AUDIT AND SECURITY. 15.1 The Contractor shall demonstrate the security of any and all systems that may contain consumer data, including the secure transmission and receipt of data and be prepared for an audit of the security measures and confirm the integrity of services; Schedule 6 of the call off Terms and Conditions describes the security requirements in detail and bidders should ensure they have fully considered them. 15.2 The Contractor shall operate the services from secure locations and ensure that all IT, communication and other systems used have the appropriate level of security and the latest IS Security Policy and Standards. 15.3 The Framework Agreement between the Contractor and the Authority shall state the confidentiality and integrity of the information passed between both parties. Subsequent call off contracts pursuant to paragraphs 3.1 and 3.2 above will be subject to each OGD’s security requirements which includes accreditation where required. Contracts with DWP are subject to formal approval by the Authority’s Departmental Security Team and will only be granted when the full technical/security features of the Contractor’s operations and solution are defined and conform to the DWP Security Accreditation procedure and policy. This may involve DWP being granted access to the following: The Contractor’s premises; Contractor documentation; Contractor data; Where the Contractor’s computer and communications system is located and how access to these and the services they provide is controlled. 15.4 In accordance with the DWP Offshoring Policy, the Contractor, or any of its sub-contractors, shall not process, host or access Authority Data from premises outside the United Kingdom without the prior written consent of DWP. Where DWP gives consent, the Contractor shall comply with any reasonable instructions notified to it by DWP in relation to the Authority Data in question. A copy of A Guide for DWP Contractors on the DWP Offshoring Policy is attached an Annex 1.
Appears in 6 contracts
Samples: Framework Agreement, Framework Agreement, Framework Agreement