Laserfiche WebLink
DocuSign Envelope ID: 348BB866-CFC7-422D-BFB7-863533B13759 <br />Attachment G <br />GLO Contract No. 22-119-004-D374 <br />Page 1 of 4 <br />GLO Information Security Appendix (CDBG) <br />1. Definitions <br />"Breach of Security" means any unauthorized access of computerized data that compromises the <br />security, confidentiality, or integrity of GLO Data that is in the possession and/or control of <br />Subrecipient (or any entity with which Subrecipient shares GLO Data as authorized herein) <br />including data that is encrypted if the person accessing the data has the key required to decrypt <br />the data, or a loss of control, compromise, unauthorized disclosure or access, failure to physically <br />secure GLO Data or when unauthorized users access PII or SPI for an unauthorized purposes. <br />The term encompasses both suspected and confirmed incidents involving GLO Data which raise <br />a reasonable risk of harm to the GLO or an individual. A Breach of Security occurs regardless of <br />whether caused by a negligent or intentional act or omission on part of Subrecipient and/or <br />aforementioned entities. <br />"GLO Data" means any data or information, which includes PII and/or SPI as defined below, <br />collected, maintained, and created by the GLO, for the purpose of providing disaster assistance <br />to an individual, that Subrecipient obtains, accesses (via records, systems, or otherwise), receives <br />(from the GLO or on behalf of the GLO), or uses in the performance of the Contract or any <br />documents related thereto. GLO Data does not include other information that is lawfully made <br />available to Subrecipient through other sources. <br />"Personal IdentiNinz Information" or "PII" means information that alone, or in conjunction with <br />other information, identifies an individual as defined at Tex. Bus. & Com Code Section <br />521.002(a)(1). <br />"Sensitive Personal Information" or "SPI" means the personal information identifying an <br />individual as defined at Tex. Bus. & Com. Code Section 521.002(a)(2). <br />All defined terms found in the Contract shall have the same force and effect, regardless of <br />capitalization. <br />2. Security and Privacy Compliance <br />2.1. Subrecipient shall keep all GLO Data received under the Contract and any documents <br />related thereto strictly confidential. <br />2.2. Subrecipient shall comply with all applicable federal and state privacy and data <br />protection laws, as well as all other applicable regulations. <br />2.3. Subrecipient shall implement administrative, physical, and technical safeguards to <br />protect GLO Data that are no less rigorous than accepted industry practices including, <br />without limitation, the guidelines in the National Institute of Standards and Technology <br />("NIST") Cybersecurity Framework Version 1.1. All such safeguards shall comply with <br />applicable data protection and privacy laws. <br />2.4. Subrecipient will legally bind any contractor(s)/subcontractor(s) to the same <br />requirements stated herein and obligations stipulated in the Contract and documents <br />related thereto. Subrecipient shall ensure that the requirements stated herein are <br />imposed on any contractor/subcontractor of Subrecipient's subcontractor(s). <br />