Audits and Security Assessments Clause Samples

The "Audits and Security Assessments" clause grants one party the right to review and evaluate the other party's systems, processes, or records to ensure compliance with agreed-upon security standards and contractual obligations. Typically, this clause outlines the procedures for conducting audits, such as providing advance notice, limiting the frequency of assessments, and specifying the scope of information that can be reviewed. Its core practical function is to provide transparency and accountability, helping to identify and address potential security vulnerabilities or non-compliance issues before they result in harm.
POPULAR SAMPLE Copied 9 times
Audits and Security Assessments. Upland shall maintain compliance with industry standards and applicable governing frameworks such as Statement on Standards for Attestation Engagements (SSAE) and The International Organization for Standardization (ISO) (e.g., SSAE 16, ISO 27001 and ISO 27018) throughout the Agreement Term. Upland shall make available to Customer, annually and upon request, all information necessary to demonstrate compliance with its obligations. Upland shall allow for and contribute to audits conducted by Customer, or third-party auditor mandated by Customer, under the following parameters: (i) the Customer may elect to conduct an audit not more than once within any 12-month period at no cost to Customer. Any additional audits within the same 12-month period shall be subject to a reasonable fee; (ii) third-party auditors mandated by Customer shall enter into confidentiality agreements with Upland that are no less restrictive than those set out in this MSA; (iii) Customer provides reasonable prior notice of such request for an audit; (iv) Customer ensures such audit shall not be unreasonably disruptive to Upland’s business; and (v) neither Customers nor its auditors shall be permitted to make unaccompanied site visits or to logically access Upland’s IT systems.
Audits and Security Assessments. The Subscription Services are hosted in and offered from AWS. Information on AWS security posture, standards and certifications can be found at ▇▇▇▇▇://▇▇▇.▇▇▇▇▇▇.▇▇▇/products/security/.
Audits and Security Assessments. Ping Identity is and will remain in compliance with the most recent SOC-2 and ISO 27001 standards throughout the term of this Agreement. Upon Customer’s written request, Ping Identity will provide Customer with access to Ping Identity’s security portal that contains, among other things, a copy of (i) the most recently completed SOC-2 Type II audit report, (ii) its public ISO 27001 certificate and non-public Statement of Applicability, and (iii) the results of any recently completed penetration testing on the Service.
Audits and Security Assessments. Mercero is and will remain in compliance with its SOC-2 statement and, with effect from July 2018, the ISO 27001 and ISO 27018 standards (collectively, “ISMS Standards”), throughout the Subscription Term. Mercero will cause its independent ISMS Standards certification auditors to verify the adequacy of the controls that Mercero applies to the Subscription Services at least annually. Mercero will provide Customer with copies of its ISMS Standards certifications applicable to Mercero’s provision of Subscription Services, upon request by Customer. Mercero will in addition provide such information regarding its information security systems, policies and procedures as Customer may reasonably request relating to Customer’s due diligence and oversight obligations under applicable laws and regulations.