [Company Address] Tel: Fax: [Company Phone] [Company Fax] [Company E-mail] May 16, 2015 [Ref. number] Marc Arnecke, PMP [Project Name] [Sub-Project, phase, etc.] The is a component of the Project
Scope of Restoration Plan
RWG Area Restoration Review Worksheet (10/28/09) EOP-006-02 Directory 8 EOP-005 NYSRG Rule G Text Restoration Plan Requirement R1.Each Reliability Coordinator shall have a Reliability Coordinator Area
Fraud Risk Management
Fraud Risk Management Overview Discussion Questions 1) Does your organization follow a specific risk management model? If so, which one? Do you think this model adequately addresses the risks your organization
U.S. Department of Energy Office of Inspector General Office of Audits and Inspections
U.S. Department of Energy Office of Inspector General Office of Audits and Inspections Audit Report Federal Energy Regulatory Commission's Monitoring of Power Grid Cyber Security DOE/IG-0846 January 2011
Governance. What s a Governance?
Governance What s a Governance? Governance FERC - Federal Energy Regulatory Commission NERC - North American Electric Reliability Council. NPCC - Northeast Power Coordinating Council NYSRC - New York State
Our Commitment to Information Security
Our Commitment to Information Security What is HIPPA? Health Insurance Portability and Accountability Act 1996 The HIPAA Privacy regulations require health care providers and organizations, as well as
CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments
CIP-010-2 Cyber Security Configuration Change Management and Vulnerability Assessments A. Introduction 1. Title: Cyber Security Configuration Change Management and Vulnerability Assessments 2. Number:
CONSULTATION PAPER Proposed Prudential Risk-based Supervisory Framework for Insurers
INSURANCE CONSULTATION PAPER Proposed Prudential Risk-based Supervisory Framework for Insurers December 2010 CONSULTATION PAPER: Proposed Risk-based Supervisory Framework (Final December 2010) Page 1 of
Information Architecture Planning Template for Health, Safety, and Environmental Organizations
Environmental Conference September 18-20, 2005 The Fairmont Hotel Information Architecture Planning Template for Health, Safety, and Environmental Organizations Presented By: Alan MacGregor ENVIRON International
Physical Security Reliability Standard Implementation
Physical Security Reliability Standard Implementation Tobias Whitney, Manager of CIP Compliance (NERC) Carl Herron, Physical Security Leader (NERC) NERC Sub-Committee Meeting New Orleans, Louisiana CIP-014
Ontario Energy Board. 2014-2017 Business Plan
Ontario Energy Board 2014-2017 Business Plan Ontario Energy Board P.O. Box 2319 2300 Yonge Street 27th Floor Toronto ON M4P 1E4 Telephone: (416) 481-1967 Facsimile: (416) 440-7656 Toll-free: 1 888 632-6273
Financial Services FINANCIAL SERVICES UTILITIES 57 FINANCIAL SERVICES AND UTILITIES 2016-2018 BUSINESS PLAN. CR_2215 Attachment 1
CR_2215 Attachment 1 Financial Services FINANCIAL SERVICES & UTILITIES 57 FINANCIAL SERVICES AND UTILITIES 2016-2018 BUSINESS PLAN Acting Branch Manager: Stacey Padbury Table of Contents INTRODUCTION Our
RESPONSIBLE CARE SECURITY CODE OF MANAGEMENT PRACTICES
RESPONSIBLE CARE SECURITY CODE OF MANAGEMENT PRACTICES Purpose and Scope The purpose of the Security Code of Management Practices is to help protect people, property, products, processes, information and
Computing Services Network Project Methodology
Computing Services Network Project Prepared By: Todd Brindley, CSN Project Version # 1.0 Updated on 09/15/2008 Version 1.0 Page 1 MANAGEMENT PLANNING Project : Version Control Version Date Author Change
Response to NIST: Developing a Framework to Improve Critical Infrastructure Cybersecurity
National Grid Overview National Grid is an international electric and natural gas company and one of the largest investor-owned energy companies in the world. We play a vital role in delivering gas and
CMS Policy for Configuration Management
Chief Information Officer Centers for Medicare & Medicaid Services CMS Policy for Configuration April 2012 Document Number: CMS-CIO-POL-MGT01-01 TABLE OF CONTENTS 1. PURPOSE...1 2. BACKGROUND...1 3. CONFIGURATION
REQUIREMENTS FOR CERTIFICATION BODIES TO DETERMINE COMPLIANCE OF APPLICANT ORGANIZATIONS TO THE MAGEN TZEDEK SERVICE MARK STANDARD
REQUIREMENTS FOR CERTIFICATION BODIES TO DETERMINE COMPLIANCE OF APPLICANT ORGANIZATIONS TO THE MAGEN TZEDEK SERVICE MARK STANDARD Foreword The Magen Tzedek Commission has established a standards and certification
Board of Directors and Management Oversight
Board of Directors and Management Oversight Examination Procedures Examiners should request/ review records, discuss issues and questions with senior management. With respect to board and senior management
North American Electric Reliability Corporation (NERC) Cyber Security Standard
North American Electric Reliability Corporation (NERC) Cyber Security Standard Symantec Managed Security Services Support for CIP Compliance Overviewview The North American Electric Reliability Corporation
Army Regulation 702 11. Product Assurance. Army Quality Program. Headquarters Department of the Army Washington, DC 25 February 2014 UNCLASSIFIED
Army Regulation 702 11 Product Assurance Army Quality Program Headquarters Department of the Army Washington, DC 25 February 2014 UNCLASSIFIED SUMMARY of CHANGE AR 702 11 Army Quality Program This major
Regulatory Compliance Framework An Electric Utility Model. Abstract. Grier Consulting Group LLC
Regulatory Compliance Framework An Electric Utility Model Abstract This presentation will describe the development of a regulatory compliance framework and toolset for use by a utility regulatory services
Internal Financial Controls
Internal Financial Controls Who All Are Responsible? 3 What is Internal Financial Control (IFC)? 5 What is Internal financial controls over financial reporting (ICFR)? Internal Controls Global Perspective
Enterprise SM VOLUME 1, SECTION 5.1: MANAGED TIERED SECURITY SERVICES
VOLUME 1, SECTION 5.1: MANAGED TIERED SECURITY SERVICES 5.1 MANAGED TIERED SECURITY SERVICES [C.2.7.4, M.2.1.3] Level 3 will support the GSA s Multi-Tier Security Profiles (MTSP) initiative in accordance
II. F. Identity Theft Prevention
II. F. Identity Theft Prevention Effective Date: May 3, 2012 Revises Previous Effective Date: N/A, New Policy I. POLICY: This Identity Theft Prevention Policy is adopted in compliance with the Federal
Federal Regulatory Agencies Administrative Guidelines. Implementation of Interagency Programs for the Supervision of Technology Service Providers
Federal Regulatory Agencies Administrative Guidelines Implementation of Interagency Programs for the Supervision of Technology Service Providers OCTOBER 2012 for the Supervision of Technology Service Providers
The Firewall Audit Checklist Six Best Practices for Simplifying Firewall Compliance and Risk Mitigation
The Firewall Audit Checklist Six Best Practices for Simplifying Firewall Compliance and Risk Mitigation Copyright, AlgoSec Inc. All rights reserved The Need to Ensure Continuous Compliance Regulations
Sound Transit Internal Audit Report - No. 2014-6
Sound Transit Internal Audit Report - No. 2014-6 Maturity Assessment: Information Technology Division Disaster Recovery Planning Report Date: June 5, 2015 Table of Contents Page Executive Summary 2 Background
Cyber Security and Privacy - Program 183
Program Program Overview Cyber/physical security and data privacy have become critical priorities for electric utilities. The evolving electric sector is increasingly dependent on information technology
CIP 010 1 Cyber Security Configuration Change Management and Vulnerability Assessments
CIP 010 1 Cyber Security Configuration Change Management and Vulnerability Assessments A. Introduction 1. Title: Cyber Security Configuration Change Management and Vulnerability Assessments 2. Number:
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE March 2012 Table of Contents Executive Summary... 1 Introduction... 1 Risk Management and Assurance (Assurance Services)... 1 Assurance Framework...
Standard CIP 003 1 Cyber Security Security Management Controls
A. Introduction 1. Title: Cyber Security Security Management Controls 2. Number: CIP-003-1 3. Purpose: Standard CIP-003 requires that Responsible Entities have minimum security management controls in place
FFIEC Cybersecurity Assessment Tool
Overview In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed the Cybersecurity Tool (), on behalf of its members,
2015 Trends & Insights
Asia Pacific Mobility The Asia Pacific Mobility Brookfield Global Relocation Services Trends & Insights report is reflective of the global economy which is strongly tied with the economic realities of
New Brunswick Electricity Business Rules
New Brunswick Electricity Business Rules Table of Contents Chapter 1 Chapter 2 Chapter 3 Chapter 4 Administration and Participation Transmission Planning and Connections Reliable Operations Billing and
Agenda. OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2. Linda Sanches, MPH Senior Advisor, Health Information Privacy 4/1/2014
OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2 Linda Sanches, MPH Senior Advisor, Health Information Privacy HCCA Compliance Institute March 31, 2014 Agenda Background Audit Phase
April 8, 2013. Ms. Diane Honeycutt National Institute of Standards and Technology 100 Bureau Drive, Stop 8930 Gaithersburg, MD 20899
Salt River Project P.O. Box 52025 Mail Stop: CUN204 Phoenix, AZ 85072 2025 Phone: (602) 236 6011 Fax: (602) 629 7988 [email protected] James J. Costello Director, Enterprise IT Security April 8,
Office of the Chief Information Officer
Office of the Chief Information Officer Business Plan: 2012 2015 Department / Ministère: Executive Council Date: November 15, 2012 1 P a g e This Page Left Intentionally Blank 2 P a g e Contents The Business
RE AP QUE PLIC FOR IONS. Compa CPRIT RFA C 12 FORM 2. Company. p.1/17
RE AP QUE ST PLIC AT RFA C 12 FORM 2 FOR IONS Compa any Formation Awards FY 2012 Fiscal Year Award Period September 1, 2011 Augustt 31, 2012 CPRIT RFA C 12 FORM 2 (Rev 6/ /30/11) Company Formation Awards
Table of Contents. Chapter 3: ESTABLISH A COMMUNICATION PLAN... 39 3.1 Discussion Questions... 40 3.2 Documenting the Communication Element...
Table of Contents Chapter 1: LAY THE GROUNDWORK... 1 1.1 Obtain Management Commitment... 1 1.2 Choose a Champion... 9 1.3 Form an EMS Team... 12 1.4 Build Support and Involve Employees... 14 1.5 Conduct
RISK-BASED REGULATION FRAMEWORK. Consultation Document. Financial Services Commission of Ontario March, 2011
RISKBASED REGULATION FRAMEWORK Consultation Document March, 2011 Table of Contents Executive Summary...3 Consultation Questions...5 1. 2. 3. Introduction...8 1.1 Background...8 1.2 Objectives...10 1.3
LogRhythm and NERC CIP Compliance
LogRhythm and NERC CIP Compliance The North American Electric Reliability Corporation (NERC) is a nonprofit corporation designed to ensure that the bulk electric system in North America is reliable, adequate
Federal Home Loan Bank Membership Version 1.0 March 2013
Introduction The Federal Home Loan Banks (FHLBanks) are cooperative institutions owned by members. The Federal Home Loan Bank Act of 1932 (FHLBank Act) created the Federal Home Loan Bank System to support
SHARED ASSESSMENTS PROGRAM STANDARDIZED INFORMATION GATHERING (SIG) QUESTIONNAIRE
SHARED ASSESSMENTS PROGRAM STANDARDIZED INFORMATION GATHERING (SIG) QUESTIONNAIRE The Shared Assessments Trust, But Verify Model The Shared Assessments Program Tools are used for managing the vendor risk
I. Purpose. Definition. a. Identity Theft - a fraud committed or attempted using the identifying information of another person without authority.
Procedure 3.6: Rule (Identity Theft Prevention) Volume 3: Office of Business & Finance Managing Office: Office of Business & Finance Effective Date: December 2, 2014 I. Purpose In 2007, the Federal Trade
Quality Management in Clinical Trials
CLINICAL CASE STUDY SERIES Quality Management in Clinical Trials Clinical trials are conducted to collect the data necessary to provide information for academia, industry, and regulators to make decisions
SUPERVISION GUIDELINE NO. 9 ISSUED UNDER THE AUTHORITY OF THE FINANCIAL INSTITUTIONS ACT 1995 (NO. 1 OF 1995) RISK MANAGEMENT
SUPERVISION GUIDELINE NO. 9 ISSUED UNDER THE AUTHORITY OF THE FINANCIAL INSTITUTIONS ACT 1995 (NO. 1 OF 1995) RISK MANAGEMENT Bank of Guyana July 1, 2009 TABLE OF CONTENTS 1.0 Introduction 2.0 Management
