Report 2014-120 Recommendation 17 Responses
Report 2014-120: California Public Utilities Commission: It Needs to Improve the Quality of Its Consumer Complaint Data and the Controls Over Its Information Systems (Release Date: April 2015)
Recommendation #17 To: Public Utilities Commission
The commission should revise its existing recovery plan to include detailed procedures for rebuilding its technology infrastructure at an alternate processing site.
Annual Follow-Up Agency Response From October 2021
The California Public Utilities Commission (CPUC) has completed migration of all systems to Gold Camp Data Center using new updated hardware, including storage and servers. CPUC has updated Data backup recovery solution which provides complete backup coverage of all systems data. CPUC is also in the process of conducting business impact analysis (BIA) and upon completion this will provide the guidance for an alternate processing site.
- Estimated Completion Date: 12/31/2022
California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented
Annual Follow-Up Agency Response From November 2020
The California Public Utilities Commission (CPUC) is in the process of relocating Information System resources to California Department of Technology data center. Once the migration of these systems is complete, CPUC will revise existing plans and procedures along with identifying alternate processing sites as needed.
- Estimated Completion Date: 12/31/2021
California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented
Annual Follow-Up Agency Response From October 2019
Updated 10/14/19 - Partially Implemented
Business continuity plan and TRP updated, email failover is managed thru CDT contract with Microsoft. New ISRP's developed and tested for Public Facing Websites and Remote Access. Content Server ISRP and testing on hold pending current OS and Software version upgrades and procurement of additional hosting resources estimated completion June 2020. Oracle Application Portal ISRP and testing on hold pending completion of migration from SF data-center to Gold Camp and procurement of additional hosting resources estimated completion December 2020.
- Estimated Completion Date: 12/31/2020
California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented
Annual Follow-Up Agency Response From October 2018
CPUC is in the process of updating business continuity plan tentative completion Jan 2019.
- Estimated Completion Date: 10/2019
California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented
Annual Follow-Up Agency Response From November 2017
CPUC is in the process of revising update Business continuity plan to incorporate the infrastructure changes.
- Estimated Completion Date: 6/30/2018
California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented
Annual Follow-Up Agency Response From October 2016
The Commission continues to work to improve the recovery plan with detailed procedures for rebuilding its technology infrastructure.
- Estimated Completion Date: 12/30/2018
California State Auditor's Assessment of Annual Follow-Up Status: Not Fully Implemented
1-Year Agency Response
CPUC Business Continuity Plan is in draft form and scheduled to be completed April 30th, 2016.
- Estimated Completion Date: 4/30/2016
- Response Date: April 2016
California State Auditor's Assessment of 1-Year Status: Partially Implemented
The commission explained that as a result of our follow up work, it reevaluated its progress and now believes it has not fully implemented this recommendation. The commission estimates that it will not achieve full compliance with SAM Chapter 5300 until December 2019.
6-Month Agency Response
Recovery plan updates will be addressed in Business continuity plan as a subset of Security assessment. Contract has been awarded and CPUC staff is working with consultants.
- Estimated Completion Date: Ongoing implementation.
- Response Date: October 2015
California State Auditor's Assessment of 6-Month Status: Pending
60-Day Agency Response
Recovery plan updates will be addressed in Business continuity plan as a subset of Security assessment (RFO was released).
- Estimated Completion Date: April 2016
- Response Date: June 2015
California State Auditor's Assessment of 60-Day Status: Pending
All Recommendations in 2014-120
Agency responses received are posted verbatim.