Self Attestation of Cybersecurity Protections GBC

  1. The following IT security policies are in place and reviewed annually and are implemented across the ESE's corporation which include officer level approval:

    1. An Information Security Policy
    2. Acceptable Use Policy
    3. Business Continuity Policy
    4. Disaster Recovery Policy
    5. Vendor Risk Management Policy
    6. Risk Assessment Policy
  2. An Incident Response Procedure is implemented that includes notification within 48 hours of knowledge of a potential incident alerting utility when Eversource's Confidential Customer Utility Information (CCUI) is potentially exposed, or of any other potential security breach.
  3. Role-based access controls (least privileged access) are used to restrict system access to authorized users and limited on a need-to-know basis.
  4. Multi-factor authentication (MFA) is used for all remote administrative access, including, but not limited to, access to production environments.
  5. All production systems are properly maintained and updated to include security patches on a periodic basis. Where a critical alert is raised, time is of the essence, and patches will be applied as soon as practicable.
  6. Antivirus software is installed on all servers and workstations and is maintained with up-to-date signatures. All Confidential Customer Utility Information is encrypted in transit utilizing industry best practice encryption methods, except that Confidential Information does not need to be encrypted during email communications.
  7. All Confidential Customer Utility Information is encrypted in transit utilizing industry best practice encryption methods, except that Confidential Information does not need to be encrypted during email communications.
  8. A Non-Disclosure Agreement (NDA) will be signed by all employees with access to CCUI that includes restrictions stated for employment term as well as when employee/contractors are terminated.
  9. All Confidential Customer Utility Information (CCUI) is secured or encrypted at rest utilizing industry best practice encryption methods or is otherwise physically secured.
  10. All CCUI is not comingled with other company's data.
  11. It is prohibited to store Confidential Customer Utility (CCUI) Information on any mobile forms of storage media, including, but not limited to, laptop PCs, mobile phones, portable backup storage media, and external hard drives, unless the storage media or data is encrypted.
  12. All Confidential Customer Utility Information (CCUI) is stored in the United States or Canada only, including, but not limited to, cloud storage environments and data management services.
  13. Your company monitors and alerts their network for anomalous cyber activity on a 24/7 basis.
  14. Security awareness training is provided to all personnel, including contractors, with access to Eversource's Confidential Customer Utility Information (CCUI).
  15. Employee background screening occurs prior to the granting their access to Confidential Customer Utility Information (CCUI).
  16. Replication of Confidential Customer Utility Information (CCUI) to non- company assets, systems, or locations is prohibited.
  17. Access to Confidential Customer Utility Information (CCUI) is revoked when no longer required, or if employees separate from the Third Party.
  18. Your company maintains an up-to-date SOC II Type 2 Audit Report from a third party on an annual basis, or other security controls audit report.
  19. The company does not operate or manufacture in any countries of interest (Russia, China, North Korea, and Iran).
  20. Eversource data will not be shared or used within the any platform in any way with a generative AI platform/tool.
  21. Your company has Cyber Insurance.
  22. Your company has been in business for more than 5 years.

NDA Statement Terms and Conditions

I agree to treat as confidential all information that will be received from Eversource Energy while participating in the Green Button platform, to use this information solely for the purpose of evaluation and analysis, not to disclose any of the data to any third party and not make it publicly available or accessible.