SECURITY PROCESS FOR SLAs Sample Clauses

SECURITY PROCESS FOR SLAs. In this work we consider security being incor- porated in an SLA already at the design-time as it is one of the most important attributes to be considered in systems being connected to the In- xxxxxx (i.e., left-hand side in Figure 2). More- over, as security is dynamic by its nature, we con- sider run-time monitoring of services and effects of changes on existing SLA guarantees and possi- ble re-negotiation process, as well (i.e., right-hand side in Figure 2). Figure 2 presents the adopted security pro- cess (Kizza, 2017) embedded in the SLA devel- opment process divided into steps from 1 to 10. The combination of process allows to address se- curity in a systematic way and develop an SLA for a service security level. Block 1 includes spec- ification of a service, e.g., its functional specifica- tion, definition of required resources and connec- tions. Block 2 contains application assumptions service design/development service operation Service Specification Security Policies Run-Time Application 2 Assumptions Security 3 Analysis Guarantees Assessment 5 10 Security Run-Time Mechanisms 8 Monitoring Refinement SLA Figure 2: Process of development and maintaining an SLA for a service security level. capturing possible instantiations of service func- tionalities for the assumed application and possi- ble user requirements. Once the service and its specification are available, in Block 3 a security analysis of the service is performed, i.e., relevant security goals are specified, threat and vulnera- bilities analyses are conducted. Based on the analysis results security goals are translated into corresponding requirements. We skip the implicit step of requirements elicita- tion and instead, as more relevant for guarantees, present security policies and security mechanisms to be implemented, in Block 4 and Block 5 corre- spondingly. The term security policy is defined in Section 2.4. We choose to separate policies and mechanisms in two blocks as we want to make sure that the detailed technical specification of a particular mechanism mentioned in policies is captured in the right way, and both further are connected to guarantees. The security process presented in Blocks 1- 5 is supported by argumentation over adequacy of security level of the service. Further, mecha- nisms and policies are translated into guarantees, see Block 6, which contains assertions of what is guaranteed, under which conditions and with which possible following actions (e.g., to update, pa...
AutoNDA by SimpleDocs

Related to SECURITY PROCESS FOR SLAs

  • SECURITY PROCESSES If requested by an Authorized User as part the Request for Quote process, Contractor shall complete a Consensus Assessment Initiative Questionnaire (CAIQ) including on an annual basis thereafter, if requested by the Authorized User. The CAIQ is available at Cloud Security Alliance (xxxxx://xxxxxxxxxxxxxxxxxxxxx.xxx/). The CAIQ may be used to assist the Authorized User in building the necessary assessment processes when engaging with Contractors. In addition to a request for a CAIQ, Contractor shall cooperate with all reasonable Authorized User requests for a Written description of Contractor’s physical/virtual security and/or internal control processes. The Authorized User shall have the right to reject any Contractor’s RFQ response or terminate an Authorized User Agreement when such a request has been denied. For example, Federal, State and local regulations and/or laws may require that Contractors operate within the Authorized User’s regulatory environment. In order to ensure that security is adequate and free of gaps in control coverage, the Authorized User may require information from the Contractor’s Service Organization Controls (SOC) audit report.

  • Security Protocols Both parties agree to maintain security protocols that meet industry standards in the transfer or transmission of any data, including ensuring that data may only be viewed or accessed by parties legally allowed to do so. Provider shall maintain all data obtained or generated pursuant to the Service Agreement in a secure digital environment and not copy, reproduce, or transmit data obtained pursuant to the Service Agreement, except as necessary to fulfill the purpose of data requests by LEA.

  • Security Program Contractor will develop and implement an effective security program for the Project Site, which program shall require the Contractor and subcontractors to take measures for the protection of their tools, materials, equipment, and structures. As between Contractor and Owner, Contractor shall be solely responsible for security against theft of and damage of all tools and equipment of every kind and nature and used in connection with the Work, regardless of by whom owned.

  • Security Procedure The Client acknowledges that the Security Procedure it has designated on the Selection Form was selected by the Client from Security Procedures offered by State Street. The Client agrees that the Security Procedures are reasonable and adequate for its wire transfer transactions and agrees to be bound by any payment orders, amendments and cancellations, whether or not authorized, issued in its name and accepted by State Street after being confirmed by any of the selected Security Procedures. The Client also agrees to be bound by any other valid and authorized payment order accepted by State Street. The Client shall restrict access to confidential information relating to the Security Procedure to authorized persons as communicated in writing to State Street. The Client must notify State Street immediately if it has reason to believe unauthorized persons may have obtained access to such information or of any change in the Client’s authorized personnel. State Street shall verify the authenticity of all instructions according to the Security Procedure.

  • Address for Service Any notice to be given or served under or arising out of a provision of the Contract must: be in writing; be delivered by hand, sent by prepaid express post or sent by email (except for notices under clauses 14 and 15 which, if sent by email, must additionally be delivered by hand or sent by prepaid express post) to the relevant address or email address: specified in the Contract Particulars; or last notified in writing to the party giving or serving the notice, for the party to whom or upon which the notice is to be given or served; be signed by the party giving or serving the notice or (on the party's behalf) by the solicitor for or attorney, director, secretary or authorised agent of the party giving or serving the notice; and in the case of notices sent by email: be in Portable Document Format (pdf) and appended as an attachment to the email; and include the words "This is a notice under clause 16.7 of the Contract" in the subject field of the email. Receipt of Notices Subject to paragraph (b), a notice given or served in accordance with clause 16.7 is taken to be received by the party to whom or upon whom the notice is given or served in the case of: delivery by hand, on delivery; prepaid express post sent to an address in the same country, on the fifth day after the date of posting; prepaid express post sent to an address in another country, on the seventh day after the date of posting; and email, the earlier of: delivery to the email address to which it was sent; or one hour after the email enters the server of the email address to which it was sent, provided that no delivery or transmission error is received by the sender within one hour of the time of sending shown on the "sent" email. In the case of notices under clauses 14 and 15, if the notice is sent by email as well as being delivered by hand or sent by prepaid express post in accordance with clause 16.7(b), the notice is taken to be received by the party to whom or upon whom the notice is given or served on the earlier of: the date the notice sent by email is taken to be received; or the date the notice delivered by hand or sent by prepaid express post is taken to be received, as determined in accordance with paragraph (a).

  • Contracting for Services It is the intent of the parties to preserve the work and job opportunities of the employees covered by this agreement. It is also, however, an obligation as well as a management prerogative of the employer to maintain the efficiency of the employer's operations and to determine methods and means by which those operations are to be conducted. The employer shall make every reasonable effort to retain the employees covered by this agreement and will not make arrangements to contract with any outside firm for any of the services ordinarily rendered by said employees which would jeopardize their continued employment without disclosure to the bargaining agent sufficiently in advance to accommodate discussion between the parties of the contemplated action. The employer shall not enter into any such contract for services unless it can be proven that said contract would result in increased efficiency of operations by way of obtaining the same services at less cost or additional services for the same cost, or unless it can be proven that such action is necessitated by financial exigency. The employer agrees it shall be a condition of any such contract for services which may displace employees covered herein, that the contractor shall offer employment to as many of said employees who would be displaced by said contract as the number of similarly qualified employees who shall be required by the contractor to effect performance of the contract. It is understood, however, that the employer may not require the terms of the contractor's offer of employment to be identical to or commensurate with those of the employee's contract with the employer. The provisions of this paragraph are subject to the grievance procedure and no work which would result in displacement of any employee within the bargaining unit shall be contracted prior to a final decision on any grievance filed under the terms of this contract.

  • Procurement of Goods and Works 3. Except as ADB may otherwise agree, Goods and Works shall only be procured on the basis of the methods of procurement set forth below:

  • Packing Materials and Containers for Shipment Packing materials and containers in which a good is packed for shipment shall be disregarded in determining whether:

  • Required Procurement Procedures for Obtaining Goods and Services The Grantee shall provide maximum open competition when procuring goods and services related to the grant-assisted project in accordance with Section 287.057, Florida Statutes.

  • Public Contracts for Services [Not applicable to agreements relating to the offer, issuance, or sale of securities, investment advisory services or fund management services, sponsored projects, intergovernmental agreements, or information technology services or products and services] Contractor certifies, warrants, and agrees that it does not knowingly employ or contract with a worker without authorization who will perform work under this Agreement and will confirm the employment eligibility of all employees who are newly hired for employment in the United States to perform work under this Agreement, through participation in the E-Verify Program or the Department program established pursuant to C.R.S. §8-17.5-102(5)(c). Contractor shall not knowingly employ or contract with a worker without authorization to perform work under this Agreement or enter into a contract with a subcontractor that fails to certify to Contractor that the subcontractor shall not knowingly employ or contract with a worker without authorization to perform work under this Agreement. Contractor (a) shall not use E-Verify Program or Department program procedures to undertake pre-employment screening of job applicants while this Agreement is being performed, (b) shall notify the subcontractor and County within three days if Contractor has actual knowledge that a subcontractor is employing or contracting with a worker without authorization for work under this Agreement, (c) shall terminate the subcontract if a subcontractor does not stop employing or contracting with the worker without authorization within three days of receiving the notice, and (d) shall comply with reasonable requests made in the course of an investigation, undertaken pursuant to C.R.S. §8-17.5-102(5), by the Colorado Department of Labor and Employment. If Contractor participates in the Department program, Contractor shall deliver to County a written, notarized affirmation, affirming that Contractor has examined the legal work status of such employee, and shall comply with all of the other requirements of the Department program. If Contractor fails to comply with any requirement of this provision or C.R.S. §8-17.5-102 et seq., County may terminate this Agreement for breach and, if so terminated, Contractor shall be liable for damages.

Time is Money Join Law Insider Premium to draft better contracts faster.