Report 2014-120 Recommendation 17 Responses

Report 2014-120: California Public Utilities Commission: It Needs to Improve the Quality of Its Consumer Complaint Data and the Controls Over Its Information Systems (Release Date: April 2015)

Recommendation #17 To: Public Utilities Commission

The commission should revise its existing recovery plan to include detailed procedures for rebuilding its technology infrastructure at an alternate processing site.

Annual Follow-Up Agency Response From October 2021

The California Public Utilities Commission (CPUC) has completed migration of all systems to Gold Camp Data Center using new updated hardware, including storage and servers. CPUC has updated Data backup recovery solution which provides complete backup coverage of all systems data. CPUC is also in the process of conducting business impact analysis (BIA) and upon completion this will provide the guidance for an alternate processing site.

California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented


Annual Follow-Up Agency Response From November 2020

The California Public Utilities Commission (CPUC) is in the process of relocating Information System resources to California Department of Technology data center. Once the migration of these systems is complete, CPUC will revise existing plans and procedures along with identifying alternate processing sites as needed.

California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented


Annual Follow-Up Agency Response From October 2019

Updated 10/14/19 - Partially Implemented

Business continuity plan and TRP updated, email failover is managed thru CDT contract with Microsoft. New ISRP's developed and tested for Public Facing Websites and Remote Access. Content Server ISRP and testing on hold pending current OS and Software version upgrades and procurement of additional hosting resources estimated completion June 2020. Oracle Application Portal ISRP and testing on hold pending completion of migration from SF data-center to Gold Camp and procurement of additional hosting resources estimated completion December 2020.

California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented


Annual Follow-Up Agency Response From October 2018

CPUC is in the process of updating business continuity plan tentative completion Jan 2019.

California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented


Annual Follow-Up Agency Response From November 2017

CPUC is in the process of revising update Business continuity plan to incorporate the infrastructure changes.

California State Auditor's Assessment of Annual Follow-Up Status: Partially Implemented


Annual Follow-Up Agency Response From October 2016

The Commission continues to work to improve the recovery plan with detailed procedures for rebuilding its technology infrastructure.

California State Auditor's Assessment of Annual Follow-Up Status: Not Fully Implemented


1-Year Agency Response

CPUC Business Continuity Plan is in draft form and scheduled to be completed April 30th, 2016.

California State Auditor's Assessment of 1-Year Status: Partially Implemented

The commission explained that as a result of our follow up work, it reevaluated its progress and now believes it has not fully implemented this recommendation. The commission estimates that it will not achieve full compliance with SAM Chapter 5300 until December 2019.


6-Month Agency Response

Recovery plan updates will be addressed in Business continuity plan as a subset of Security assessment. Contract has been awarded and CPUC staff is working with consultants.

California State Auditor's Assessment of 6-Month Status: Pending


60-Day Agency Response

Recovery plan updates will be addressed in Business continuity plan as a subset of Security assessment (RFO was released).

California State Auditor's Assessment of 60-Day Status: Pending


All Recommendations in 2014-120

Agency responses received are posted verbatim.