Orange County NC Website
<br />If No, Explain: TMA Response: Although this item is not covered under our standard <br />Subscription Agreement, TMA will work with the County to define language that is <br />mutually agreeable for disposal of data. <br /> <br />6. What are the Cloud provider’s obligation to the County in the event of confirmed or <br />suspected data breaches? <br />TMA Response: This is not covered in contractual language. TMA will work with the <br />County to define language that is mutually acceptable. Please note that if a data breach is <br />suspected, TMA would contact the County regarding the suspected breach. <br /> <br />7. Is the Cloud provider obligated to inform the County of all locations in which the data is <br />stored (including backups) and to continually keep the County informed of any changes <br />to those locations? <br />TMA Response: No <br /> <br />If No, Explain: TMA Response: This is not covered within the Subscription Agreement. <br />However, this information is readily accessible. TMA utilizes two SSAE-16 II data <br />centers for our production and DR sites. If required, TMA will work with the County to <br />define contractual language that is mutually acceptable for this provision. <br /> <br />8. What are the Cloud provider’s contractual obligations with respect to litigation holds on <br />County data? <br />TMA Response: Please see the TMA Subscription Agreement in the Attachments section <br />of our proposal for contractual obligations associated with our hosted environment. <br />TMA is open to working with the county on a mutually accepted agreement should <br />modifications be required. <br /> <br />9. What are the Cloud provider’s contractual prohibitions on disclosing data to individuals, <br />groups or organizations making record requests, unless so directed by an authorized <br />County official? <br />TMA Response: Please see the TMA Systems, LLC Privacy Policy and the TMA <br />Systems Subscription Agreement in the Attachments section of our proposal for <br />contractual obligations. <br /> <br />10. Does the contract obligate the Cloud provider to allow third-party audits and/or <br />certifications related to infrastructure and security, including penetration testing and <br />vulnerability assessment, as requested by the County? <br />TMA Response: No <br /> <br />If No, Explain: TMA Response: TMA does utilize qualified 3rd party firms for security <br />and penetration testing. Additionally, TMA is open to working with the County related <br />to County testing. However, this would need to be coordinated with TMA’s CIO, as our <br />hosted environment is a shared environment with our other SaaS customers. <br /> <br />11. Does the contract obligate the Cloud provider to allow third party onsite inspections of <br />DocuSign Envelope ID: D1041CA6-DBD4-42BE-8B32-7C592BF2BA15DocuSign Envelope ID: 3E613CA5-0A37-4CD3-890F-47CC5E2F38B1