Security Standards.
Encore agrees that it shall implement and maintain administrative, electronic, technical, and physical safeguards and procedures in connection with accessing, processing, using, transmitting, disposing of, or otherwise handling Client Personal Data or accessing Client Systems. Encore’s safeguards under this Addendum shall be those that are commercially reasonable and appropriate to the nature, scope, and sensitivity of the Client Personal Data and to the systems and platforms Encore uses to provide the Services.
Encore also agrees to:
Regularly test or otherwise monitor the effectiveness of the key controls, systems, and procedures of the safeguards set forth herein, including those to detect actual and attempted attacks on, or intrusions into, information systems that store, process, provide access to, or transmit Client Data or can be utilized to access Client Systems.
For information systems that process, provide access to, or transmit Client Data or can be utilized to access Client Systems, implement monitoring and testing protocols that shall include continuous monitoring and periodic penetration testing and vulnerability assessments. Encore shall conduct:
Periodic penetration testing of Encore’s information systems at a frequency and scope informed by the relevant identified risks in accordance with the risk assessment set forth herein; and
Vulnerability assessments, including any systemic scans or reviews of information systems reasonably designed to identify publicly-known security vulnerabilities in Encore’s information systems at a frequency and scope informed by the risk assessment and appropriate to the nature and sensitivity of the Client Personal Data.
Implement policies and procedures to ensure that Encore personnel are able to enact Encore’s information security program by:
Providing Encore personnel with security awareness training that is updated as necessary to reflect risks by the risk assessment references herein;
Utilizing qualified information security personnel employed by Encore or an Affiliate or service provider sufficient to manage Encore’s information security risks and to perform or oversee the information security program;
Providing Encore’s information security personnel with security updates and training sufficient to address relevant security risks; and
Verifying that Encore’s key information security personnel take steps to maintain current knowledge of changing information security threats and countermeasures.
Establish a written incident response plan designed to promptly respond to and recover from any security event materially affecting the confidentiality, integrity, or availability of Client Data in Encore’s control. Such incident response plan may address, as appropriate, areas such as:
The goals of the incident response plan;
The internal processes for responding to a security event;
The definition of clear roles, responsibilities, and levels of decision-making authority;
External and internal communications and information sharing;
Identification of requirements for the remediation of any identified weaknesses in information systems and associated controls;
Documentation and reporting regarding security events and related incident response activities; and
The evaluation and revision as necessary of the incident response plan following a security event.
Class aptent taciti sociosqu ad litora torquent per conubia nostra.
Quisque lectus nisi, lobortis ut suscipit et, lobortis ut lorem.