Impact Assessments 5.1 The Parties shall: (a) provide all reasonable assistance to the each other to prepare any data protection impact assessment as may be required (including provision of detailed information and assessments in relation to Processing operations, risks and measures); and (b) maintain full and complete records of all Processing carried out in respect of the Personal Data in connection with the contract, in accordance with the terms of Article 30 GDPR.
Risk Assessments a. Risk Assessment - DST shall, at least annually, perform risk assessments that are designed to identify material threats (both internal and external) against Fund Data, the likelihood of those threats Schedule 10.2 p.2 occurring and the impact of those threats upon DST organization to evaluate and analyze the appropriate level of information security safeguards (“Risk Assessments”). b. Risk Mitigation - DST shall use commercially reasonable efforts to manage, control and remediate threats identified in the Risk Assessments that it believes are likely to result in material unauthorized access, copying, use, processing, disclosure, alteration, transfer, loss or destruction of Fund Data, consistent with the Objective, and commensurate with the sensitivity of the Fund Data and the complexity and scope of the activities of DST pursuant to the Agreement. c. Security Controls Testing - DST shall, on approximately an annual basis, engage an independent external party to conduct a review (including information security) of DST’s systems that are related to the provision of services. DST shall have a process to review and evaluate high risk findings resulting from this testing.
Safeguarding requirements and procedures (1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls: (i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). (ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute. (iii) Verify and control/limit connections to and use of external information systems. (iv) Control information posted or processed on publicly accessible information systems. (v) Identify information system users, processes acting on behalf of users, or devices. (vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems. (vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. (viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. (ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices. (x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems. (xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. (xii) Identify, report, and correct information and information system flaws in a timely manner. (xiii) Provide protection from malicious code at appropriate locations within organizational information systems. (xiv) Update malicious code protection mechanisms when new releases are available. (xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.
Environmental Review (a) Buyer shall have the right to conduct or cause a consultant (“Buyer’s Environmental Consultant”) to conduct an environmental review of the Assets and Seller’s records pertaining to the Assets (as set forth in Section 3.01) prior to the expiration of the Examination Period (“Buyer’s Environmental Review”). The cost and expense of Buyer’s Environmental Review, if any, shall be borne solely by Buyer. The scope of work comprising Buyer’s Environmental Review shall not include any intrusive test or procedure without the prior written consent of Seller. Buyer shall (and shall cause Buyer’s Environmental Consultant to): (i) consult with Seller before conducting any work comprising Buyer’s Environmental Review, (ii) perform all such work in a safe and workmanlike manner and so as to not unreasonably interfere with Seller’s operations and (iii) comply with all applicable laws, rules, and regulations. Seller shall use commercially reasonable efforts to obtain any Third Party consents and otherwise cooperate with Buyer in conducting Buyer’s Environmental Review and any activities related thereto. Seller shall have the right to have a representative or representatives accompany Buyer and Buyer’s Environmental Consultant at all times during Buyer’s Environmental Review. With respect to any samples taken in connection with Buyer’s Environmental Review, Buyer shall take split samples, providing one of each such sample, properly labeled and identified, to Seller. The Parties shall execute a “common undertaking” letter regarding the confidentiality for the Environmental Review where appropriate. Buyer hereby agrees to release, defend, indemnify and hold harmless Seller from and against all claims, losses, damages, costs, expenses, causes of action and judgments of any kind or character (INCLUDING THOSE RESULTING FROM SELLER’S SOLE, JOINT, COMPARATIVE OR CONCURRENT NEGLIGENCE OR STRICT LIABILITY) to the extent arising out of Buyer’s Environmental Review. Buyer hereby covenants and agrees that it will have at least $2,000,000 of general liability insurance to cover its indemnification hereunder prior to the commencement of the Environmental Review. (b) Unless otherwise required by applicable law, Buyer shall (and shall cause Buyer’s Environmental Consultant to) treat confidentially any matters revealed by Buyer’s Environmental Review and any reports or data generated from such review (the “Environmental Information”), and Buyer shall not (and shall cause Buyer’s Environmental Consultant to not) disclose any Environmental Information to any Governmental Authority or other Third Party without the prior written consent of Seller unless otherwise required by law. Unless otherwise required by law, prior to the Closing, Buyer may use the Environmental Information only in connection with the transactions contemplated by this Agreement. If Buyer, Buyer’s Environmental Consultant, or any Third Party to whom Buyer has provided any Environmental Information become legally compelled to disclose any of the Environmental Information, Buyer shall, as soon as reasonably practicable, provide Seller with good faith notice prior to any such disclosure so as to allow Seller to attempt to file any protective order, or seek any other remedy, as it deems appropriate under the circumstances. If this Agreement is terminated prior to the Closing, Buyer shall deliver the Environmental Information to Seller, which Environmental Information shall become the sole property of Seller. Buyer shall provide two (2) copies of the Environmental Information to Seller without charge. (c) Buyer acknowledges that the Assets have been used for exploration, development, and production of oil and gas and that there may be petroleum, produced water, wastes, or other substances or materials located in, on or under or associated with the Assets. Equipment and sites included in the Assets may contain asbestos, hazardous substances, or naturally occurring radioactive material (“NORM”). NORM may affix or attach itself to the inside of w▇▇▇▇, materials, and equipment as scale, or in other forms. The w▇▇▇▇, materials, and equipment located on the Assets may contain NORM and other wastes or hazardous substances. NORM containing material and/or other wastes or hazardous substances may have come in contact with various environmental media, including without limitation, water, soils or sediment. Special procedures may be required for the assessment, remediation, removal, transportation, or disposal of environmental media, wastes, asbestos, hazardous substances and NORM from the Assets.
Environmental Audits and Reports As soon as practicable following receipt thereof, copies of all material environmental audits, investigations, analyses and reports of any kind or character, whether prepared by personnel of Company or any of its Subsidiaries or by independent consultants, Government Authorities or any other Persons, with respect to significant environmental matters at any Facility that, individually or in the aggregate, could reasonably be expected to result in a Material Adverse Effect or with respect to any Environmental Claims that, individually or in the aggregate, could reasonably be expected to result in a Material Adverse Effect;