Independent Review of Information Security Sample Clauses

Independent Review of Information Security. Supplier shall review at least annually, or when significant changes to the security implementation occur, Supplier's approach to managing information security and its control objectives, controls, policies, processes, and procedures. The review shall include an assessment of Supplier's adherence to its security plan, address the need for changes to the approach to security in light of evolving circumstances, and be carried out by individuals independent of the area under review who have the appropriate skills and experience.
AutoNDA by SimpleDocs
Independent Review of Information Security. Xxxxxx+Gyr’s approach to managing information security and its implementation (i.e., control objectives, controls, policies, processes, and procedures for information security) is reviewed independently at planned intervals or when significant changes occur.
Independent Review of Information Security a) Performance of audits b) Review of compliance with security policies and standards c) Verification of compliance with technical specifications

Related to Independent Review of Information Security

  • Furnishing of Information and Inspection of Receivables The Seller will furnish to the Administrator and each Purchaser Agent from time to time such information with respect to the Pool Receivables as the Administrator or such Purchaser Agent may reasonably request. The Seller will, at the Seller’s expense, at any time during regular business hours with prior written notice (i) permit the Administrator or any Purchaser Agent, or their respective agents or representatives, (A) to examine and make copies of and abstracts from all books and records relating to the Pool Receivables or other Pool Assets and (B) to visit the offices and properties of the Seller for the purpose of examining such books and records, and to discuss matters relating to the Pool Receivables, other Pool Assets or the Seller’s performance hereunder or under the other Transaction Documents to which it is a party with any of the officers, directors, employees or independent public accountants of the Seller (provided that representatives of the Seller are present during such discussions) having knowledge of such matters; provided, that so long as no Termination Event has occurred and is continuing such examinations and visits shall not exceed one (1) per year and (ii) without limiting the provisions of clause (i) above, from time to time during regular business hours, at the Seller’s expense, upon reasonable prior written notice from the Administrator and the Purchaser Agents, permit certified public accountants or other auditors acceptable to the Administrator to conduct a review of its books and records with respect to the Pool Receivables; provided, that so long as no Termination Event has occurred and is continuing, the Seller shall be required to reimburse the Administrator and Purchaser Agents for only one (1) such audit per year. For the avoidance of doubt, the Administrator may require examinations and audits in addition to the examinations and audits specified in clause (i) and clause (ii) above, but the expense of any such additional examination or audit shall be borne by the Administrator and not the Seller.

  • Independent Review Contractor shall provide the Secretary of ADS/CIO an independent expert review of any Agency recommendation for any information technology activity when its total cost is $1,000,000.00 or greater or when CIO requires one. The State has identified two sub-categories for Independent Reviews, Standard and Complex. The State will identify in the SOW RFP the sub-category they are seeking. State shall not consider bids greater than the maximum value indicated below for this category. Standard Independent Review $25,000 Maximum Complex Independent Review $50,000 Maximum Per Vermont statute 3 V.S.A. 2222, The Secretary of Administration shall obtain independent expert review of any recommendation for any information technology initiated after July 1, 1996, as information technology activity is defined by subdivision (a) (10), when its total cost is $1,000,000 or greater or when required by the State Chief Information Officer. Documentation of this independent review shall be included when plans are submitted for review pursuant to subdivisions (a)(9) and (10) of this section. The independent review shall include: • An acquisition cost assessment • A technology architecture review • An implementation plan assessment • A cost analysis and model for benefit analysis • A procurement negotiation advisory services contract • An impact analysis on net operating costs for the agency carrying out the activity In addition, from time to time special reviews of the advisability and feasibility of certain types of IT strategies may be required. Following are Requirements and Capabilities for this Service: • Identify acquisition and lifecycle costs; • Assess wide area network (WAN) and/or local area network (LAN) impact; • Assess risks and/or review technical risk assessments of an IT project including security, data classification(s), subsystem designs, architectures, and computer systems in terms of their impact on costs, benefits, schedule and technical performance; • Assess, evaluate and critically review implementation plans, e.g.: • Adequacy of support for conversion and implementation activities • Adequacy of department and partner staff to provide Project Management • Adequacy of planned testing procedures • Acceptance/readiness of staff • Schedule soundness • Adequacy of training pre and post project • Assess proposed technical architecture to validate conformance to the State’s “strategic direction.” • Insure system use toolsets and strategies are consistent with State Chief Information Officer (CIO) policies, including security and digital records management; • Assess the architecture of the proposed hardware and software with regard to security and systems integration with other applications within the Department, and within the Agency, and existing or planned Enterprise Applications; • Perform cost and schedule risk assessments to support various alternatives to meet mission need, recommend alternative courses of action when one or more interdependent segment(s) or phase(s) experience a delay, and recommend opportunities for new technology insertions; • Assess the architecture of the proposed hardware and software with regard to the state of the art in this technology. • Assess a project’s backup/recovery strategy and the project’s disaster recovery plans for adequacy and conformance to State policy. • Evaluate the ability of a proposed solution to meet the needs for which the solution has been proposed, define the ability of the operational and user staff to integrate this solution into their work.

  • Due Diligence Review; Information The Company shall make available, during normal business hours, for inspection and review by the Investors, advisors to and representatives of the Investors (who may or may not be affiliated with the Investors and who are reasonably acceptable to the Company), all financial and other records, all SEC Filings (as defined in the Purchase Agreement) and other filings with the SEC, and all other corporate documents and properties of the Company as may be reasonably necessary for the purpose of such review, and cause the Company’s officers, directors and employees, within a reasonable time period, to supply all such information reasonably requested by the Investors or any such representative, advisor or underwriter in connection with such Registration Statement (including, without limitation, in response to all questions and other inquiries reasonably made or submitted by any of them), prior to and from time to time after the filing and effectiveness of the Registration Statement for the sole purpose of enabling the Investors and such representatives, advisors and underwriters and their respective accountants and attorneys to conduct initial and ongoing due diligence with respect to the Company and the accuracy of such Registration Statement. The Company shall not disclose material nonpublic information to the Investors, or to advisors to or representatives of the Investors, unless prior to disclosure of such information the Company identifies such information as being material nonpublic information and provides the Investors, such advisors and representatives with the opportunity to accept or refuse to accept such material nonpublic information for review and any Investor wishing to obtain such information enters into an appropriate confidentiality agreement with the Company with respect thereto.

  • Access to Information; Independent Investigation Prior to the execution of this Agreement, the Subscriber has had the opportunity to ask questions of and receive answers from representatives of the Company concerning an investment in the Company, as well as the finances, operations, business and prospects of the Company, and the opportunity to obtain additional information to verify the accuracy of all information so obtained. In determining whether to make this investment, Subscriber has relied solely on Subscriber’s own knowledge and understanding of the Company and its business based upon Subscriber’s own due diligence investigation and the information furnished pursuant to this paragraph. Subscriber understands that no person has been authorized to give any information or to make any representations which were not furnished pursuant to this Section 2 and Subscriber has not relied on any other representations or information in making its investment decision, whether written or oral, relating to the Company, its operations and/or its prospects.

  • Furnishing of Information and Inspection of Records The Borrower will furnish to the Deal Agent, each Lender, the Backup Servicer and the Collateral Agent, from time to time, such information with respect to the Loans and Contracts as may be reasonably requested, including, without limitation, a computer file or other list identifying each Loan and Contract by pool number, account number and dealer number and by the Outstanding Balance and identifying the Obligor on such Loan or Contract. The Borrower will, at any time and from time to time during regular business hours, upon reasonable notice, permit the Deal Agent, each Lender, the Backup Servicer and the Collateral Agent, or its agents or representatives, to examine and make copies of and abstracts from all Records, to visit the offices and properties of the Borrower for the purpose of examining such Records, and to discuss matters relating to the Loans or Contracts or the Borrower’s performance hereunder and under the other Transaction Documents with any of the officers, directors, employees or independent public accountants of the Borrower having knowledge of such matters; provided, however, that the Deal Agent, each Lender and the Collateral Agent each acknowledges that in exercising the rights and privileges conferred in this Section 5.1(m) it or its agents and representatives may, from time to time, obtain knowledge of information, practices, books, correspondence and records of a confidential nature and in which the Borrower has a proprietary interest. The Deal Agent, each Lender and the Collateral Agent each agrees that all such information, practices, books, correspondence and records are to be regarded as confidential information and agrees that it shall retain in strict confidence and shall use its reasonable efforts to ensure that its agents and representatives retain in strict confidence, and will not disclose without the prior written consent of the Borrower, any such information, practices, books, correspondence and records furnished to them except that it may disclose such information: (i) to its officers, directors, employees, agents, counsel, accountants, auditors, affiliates, advisors or representatives (provided that such Persons are informed of the confidential nature of such information); (ii) to the extent such information has become available to the public other than as a result of a disclosure by or through the Deal Agent, any Lender, the Collateral Agent or its officers, directors, employees, agents, counsel, accountants, auditors, affiliates, advisors or representatives; (iii) to the extent such information was available to the Deal Agent, any Lender or the Collateral Agent on a non-confidential basis prior to its disclosure hereunder; (iv) to the extent the Deal Agent, any Lender or the Collateral Agent should be (A) required under the Transaction Documents or in connection with any legal or regulatory proceeding or (B) requested by any bank regulatory authority to disclose such information; or (v) to any Lender or prospective assignee or Lender; provided, that the relevant Lender shall notify such prospective assignee or Lender of the confidentiality provisions of this Section 5.1(m).

  • Furnishing of Information; Public Information (a) Until the earliest of the time that (i) no Purchaser owns Securities or (ii) the Warrants have expired, the Company covenants to maintain the registration of the Common Stock under Section 12(b) or 12(g) of the Exchange Act and to timely file (or obtain extensions in respect thereof and file within the applicable grace period) all reports required to be filed by the Company after the date hereof pursuant to the Exchange Act even if the Company is not then subject to the reporting requirements of the Exchange Act. (b) At any time during the period commencing from the six (6) month anniversary of the date hereof and ending at such time that all of the Securities may be sold without the requirement for the Company to be in compliance with Rule 144(c)(1) and otherwise without restriction or limitation pursuant to Rule 144, if the Company (i) shall fail for any reason to satisfy the current public information requirement under Rule 144(c) or (ii) has ever been an issuer described in Rule 144(i)(1)(i) or becomes an issuer in the future, and the Company shall fail to satisfy any condition set forth in Rule 144(i)(2) (a “Public Information Failure”) then, in addition to such Purchaser’s other available remedies, the Company shall pay to a Purchaser, in cash, as partial liquidated damages and not as a penalty, by reason of any such delay in or reduction of its ability to sell the Securities, an amount in cash equal to two percent (2.0%) of the aggregate Subscription Amount of such Purchaser’s Securities on the day of a Public Information Failure and on every thirtieth (30th) day (pro rated for periods totaling less than thirty days) thereafter until the earlier of (a) the date such Public Information Failure is cured and (b) such time that such public information is no longer required for the Purchasers to transfer the Shares and Warrant Shares pursuant to Rule 144. The payments to which a Purchaser shall be entitled pursuant to this Section 4.2(b) are referred to herein as “Public Information Failure Payments.” Public Information Failure Payments shall be paid on the earlier of (i) the last day of the calendar month during which such Public Information Failure Payments are incurred and (ii) the third (3rd) Business Day after the event or failure giving rise to the Public Information Failure Payments is cured. In the event the Company fails to make Public Information Failure Payments in a timely manner, such Public Information Failure Payments shall bear interest at the rate of 1.5% per month (prorated for partial months) until paid in full. Nothing herein shall limit such Purchaser’s right to pursue actual damages for the Public Information Failure, and such Purchaser shall have the right to pursue all remedies available to it at law or in equity including, without limitation, a decree of specific performance and/or injunctive relief.

  • Accuracy and Completeness of Information No written information, report or other papers or data (excluding financial projections and other forward looking statements) furnished to the Agent or any Lender by, on behalf of, or at the direction of, the Borrower, any other Obligor or any of their respective Subsidiaries in connection with or relating in any way to this Agreement, contained any untrue statement of a fact material to the creditworthiness of the Borrower, any other Obligor or any of their respective Subsidiaries or omitted to state a material fact necessary in order to make such statements contained therein, in light of the circumstances under which they were made, not misleading. The written information, reports and other papers and data with respect to the Borrower, any other Obligor or any of their respective Subsidiaries or the Unencumbered Assets (other than projections and other forward-looking statements) furnished to the Agent or the Lenders in connection with or relating in any way to this Agreement was, at the time so furnished, complete and correct in all material respects, or has been subsequently supplemented by other written information, reports or other papers or data, to the extent necessary to give in all material respects a true and accurate knowledge of the subject matter. All financial statements furnished to the Agent or any Lender by, on behalf of, or at the direction of, the Borrower, any other Obligor or any of their respective Subsidiaries in connection with or relating in any way to this Agreement, present fairly, in accordance with GAAP consistently applied throughout the periods involved, the financial position of the Persons involved as at the date thereof and the results of operations for such periods. All financial projections and other forward looking statements prepared by, or on behalf of the Borrower, any other Obligor or any of their respective Subsidiaries that have been or may hereafter be made available to the Agent or any Lender were or will be prepared in good faith based on reasonable assumptions. No fact or circumstance is known to the Borrower which has had, or may in the future have (so far as the Borrower can reasonably foresee), a Material Adverse Effect which has not been set forth in the financial statements referred to in Section 6.1(k) or in such information, reports or other papers or data or otherwise disclosed in writing to the Agent and the Lenders prior to the Effective Date.

  • Information Security IET information security management practices, policies and regulatory compliance requirements are aimed at assuring the confidentiality, integrity and availability of Customer information. The UC Xxxxx Cyber-safety Policy, UC Xxxxx Security Standards Policy (PPM Section 310-22), is adopted by the campus and IET to define the responsibilities and key practices for assuring the security of UC Xxxxx computing systems and electronic data.

  • Furnishing of Information Until the earliest of the time that (i) no Purchaser owns Securities or (ii) the Warrants have expired, the Company covenants to timely file (or obtain extensions in respect thereof and file within the applicable grace period) all reports required to be filed by the Company after the date hereof pursuant to the Exchange Act even if the Company is not then subject to the reporting requirements of the Exchange Act.

  • Security of Information Unless otherwise specifically authorized by the DOH Chief Information Security Officer, Contractor receiving confidential information under this contract assures that: • Encryption is selected and applied using industry standard algorithms validated by the National Institute of Standards and Technology (NIST) Cryptographic Algorithm Validation Program against all information stored locally and off-site. Information must be encrypted both in-transit and at rest and applied in such a way that it renders data unusable to anyone but authorized personnel, and the confidential process, encryption key or other means to decipher the information is protected from unauthorized access. • It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer (OCIO) policy 141, Securing Information Technology Assets, available at: xxxxx://xxxx.xx.xxx/policy/securing-information-technology-assets. • It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH Chief Information Security Officer. • DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. • It has implemented physical, electronic and administrative safeguards that are consistent with OCIO security standard 141.10 and ISB IT guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: o Documented access authorization and change control procedures; o Card key systems that restrict, monitor and log access; o Locked racks for the storage of servers that contain Confidential Information or use AES encryption (key lengths of 256 bits or greater) to protect confidential data at rest, standard algorithms validated by the National Institute of Standards and Technology (NIST) Cryptographic Algorithm Validation Program (CMVP); o Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; o Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; o Complex passwords that are systematically enforced and password expiration not to exceed 120 days, dependent user authentication types as defined in OCIO security standards; o Strong multi-factor authentication mechanisms that assure the identity of individuals who access Confidential Information; o Account lock-out after 5 failed authentication attempts for a minimum of 15 minutes, or for Confidential Information, until administrator reset; o AES encryption (using key lengths 128 bits or greater) session for all data transmissions, standard algorithms validated by NIST CMVP; o Firewall rules and network address translation that isolate database servers from web servers and public networks; o Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; o Log management and intrusion detection/prevention systems; o A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.

Draft better contracts in just 5 minutes Get the weekly Law Insider newsletter packed with expert videos, webinars, ebooks, and more!