General Security Requirements. (a) GA will maintain a written, information security program designed to protect the confidentiality, integrity and availability of Confidential Information in paper or other records and within its information system, including computers, devices, applications, and any wireless systems, and designed to perform the following core information security functions: (i) identify and assess both internal and external information security risks (“Risk Assessment”); (ii) utilize a defensive infrastructure; (iii) implement policies and procedures that protect Confidential Information from unauthorized Use; (iv) detect, respond to, and mitigate, Information Security Breaches and Security Incidents, restoring normal operations and services; and (v) fulfill regulatory reporting obligations. (b) The Risk Assessment performed by GA will be: (i) sufficient to inform the design of the information security program; (ii) updated as reasonably necessary to address changes to GA’s information systems, records, Confidential Information, and business operations; and
Appears in 4 contracts
Samples: Medicare Advantage and Part D Prescription Contract, Appointment Agreement, Agent Appointment Agreement