|
City of Everett
<br /> Cloud and/or Offsite Hosting Terms and Conditions
<br /> Contract#2020-062,Appendix Part B-1 between City of Everett and StreamLink Software Inc DBA
<br /> AmpliFund dated January 26th,2021.
<br /> This document shall become part of the final contract.
<br /> Terms and Conditions Clauses 1-13 are mandatory for every engagement. Exceptions will be
<br /> considered non-compliant and non-responsive.
<br /> Tiered Coverage Schedule
<br /> Level Number of Pit records Level of cyber liability insurance required (occurrence=data breach)
<br /> 1 1-10,000 $2,000,000 per occurrence
<br /> 2 10,001 —50,000 $3,000,000 per occurrence
<br /> 3 50,001 —100,000 $4,000,000 per occurrence
<br /> 4 100,001 —500,000 $15,000,000 per occurrence
<br /> 5 500,001 —1,000,000 $30,000,000 per occurrence
<br /> 1,000,001 —
<br /> 6 10,000,000 $100,000,000 per occurrence
<br /> The policy shall comply with the following requirements:
<br /> • Issued by an insurance company acceptable to the City of Everett and valid for the entire term of
<br /> the contract,inclusive of any term extension(s).
<br /> • Liability limits will be calculated based on the maximum system record count and the Ponemon
<br /> Institute average Public Sector Breach cost per record(currently$154).Refer to the Tiered
<br /> Coverage Schedule above.
<br /> • Shall include,but not be limited to,coverage for liabilities arising out of premises,operations,
<br /> independent contractors, products, completed operations,and liability assumed under an insured
<br /> contract.
<br /> • At a minimum,the policy must include third party coverage for credit monitoring; notification costs
<br /> to data breach victims; and regulatory penalties and fines.
<br /> • Shall apply separately to each insured against whom claim is made or suit is brought subject to
<br /> the Service Provider's limit of liability.
<br /> • Shall include a provision requiring that the policy cannot be cancelled without thirty days written
<br /> notice to the City of Everett.
<br /> • The Service Provider shall be responsible for any deductible or self-insured retention contained in
<br /> the insurance policy.
<br /> • The coverage under the policy shall be primary,and not excess,to any other insurance carried by
<br /> the Service Provider.
<br /> • In the event contractor fails to keep in effect at all times the insurance coverage required by this
<br /> provision,the City may, in addition to any other remedies it may have,terminate the contract
<br /> upon the occurrence of such event,subject to the provisions of the contract.
<br /> 5. Breach Notification and Recovery: City of Everett requires public breach notification when
<br /> citizens'personally identifiable information is lost or stolen.Additionally, unauthorized access or
<br /> disclosure of non-public data is considered to be a breach. The Service Provider will provide
<br /> notification without unreasonable delay and all communication shall be coordinated with the City
<br /> of Everett. When the Service Provider or their subcontractors are liable for the loss,the Service
<br /> Provider shall bear all costs associated with the investigation, response and recovery from the
<br /> breach including but not limited to credit monitoring services with a term of at least 3 years,
<br /> mailing costs,website, and toll free telephone call center services. The City of Everett shall not
<br /> agree to any limitation on liability that relieves a Contractor from its own negligence or to the
<br /> extent that it creates an obligation on the part of the State to hold a Contractor harmless.
<br /> 2IPage
<br />
|