REMEDIATION AND INCIDENT MANAGEMENT Sample Clauses

REMEDIATION AND INCIDENT MANAGEMENT a. In the event of a finding by QSA, or some other circumstance whose consequence is that Contractor is not actually in compliance with PCI DSS, then Contractor shall: i. Immediately inform the University of the nature of the PCI DSS compliance deficiencies. ii. Promptly plan such remedial actions as necessary to cure any and all PCI DSS compliance deficiencies. Within 30 days, the Contractor shall review their remediation plan with a QSA and obtain a written confirmation of the QSA’s opinion that such plan will remediate Contractor’s PCI DSS deficiencies. Contractor shall then promptly execute this QSA‐reviewed remediation plan. b. In the event of a data breach or intrusion or otherwise unauthorized access to cardholder data for which Contractor is responsible, Contractor shall notify University’s Office of Merchant Services no later than 48 hours of confirming the Data Breach to allow the proper PCI DSS compliant breach notification process to commence.
AutoNDA by SimpleDocs

Related to REMEDIATION AND INCIDENT MANAGEMENT

  • Incident Notice and Remediation If Contractor becomes aware of any Incident, it shall notify the State immediately and cooperate with the State regarding recovery, remediation, and the necessity to involve law enforcement, as determined by the State. Unless Contractor can establish that none of Contractor or any of its agents, employees, assigns or Subcontractors are the cause or source of the Incident, Contractor shall be responsible for the cost of notifying each person who may have been impacted by the Incident. After an Incident, Contractor shall take steps to reduce the risk of incurring a similar type of Incident in the future as directed by the State, which may include, but is not limited to, developing and implementing a remediation plan that is approved by the State at no additional cost to the State.

  • Incident Event and Communications Management a. Incident Management/Notification of Breach - DST shall develop, implement and maintain an incident response plan that specifies actions to be taken when DST or one of its subcontractors suspects or detects that a party has gained material unauthorized access to Fund Data or systems or applications containing any Fund Data (the “Response Plan”). Such Response Plan shall include the following: i. Escalation Procedures - An escalation procedure that includes notification to senior managers and appropriate reporting to regulatory and law enforcement agencies. This procedure shall provide for reporting of incidents that compromise the confidentiality of Fund Data (including backed up data) to Fund via telephone or email (and provide a confirmatory notice in writing as soon as practicable); provided that the foregoing notice obligation is excused for such period of time as DST is prohibited by law, rule, regulation or other governmental authority from notifying Fund. ii. Incident Reporting - DST will use commercially reasonable efforts to promptly furnish to Fund information that DST has regarding the general circumstances and extent of such unauthorized access to the Fund Data.

  • Virus Management DST shall maintain a malware protection program designed to deter malware infections, detect the presence of malware within DST environment.

  • Remediation The Charter School shall provide remediation in required cases pursuant to State Board of Education Rule 160-4-5-.01 and No Child Left Behind.

  • Environmental Management (a) The Operator must, prior to the commencement of any Train Services (including any new or varied Train Services): (i) cause a suitably qualified person reasonably acceptable to both Parties to prepare a report (“Environmental Investigation and Risk Management Report”) containing an environmental investigation component and an environmental risk management component which respectively identify: (A) possible risks of Environmental Harm arising out of the proposed use of the Nominated Network by the Operator, including risks associated with those matters identified in Part 3 of Schedule 6; and (B) the manner in which the Operator proposes to address the possible risks of Environmental Harm identified in the Environmental Investigation and Risk Management Report as well as the roles and responsibilities, including financial responsibility, for the control measures proposed and an audit regime, provided that if the Operator has an existing Environmental Management System it proposes to use in connection with the proposed Train Services on the Nominated Network, the Environmental Investigation and Risk Management Report should also detail the extent to which the Operator believes its existing Environmental Management System addresses the risks identified in the Environmental Investigation and Risk Management Report; and (ii) provide a copy of the Environmental Investigation and Risk Management Report to Aurizon Network for its consideration and, if requested by Aurizon Network, a copy of the relevant parts of the Operator’s existing Environmental Management System referred to in the Environmental Investigation and Risk Management Report. (b) If the Environmental Investigation and Risk Management Report discloses areas of risk which, in the reasonable opinion of Aurizon Network, cannot be adequately managed by the proposals set out in the Environmental Investigation and Risk Management Report or, in the reasonable opinion of Aurizon Network, fails to identify and adequately deal with additional relevant environmental risks, then Aurizon Network may give notice to that effect to the Operator within thirty (30) days after the date on which the Environmental Investigation and Risk Management Report was received by Aurizon Network (or such other period as the Parties, acting reasonably, may agree), detailing the risks not so adequately managed or not so identified or adequately dealt with. If Aurizon Network does not give such notice, the Environmental Investigation and Risk Management Report, subject to Clause 9.1(k), shall be included in Part 1 of Schedule 9 and amendments made to this Agreement [(including variations to the Base Access Charges)] if applicable. [Bracketed text is only included where Operator pays non-TOP Access Charges] (c) If Aurizon Network gives notice pursuant to Clause 9.1 (b) the Operator may respond, by a date agreed by the Parties, with a written proposal which demonstrates how the Operator proposes to manage those risks (“Operator’s Proposal”). The Operator’s Proposal must: (i) contain an investigation of the areas of risk and/or additional relevant environmental risks referred to in Clause 9.1(b); (A) specify risk abatement or attenuation measures which the Operator proposes to undertake in relation to them; and/or (B) specify how the Access Charges might contain a component reflecting the cost to Aurizon Network of assuming all or some portion of the risk; (ii) in relation to paragraph (ii)(A) specify a timeframe for implementation of those measures; and (iii) specify details of any public consultation the Operator proposes to undertake in connection with the implementation of any such measures. (d) Aurizon Network may, acting reasonably, accept or reject all or part of the Operator’s Proposal. (e) If Aurizon Network accepts the Operator’s Proposal, then it will be incorporated into and form part of the Environmental Investigation and Risk Management Report which, subject to Clause 9.1(k), shall be included in Part 1 of Schedule 9 and amendments made to the Agreement [(including variations to the Base Access Charges)] if applicable. [Bracketed text is only included where Operator pays non-TOP Access Charges] (f) If the Operator fails to submit to Aurizon Network an Operator’s Proposal by the date agreed by the Parties or if Aurizon Network rejects all or part of the Operator’s Proposal, Aurizon Network may advise the Operator of the risks not adequately managed or not identified or adequately dealt with and then either Party may refer the issue of whether the Environmental Investigation and Risk Management Report and/or the Operator’s Proposal does or does not adequately manage or does or does not identify or adequately deal with the relevant environmental risks to an expert for determination in accordance with Clause 18.3. (g) If the expert determines that the Environmental Investigation and Risk Management Report and/or Operator’s Proposal does adequately manage the risks or identifies and adequately deals with the risks, then the Environmental Investigation and Risk Management Report as modified by the Operator’s Proposal (if applicable) will, subject to Clause 9.1(k), be accepted and included in Part 1 of Schedule 9 and amendments made to this Agreement [(including variations to the Base Access Charges)] if applicable. [Bracketed text is only included where Operator pays non-TOP Access Charges] (h) If the expert determines that the Environmental Investigation and Risk Management Report and/or Operator’s Proposal does not adequately manage the risks or does not identify and adequately deal with the risks, then provided the Operator amends the Environmental Investigation and Risk Management Report in accordance with the expert’s determination and/or recommendations within the time frame specified by the expert, the Environmental Investigation and Risk Management Report as amended will, subject to Clause 9.1(k), be accepted and included in Part 1 of Schedule 9 and amendments made to the Agreement [(including variations to the Base Access Charges)] if applicable. [Bracketed text is only included where Operator pays non-TOP Access Charges] (i) If the expert determines that the Environmental Investigation and Risk Management Report and/or Operator’s Proposal does not adequately manage the risks or does not identify and adequately deal with the risks and the Operator fails to amend the Environmental Investigation and Risk Management Report in accordance with the expert’s determination and/or recommendations within the time frame specified by the expert, Aurizon Network may terminate this Agreement by written notice to the Operator and the End User. (j) The Parties agree to implement the determination of the expert. (k) If: (i) an Environmental Investigation and Risk Management Report is included in Part 1 of Schedule 9; and (ii) amendments (if any) are made to this Agreement as a result of or in connection with that inclusion of the Environmental Investigation and Risk Management Report, then the commencement of the amendment of this Agreement to include the Environmental Investigation and Risk Management Report and those amendments is subject to and conditional upon the Operator being notified by Aurizon Network that all necessary amendments (if any) to the End User Access Agreement (including variations to the amounts payable by the End User) have been made in respect of such matters and any relevant nomination of the Operator by the End User in accordance with the End User Access Agreement has, if necessary, been varied.

  • Responsibility for Environmental Contamination 5.20.1 Neither Party shall be liable to the other for any costs whatsoever resulting from the presence or release of any Environmental Hazard that either Party did not introduce to the affected Work Location. Both Parties shall defend and hold harmless the other, its officers, directors and employees from and against any losses, damages, claims, demands, suits, liabilities, fines, penalties and expenses (including reasonable attorneys' fees) that arise out of or result from (i) any Environmental Hazard that the Indemnifying Party, its contractors or agents introduce to the Work Locations or (ii) the presence or release of any Environmental Hazard for which the Indemnifying Party is responsible under Applicable Law. 5.20.2 In the event any suspect materials within Qwest-owned, operated or leased facilities are identified to be asbestos containing, CLEC will ensure that to the extent any activities which it undertakes in the facility disturb such suspect materials, such CLEC activities will be in accordance with applicable local, state and federal environmental and health and safety statutes and regulations. Except for abatement activities undertaken by CLEC or equipment placement activities that result in the generation of asbestos-containing material, CLEC does not have any responsibility for managing, nor is it the owner of, nor does it have any liability for, or in connection with, any asbestos-containing material. Qwest agrees to immediately notify CLEC if Qwest undertakes any asbestos control or asbestos abatement activities that potentially could affect CLEC personnel, equipment or operations, including, but not limited to, contamination of equipment.

  • Orientation and In-Service Program The Hospital recognizes the need for a Hospital Orientation Program of such duration as it may deem appropriate taking into consideration the needs of the Hospital and the nurses involved.

  • Environmental Remediation Failure to remediate (or pursue the remediation process with due diligence and good faith) within the time period required by law or governmental order, (or within a reasonable time in light of the nature of the problem if no specific time period is so established), environmental problems in violation of Applicable Law related to Properties of the Borrower and/or its Subsidiaries where the estimated cost of remediation is in the aggregate in excess of Seventy-Five Million Dollars ($75,000,000), in each case after all administrative hearings and appeals have been concluded.

  • Investigations and Remediations Lessor shall retain the responsibility and pay for any investigations or remediation measures required by governmental entities having jurisdiction with respect to the existence of Hazardous Substances on the Premises prior to the Start Date, unless such remediation measure is required as a result of Lessee's use (including "Alterations", as defined in Paragraph 7.3(a) below) of the Premises, in which event Lessee shall be responsible for such payment. Lessee shall cooperate fully in any such activities at the request of Lessor, including allowing Lessor and Lessor's agents to have reasonable access to the Premises at reasonable times in order to carry out Lessor's investigative and remedial responsibilities.

  • Contractor Responsibility for System Agency’s Termination Costs If the System Agency terminates the Contract for cause, the Contractor shall be responsible to the System Agency for all costs incurred by the System Agency and the State of Texas to replace the Contractor. These costs include, but are not limited to, the costs of procuring a substitute vendor and the cost of any claim or litigation attributable to Contractor’s failure to perform any Work in accordance with the terms of the Contract.

Draft better contracts in just 5 minutes Get the weekly Law Insider newsletter packed with expert videos, webinars, ebooks, and more!