Loading...
The URL can be used to link to this page
Your browser does not support the video tag.
Home
My WebLink
About
2019-182-E IT - SecureWorks Emergency Incident Response Services
DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 q Securewcirks STATEMENT OF WORK Security Consult 'ing i u ions Prepared for Orange County, NC Prepared By Bo Gorham soV Q555439-03182019 Release Date March 20, 2019 Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 SOW-09122018 This Statement of Work ("SOW") is entered into by and between Secureworks, Inc., with its principal place of business located at One Concourse Parkway, Suite 500, Atlanta, GA 30328 ("Secureworks") and Orange County, North Carolina with its principal place of business located at 200 S. Cameron Street, Hillsborough, NC 27278 ("Customer")as of the SOW Effective Date, which is defined by the latest date in the signature blocks below. Secureworks and Customer hereafter referred to together as the "parties", and each, a "party". This SOW is governed by and subject to the terms and conditions of: (a)the separately signed agreement executed by the parties that expressly authorizes Customer to order the services described herein from Secureworks, or(b)the Secureworks Master Services Agreement available at https://www.Secureworks.com/msa-us,(the "MSA")which is incorporated by reference in its entirety herein. Capitalized terms not defined herein shall have the meaning ascribed to them in the MSA. 1 Scope Under this SOW, Secureworks will provide Customer with Emergency Incident Response service ("Service") as such Service is described in detail below. 1.1 Emergency Incident Response Services Customer agrees to the purchased hours as set forth in Service Fees and Expenses section below ("Committed Hours"). Emergency Incident Response Services performed by Secureworks represents an Engagement ("Engagement'). Services include the following: • Incident support and coordination • Digital media handling guidance and support • Deployment support of host-based, network-based, and log analysis technologies • Network testing services • Incident Response analysis for on-premise and cloud infrastructure — Host-based — Network-based — Malicious code — Logs — Threat intelligence analysis • Remediation planning guidance The work provided by Secureworks described within this Statement of Work will be delivered according to the Customer-provided information found in Appendix 2: Additional Scoping Detail. 1.2 Out of Scope Secureworks reserves the right to decline requests which: • Are beyond the scope of the Services as defined herein • Are beyond the capability of Secureworks to deliver within contracted service levels • Might violate legal or regulatory requirements Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 SOW-09122018 2 Service Delivery 2.1 Delivery Coordination Secureworks will provide coordination for the services in scope with appropriate communication and updates to the stakeholder community. The coordinator will oversee logistics for people, processes and tools as well as timeline and meeting facilitation. The scope of delivery coordination includes: • Develop delivery timeline with Customer and with Secureworks resources • Work with Customer to identify and address issues or concerns that impact service delivery • Periodic, high-level updates on progress • Confirm delivery and procure project sign-off 2.2 Scheduling Upon scoping and identifying the nature of the cyber incident, Secureworks personnel will be scheduled that are consistent with Customer response goals, specified sense of urgency, and applicable laws or ordinances 2.3 Delivery For locations deemed by Secureworks as unsafe, Secureworks solely reserves the right to limit travel to those locations or to require a security escort at additional customer expense. Customer will be notified at the time services are requested if additional security is required, and Customer will be required to authorize the additional expense before travel is arranged. 3 Customer Obligations Customer acknowledges that Secureworks' ability to perform the Services is contingent upon the following: • Customer resources are scheduled and available. • If Customer does not own network resources, including IP addresses, hosts, facilities or web applications, it will have obtained consent and authorization from the applicable third party, in form and substance satisfactory to Secureworks, to permit Secureworks to provide the Service. • For onsite Services, Customer will provide suitable workspace for Secureworks resources, and necessary access to systems, network, and devices. • Replies to all requests are prompt and in accordance with the delivery dates established in the Scheduling phase. • Customer scheduled downtime and change windows allow adequate time for Secureworks performance of the Services. • Customer will promptly inform Customer personnel and third parties of testing activities to prevent disruption to Secureworks business (e.g., takedown requests, ISP blacklisting). • All required information (key personnel contact information, credentials, etc.)will be provided to Secureworks prior to onsite arrival. Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 SOW-09122018 4 Deliverable Secureworks will work with Customer to determine the appropriate deliverables, delivery method, and cadence. MethodService Report Delivery Schedule Delivery Incident Response Status Updates Agreed-upon intervals Agreed-upon methods Engagements Incident Response Final Upon completion of the Secure Email, Client Engagements individual Engagement Portal, Secure File Sharing 4.1 Status Updates Status Updates may be verbal or written and may include: • Summary of completed activities • Issues requiring attention • Planning for the next work effort period 4.2 Final Report Final Report may include: • Executive summary, outlining key findings and recommendations • Methods, detailed findings, narratives and recommendations • Attachments providing relevant details and supporting data Secureworks will issue a Final Report to the Customer-designated point of contact within three (3)weeks of completing the active phases of the Engagement. Customer shall then have three (3)weeks from Secureworks delivery of the Final Report to provide comments. Should Customer provide comments, the Final Report shall be deemed complete upon the earlier of the date which (1) Secureworks provides responses to these comments or(2) Secureworks delivers a revised Final Report. If no comments are received from Customer before the expiration of the review period, or upon Customer's written acceptance of the Report, the Final Report will be deemed complete and referred to as the "Completed Final Report". 5 Service Fees and Expenses Until this SOW is fully executed by both parties, the fees proposed herein are only valid for 90 days from the date received. 5.1 Service Fees Service Name Committed Hour Fee Total Fee Incident Management Emergency 40 $420 USD 16,800 USD Services Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 SOW-09122018 5.2 Billing Terms • Service Fees for Committed Hours are 100% billable upon SOW execution • Additional hourly fees for Services are billable monthly in arrears 5.2.1 Additional Hours • Additional blocks of hours may be purchased in advance of or upon exhaustion of contracted hours at the contracted rate referenced in the Services Fees Section via e-mail authorization from Customer. • Requests for additional hours must be sent by e-mail from Customer to irservices(D_secureworks.com and Customer acknowledges and agrees that any such e-mail will be from a representative of Customer authorized to commit Customer to the purchase of the additional hours and is binding on Customer. • Customer acknowledges and agrees that if Purchase Orders (P.O.$) are required for the transaction with Secureworks to extend the contracted hours, an updated P.O. will be issued to Secureworks for the number of hours specified in the authorizing e-mail within seven (7) calendar days from the date of the acknowledged receipt of the e-mail by Secureworks. If an updated P.O. is not received within 7 calendar days, Secureworks may terminate the engagement and, in any event, Customer acknowledges and agrees that it remains responsible for any additional hours worked by Secureworks until such P.O. is received. 5.2.2 Committed Hours • Customer may terminate an Engagement by providing 24-hour advance notice to stop all work against this SOW. Committed Hours will be forfeited if Engagement is terminated prior to exhaustion of those hours. • Notice for termination of Engagement must be sent by email to irservices(o)_Secureworks.com. • Consumed hours will be calculated in quarter-hour increments. • All Committed Hours are non-refundable and non-transferable for other Secureworks services. Any unused hours within a given year expire and are forfeited on the anniversary of SOW execution. 5.3 Expenses Customer agrees to reimburse Secureworks for all reasonable and actual expenses incurred in conjunction with delivery of the Service. These expenses include, but are not limited to: • Travel fees related to transportation, meals and lodging to perform the Services, including travel to the Customer location(s). • Media storage, specific equipment, or licensing necessary for forensic work. • Monthly fees for other purchased infrastructure to support service delivery(e.g., public cloud computing services) may apply, should Secureworks and Customer agree that usage is necessary to complete the Engagement. 6 SOW Term The term of this SOW shall commence on the SOW Effective Date and terminate on the earlier to occur of (i)the date which is one (1) year thereafter, or(ii)the completion of the Services (the "SOW Term"). Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 SOW-09122018 The term of the Services for Emergency Incident Response shall commence on the SOW Effective Date and terminate on the earlier to occur of(i)the SOW Term, or(ii) upon exhaustion of the original Committed Hours and completion of any outstanding time and materials billing (the "Services Term"). To the extent that Customer authorizes work effort for an Engagement, and such work effort extends beyond the SOW Term or Services Term, the SOW Term and Services Term shall be extended to the completion of such continued work effort through the date of the Completed Final Report (the"Extended Term"). During such Extended Term, the terms and conditions of this SOW and the MSA shall be in full force and effect. 7 Disclaimers 7.1 Onsite Services Notwithstanding Secureworks' employees' placement at the Customer location, Secureworks retains the right to control the work of such employees. For international travel, onsite Services may require additional documentation, such as visas, visitor invitations, etc. which may affect timing of the Services and reimbursable expenses. 7.2 Security Services Should this SOW include security scanning, testing, assessment, forensics, or remediation Services ("Security Services"), Customer understands that Secureworks may use various methods and software tools to probe network resources for security-related information and to detect actual or potential security flaws and vulnerabilities. Customer hereby authorizes Secureworks to perform such Security Services (and all such tasks and tests reasonably contemplated by or reasonably necessary to perform the Security Services or otherwise approved by Customer from time to time)on network resources with the internet protocol ("IP")Addresses identified by Customer. Customer represents that, if Customer does not own such network resources, it will have obtained consent and authorization from the applicable third party, in form and substance satisfactory to Secureworks, to permit Secureworks to provide the Security Services. Secureworks shall perform the Security Services during a timeframe mutually agreed upon with Customer. The Security Services, such as penetration testing or vulnerability assessments, may also entail buffer overflows, fat pings, operating system specific exploits, and attacks specific to custom coded applications but will exclude intentional and deliberate denial of service ("DoS")attacks. Furthermore, Customer acknowledges that the Security Services described herein could possibly result in service interruptions or degradation regarding the Customer systems and accepts those risks and consequences. Customer hereby consents and authorizes Secureworks to provide any or all the Security Services with respect to the Customer systems. Customer further acknowledges it is Customer responsibility to restore network computer systems to a secure configuration after Secureworks' testing. 7.3 Record Retention Secureworks will retain a copy of the Customer Reports and supporting Customer Data in accordance with Secureworks' record retention policy, which provides such retention for a period commensurate with such Customer Reports and supporting Customer Data usefulness and Secureworks' legal and regulatory requirements and Secureworks' directives. Unless Customer gives Secureworks written notice to the contrary prior thereto, then thirty(30) days after delivery of its final report, Secureworks shall have the right, in its sole discretion, to dispose of all acquired hard drive images and other report backup information acquired in connection with its performance of its obligations under this SOW. Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 SOW-09122018 7.4 Post-Engagement Activities Thirty(30) days after the Completed Final Report, Secureworks will commence with the appropriate media sanitization and/or destruction procedures of the Customer acquired images, hard drives or other media obtained by Secureworks in the performance of the Services hereunder(the "Incident Media"), unless prior to such commencement, Customer has specified in writing to Secureworks any special requirements for Secureworks to return such Incident Media (at Customer's sole expense). Upon Customer's request, Secureworks will provide options for the transfer to Customer of Incident Media and the related costs thereto. If so requested, Secureworks will provide a confirmation letter to Customer addressing completion and scope of these post incident activities, in Secureworks' standard form. Unless agreed to otherwise by the parties, Secureworks shall, in its sole discretion, dispose of the Incident Media on or after the Engagement conclusion and only maintain a copy of the Completed Final Report and associated deliverables. 7.5 Legal Proceedings If Customer knows or has reason to believe that Secureworks or its employees performing Services under this SOW have or will become subject to any order or process of a court, administrative agency or governmental proceeding (e.g., subpoena to provide testimony or documents, search warrant, or discovery request), which will require Secureworks or such employees to respond to such order or process and/or to testify at such proceeding, Customer will (i) promptly notify Secureworks, unless otherwise prohibited by such order or process, (ii) use commercially reasonable efforts to reduce the burdens associated with the response, and (iii) reimburse Secureworks for(a) its employees' time spent as to such response at the hourly rate reflected in this SOW, (b) its reasonable and actual attorney's fees as to such response, and (c) its reasonable and actual travel expenses incurred as to such response. Nothing in this paragraph shall apply to any legal actions or proceedings between Customer and Secureworks as to the Services or this SOW. 7.6 Endpoint Assessment Unless otherwise agreed upon in writing, if a software agent has been deployed as part of an Engagement, within thirty(30) days following the date of the Completed Final Report(the "Thirty Day Period"), Customer shall uninstall any and all copies of the software agent used for the Engagement. During the Thirty Day Period, (i) Customer shall not use the software agent, and (ii)the license and use restrictions that apply to the software agent remain in effect notwithstanding the expiration of termination of the Service. Customer will install Secureworks' proprietary software agent if Endpoint Assessment Services are in scope. Customer(i)will use the Endpoint Assessment software agent for its internal security purposes, and (ii)will not, for itself, any Affiliate of Customer or any third party: (a) decipher, decompile, disassemble, reconstruct, translate, reverse engineer, or discover any source code of the software agent; and (b)will not remove any language or designation indicating the confidential nature thereof or the proprietary rights of Secureworks from the software agent. Customer will uninstall the software agent as described in this SOW. Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 This SOW is agreed to by the parties. Any terms and conditions attached to a purchase order submitted by Customer in connection with this SOW are null and void. Secureworks, Inc. Orange County of NC 1 Concourse Pkwy, NE#500, 200 S Cameron St Atlanta, GA 30328 Hillsborough, NC 27278-2505 DocuSigned by: cuSigned by: 1fr' s A4yr v�. By: ............................... By: ......... 3E8'1B12B364B4... ................ 65E65A@F7F26dA5... Printed: Debbie Bernhardt.............................. Printed: Travis Myren..................................... Title: Senior Manager Commercial Title: Deputy County Manager................... Contracts/SWRX Legal....................................... 3/21/2019 Date: .......................................................... 3/20/2019 Date: ........................................................... SFDC: Document Information Customer Name Orange County Government Document Author Bo Gorham Customer Account Manager Tracey Fries - Norris Document Date 3/18/2019 Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 Appendix 1 : Service Descriptions 7.7 Emergency Incident Response Services During the Services Term, Secureworks agrees to provide Emergency Incident Response Services to Customer. These services can be provided remotely or onsite. The activities to be performed may include, but are not limited to: • Incident support and coordination • Digital media handling guidance and support • Deployment support of host-based, network-based, and log analysis technologies • Network testing services • Incident Response analysis for on-premise and cloud infrastructure — Host-based — Network-based — Malicious code — Logs — Threat intelligence analysis • Remediation planning guidance 7.7.1 Digital Forensic Analysis Services As part of Emergency Incident Response Services, Secureworks may acquire and analyze a variety of formats for forensic analysis and data recovery, including but not limited to: • Disk drives • RAID systems • Portable storage drives • Mobile devices • Network packet captures • Cleartext log files 7.7.2 Malware Analysis and Reverse Engineering Services As part of Emergency Incident Response Services, Secureworks may perform static, dynamic, and reverse engineering analysis to assist in understanding the function of Customer-supplied files. Secureworks will provide analysis results, to include cyber threat intelligence based on correlation across Secureworks datasets, and will advise on mitigation actions to reduce the impact of the sample on Customer infrastructure. Appendix 2: Additional Scoping Detail 8 Additional Scoping Detail The following criteria has been provided by Customer to derive scope and pricing described within this Statement of Work. Secureworks will deliver the services described herein according to the following. Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution DocuSign Envelope ID:OADE138B-093C-4937-85B5-78AC72BBFDD6 Significant changes to the Customer environment that exceed this information may result in Scope changes and additional fees through a Change Order. Actions to Take: • Deploy Red Cloak to approximately 1,400 Windows endpoints for outbreak response • Provide IR Services for Mutually Defined Objectives • Provide Written Report Classification://Secureworks/Confidential -Limited External Distribution: //Secureworks/Confidential- Limited External Distribution ATE ,a1�o�® CERTIFICATE OF LIABILITY INSURANCE D03/22/2019DIYYYv) THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER. THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S), AUTHORIZED REPRESENTATIVE OR PRODUCER,AND THE CERTIFICATE HOLDER. IMPORTANT: If the certificate holder is an ADDITIONAL INSURED,the policy(ies) must have ADDITIONAL INSURED provisions or be endorsed. If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy, certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s). PRODUCER CONTACT MARSH RISK&INSURANCE SERVICES NAME: PHO345 CALIFORNIA STREET,SUITE 1300 A/CNNo Ext: A/C No), CALIFORNIA LICENSE NO.0437153 E-MAIL SAN FRANCISCO,CA 94104 ADDRESS: Attn:San Francisco.Certs@marsh.com/FAX 212-948-0398 INSURER(S)AFFORDING COVERAGE NAIC# INSURER A:National Union Fire Ins Co Pittsburgh PA 19445 INSURED Dell Technologies Inc. INSURER B: See Attached and all Subsidiaries INSURER C:Lloyd's of London-Syndicate 2623/623 at Lloyd's 15792 One Dell Way-RR1-50 INSURER D: Round Rock,TX 78682 INSURER E: INSURER F: COVERAGES CERTIFICATE NUMBER: SEA-003607482-01 REVISION NUMBER: 2 THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED. NOTWITHSTANDING ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES.LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. INSR TYPE OF INSURANCE ADDL SUBR POLICY EFF POLICY EXP LIMITS LTR INSD WVD POLICY NUMBER MM/DDIYYYY MM/DDIYYYY A X COMMERCIAL GENERAL LIABILITY GL5425904 03/01/2019 03/01/2020 EACH OCCURRENCE $ 2,000,000 DAMAGE TO CLAIMS-MADE � OCCUR PREMISES (a oNcur RENTED ) $ 2,000,000 MED EXP(Any one person) $ 10,000 PERSONAL&ADV INJURY $ 2,000,000 GEN'L AGGREGATE LIMIT APPLIES PER: GENERAL AGGREGATE $ 10,000,000 X POLICY❑ PRO- POLICY ❑ LOC PRODUCTS-COMP/OP AGG $ 10,000,000 OTHER: $ A AUTOMOBILE LIABILITY CA4993096(AOS) 03/01/2019 03/01/2020 COEaMBINED accident SINGLE LIMIT $ 2,000,000 A X ANY AUTO CA4993097(MA) 03/01/2019 03/01/2020 BODILY INJURY(Per person) $ OWNED SCHEDULED BODILY INJURY(Per accident) $ AUTOS ONLY AUTOS X HIRED X NON-OWNED PROPERTY DAMAGE $ AUTOS ONLY AUTOS ONLY Per accident X UMBRELLA LIAB X OCCUR 28295092 03/01/2019 03/01/2020 EACH OCCURRENCE $ 10,000,000 EXCESS LIAB CLAIMS-MADE AGGREGATE $ 10,000,000 DED RETENTION$ $ B WORKERS COMPENSATION SEE FOLLOWING PAGE 03/01/2019 03/01/2020 X PER OTH- AND EMPLOYERS'LIABILITY STATUTE ER ANYPROPRIETOR/PARTNER/EXECUTIVE Y/N Workers Compensation excluded E.L.EACH ACCIDENT $ 1�����00� OFFICER/MEMBER EXCLUDED? N/A in ND,OH&WA (Mandatory in NH) E.L.DISEASE-EA EMPLOYEE $ 1,000,000 If yes,describe under 1,000,000 DESCRIPTION OF OPERATIONS below E.L.DISEASE-POLICY LIMIT $ C Professional/E&O/ FINPT1800039 06/01/2018 06/01/2019 Each Claim/Aggregate 20,000,000 Technology Errors&Omissions (Claims Made) DESCRIPTION OF OPERATIONS I LOCATIONS/VEHICLES (ACORD 101,Additional Remarks Schedule,may be attached if more space is required) The above referenced Errors and Omissions policy shall include technology/professional liability,and data protection liability(cyber liability)insurance providing protection against:(a)errors and omissions in the performance of professional services;(b)breaches of security;(c)violation or infringement of any right of privacy,breach of federal,state,or foreign security and/or privacy laws or regulations;and(d)data theft, damage,destruction,or corruption. CERTIFICATE HOLDER CANCELLATION Orange County IT SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE 131 West Margaret Lane#300 THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN Hillsborough,NC 27278 ACCORDANCE WITH THE POLICY PROVISIONS. AUTHORIZED REPRESENTATIVE of Marsh Risk&Insurance Services Stephanie Guaiumi @ 1988-2016 ACORD CORPORATION. All rights reserved. ACORD 25(2016/03) The ACORD name and logo are registered marks of ACORD AGENCY CUSTOMER ID: CN1 01 640 1 93 LOC#: San Francisco AC"R o ADDITIONAL REMARKS SCHEDULE Page 2 of 2 AGENCY NAMED INSURED MARSH RISK&INSURANCE SERVICES Dell Technologies Inc. and all Subsidiaries POLICY NUMBER One Dell Way-RR1-50 Round Rock,TX 78682 CARRIER NAIC CODE EFFECTIVE DATE: ADDITIONAL REMARKS THIS ADDITIONAL REMARKS FORM IS A SCHEDULE TO ACORD FORM, FORM NUMBER: 25 FORM TITLE: Certificate of Liability Insurance DELL INC.-WORKERS COMPENSATION/EMPLOYERS LIABILITY; EFFECTIVE 3/1/2019- EXPIRATION 3/1/2020 Insurer: New Hampshire Insurance Co. NAIC#23841 WC012717139-All Other States WC012717141-FL WC012717142-MA,WI,WY and Stop Gap EL:ND,OH,WA WC012717138-AK,AZ,IL,KY NC,NH,NJ,PA,UT,VA,VT Insurer: American Home Assurance Company NAIC#19380 WC012717140-CA ACORD 101 (2008/01) ©2008 ACORD CORPORATION. All rights reserved. The ACORD name and logo are registered marks of ACORD