Orange County NC Website
32 <br /> 10. Communications a. Maintain a secure boundary using firewalls and network traffic filtering <br /> Security b. Require internal segmentation to isolate critical systems from general purpose networks <br /> c. Require periodic reviews and testing of network controls <br /> 11. System <br /> Acquisition, a. Assign responsibility for system security, system changes and maintenance <br /> Development and b. Test, evaluate and authorize major system components prior to implementation <br /> Maintenance <br /> 12. Supplier Periodically review available security assessment reports of vendors hosting the <br /> Relationships CrowdStrike Systems to assess their security controls and analyze any exceptions set forth <br /> in such reports <br /> 13. Information a. Monitor the access, availability, capacity and performance of the CrowdStrike Systems, <br /> Security Breach and related system logs and network traffic using various monitoring software and <br /> Management services <br /> b. Maintain incident response procedures for identifying, reporting, and acting on Security <br /> Breaches <br /> c. Perform incident response table-top exercises with executives and representatives from <br /> across various business units <br /> d. Implement plan to address gaps discovered during exercises <br /> e. Establish a cross-disciplinary Security Breach response team <br /> 14. Business a. Design business continuity with goal of 99.9% uptime SLA <br /> Continuity b. Conduct scenario based testing annually <br /> Management <br /> 15. Compliance a. Establish procedures designed to ensure all applicable statutory, regulatory and <br /> contractual requirements are adhered to <br /> CrowdStrike Form May 27 2019 17 of 17 <br />