Data Security Requirements Without limiting Contractor’s obligation of confidentiality as further described in this Contract, Contractor must establish, maintain, and enforce a data privacy program and an information and cyber security program, including safety, physical, and technical security and resiliency policies and procedures, that comply with the requirements set forth in this Contract and, to the extent such programs are consistent with and not less protective than the requirements set forth in this Contract and are at least equal to applicable best industry practices and standards (NIST 800-53).
Disclosure and Use Restrictions Executive agrees and covenants: (i) to treat all Confidential Information as strictly confidential; (ii) not to directly or indirectly disclose, publish, communicate, or make available Confidential Information, or allow it to be disclosed, published, communicated, or made available, in whole or part, to any entity or person whatsoever (including other employees of the Company) not having a need to know and authority to know and use the Confidential Information in connection with the business of the Company and, in any event, not to anyone outside of the direct employ of the Company except as required in the performance of Executive’s authorized employment duties to the Company or with the prior consent of the Board acting on behalf of the Company in each instance (and then, such disclosure shall be made only within the limits and to the extent of such duties or consent); and (iii) not to access or use any Confidential Information, and not to copy any documents, records, files, media, or other resources containing any Confidential Information, or remove any such documents, records, files, media, or other resources from the premises or control of the Company, except as required in the performance of Executive’s authorized employment duties to the Company or with the prior consent of the Board acting on behalf of the Company in each instance (and then, such disclosure shall be made only within the limits and to the extent of such duties or consent). Nothing herein shall be construed to prevent disclosure of Confidential Information as may be required by applicable law or regulation, or pursuant to the valid order of a court of competent jurisdiction or an authorized government agency, provided that the disclosure does not exceed the extent of disclosure required by such law, regulation, or order. Executive shall promptly provide written notice of any such order to the Board.
Disclosure and Use 20.2.1 Each Receiving Party agrees that, from and after the Effective Date: (a) all such Proprietary Information communicated or discovered, whether before, on or after the Effective Date, in connection with this Agreement shall be held in confidence to the same extent as such Receiving Party holds its own confidential information; provided, that such Receiving Party shall not use less than a reasonable standard of care in maintaining the confidentiality of such information; (b) it will not, and it will not permit any of its employees, contractors, consultants, agents or affiliates to disclose such Proprietary Information to any other third person; (c) it will disclose Proprietary Information only to those of its employees, contractors, consultants, agents and affiliates who have a need for it in connection with the use or provision of services required to fulfill this Agreement; (d) it will, and will cause each of its employees, contractors, consultants, agents and affiliates to use such Proprietary Information only to effectuate the terms and conditions of this Agreement and for no other purpose; (e) it will cause each of its affiliates to execute individual confidentiality agreements containing the same restrictions as this Article XX; and (f) it will, and will cause each of its employees, contractors, consultants, agents and affiliates, to use such Proprietary Information to create only that Derivative Information necessary for such Receiving Party's compliance with Applicable Law or its performance under the terms of this Agreement. 20.2.2 Any Receiving Party so disclosing Proprietary Information to its employees, contractors, consultants, agents or affiliates shall be responsible for any breach of this Agreement by any of its employees, contractors, consultants, agents or affiliates and such Receiving Party agrees to use its reasonable efforts to restrain its employees, contractors, consultants, agents or affiliates from any prohibited or unauthorized disclosure or use of the Proprietary Information and to assist the Disclosing Party in its efforts to protect such information from disclosure. Each Receiving Party making such disclosure shall notify the Disclosing Party as soon as possible if it has knowledge of a breach of this Agreement in any material respect. 20.2.3 Proprietary Information shall not be reproduced by any Receiving Party in any form except to the extent (i) necessary to comply with the provisions of Section 20.3 and (ii) reasonably necessary to perform its obligations under this Agreement. All such reproductions shall bear the same copyright and proprietary rights notices as are contained in or on the original.
Security Requirements 7.1 The Authority will review the Contractor’s Security Plan when submitted by the Contractor in accordance with the Schedule (Security Requirements and Plan) and at least annually thereafter.
Confidentiality and Security Section 1: Service Provider agrees that all of its employees, contractors, subcontractors, or associates will comply with all state and federal law and with TJJD policies regarding maintaining the confidentiality of TJJD youth, including, but not limited to, maintaining confidentiality of student records and identifying information. Section 2: Service Provider agrees that all information regarding TJJD and/or its youth that is gathered, produced, or otherwise derived from this contract shall remain confidential and subject to release only by permission of TJJD. Section 3: Service Provider’s employees, contractors, subcontractors, or associates who visit any TJJD facility will comply with that facility's security regulations. Section 4: Identifying pictures, appearances, films, or reports of TJJD youth may not be disclosed by Service Provider without the written consent of TJJD, of the youth and, if under age 18, of the youth’s parent, guardian, or managing conservator.
Data Protection and Security A. In this Agreement the following terms shall have the meanings respectively ascribed to them:
New Hampshire Specific Data Security Requirements The Provider agrees to the following privacy and security standards from “the Minimum Standards for Privacy and Security of Student and Employee Data” from the New Hampshire Department of Education. Specifically, the Provider agrees to: (1) Limit system access to the types of transactions and functions that authorized users, such as students, parents, and LEA are permitted to execute; (2) Limit unsuccessful logon attempts; (3) Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; (4) Authorize wireless access prior to allowing such connections; (5) Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity; (6) Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions; (7) Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; (8) Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services; (9) Enforce a minimum password complexity and change of characters when new passwords are created; (10) Perform maintenance on organizational systems; (11) Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance; (12) Ensure equipment removed for off-site maintenance is sanitized of any Student Data in accordance with NIST SP 800-88 Revision 1; (13) Protect (i.e., physically control and securely store) system media containing Student Data, both paper and digital; (14) Sanitize or destroy system media containing Student Data in accordance with NIST SP 800-88 Revision 1 before disposal or release for reuse; (15) Control access to media containing Student Data and maintain accountability for media during transport outside of controlled areas; (16) Periodically assess the security controls in organizational systems to determine if the controls are effective in their application and develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems; (17) Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems; (18) Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception); (19) Protect the confidentiality of Student Data at rest; (20) Identify, report, and correct system flaws in a timely manner; (21) Provide protection from malicious code (i.e. Antivirus and Antimalware) at designated locations within organizational systems; (22) Monitor system security alerts and advisories and take action in response; and (23) Update malicious code protection mechanisms when new releases are available.
Reporting Status and Securities Laws Matters Buyer is a "reporting issuer" and not on the list of reporting issuers in default under applicable Canadian securities laws in any of the provinces or territories of Canada. No delisting, suspension of trading in or cease trading order with respect to any securities of Buyer and, to the knowledge of Buyer, no inquiry or investigation (formal or informal) of any Securities Authorities is in effect or ongoing or, to the knowledge of Buyer, expected to be implemented or undertaken with respect to the foregoing.
Indenture and Securities Solely Corporate Obligations No recourse for the payment of the principal of or premium, if any, or interest on any Security, or for any claim based thereon or otherwise in respect thereof, and no recourse under or upon any obligation, covenant or agreement of the Company in this Indenture or in any supplemental indenture or in any Security, or because of the creation of any indebtedness represented thereby, shall be had against any incorporator, stockholder, employee, agent, officer, or director or subsidiary, as such, past, present or future, of the Company or of any successor corporation, either directly or through the Company or any successor corporation, whether by virtue of any constitution, statute or rule of law, or by the enforcement of any assessment or penalty or otherwise; it being expressly understood that all such liability is hereby expressly waived and released as a condition of, and as a consideration for, the execution of this Indenture and the issue of the Securities.
Restriction on Disclosure and Use of Confidential Information Executive agrees that Executive shall not, directly or indirectly, use any Confidential Information on Executive’s own behalf or on behalf of any Person other than Employer, or reveal, divulge, or disclose any Confidential Information to any Person not expressly authorized by Employer to receive such Confidential Information. This obligation shall remain in effect for as long as the information or materials in question retain their status as Confidential Information. Executive further agrees to fully cooperate with Employer in maintaining the Confidential Information to the extent permitted by law. The Parties acknowledge and agree that this Agreement is not intended to, and does not, alter either Employer’s rights or Executive’s obligations under any state or federal statutory or common law regarding trade secrets and unfair trade practices. Anything herein to the contrary notwithstanding, Executive shall not be restricted from disclosing information that is required to be disclosed by law, court order, or other valid and appropriate legal process; provided, however, that in the event such disclosure is required by law, Executive shall provide Employer with prompt notice of such requirement so that Employer may seek an appropriate protective order prior to any such required disclosure by Executive. Executive understands and acknowledges that nothing in this section limits Executive’s ability to report possible violations of federal, state, or local law or regulation to any governmental agency or entity; to communicate with any government agencies or otherwise participate in any investigation or proceeding that may be conducted by any government agencies in connection with any charge or complaint, whether filed by Executive, on Executive’s behalf, or by any other individual; or to make other disclosures that are protected under the whistleblower provisions of federal, state, or local law or regulation, and Executive shall not need the prior authorization of Employer to make any such reports or disclosures and shall not be required to notify Employer that Executive has made such reports or disclosures. In addition, and anything herein to the contrary notwithstanding, Executive is hereby given notice that Executive shall not be criminally or civilly liable under any federal or state trade secret law for disclosing a trade secret (as defined by 18 U.S.C. § 1839) in confidence to a federal, state, or local government official, either directly or indirectly, or to an attorney, in either event solely for the purpose of reporting or investigating a suspected violation of law; or disclosing a trade secret (as defined by 18 U.S.C. § 1839) in a complaint or other document filed in a lawsuit or other proceeding, if such filing is made under seal.