Control Objectives definition
Examples of Control Objectives in a sentence
Contractor’s Program and Policy must align with appropriate industry security frameworks and standards such as National Institute of Standards and Technology (“NIST”) 800-53 Special Publication Revision 4, Federal Information Processing Standards (“FIPS”) 199, Federal Risk and Authorization Management Program (“FedRamp”), or Control Objectives for Information and Related Technology (“COBIT”).
On award of the Contract, the Contractor must comply with State and federal statutory and regulatory requirements, and rules; National Institute of Standards and Technology (NIST) publications; Control Objectives for Information and Related Technology (COBIT); all other industry specific standards; national security best practices and all requirements herein.
Licensor will follow a cyber-security framework of current standards and controls against relevant criteria such as those outlined by International Standards Organization (“ISO”) 27001/27001, National Institute of Standards and Technology (“NIST”), Center for Internet Security (“CIS”) Critical Security Controls, Control Objectives for Information and Related Technologies (“COBIT”), Open Web Application Security Project (“OWASP”) or other acceptable industry standards, as approved by K-C in writing.
In regards to compliance with the protective measures and safeguards outlined in Annex 2 of this DPA, Processor agrees to maintain an Information Security Management System in accordance to ISO 27001:2013 Control Objectives and its verified effectiveness, parties refer to the existing certification issued and available to Company upon request as proof of the appropriate guarantees.
HPI may update the Control Objectives at any time during the Term, provided that, subject to the Change Control Procedure, HPI will be responsible for any additional costs incurred by HPES in complying with the updated Control Objectives to the extent that such updated Control Objectives apply only to HPI and not to any other customer of HPES.
To the extent that such updated Control Objectives apply to other customers of HPES, then the costs associated with compliance with such updated Control Objectives will be, subject to the Change Control Procedure, equitably allocated among HPI and such other customers.
As requested by Company, Provider shall either (i) certify to Company in writing that during the applicable SAS 70 Gap Period no changes have been made to the Services, the manner in which the Services are provided or operated, applicable controls, or the Control Objectives that could reasonably be expected to have any impact on the contents of, or opinions set forth in, the applicable SAS 70 Type II Report; or (ii) provide Company with a written description of any such changes.
Company may update the Control Objectives at any time during the Term (or the Termination Assistance Period) provided that, subject to the Change Control Process, Company shall be responsible for any additional costs incurred by Provider in complying with the updated Control Objectives to the extent that such updated Control Objectives apply only to Company and not to any other customer of Provider.
In addition to the Control Objectives, Provider shall provide whatever assistance is necessary to assist Company in complying with such requirements with respect to its outsourced functions.
To the extent that such updated Control Objectives apply to other customers of Provider, then the costs associated with compliance with such updated Control Objectives shall be, subject to the Change Control Process, equitably allocated among Company and such customers.