Laserfiche WebLink
A 1 <br />E N E R G Y <br />P U B L I C U T I L I T I E S <br />RIVERSIDE PUBLIC UTILITIES <br />Board Memorandum <br />BOARD OF PUBLIC UTILITIES <br />DATE: FEBRUARY 5, 2016 <br />ITEM NO: 5 <br />File ID — 16 -0202 — C <br />SUBJECT: PROFESSIONAL SERVICES AGREEMENT FOR A VULNERABILITY ASSESSMENT <br />REPORT FOR RIVERSIDE PUBLIC UTILITIES — FOR $342,000 <br />ISSUE: <br />The issues for the Board of Public Utilities consideration are approval of a Professional Consulting Services <br />Agreement with Securicon, LLC for a Vulnerability Assessment Report and approval of the related Work <br />Order No. 1610130. <br />RECOMMENDATIONS: <br />That the Board of Public Utilities: <br />1. Approve Work Order No. 1610130 in the amount of $342,000; and <br />2. Approve a Professional Services Agreement with Securicon, LLC located in Alexandria, Virginia, for <br />preparation of the Vulnerability Assessment Report. <br />BACKGROUND: <br />Riverside Public Utilities (RPU) is requesting approval for the services of a professional consulting firm to <br />conduct a vulnerability assessment and to develop guidelines for the City's physical and cyber security <br />environments. In accordance with the latest best practices and generally accepted methodologies in physical <br />and cyber security, the consultant will develop physical and cyber security guidelines. The guidelines will <br />establish standards for personnel and asset protection, physical security and continuity of operations of water, <br />electric and power generation systems, and the operation and maintenance of control systems. In addition, a <br />checklist will be developed to document existing security features, vulnerabilities, and needed improvements. <br />The consulting firm will evaluate RPU's current policies and guidelines, and will assess all critical facilities <br />including water wells, water treatment plants, water storage reservoirs, pump stations, power generation <br />plants, electric substations, major electric supply remission points, major communication hubs, and office <br />buildings. The firm will conduct a gap analysis outlining deviations in the current implementation against the <br />new guidelines, and will document vulnerabilities that could lead to reduced integrity, confidentiality, or <br />availability of the City's critical data. Recommendations will be made to address root causes of any identified <br />vulnerabilities to reduce future risk, with planning level cost estimates for implementing physical and cyber <br />security enhancements. <br />The need for such an assessment stems from increased cyber and physical security threats to the utility <br />environment. Physical security threats, such as copper theft, have been known for years. However, more <br />sophisticated threats have emerged, reiterating the need to continue to develop and enhance guidelines and <br />practices to prepare for such attacks. <br />