Laserfiche WebLink
and who agree to comply with use and non-disclosure restrictions similar to those contained within this <br /> Agreement. <br /> 6. Security of Consumer Information. Each Party shall implement and maintain a Security Program that <br /> includes appropriate administrative, technical and physical safeguards reasonably designed to: (1) ensure <br /> the security and confidentiality of Consumer Information within its systems; (11) protect against any <br /> anticipated threats or hazards to the security or integrity of Consumer Information within its systems;and <br /> (iii)protect against unauthorized access to or use of Consumer Information stored on its systems;and(iv) <br /> dispose of Consumer Information in a secure manner per applicable Rules and Laws. <br /> a. In order to comply with safeguard obligations generally described in the preceding paragraph, each <br /> Party shall (1) designate an employee or employees to coordinate its Security Program, (2) identify <br /> reasonably foreseeable internal and external risks to the security, confidentiality and integrity of <br /> Consumer Information located on its systems that could result in the unauthorized disclosure,misuse, <br /> alteration, destruction or other compromise of such information, and assess the sufficiency of any <br /> safeguards in place to control these risks. At a minimum, such risk assessment should include <br /> consideration of risks in each relevant area of a Party's operations, including: (i) employee training <br /> and management; (ii) information systems, including network and software design, as well as <br /> information processing, storage, transmission and disposal; and (iii) detecting, preventing and <br /> responding to attacks, intrusions, or other systems failures, which shall include the use of <br /> commercially reasonable efforts to establish procedures and logging mechanisms for FORTE systems <br /> and networks that will allow tracking and analysis in the event there is a compromise of its systems, <br /> and maintain an audit trail history for at least three (3) months for review by AGENCY upon <br /> reasonable request; (3) design and implement information safeguards to control the risks identified <br /> through risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards' <br /> key controls, systems, and procedures; and (4) use commercially reasonable efforts to assure data <br /> security when disposing of any Consumer Information. <br /> 7. Disclosures. Neither Party shall have an obligation to maintain the confidentiality of any Consumer <br /> Information which: (1) has been received by it from a third party without restriction on disclosure and <br /> without breach of agreement or other wrongful act by the receiving party; or (ii) is independently <br /> developed by it without reference to any Consumer Information. If required by any court of competent <br /> jurisdiction or other governmental authority,each Party may disclose to such authority,data,information <br /> or materials involving or pertaining to Consumer Information to the extent required by such order or <br /> authority. FORTE shall, if not otherwise prohibited, give the other Party as much advance notice of the <br /> possibility of such disclosure as is practical so that it may, at its own expense, attempt to stop such <br /> disclosure or obtain a protective order concerning such disclosure. <br /> 8. Breach Notification. In the event of an actual or validated breach of security of a Party's system,website, <br /> database, equipment or storage medium or facility that results in unauthorized access to Consumer <br /> Information on a Party's system by any third party(including any consultant or subcontractor of the Party <br /> that is not authorized to access such information), the Party that experienced the breach shall notify the <br /> other Party within a commercially reasonable time after taking any appropriate measures necessary to <br /> prevent further access, and shall take commercially reasonable efforts to resecure its systems as soon as <br /> possible. The Party that experienced the breach shall provide any information that the other Party <br /> reasonably requests pertaining to the incident,unless prohibited from doing so by applicable Rule or Law <br /> and shall provide reasonable cooperation to investigate any such incident. In addition, in the event of an <br /> actual or validated breach of security to a Party's system regarding PCI data related to AGENCY's <br /> account with FORTE, the Party that experienced the breach shall, to the extent reasonably practicable, <br /> cooperate with the investigative actions of the appropriate forensic unit and/or law enforcement agency <br /> and agrees to provide the other Party with a copy of the final Incident Report,if any,upon request. <br /> 22.11.30 <br /> Page 20 <br /> CSG165915.0 03-19 26 <br />