Request to pull July 15 agenda items 4D and 4F for brief discussion

Hi Mike,

Thank you again for the thorough response. I appreciate you coordinating with IT and Engineering staff, and I also appreciate that you and staff will be available tonight if Council has additional questions.

Your response answered many of the questions I raised and was helpful in understanding how the City is approaching these systems. Given that Council may act on these items tonight, I would appreciate any additional responses staff can provide before or during the meeting. If some of these questions require more time, it would still be helpful for Council and the public to know which items remain under review.

On the Aclara item, you noted that Aclara retains approximately three years of meter-reading history in the cloud, while the City’s on-premises database currently retains that data indefinitely. Is there a formal retention policy for the City-held meter data, and what is the operational reason for indefinite retention?

You also noted that access is role-based and activity is logged. Is there a periodic audit process for those logs? If so, how often are they reviewed, and by whom?

You mentioned that meter data may be released through the public records request process. Given that hourly, address-specific water-use data can potentially reveal household routines, occupancy patterns, vacations, caregiving patterns, or other sensitive details, has the City considered whether any Oregon public-records exemptions, redaction practices, or special review procedures should apply before releasing that kind of granular utility data?

I also noticed that WaterSmart/WaterWise does not appear to be discussed in the public agenda packet. Since staff’s response indicates that meter data is integrated with that platform, could the City clarify what data is shared with it and what privacy, retention, vendor-use, and security terms govern that relationship?

Finally, does the Aclara agreement itself limit Aclara’s use of City or customer data, separate from the City’s own stated limits on use of the data?

On the ProjectTeam item, your response identifies several important controls, including MFA, role-based access controls, encryption, logging, security assessments, AWS hosting, and cyber-liability insurance.

For my understanding, has the City directly reviewed the underlying SOC 2, FedRAMP, GovRAMP, or comparable documentation as part of its security review, or is the City relying on vendor representations for some of those controls? Also, has the City reviewed a full list of subprocessors beyond AWS, and what is the contractual breach-notification timeline?

I do not raise these questions as criticism of staff or of either procurement. My larger concern is that privacy and cybersecurity issues now appear in many routine systems, including utilities, cloud platforms, GIS tools, permitting systems, transit technology, and contractor portals.

This exchange has been helpful because it shows how much important information may not be visible in the public packet alone. My hope is that Bend can eventually build a standard privacy and cybersecurity checklist into technology procurements and renewals, so these questions are considered consistently and early.

Thank you again for taking the time to engage on this. I appreciate it.

Best,

Jonathan Westmoreland
Bend Privacy Alliance

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *