Town CrierWest Orange, New Jersey
← Back to search

Supporting Documentation · Jan 6, 2015

11-15 Exhibits to Resolution Awarding Contract for 911 System Maintenance and Repair.pdf

Preserved file SHA-256c64ab1e2bb206146c4660bc566c5f1e4fca8ca686497d1305ceee0ffc4e0b340

Indexed text · page 57

Show all pages
Page 57

6. Data Scope: All provisions applicable to data include data in any form of transmission or storage, including but not limited to: database files, text files, backup files, log files, XML files, and printed copies of the data. 7. Data Re-Use: All State provided data shall be used expressly and solely for the purposes enumerated in the contract. Data shall not be distributed, repurposed or shared across other applications, environments, or business units of the contractor. No State data of any kind shall be transmitted, exchanged or otherwise passed to other contractors or interested parties except on a case-by-case basis as specifically agreed to in writing by the State Contract Manager. 8. Data Breach: Unauthorized Release Notification: The contractor shall comply with all applicable State and Federal laws that require the notification of individuals in the event of unauthorized release of personally-identifiable information or other event requiring notification. In the event of a breach of any of the contractor’s security obligations or other event requiring notification under applicable law (“Notification Event”), the contractor shall assume responsibility for informing the State Contract Manager and all such individuals in accordance with applicable law and to indemnify, hold harmless and defend the State of New Jersey, its officials, and employees from and against any claims, damages, or other harm related to such Notification Event. 9. End of Contract Data Handling: Upon termination of this Contract the contractor shall erase, destroy, and render unreadable all contractor copies of State data according to the standards enumerated in accordance with the State’s Information Disposal and Media Sanitation policy, 09-10-NJOIT (www.nj.gov/it/ps) and certify in writing that these actions have been complete within thirty (30) days of the termination of this Contract or within seven (7) days of the request of an agent of the State whichever shall come first. 10. Security Audit: The contractor must allow State assigned staff full access to all operations for security inspections and audits which may include reviews of all issues addressed in description of the security approach and

Page 57

low State assigned staff full access to all operations for security inspections and audits which may include reviews of all issues addressed in description of the security approach and willingness to enter into good faith discussions to implement any changes. 5.9.3 SECURITY PLAN The contractor must provide a security plan. The document shall describe the administrative, physical, technical and systems controls to be used by the system and/or services. The contractor's security plan must, at a minimum, provide security measures for the following areas: - Facilities Physical Security - System Security - System Data Security - Administrative and Personnel Security The security plan shall provide for review of the contractor's operations and control system. The contractor shall have the capability to detect and report attempted unauthorized entries into the facility and system. All security requirements for the contractor apply to development, testing, production and backup systems. The contractor shall provide a summary overview of the security document and describe how it has been incorporated into a larger security program for automated data processing. In the plan, the contractor shall highlight security features of the system. 51

File revisions (1)