Laserfiche WebLink
Amendment <br /> NOW, THEREFORE, in consideration of the mutual covenants contained herein, <br /> the sufficiency of which is hereby acknowledged, the Agencies and the <br /> Contractor hereby agree to amend the Contract as follows: <br /> 1.0 System Security <br /> Section 3.1-11, Security of RFC System, is hereby amended to read as follows: <br /> 3.1-11 Security of RFC System <br /> 11.1 Contractor shall maintain the security of the RFC System, including <br /> security for all computer systems, information and monetary transactions, <br /> in accordance with the professional standards of persons and firms with <br /> specialized knowledge, expertise and experience who are leading <br /> designers and providers of systems, software and hardware used in the <br /> automated smart card fare payment industry. Such security shall include, <br /> without limitation: (i) maintaining physical security of the RFC System, to <br /> ensure that no unauthorized person shall have access to the RFC System; <br /> (ii) creating firewalls, password protections, and other appropriate <br /> measures to protect against unauthorized access to the RFC System or to <br /> Customer information by Contractor's employees, Agency employees or <br /> third parties; (iii) protecting against penetration of security and <br /> manipulation of customer account data by Contractor's personnel, Agency <br /> personnel or third parties; and (iv) additional security measures as <br /> specified in the Services and Equipment Specifications in Divisions II and <br /> III. <br /> 11.2 Contractor shall update its security procedures as technology and <br /> security threats evolve to provide security capabilities at all times that are <br /> in accordance with the professional standards of persons and firms with <br /> specialized knowledge, expertise and experience who are leading <br /> designers and providers of systems, software and hardware used in the <br /> automated smart card fare payment industry. <br /> 11.3 Contractor shall have its security procedures and physical facilities <br /> audited by a qualified, nationally recognized firm, and Contractor shall <br /> take such actions as may be identified in such audit as necessary to <br /> comply with the professional standards of persons and firms with <br /> specialized knowledge, expertise and experience who are leading <br /> designers and providers of systems, software and hardware used in the <br /> automated smart card fare payment industry. The Contractor's initial <br /> security audit shall consist of the following tasks at a minimum: <br /> CCA#3-Attachment A 2 <br />