Cyber Security Requirements. The Contractor Sample Clauses

Cyber Security Requirements. The Contractor. (a) represents and warrants to OPG that: (i) the Contractor has a written and enforceable cyber security policy, and has established and maintains a cyber security program that is designed and implemented to prevent, detect and respond to cyber attacks that may impact OPG Systems and Information; and (ii) the Contractor’s Personnel (which, for the purposes of these requirements, includes any of the Contractor’s personnel having access to OPG Systems and Information) have completed position-appropriate cyber security training; (b) will immediately revoke all access to OPG Systems and Information for any of the Contractor’s Personnel who is terminated or no longer needs access to OPG Systems and Information; (c) will notify OPG by sending an email to xxxx@xxx.xxx within 48 hours after discovering any security breach, incident or vulnerability impacting or otherwise involving OPG Systems and Information (including any Cyber Equipment if the Contractor, acting reasonably, believes any such security breach, incident or vulnerability may have impacted or may potentially impact OPG Systems and Information), and furthermore if such security breach, incident or vulnerabilities relates to any Cyber Asset, Cyber Equipment, or Cyber Service, the Contractor will also: (i) include in such written notification of any security breach, incident or vulnerability to OPG a description of the breach, incident or vulnerability, its potential security impact, its root cause, a remediation plan, and recommended mitigating or corrective actions; and (ii) promptly and continuously cooperate and coordinate with OPG to prevent, stop, contain, mitigate, resolve, recover from, respond to, and otherwise deal with any security breach, incident or vulnerability, including by providing OPG with ongoing status reports;
AutoNDA by SimpleDocs

Related to Cyber Security Requirements. The Contractor

  • Data Security Requirements Without limiting Contractor’s obligation of confidentiality as further described in this Contract, Contractor must establish, maintain, and enforce a data privacy program and an information and cyber security program, including safety, physical, and technical security and resiliency policies and procedures, that comply with the requirements set forth in this Contract and, to the extent such programs are consistent with and not less protective than the requirements set forth in this Contract and are at least equal to applicable best industry practices and standards (NIST 800-53).

  • Security Requirements 7.1 The Authority will review the Contractor’s Security Plan when submitted by the Contractor in accordance with the Schedule (Security Requirements and Plan) and at least annually thereafter.

  • New Hampshire Specific Data Security Requirements The Provider agrees to the following privacy and security standards from “the Minimum Standards for Privacy and Security of Student and Employee Data” from the New Hampshire Department of Education. Specifically, the Provider agrees to: (1) Limit system access to the types of transactions and functions that authorized users, such as students, parents, and LEA are permitted to execute; (2) Limit unsuccessful logon attempts; (3) Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; (4) Authorize wireless access prior to allowing such connections; (5) Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity; (6) Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions; (7) Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; (8) Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services; (9) Enforce a minimum password complexity and change of characters when new passwords are created; (10) Perform maintenance on organizational systems; (11) Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance; (12) Ensure equipment removed for off-site maintenance is sanitized of any Student Data in accordance with NIST SP 800-88 Revision 1; (13) Protect (i.e., physically control and securely store) system media containing Student Data, both paper and digital; (14) Sanitize or destroy system media containing Student Data in accordance with NIST SP 800-88 Revision 1 before disposal or release for reuse; (15) Control access to media containing Student Data and maintain accountability for media during transport outside of controlled areas; (16) Periodically assess the security controls in organizational systems to determine if the controls are effective in their application and develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems; (17) Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; (18) Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception); (19) Protect the confidentiality of Student Data at rest; (20) Identify, report, and correct system flaws in a timely manner; (21) Provide protection from malicious code (i.e. Antivirus and Antimalware) at designated locations within organizational systems; (22) Monitor system security alerts and advisories and take action in response; and (23) Update malicious code protection mechanisms when new releases are available.

  • Federal Medicaid System Security Requirements Compliance Party shall provide a security plan, risk assessment, and security controls review document within three months of the start date of this Agreement (and update it annually thereafter) in order to support audit compliance with 45 CFR 95.621 subpart F, ADP System Security Requirements and Review Process.

  • Compliance with USA Patriot Act In accordance with the requirements of the USA Patriot Act (Title III of Pub. L. 107-56 (signed into law October 26, 2001)), the Underwriters are required to obtain, verify and record information that identifies their respective clients, including the Company, which information may include the name and address of their respective clients, as well as other information that will allow the Underwriters to properly identify their respective clients.

  • Facility Requirements 1. Maintain wheelchair accessibility to program activities according to governing law, including the Americans With Disabilities Act (ADA), as applicable. 2. Provide service site(s) that will promote attainment of Contractor’s program objectives. Arrange the physical environment to support those activities. 3. Decrease program costs when possible by procuring items at no cost from County surplus stores and by accepting delivery of such items by County.

  • Cyber Security Insurance for loss to the Owner due to data security and privacy breach, including costs of investigating a potential or actual breach of confidential or private information. (Indicate applicable limits of coverage or other conditions in the fill point below.) « »

  • Compliance with Patriot Act In order to comply with laws, rules, regulations and executive orders in effect from time to time applicable to banking institutions, including those relating to the funding of terrorist activities and money laundering (“Applicable Law”), the Owner Trustee is required to obtain, verify and record certain information relating to individuals and entities which maintain a business relationship with the Owner Trustee. Accordingly, the Seller shall cause to be provided to the Owner Trustee upon its reasonable request from time to time such identifying information and documentation as may be available to the Seller in order to enable the Owner Trustee to comply with Applicable Law.

  • Compliance with Statutes, Regulations, Etc The Borrower will, and will cause each Subsidiary to, comply with all applicable laws, rules, regulations and orders applicable to it or its property, including all governmental approvals or authorizations required to conduct its business, and to maintain all such governmental approvals or authorizations in full force and effect, in each case except where the failure to do so could not reasonably be expected to have a Material Adverse Effect.

  • Business Day Requirements In the event that any notice or other action or omission is required to be taken by a Party under this Agreement on a day that is not a Business Day then such notice or other action or omission shall be deemed to be required to be taken on the next occurring Business Day.

Draft better contracts in just 5 minutes Get the weekly Law Insider newsletter packed with expert videos, webinars, ebooks, and more!