2021-0303-04-Presentation-IT-and-AMI-Audit.pdf

Krishna1110 10 views 18 slides Jul 01, 2024
Slide 1
Slide 1 of 18
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18

About This Presentation

auditing


Slide Content

Silicon Valley Clean Energy Authority
Report to the Audit Committee
March 3, 2021Item 3
PRESENTATION
PISENTI&BRINKER LLP
C e r t i f i e dP u b l i cA c c o u n t a n t s&A d v i s o r s

Introduction
•Brett Bradford, CPA
•Audit Partner
•17 years in public accounting and performing audits
of government entities
•Currently working with several CCA’s throughout
California
•Andrea Lifto, CPA
•Engagement Manager
•5 years in public accounting and performing audits of
governments (CCA’s)Item 3
PRESENTATION
Anindependentlyownedmember
RSMUSAlliance
RSM PISENTI&BRINKER L L P
C e r t i f i e dP u b l i cA c c o u n t a n t s&A d v i s o r s

Results of current year audit:
•Audit is near completion. We expect to report the following:
•Unmodified opinion –Based on our audit, the financial
statements are materially accurate.
•No significant deficiencies in internal control have
been noted.Item 3
PRESENTATION

Audit of the year ended September 30, 2020
Financial Statements
Relative Roles & Responsibilities
•Managementis responsible for preparing the Financial Statements
and establishing a system of internal control
•Auditor is responsible for auditing the Financial Statements
•Considering risks of material misstatement in the Financial
Statements
•Considering internal controls relevant to the Financial Statements
•Performing tests of year-end balances based on risk assessment
•Evaluating adequacy of disclosuresItem 3
PRESENTATION

Risk Assessment for the year ended
September 30, 2020
Our audit is a risk-based audit. Risk assessment procedures include:
•Gain understanding of the entity’s operating characteristics,
practices, and procedures.
•Compare to our knowledge of similar entities, industry and
professional guidance.
•Review procedures and controls surrounding significant
transaction cycles and business processes.Item 3
PRESENTATION

Audit Procedures
Significant areas of focus
•Revenue recognition
•Accounts receivable and revenue
•Test a sample of customer billings
•Relate total cash received during the year to revenue
•Look at cash received subsequent to year-end and relate to A/R
•Review revenue recognition through year-end and the method for determining
(accrued revenue)
•Cash
•Confirmations sent to financial institutionsItem 3
PRESENTATION
Anindependentlyownedmember
RSMUSAlliance
RSM PISENTI&BRINKER L L P
C e r t i f i e dP u b l i cA c c o u n t a n t s&A d v i s o r s

Audit Procedures
Significant areas of focus
•Accrued Cost of Electricity
•Review subsequent bills from electricity providers and cash payments
•Other Liabilities
•Reviewed contracts and other support to determine completeness of amounts
recorded
•Financial Statement Note Disclosures –Complete and without biasItem 3
PRESENTATION
Anindependentlyownedmember
RSMUSAlliance
RSM PISENTI&BRINKER L L P
C e r t i f i e dP u b l i cA c c o u n t a n t s&A d v i s o r s

Required Board Communications
•The significant accounting
policies adopted by SVCE
throughout the period audited
appear appropriate and
consistently applied.
•No alternative treatments of
accounting principles for material
items in the financial statements
have been discussed with
management.Item 3
PRESENTATION

Required Board Communications (continued)
•We are not expecting to propose
any adjustments to the financial
statements.
•We have not identified any
significant or unusual
transactions or applications of
accounting principles where a
lack of authoritative guidance
exists.
Other required communications with those charged with governance:Item 3
PRESENTATION

Required Board Communications (continued)
•There have been no
disagreements with management
concerning the scope of our audit,
the application of accounting
principles, or the basis for
management’s judgements on any
significant matters.
•We have not encountered any
difficulties in dealing with
management during the
performance of our audit.
Other required communications with those charged with governance:Item 3
PRESENTATION

Brett Bradford: 707-577-1582
Andrea Lifto: 707-559-7317
Questions?Item 3
PRESENTATION
PISENTI&BRINKER LLP
CertifiedPublicAccountants &Advisors

2021 IT Audit
1Item 4
PRESENTATION

Cybersecurity Facts and Stats
2
•Cyber crime damage costs to hit $6 trillion annually by 2021
•Human attack surface to reach 6 billion people by 2022
•Global ransomware damage costs are predicted to exceed $5 billion in 2017
•There is a hacker attack every 39 seconds
•43% of cyber attacks target small business
•The average cost of a data breach in 2020 will exceed $150 million
•Since 2013 there are 3,809,448 records stolen from breaches every day
•91% of cyber attacks start with an email.
•95% of cybersecurity breaches are due to human error
SILICONVALLEY
CLEANENERGYItem 4
PRESENTATION

4th Annual IT Security Audit
3
Mission Statement -Develop a Cybersecurity program that is
designed to deal with SVCE risks, business challenges and
budget that is able to grow and adapt based on the evolution
of SVCE.
•Audit will cover the same items as last year with
additional emphasis on work from home technology
•Continue in depth Penetration and Vulnerability testing
•Continue demand for higher level deliverables and reports
•Asking for WFH and Covidrecommendations
•Revising current SVCE IT policies and new policy
development
SILICONVALLEY
CLEANENERGYItem 4
PRESENTATION

2021 IT Cyber Audit Timeline
4
RFP currently
posted through
Mid-March
2021
Audit starts
April 2021
Audit wraps
June 2021
Remediations
will start in
August and run
through
October 2021
SILICONVALLEY
CLEANENERGYItem 4
PRESENTATION

What will the Audit Cover?
5Item 4
PRESENTATION

2022 AMI Audit
6Item 4
PRESENTATION

7
Automated Meter Infrastructure (AMI)
audit required by CPUC triennially
CPUC Decision 12-08-045
Regulatory
AMI specific IT controls related to
the acquisition, storage and
processing of AMI (customer
data) related data
General IT controls (such as patch
management, IT governance,
backup-recovery)
Written Polices and Procedures
Focus
AMI Audit 2022Item 4
PRESENTATION
Tags