My WebLink
|
Help
|
About
|
Sign Out
Home
Browse
Search
Item 26 - Agreement with Allied Network Solutions, Inc. for Adobe Software and Subscription
Clerk
>
Agenda Packets / Staff Reports
>
City Council (2004 - Present)
>
2025
>
01/21/2025 Regular & Special SA
>
Item 26 - Agreement with Allied Network Solutions, Inc. for Adobe Software and Subscription
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
1/27/2025 5:03:20 PM
Creation date
1/21/2025 2:16:24 PM
Metadata
Fields
Template:
City Clerk
Doc Type
Agenda Packet
Agency
Information Technology
Item #
26
Date
1/21/2025
Jump to thumbnail
< previous set
next set >
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
762
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
View images
View plain text
sricnw~ <br />SUBSCRIPTION SERVICE GU DE <br />EFFECTIVE DATE: NOVEMBER 12, 2014 <br />fencing, berms, guarded gates), on -site guards, biometric controls, CCTV, and secure cages; and (ii) fire <br />detection and fire suppression systems both localized and throughout the data centerfloor. <br />(b) Systems, Machines and Devices: (i) Physical protection mechanisms; and (ii) entry <br />controls to limit physical access. <br />(c) Media: (i) Industry standard destruction of sensitive materials before disposition of <br />media; (ii) secure safe for storing damaged hard disks prior to physical destruction; and (iii) physical destruction of <br />all decommissioned hard disks storing Customer Data. <br />3.2. Technical Security Measures <br />(a) Access Administration. Access to the Subscription Service by ServiceNow employees <br />and contractors is protected by authentication and authorization mechanisms. User authentication is required to <br />gain access to production and sub -production systems. Access privileges are based on job requirements and are <br />revoked upon termination of employment or consulting relationship. Production infrastructure includes appropriate <br />user account and password controls (for example, the required use of virtual private network connections, <br />complex passwords with expiration dates, and a two -factored authenticated connection) and is accessible for <br />administration. <br />(b) Logging and Monitoring. The production infrastructure log activities are centrally <br />collected and are secured in an effort to prevent tampering and are monitored for anomalies by a trained <br />security team. <br />(C) Firewall System. An industry -standard firewall is installed and managed to protect <br />ServiceNow systems by residing on the network to inspect all ingress connections routed to the <br />ServiceNow environment. <br />(d) Vulnerability Management. ServiceNow conducts periodic independent security risk <br />evaluations to identify critical information assets, assess threats to such assets, determine potential <br />vulnerabilities, and provide for remediation. When software vulnerabilities are revealed and addressed by a <br />vendor patch, ServiceNow will obtain the patch from the applicable vendor and apply it within an appropriate <br />timeframe in accordance with ServiceNow's then current vulnerability management and security patch <br />management standard operating procedure and only after such patch is tested and determined to be safe for <br />installation in all production systems. <br />(e) Antivirus. ServiceNow updates anti -virus, anti-malware, and anti-spyware software on <br />regular intervals and centrally logs events for effectiveness of such software. <br />(f) Change Control. ServiceNow ensures that changes to platform, applications and <br />production infrastructure are evaluated to minimize risk and are implemented following ServiceNow's standard <br />operating procedure. <br />3.3. Administrative Security Measures <br />(a) Data Center Inspections. ServiceNow performs routine reviews at each data center to <br />ensure that it continues to maintain the security controls necessary to comply with the Security Program. <br />(b) Personnel Security. ServiceNow performs background and drug screening on all <br />employees and all contractors who have access to Customer Data in accordance with ServiceNow's then current <br />applicable standard operating procedure and subject to applicable law. <br />(c) Security Awareness and Training. ServiceNow maintains a security awareness program <br />that includes appropriate training of ServiceNow personnel on the Security Program. Training is conducted at time <br />of hire and periodically throughout employment at ServiceNow. <br />(d) Vendor Risk Management. ServiceNow maintains a vendor risk management program <br />that assesses all vendors that access, store, process or transmit Customer Data for appropriate security controls <br />and business disciplines. <br />SERVICENOw CONFIDENTIAL Page 8 (version 11/12/2014) <br />
The URL can be used to link to this page
Your browser does not support the video tag.