Orange County NC Website
DocuSign Envelope ID: D1041CA6-DBD4-42BE-8B32-7C592BF2BA15 <br /> If No, Explain: TMA Response: Although this item is not covered under our standard <br /> Subscription Agreement, TMA will work with the County to define language that is <br /> mutually agreeable for disposal of data. <br /> 6. What are the Cloud provider's obligation to the County in the event of confirmed or <br /> suspected data breaches? <br /> TMA Response: This is not covered in contractual language. TMA will work with the <br /> County to define language that is mutually acceptable. Please note that if a data breach is <br /> suspected, TMA would contact the County regarding the suspected breach. <br /> 7. Is the Cloud provider obligated to inform the County of all locations in which the data is <br /> stored (including backups) and to continually keep the County informed of any changes <br /> to those locations? <br /> TMA Response: No <br /> If No, Explain: TMA Response: This is not covered within the Subscription Agreement. <br /> However, this information is readily accessible. TMA utilizes two SSAE-16 II data <br /> centers for our production and DR sites. If required, TMA will work with the County to <br /> define contractual language that is mutually acceptable for this provision. <br /> 8. What are the Cloud provider's contractual obligations with respect to litigation holds on <br /> County data? <br /> TMA Response: Please see the TMA Subscription Agreement in the Attachments section <br /> of our proposal for contractual obligations associated with our hosted environment. <br /> TMA is open to working with the county on a mutually accepted agreement should <br /> modifications be required. <br /> 9. What are the Cloud provider's contractual prohibitions on disclosing data to individuals, <br /> groups or organizations making record requests, unless so directed by an authorized <br /> County official? <br /> TMA Response: Please see the TMA Systems, LLC Privacy Policy and the TMA <br /> Systems Subscription Agreement in the Attachments section of our proposal for <br /> contractual obligations. <br /> 10. Does the contract obligate the Cloud provider to allow third-party audits and/or <br /> certifications related to infrastructure and security, including penetration testing and <br /> vulnerability assessment, as requested by the County? <br /> TMA Response: No <br /> If No, Explain: TMA Response: TMA does utilize qualified 3rd party firms for security <br /> and penetration testing. Additionally, TMA is open to working with the County related <br /> to County testing. However, this would need to be coordinated with TMA's CIO, as our <br /> hosted environment is a shared environment with our other SaaS customers. <br /> 11. Does the contract obligate the Cloud provider to allow third party onsite inspections of <br />