Loading...
HomeMy WebLinkAbout2024-308-E-IT Dept-Trustedsec-Penetration testing and cybersecurity consultingRevised 01/24 1 [Departmental Use Only] TITLE Trustedsec FY 24 NORTH CAROLINA SERVICES AGREEMENT NO RFP/RFQ ORANGE COUNTY This Services Agreement (hereinafter “Agreement”), made and entered into this 30th day of May, 2024, (“Effective Date”) by and between Orange County, North Carolina a political subdivision of the State of North Carolina (hereinafter, the "County") and Trustedsec, LLC, (hereinafter, the "Provider"). WITNESSETH: That the County and Provider, for the consideration herein named, do hereby agree as follows: 1. Services a. Scope of Work. i) This Agreement is for services to be rendered by Provider to County with respect to (insert type of project): Penetration testing and cybersecurity consulting ii) By executing this Agreement, the Provider represents and agrees that Provider is qualified to perform and fully capable of performing and providing the services required or necessary under this Agreement in a fully competent, professional and timely manner. iii) Time is of the essence with respect to this Agreement. iv) The services to be performed under this Agreement consist of Basic Services, as described and designated in Section 3 hereof. Compensation to the Provider for Basic Services under this Agreement shall be as set forth herein. 2. Responsibilities of the Provider a. Services to be provided. The Provider shall provide the County with all services required in Section 3 to satisfactorily complete the Project within the time limitations set forth herein and in accordance with the highest professional standards. b. Standard of Care. i) The Provider shall exercise reasonable care and diligence in performing services under this Agreement in accordance with the highest generally accepted standards of this type of Provider practice throughout the United States and in accordance with applicable federal, state and local laws and regulations applicable to the performance of these services. Provider is solely responsible for the professional DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Revised 01/24 2 quality, accuracy and timely completion and submission of all work related to the Basic Services. ii) Provider shall be responsible for all errors or omissions of its agents, contractors, employees, or assigns in the performance of the Agreement. Provider shall correct any and all errors, omissions, discrepancies, ambiguities, mistakes or conflicts at no additional cost to the County. iii) The Provider shall not, except as otherwise provided for in this Agreement, subcontract the performance of any work under this Agreement without prior written permission of the County. No permission for subcontracting shall create, between the County and the subcontractor, any contract or any other relationship. iv) Provider is an independent contractor of County. Any and all employees of the Provider engaged by the Provider in the performance of any work or services required of the Provider under this Agreement, shall be considered employees or agents of the Provider only and not of the County, and any and all claims that may or might arise under any workers compensation or other law or contract on behalf of said employees while so engaged shall be the sole obligation and responsibility of the Provider. v) If activities related to the performance of this Agreement require specific licenses, certifications, or related credentials Provider represents that it or its employees, agents and subcontractors engaged in such activities possess such licenses, certifications, or credentials and that such licenses certifications, or credentials are current, active, and not in a state of suspension or revocation. vi) Should any documents, exhibits, or addenda be attached to this Agreement, the terms of this Agreement shall have priority in any conflict with or among the terms of such referenced documents, exhibits. vii) Should this Agreement involve project designs, the construction or creation of which is to be bid out or fulfilled by other contractors, and bidding or negotiation with contractors produce prices which, when added to the other elements of the approved total project cost, produce a cost that is in excess of the approved total project cost, the Provider shall participate with the County in negotiation and design adjustments to the extent such are necessary to obtain prices within the approved total project cost. All activity of the Provider with respect to these matters shall constitute Basic Services and shall be performed by the Provider without additional compensation. If negotiation and design adjustments fail to bring costs within the total project cost the County may reject all bids and Provider will redesign or reduce portions of the project in an effort to reduce the bid prices to within the total project cost and rebid the project. One such redesign is included within Basic Services. If this second letting for bids does not produce bids that are within the approved total project cost initially or after negotiations with the contractor the cost is not reduced to an amount within the total project cost, the Provider is not obligated to engage in further redesign. 3. Basic Services DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Revised 01/24 3 a. Basic Services. The Services to be rendered pursuant to this Agreement are as follows (fully describe services to be provided): Penetration testing and cybersecurity consulting 4. Duration of Services a. Term. The term of this Agreement shall be from 31 May 2024 to 30 May 2025. b. Scheduling of Services. i) The Provider shall schedule and perform its activities in a timely manner. ii) Should the County determine that the Provider is behind schedule, it may require the Provider to expedite and accelerate its efforts, including providing additional resources and working overtime, as necessary, to perform its services in accordance with the approved project schedule at no additional cost to the County. iii) The Commencement Date for the Provider's Basic Services shall be 31 May 2024. 5. Compensation a. Compensation for Basic Services. Compensation for Basic Services shall include all compensation due the Provider from the County for all services satisfactorily (as determined by the County) performed pursuant to this Agreement. The maximum amount payable for Basic Services shall not exceed twenty-one-thousand-five-hundred and 00/100 Dollars ($21,500.00) (See Attachment A). Payment for satisfactorily performed Basic Services shall become due and payable within thirty (30) days of Provider properly invoicing County. Payment shall be subject to provisions of Section 5(b). b. Disputes. In the event the amount stated on an invoice is disputed by the County, the County may withhold payment of all or a portion of the amount stated on an invoice until the parties resolve the dispute. Should Provider fail to perform its duties under the terms of this Agreement, County may, without fault or penalty, withhold any payment associated with the work to be performed until such time as said work is completed. c. Additional Services. County shall not be responsible for costs related to any services in addition to the Basic Services performed by Provider unless County requests such additional services in writing and such additional services are evidenced by a written amendment to this Agreement. 6. Responsibilities of the County a. Cooperation and Coordination. The County has designated (Robert Reynolds) to act as the County's representative with respect to the Project who shall have the authority to render decisions within guidelines established by the County Manager or the County Board of Commissioners and who shall be available during working hours as often as may be reasonably required to render decisions and to furnish information. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Revised 01/24 4 7. Insurance a. General Requirements. Provider shall obtain, at its sole expense, Commercial General Liability Insurance, Automobile Insurance, Workers’ Compensation Insurance, and any additional insurance as may be required by County’s Risk Manager as such insurance requirements are described in the Orange County Risk Transfer Policy and Orange County Minimum Insurance Coverage Requirements (each document is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php). If County’s Risk Manager determines additional insurance coverage is required such additional insurance shall consist of N/A (if no additional insurance required mark N/A as being not applicable). Provider shall not commence work until such insurance is in effect and certification thereof has been received by the County's Risk Manager. 8. Indemnity a. Indemnity. To the extent authorized by North Carolina law the Provider agrees, without limitation, to defend, indemnify and hold harmless the County from all loss, liability, claims or expense, including attorney's fees, arising out of or related to the Project and arising from property damage or bodily injury including death to any person or persons caused in whole or in part by the negligence or misconduct of the Provider except to the extent same are caused by the negligence or willful misconduct of the County. It is the intent of this provision to require the Provider to indemnify the County to the fullest extent permitted under North Carolina law. 9. Amendments to the Agreement a. Changes in Basic Services. Changes in the Basic Services and entitlement to additional compensation or a change in duration of this Agreement shall be made by a written Amendment to this Agreement executed by the County and the Provider. The Provider shall proceed to perform the Services required by the Amendment only after receiving a fully executed Amendment from the County. 10. Termination a. Termination for Convenience of the County. This Agreement may be terminated without cause by the County and for its convenience upon seven (7) days’ prior written notice to the Provider. b. Other Termination. The Provider may terminate this Agreement based upon the County's material breach of this Agreement; provided, the County has not taken all reasonable actions to remedy the breach. The Provider shall give the County seven (7) days' prior written notice of its intent to terminate this Agreement for cause. Either party may terminate this Agreement upon notice to the other party that obligations pursuant to this Agreement are made impractical due to declarations of emergency by Orange County or by North Carolina due to events directly impacting Orange County. Both parties shall remain responsible for all payment and performance due up to the receipt of such notice, but shall have no further obligation or responsibility beyond that date provided the terminating party has taken all reasonable steps to complete the performance of its DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Revised 01/24 5 obligations. c. Compensation After Termination. i) In the event of termination, the Provider shall be paid that portion of the fees and expenses that it has earned to the date of termination, less any costs or expenses incurred or anticipated to be incurred by the County due to errors or omissions of the Provider. Upon request of the County, the Provider shall submit to County all relevant documentation, including but not limited to, job cost records, to support its claims for final compensation. ii) Should this Agreement be terminated, the Provider shall deliver to the County within seven (7) days, at no additional cost, all deliverables including any electronic data or files relating to the Project. d. Waiver. The payment of any sums by the County under this Agreement or the failure of the County to require compliance by the Provider with any provisions of this Agreement or the waiver by the County of any breach of this Agreement shall not constitute a waiver of any claim for damages by the County for any breach of this Agreement or a waiver of any other required compliance with this Agreement. e. Suspension. County may suspend the Basic Services and this Agreement at any time for County’s convenience and without penalty to County upon three (3) days’ notice to Provider. Upon any suspension by County, Provider shall discontinue work on the Basic Services and shall not resume the Basic Services until notified to proceed by County. 11. Additional Provisions a. Limitation and Assignment. The County and the Provider each bind themselves, their successors, assigns and legal representatives to the terms of this Agreement. Neither the County nor the Provider shall assign or transfer its interest in this Agreement without the written consent of the other. b. Governing Law. This Agreement and the duties, responsibilities, obligations and rights of respective parties hereunder shall be governed by the laws of the State of North Carolina. By executing this Agreement Provider affirms that Provider and any subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.81. c. Non-Discrimination. Provider shall at all times remain in compliance with all applicable local, state, and federal laws, rules, and regulations including but not limited to all state and federal non-discrimination laws, policies, rules, and regulations and the Orange County Non-Discrimination Policy and Orange County Living Wage Policy (each Orange County policy is incorporated herein by reference and may be viewed at DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Revised 01/24 6 http://www.orangecountync.gov/departments/purchasing_division/contracts.php.) Any violation of the Orange County Non-Discrimination Policy is a breach of this Agreement and County may immediately terminate this Agreement without further obligation on the part of the County. This paragraph is not intended to limit and does not limit the definition of breach to discrimination. d. Dispute Resolution. Any and all suits or actions to enforce, interpret or seek damages with respect to any provision of, or the performance or non-performance of, this Agreement shall be brought in the General Court of Justice of North Carolina sitting in Orange County, North Carolina. It is agreed by the parties that no other court shall have jurisdiction or venue with respect to such suits or actions. Binding arbitration may not be initiated by either Party, however, the Parties may agree to nonbinding mediation of any dispute prior to the bringing of such suit or action. e. Entire Agreement. This Agreement represents the entire and integrated agreement between the County and the Provider and supersedes all prior negotiations, representations or agreements, either written or oral. This Agreement may be amended only by written instrument signed by both parties. Modifications may be evidenced by facsimile signatures. f. Severability. If any provision of this Agreement is held as a matter of law to be unenforceable, the remainder of this Agreement shall be valid and binding upon the Parties. g. Ownership of Work Product. Should Provider’s performance of this Agreement generate documents, items or things that are specific to this Project such documents, items or things shall become the property of the County and may be used on any other project without additional compensation to the Provider. The use of the documents, items or things by the County or by any person or entity for any purpose other than the Project as set forth in this Agreement shall be at the full risk of the County. h. Non-Appropriation. Provider acknowledges that County is a governmental entity, and the validity of this Agreement is based upon the availability of public funding under the authority of its statutory mandate. In the event that public funds are unavailable or not appropriated for the performance of County’s obligations under this Agreement, then this Agreement shall automatically expire without penalty to County immediately upon written notice to Provider of the unavailability or non-appropriation of public funds. It is expressly agreed that County shall not activate this non-appropriation provision for its convenience or to circumvent the requirements of this Agreement. In the event of a change in the County’s statutory authority, mandate or mandated functions, by state or federal legislative or regulatory action, which adversely affects County’s authority to continue its obligations under this Agreement, then this Agreement shall automatically terminate without penalty to County upon written notice to Provider of such limitation or change in County’s legal authority. i. Signatures. This Agreement together with any amendments or modifications may be DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Revised 01/24 7 executed electronically. All electronic signatures affixed hereto evidence the consent of the Parties to utilize electronic signatures and the intent of the Parties to comply with Article 11A and Article 40 of North Carolina General Statute Chapter 66. j. Notices. Any notice required by this Agreement shall be in writing and delivered by certified or registered mail, return receipt requested to the following: Orange County Provider’s Name Attention:Robert Reynolds Trustedsec, LLC P.O. Box 8181 2485 Southwestern Blvd Hillsborough, NC 27278 Fairlawn, OH 44333 [SIGNATURE PAGE TO FOLLOW] DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Revised 01/24 8 IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have hereunder set their hands and seal, all as of the day and year first above written. ORANGE COUNTY: PROVIDER: By: _________________________________ Bonnie Hammersley, County Manager By: __________________________________ Chris Boesch, VP Sales and Marketing Printed Name and Title DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 5/30/20245/31/2024 Revised 01/24 9 ORANGE COUNTY—INTERNAL USE ONLY ______________________________________________________________________________ Finance Information Vendor Name: Trustedsec, LLC Vendor Contact Person: Chris Boesch Phone: 877-550-4728 x7032 Address: 3485 Southwestern Blvd City Fairlawn State: OH Zip: 44333 Department: IT Amount: $21,500.00 Purpose: Penetration testing and cybersecurity consulting Budget Code(s): 10315020-630000 Vendor # 68491 Vendor Status with NCSOS: Current - Active Vendor is a BOCC consultant: Yes No Contract Details Contract Type: New Amendment (Original Contract: ) (Most Recent Amendment ) Effective Date 30 May 2024 End Date 30 May 2025 Notice Date (Notice Purpose ) Award Approved by Board (Agenda Date: ); Made or Administered by Signature Authority - BOCC Express Delegation (Agenda Date: ) - Policy 9.4: Under $5,000; Service Under $90,000; Construction Under $250,000 - Budget Policy Section XV (Capital Improvement Project: ) Bidding Informal Bidding ($30k-$90k); Formal RFP ($90k+); Other (<$30k); Exception(# ) Department Affirmation This agreement is approved as to technical form and content and I as Department Director affirmatively state work on this project has not been initiated prio r to execution of the agreement. This agreement is approved as to technical form and content. Services related to this agreement have alread y begun or been completed. Description of the nature of the emergency condition that was addressed: Department Director’s Signature ________________________________________ Date: ________ Information Technologies This agreement has been reviewed and is approved as to information technology content and specifications: Office of the Chief Information Officer___________________________________ Date: ________ Inapplicable because no hardware/software purchases or related services Risk Management This agreement is approved for sufficiency of insurance standards, specifications, and requirements: Office of the Risk Management Officer___________________________________ Date: _________ Financial Services This instrument has been pre-audited in the manner required by the Local Government Budget and Fiscal Control Act: Office of the Chief Financial Officer ____________________________________ Date: _________ Legal Services This agreement is approved as to legal form and sufficiency: Office of the County Attorney __________________________________________Date: ________ Clerk to the Board All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov The following signature block is for hard copies only and is not required for Docusign contracts: Received for record retention: Office of the Clerk to the Board __________________________________________Date:________ DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 5/30/2024 5/30/2024 5/31/2024 5/31/2024 5/31/2024 Version 1.0 | May 23, 2024 2024 Penetration Testing Proposal Prepared for: Orange County North Carolina 300 West Tryon Street, PO Box 8181 Hillsborough, NC 27278 Attachment ADocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC May 23, 2024 Prepared for: Orange County North Carolina 300 West Tryon Street, PO Box 8181 Hillsborough Contained within this Statement of Work (SOW) are the methodologies around penetration testing services. TrustedSec will perform an in-depth analysis of the external and internal presence at Orange County North Carolina. The penetration testing assessment will simulate an attacker attempting to identify and exploit weaknesses in Orange County North Carolina systems from multiple avenues. TrustedSec will begin the assessment by simulating novice attackers and gradually increase the skill and sophistication used in the attacks throughout the lifecycle of the engagement. If an exposure is identified, TrustedSec will attempt to penetrate the network and gain unauthorized access to Orange County North Carolina’s infrastructure. TrustedSec leverages the Penetration Testing Execution Standard (PTES) (http://www.pentest- standard.org) for all Penetration Testing assessment methodologies. TrustedSec’s Founder and Chief Hacking Officer co-founded PTES, which is used as a standard for Penetration Testing within the security industry. We appreciate the opportunity to present this proposal to Orange County North Carolina and look forward to a long-lasting partnership. If there are any questions, please feel free to contact us at any time. Jake Glomb| Account Manager 3485 Southwestern Boulevard Fairlawn, OH 44333 Office: 877.550.4728 x7057 Mobile: 330.416.6659 Email: jake.glomb@TrustedSec.com DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 4 Document Disclaimer Statement This disclaimer governs the use of this document. Client shall own all rights, title, and interest in any written summaries, reports, analyses, findings, or other information or documentation prepared for Client in connection with TrustedSec, LLC, its agents, officers, directors, employees, affiliates, and assigns (collectively 'TrustedSec') consulting services to Client. TrustedSec disclaims any and all liability for any damages (whether foreseen or unforeseen, direct, indirect, consequential, incidental, special, exemplary, or punitive) arising from or related to the reliance by anyone on this document or any contents thereof. Copyrights and Trademarks © 2024 TrustedSec, LLC. All rights reserved. No claim is made to the exclusive right to use any trademarks or trade names found in this document. TrustedSec disclaims responsibility for errors or omissions in typography or photography. TrustedSec Confidential This document has been classified as TrustedSec Confidential. This is an internal TrustedSec designation with the highest classification ranking for Client data. Stringent protection of this document is required by TrustedSec's information classification policy and security controls. Additionally, the information contained in this document is strictly prohibited from any type of release except to the Client. Notice Under 18 USC 1030 & Notice Regarding Criminal Charges Client agrees to inform all appropriate parties and authorities including any and all third parties who may be affected as required to conduct services as outlined in this SOW, including but not limited to PTES, and agrees not to file a complaint with legal or public authorities for the penetration testing. Furthermore, Client agrees to come to the aid of TrustedSec if the local police, sheriff, FBI, FTC, or other governmental agency should detain or question them in any manner during the course of services provided under this SOW. The Client agrees to defend and hold TrustedSec harmless from any civil or criminal liability or damage arising from the performance of services under this SOW, including, but not limited to, claims for violations of property trespass, breaking and entering, privacy laws, and criminal computer laws including, but not limited to, 18 USC 1030 and any federal, state, or local laws. Furthermore, Client shall indemnify and hold TrustedSec harmless for any and all claims, damages, expenses, and liabilities to any third party which may arise as a result of such services being performed under this SOW. Legacy Data It is understood by Client that there is an element of risk associated with the provision of the Services relating to technical testing. This risk includes the potential that certain electronic and nonoperational data or code may remain on Client’s system after the provision of Services by Consultant or its subcontractors (“Legacy Data”) and that Client or its agents may mistakenly perceive such Legacy Data to be malicious in nature and take corrective actions based on such mistaken belief. Although Consultant and its subcontractors will put forth commercially reasonable efforts to remove Legacy Data from Client’s system after the provision of Services, it is understood and agreed by Client that there is no guarantee that there will be no Legacy Data left remaining on Client’s system after the provision of Services, nor that Consultant or its subcontractors will remove all Legacy Data from Client’s systems after the provision of Services. CONSULTANT DOES NOT ASSUME ANY RESPONSIBILITY OR LIABILITY FOR ANY ACT OR OMISSION BY CLIENT OR ITS AGENTS ARISING FROM OR RELATING TO THE DISCOVERY OF ANY LEGACY DATA, REGARDLESS OF WHETHER SUCH LEGACY DATA WAS LEFT INTENTIONALLY, BY DESIGN, BY ERROR OR OTHERWISE. NOTWITHSTANDING ANYTHING HEREIN TO THE CONTRARY, CONSULTANT EXPRESSLY DISCLAIMS ALL WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED. IN PARTICULAR, CONSULTANT MAKES NO WARRANTY THAT CLIENT’S SYSTEM WILL BE FREE OF LEGACY DATA AFTER THE PROVISION OF SERVICES. IN NO EVENT SHALL CONSULTANT BE LIABLE TO CLIENT OR TO ANY THIRD PARTY FOR DAMAGES RESULTING FROM DISCOVERY OF LEGACY DATA AND ACTS OR OMISSIONS BASED THEREUPON. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 5 Table of Contents 1 ENGAGEMENT PROCESS ................................................................................................... 6 ENGAGEMENT COORDINATION ............................................................................................ 6 TRUSTEDSEC FILE SHARING ................................................................................................. 6 TECHNICAL ASSESSMENTS ................................................................................................... 7 1.3.1 PENETRATION TESTING EXECUTION STANDARD (PTES) PHASES ................................................... 7 1.3.2 REPORT TIMING ......................................................................................................................... 9 1.3.3 VULNERABILITY SCANNERS ......................................................................................................... 9 1.3.4 REMOTE RETEST & ATTESTATION REPORTING ............................................................................ 10 1.3.5 REMOTE PENETRATION TESTING ............................................................................................... 10 2 PENETRATION TESTING .................................................................................................. 11 EXTERNAL PENETRATION TESTING ..................................................................................... 11 INTERNAL PENETRATION TESTING ...................................................................................... 11 3 STATEMENT OF WORK .................................................................................................... 12 ENGAGEMENT SCOPE ........................................................................................................ 12 3.1.1 TECHNICAL DELIVERABLES ........................................................................................................ 14 4 ENGAGEMENT PRICING .................................................................................................. 16 PAYMENT SCHEDULE ......................................................................................................... 16 TRAVEL & EXPENSES ......................................................................................................... 16 CHANGE IN SCOPE OF SERVICES ......................................................................................... 17 AUTHORIZATION .............................................................................................................. 17 5 WORLD-CLASS TALENT AND ADVANCED RESEARCH ................................................... 18 DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 6 1 Engagement Process Engagement Coordination TrustedSec believes strong, open, and continual communication is vital to the success of all engagements. Engagement Coordinators work with clients to best align the consulting team's expertise with the engagement’s scope and timeline. Every engagement begins with a series of dialogues to identify the goals and objectives of the assessment to ensure that all expectations are exceeded. As part of the engagement team, a consulting lead will be established as the primary point of contact for executing the assessment. It is their responsibility to ensure timely communication during the engagement while monitoring established milestones. Assigned personnel will be accessible, working closely to guarantee a collaborative and open communication strategy. Upon request, TrustedSec can also deliver assessment updates and the overall status. TrustedSec consultants will be readily available and can be reached by phone, email, or in-person if on-site. This availability also extends beyond the engagement should questions of points of clarification arise. Should a critical or high-severity deficiency be identified, it will be communicated immediately along with remediation details. Open communication is vital during any engagement type, and TrustedSec will ensure that Orange County North Carolina can quickly reach the appropriate points of contact. TrustedSec File Sharing When working with TrustedSec, Orange County North Carolina points of contact (PoCs) will be enrolled in the TrustedSec Hub (TSHUB) Client Portal hosted on-site in the TrustedSec datacenter. This portal is used to enable file transfers, share engagement documentation, and provide an easy way to facilitate communication securely. TSHUB uses military-grade encryption for all client containers, with all client files stored in an encrypted format on disk and at rest in their own individual encrypted container. The site itself supports multi-factor authentication and ensures the highest level of security requirements for our clients. For clients who are unable to use the TrustedSec file-sharing system, TrustedSec can use Orange County North Carolina’s file-sharing service, PGP-encrypted emails, or encrypted (AES256) zip files. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 7 Technical Assessments 1.3.1 Penetration Testing Execution Standard (PTES) Phases TrustedSec uses the Penetration Testing Execution Standard (PTES), a standard that has gained wide adoption within the security community, as a methodical way to approach Penetration Testing. PTES defines a penetration test as the ability to attack an organization as an adversary, with a goal of affecting a company’s potential to generate revenue. Additionally, TrustedSec also utilizes the NIST SP800-115, Technical Guide to Information Security Testing and Assessment, as a framework for security testing. Pre-Engagement Interaction The pre-engagement interaction phase will focus heavily on understanding Orange County North Carolina's purpose for the penetration test and expected outcomes during the assessment. This is a foundational meeting for establishing the criteria, expectations, and delivery times for the assessment. As part of this assessment, formal points of contact and escalation points will be determined. Intelligence Gathering During this phase, TrustedSec will perform reconnaissance of Orange County North Carolina and identify any Open Source Intelligence (OSINT) that may be applicable for attacking the organization. This information will help in identifying the most impactful point of entry into the organization or infrastructure. Intelligence Gathering relies heavily upon understanding the organization and how it performs business on a broad scale. As an attacker, using this information is highly beneficial for profiling how the attack will occur. Threat Modeling Using the information obtained from the Intelligence Gathering phase, TrustedSec will begin to profile Orange County North Carolina and identify the best route of entry. Threat Modeling uses a solid understanding of a client’s environment to profile the best way into the organization. Simple probing will be used during this phase to identify protection mechanisms, versions, and other non-obtrusive aspects to understand how the infrastructure is designed. Vulnerability Analysis The vulnerability analysis phase focuses heavily on taking the information from the Threat Modeling phase and determining the best route into the organization. During a penetration test, TrustedSec acts as the attacker and finding the easiest route into the organization is the top priority. Understanding how the business functions and what systems are in place in those areas is highly important to the assessment. During this phase, the best attack vectors are selected. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 8 Exploitation The Exploitation phase is a precision-strike against a target where there is a high confidence level that the attack will be successful. This phase highlights the ability to circumvent the controls in place, and to gain access to unauthorized systems, facilities, or information. Under no circumstances will TrustedSec perform denial-of-service (DoS) activities. Regarding exploitation that has the potential to cause loss of availability, TrustedSec will communicate these activities prior to running any system-limiting attacks. As necessary, an agreement can be negotiated to run off-hours, or perform a manual validation of the exposure. TrustedSec conducts all exploitation activities with a high degree of caution prior to executing these forms of attack. Post-Exploitation In this phase, TrustedSec will locate key systems, sensitive data, and additional exposures to showcase maximum impact to the organization. The goal of this phase is to identify critical or confidential information, with the likelihood of further exploitation and potential exposure of that information during an attack. Often, one single exposure, or a series of vulnerabilities chained together, allow for TrustedSec to breach the perimeter defenses (or internal systems) and further compromise systems, based on the information obtained from the compromise. All of this is accomplished while avoiding detection and evading common preventative technologies (such as end point protections, application whitelisting, next generation firewalls, etc.). During the Post-Exploitation phase, TrustedSec will attempt to identify intellectual property, personally identifiable information (PII), and regulated data. Sensitive systems will be targeted, as well as users with elevated privileges, in order to gain a higher degree of control within the network environment. Reporting The Reporting phase is by far the most important aspect of any testing activities. The ability to effectively communicate how the attacks were successful, and most importantly, how to mitigate them moving forward, is paramount. TrustedSec spends a great deal of time and effort on this phase of the engagement. Each report is unique to the client and focuses heavily on understanding the exposure, ways to reproduce the vulnerability, and the recommended mitigation steps. TrustedSec organizes vulnerabilities into two categories: strategic and technical. Technical Findings are simply the exposure (the exploit, vulnerability, etc.) and the suggested remediation steps. Strategic Recommendations are systemic exposures identified during the assessment that may indicate security program deficiencies. If solely Technical Findings DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 9 were focused on without resolving the Strategic Recommendations, the deficiencies would likely reappear gradually over time. As an attacker, TrustedSec can determine systemic weaknesses within the overall security program. For example, if as part of the penetration test, third-party solutions are fully compromised, it would indicate an issue around the client’s third-party risk management program and the depth of review that is conducted when using a third-party. A second example could be that TrustedSec identifies instances of SQL Injection and other critical application flaws. This would indicate that the software development lifecycle may not have security fully injected and in-depth reviews are not fully functioning within the organization. Specific remediation steps around each strategic finding will be developed to help accelerate a program where it may be deficient or non-existent. Technical Findings that provide immediate exposure are important to fix, as they provide direct exposure. Without remediating the strategic findings, new exposures will surface down the road, and there will be a continuous battle of remediation and identification of critical threats to the organization. The report consists of several sections. First, the Executive Summary, which contains a high-level analysis of what was performed and a general review of the discovered findings. From there, a Penetration Testing walkthrough is designed using diagrams and step-by- step details on how the penetration test occurred. Moving further into the report are Strategic Recommendations and Technical Findings, which are broken down based on severity. Lastly, any supporting information such as screenshots, reproduction of exposure information, and appendices are included. 1.3.2 Report Timing Unless otherwise defined under this Statement of Work (SOW), within two (2) weeks of conclusion of the work described above, TrustedSec will issue a formal draft report to the primary PoC. TrustedSec shall make every reasonable effort to promptly correct any inconsistencies identified by Orange County North Carolina and shall resubmit the deliverable for Orange County North Carolina’s review. If there are no comments within the two-week comment period, TrustedSec will consider the report final. 1.3.3 Vulnerability Scanners After the Post-Exploitation phase of the engagement, TrustedSec will explore other avenues for attack in the time remaining. At the very end of the assessment, TrustedSec will conduct a vulnerability scan during the timeframe of the assessment and explore any other alternatives that were not investigated. Vulnerability scanners are good for basic detection of “low-hanging fruit,” however, TrustedSec has found that they only catch a small percentage of actual vulnerabilities. TrustedSec uses industry scanning technology tools to ensure maximum detection of exposures during assessments. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 10 1.3.4 Remote Retest & Attestation Reporting Once testing is complete, Orange County North Carolina can remediate identified issues. Once the identified findings have been remediated, Orange County North Carolina can request a scheduled retest of critical and high-risk findings for external penetration and web application testing to confirm successful remediation. This covers one (1) retest of only the externally facing critical and high-risk findings. All testing will be done remotely against the hosts defined in-scope. Internal or on-site remediation testing is considered out of scope, unless additional testing is provisioned in the SOW. TrustedSec will issue an in-depth letter that attests to the scope of testing, and that Orange County North Carolina has performed due diligence, from an Information Security standpoint, by engaging an experienced, trusted, and independent third-party to evaluate the security of the network environment. All testing will be done remotely against externally facing hosts, as defined above. If on-site retesting is to occur, a new SOW must be prepared. All retest work will be completed within sixty (60) days of the issuance of the initial draft report. 1.3.5 Remote Penetration Testing The TrustedSec Attack Platform (TAP) device is a custom solution developed at TrustedSec to perform remote Penetration Testing for clients. TrustedSec has the ability to quickly deploy these remote devices, which can be connected at any point of the network, establishing a secure tunnel back to the TrustedSec headquarters. This device allows TrustedSec to perform internal penetration tests without requiring consultants to be on- site. This helps to not only reduce travel expenses, but decreases the burden on consultant travel, and allows additional consultants to join and collaborate on the assessment. This system was developed internally by TrustedSec and has been improved extensively over the years. The device is preconfigured with all the tools that consultants are accustomed to using during an assessment. This option is highly recommended for remote locations, travel cost reductions, long-term contracts, and more. The TAP device can perform internal Penetration Testing services, incident response, and wireless assessments. Note: The TAP device must be returned to TrustedSec within four (4) weeks of report delivery. Failure to do so will result in a fee of $1,500. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 11 2 Penetration Testing Penetration Testing evaluates the effectiveness of the Information Security programs clients have in place and identifies security deficiencies that could put the organization and its information assets at risk. Penetration Testing is a sanctioned service in which TrustedSec simulates an attacker attempting to circumvent security controls and gain unauthorized access to client systems or facilities. Whether from malicious users, malware, insider threats, or a regulatory compliance perspective, it showcases the potential to impact the business’ ability to generate revenue. TrustedSec's comprehensive methodologies span multiple technologies and security control areas, from physical security, to personnel and procedural security controls, to system and application-level exploitation. Penetration Testing is designed to impact the organization to identify systemic weaknesses within the overall Information Security program. They are great leverage points for the security group to get management exposure and emphasize the importance of critical security programs. External Penetration Testing External Penetration Tests are conducted from outside the target organization and are meant to test the perimeter defenses by simulating an attacker attempting to gain access from the Internet. This test often begins with Open Source Intelligence (OSINT) gathering to enumerate information about the company and potential systems for attack. Open services are identified and analyzed for vulnerabilities that could be exploited and are provided a means for further access into the network. A low-and-slow methodology is utilized to remain as undetectable as possible to monitoring and detection systems. As the testing progresses, the amount of noise generated is gradually increased to determine the detection threshold, if any. A vulnerability scan is performed in the latter stages of this process to serve as a secondary check for the manual testing efforts. Internal Penetration Testing An Internal Penetration Test simulates an attacker or malicious insider that has already gained access to the internal network environment. Consultants connect to a designated network jack, or remotely via the TAP device, situated within the user population. Reconnaissance is performed within the direct network segment, determining adjacent hosts to attack. Attempts are made to compromise vulnerable systems, escalate privileges, and compromise the domain. Sensitive information will be located that may expose personally identifiable information (PII), Payment Card Industry (PCI) data, or company trade secrets that could impact the organization's ability to conduct business. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 12 3 Statement of Work This STATEMENT OF WORK (“SOW”), effective as of May 23, 2024 is made pursuant to an agreement by and between TrustedSec, LLC with its principal place of business located at 3485 Southwestern Boulevard Fairlawn, OH 44333, and Orange County North Carolina, with its principal place of business located at 300 West Tryon Street, PO Box 8181 Hillsborough. Engagement Scope This section contains the overall scope for the engagement, as discussed with Orange County North Carolina. Based on TrustedSec’s understanding of the environment, we have scoped the time and cost of the proposed services with the assumptions below. If it is determined that there is a vast difference in the actual environment (either smaller or larger), TrustedSec requests the right to adjust the actual effort required and costs associated with the assessment. Any cost estimate or timeline changes needed will be promptly shared with Orange County North Carolina, and a Change Order will be drawn as appropriate to satisfy the changes. This is uncommon; however, it can happen based on additional discoveries or further evaluation from TrustedSec. Geographic Locations • TrustedSec Headquarters, Fairlawn, OH, US • Work will be performed remotely External Penetration Test • Up to one (1) week of testing and reporting • A one-time retest is included but limited to critical and high-severity findings and must be done within 60 days of the completion of the engagement Internal Penetration Test • Up to 500 internal IP addresses/hosts/systems/devices total • Internal retesting requests will be subject to a change order and an additional fee Out of Scope: • Any location or work that is not specifically listed as in-scope shall be considered out of scope Dependencies and Assumptions The following terms are set forth to determine the roles and responsibilities that both parties DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 13 are to maintain. This is done to eliminate confusion and prevent delays in on-site data gathering. Failure to maintain these terms may result in extended data collection, additional labor fees, and related travel expenses to cover the extra time spent. • Scoped pricing is based upon the information provided by Orange County North Carolina via initial discovery documents/conversations with TrustedSec prior to the start of the engagement. Additional applications, divisions, domains, or systems found during the discovery phase of the engagement that are not stated in the scope of work will incur additional fees, and may result in the need for an agreed upon Change Request. • The work is to be performed consecutively until engagement completion. There will be no break in services other than weekends and/or recognized holidays. • TrustedSec assumes that all client data gathering activities will be executed efficiently, and data will be promptly submitted to consultants. • If TrustedSec is unable to begin testing as scheduled, any resultant inactive consultant time will be deducted from the total active testing window. • Client will designate one (1) employee to serve as a primary point-of-contact (PoC) for the TrustedSec engagement team. The client-designated PoC will be responsible for and have the authority to schedule client resources for required meetings, interviews, and other needs to complete the work within the specified engagement parameters. • Where applicable, Client is responsible for notifying impacted third parties of the testing as needed, and said testing is conducted with the expressed authority of Client Officers or Directors (See Notice in Document Disclaimer Statement). • No TrustedSec employee is expected to work more than ten (10) consecutive hours. • Client will provide access to all proprietary information, applications, and systems necessary to the success of this engagement. • Any special conditions not stipulated at the time of this quotation, such as late evening/early morning hour requirements, may result in additional fees. • TrustedSec will not perform any additional work outside of the scope of work described in this proposal without the expressed permission of authorized personnel of Orange County North Carolina, including a signed Change Order. • Assessments (excluding Incident Response) will be performed during normal business hours 8:00 AM - 5:00 PM. Should assessments be performed during off-hours, an additional cost will be sent through a change order. Rescheduling Fee Aligning resources to provide the most value to our clients is a constant challenge. TrustedSec will always make every effort to meet any needs of Orange County North Carolina. However, if there are any changes to the schedule required by Orange County DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 14 North Carolina once a start date for the services being provided under this SOW has been agreed upon, a rescheduling fee may be charged as per the following schedule: • Greater than 15 business days: No rescheduling fee will be charged. • Less than 15 business days but greater than five (5) business days: A 25% rescheduling may be charged. • Less than five (5) business days: A 50% rescheduling fee may be charged, in addition to any fees incurred (such as airline tickets, etc.) if applicable. 3.1.1 Technical Deliverables TrustedSec generates one (1) technical report which includes an executive summary for each SOW. One report section per fee page line item is typically included. Sanitized sample reports are available for review upon request. In certain circumstances, more than one (1) technical report may be generated for an engagement; For example, if an application assessment is being performed alongside an External or Internal Penetration Test, a separate report will be generated for the application assessment(s). Executive Summary • An Executive Summary will be produced at the conclusion of the assessment, summarizing the objectives of the engagement, work performed, findings, and remediation strategy. The Executive Summary is, by default, a part of the technical report unless otherwise indicated during the scoping process. Technical Report • A document will detail the Technical Findings and Strategic Recommendations regarding any identified weaknesses in the environment. The document will also articulate the work performed, list the steps to reproduce each issue and provide Severity Ratings for each vulnerability. The initial report will be targeted for delivery as a PDF within 10 business days of the conclusion of the overall engagement effort. Attestation Letter (Upon Request) • If requested, a Orange County North Carolina-facing document summarizing the effort and methodology that was executed and provides assurance that Orange County North Carolina actively performs their due diligence with regard to third-party validation of Information Security controls (relative to those phases included in the given assessment engagement). Presentation of Findings (Upon Request) • If requested, the TrustedSec findings presentation will be delivered remotely via web conference to the audience chosen by Orange County North Carolina. Traditionally focused on an executive-level out-brief, this presentation describes the effort DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 15 executed, provides an overview of the results, and describes the next steps outlined for the organization. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 16 4 Engagement Pricing The fixed fees for the Services to be performed by TrustedSec under this SOW are in US dollars and are detailed in the table below. Acceptance of this SOW authorizes TrustedSec to perform a security assessment and other related services for Orange County North Carolina. Proposal is valid for 30 calendar days. Service Description SKU Cost External Penetration Test Through discovery, analysis, and controlled exploitation, this assessment tests the organization’s Internet-facing perimeter with no privileged information about the environment. TS-50100 $14,000 Internal Penetration Test Designed to emulate real world attack scenarios, internal assessments target an organization from within its physical perimeter. TS-50200 $7,500 Total Engagement Cost $21,500 Payment Schedule Payment is based on the following schedule: • 100% of total cost billable at first report delivery. Payment terms Net 30. • A 5% late fee will be added for payments that exceed payment terms. • Report delivery is subject to the terms and conditions set forth within this statement of work. • Acceptable forms of payment are check, ACH, wire transfer, or credit card (QuickBooks email link under $15,000). Travel & Expenses TrustedSec fees outlined in the scope of services do not include out-of-pocket expenses, such as transportation, meals, and lodging for travel to perform any of the services. TrustedSec will make every attempt to incur reasonable expenses associated with the execution of the engagement and will handle the processing of those approved expenses in accordance with the Travel Policy terms from the Master Services Agreement. Valid expenses typically include parking, meals, lodging, and communication costs. Travel costs include airfare, mileage (if a personal car is used), and automobile rental. If international travel is required, additional expenses may be incurred, including business class ticketing DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 17 on flights. TrustedSec consultants use business class when the combined flight connection exceeds 3,400 miles in a single direction. Change in Scope of Services If unforeseen factors change this scope of work and/or impact the term and cost of provided services, Orange County North Carolina and TrustedSec may mutually revise the SOW. TrustedSec shall provide Orange County North Carolina with an estimate of the impact of such revisions on the fees, payment terms, completion schedule, and other applicable provisions of the SOW. If the parties mutually agree to such changes, a written description of the agreed change (Change Order) shall be prepared, incorporating such changes to the SOW and shall be signed by both parties. The terms of a Change Order Form prevail over those of the SOW. Authorization By the signatures of their duly authorized representatives below, Orange County North Carolina and TrustedSec, intending to be legally bound, agree to all the provisions of this Statement of Work as of the Effective Date set forth below. Printed Name for Orange County North Carolina Printed Name for TrustedSec, LLC Title (Must be Officer or Director) Title Orange County North Carolina Signature TrustedSec, LLC Signature Date Date DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC Orange County North Carolina TrustedSec Confidential 18 5 World-Class Talent and Advanced Research Hackers constantly innovate to evade detections. One tool in TrustedSec's arsenal to match this is the TrustedSec Research Unit (TRU). TrustedSec employs a dedicated team of non- billable resources that are constantly researching and developing tactics, techniques, and procedures (TTPs) that enable operators to be successful during simulations of advanced threats. TRU is a team made up of highly skilled developers and operators who have deep understanding of modern defenses and attack techniques. TrustedSec built out the research team after seeing a security industry shift toward needing more advanced tooling for rapidly maturing clients. Traditionally, companies built TTP’s during consultant bench time or as side projects. The dedicated team cultivates a formal development process and ensures that resources are available to support operators during an engagement at a moment’s notice. The team is also available during engagements to build new capabilities and techniques in the TrustedSec lab. It is common for the team to step in and help develop a privilege escalation exploit or build a workaround for a security product that typically only advance nation-states or hacking groups would know. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 10/01/2022 CJISD-ITS-DOC-08140-5.9.1 H-6 FEDERAL BUREAU OF INVESTIGATION CRIMINAL JUSTICE INFORMATION SERVICES SECURITY ADDENDUM The goal of this document is to augment the CJIS Security Policy to ensure adequate security is provided for criminal justice systems while (1) under the control or management of a private entity or (2) connectivity to FBI CJIS Systems has been provided to a private entity (contractor). Adequate security is defined in Office of Management and Budget Circular A- 130 as “security commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.” The intent of this Security Addendum is to require that the Contractor maintain a security program consistent with federal and state laws, regulations, and standards (including the CJIS Security Policy in effect when the contract is executed), as well as with policies and standards established by the Criminal Justice Information Services (CJIS) Advisory Policy Board (APB). This Security Addendum identifies the duties and responsibilities with respect to the installation and maintenance of adequate internal controls within the contractual relationship so that the security and integrity of the FBI's information resources are not compromised. The security program shall include consideration of personnel security, site security, system security, and data security, and technical security. The provisions of this Security Addendum apply to all personnel, systems, networks and support facilities supporting and/or acting on behalf of the government agency. 1.00 Definitions 1.01 Contracting Government Agency (CGA) - the government agency, whether a Criminal Justice Agency or a Noncriminal Justice Agency, which enters into an agreement with a private contractor subject to this Security Addendum. 1.02 Contractor - a private business, organization or individual which has entered into an agreement for the administration of criminal justice with a Criminal Justice Agency or a Noncriminal Justice Agency. 2.00 Responsibilities of the Contracting Government Agency. 2.01 The CGA will ensure that each Contractor employee receives a copy of the Security Addendum and the CJIS Security Policy and executes an acknowledgment of such receipt and the contents of the Security Addendum. The signed acknowledgments shall remain in the possession of the CGA and available for audit purposes. The acknowledgement may be signed by hand or via digital signature (see glossary for definition of digital signature). 3.00 Responsibilities of the Contractor. 3.01 The Contractor will maintain a security program consistent with federal and state laws, regulations, and standards (including the CJIS Security Policy in effect when the contract is executed and all subsequent versions), as well as with policies and standards established by the Criminal Justice Information Services (CJIS) Advisory Policy Board (APB). 4.00 Security Violations. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 10/01/2022 CJISD-ITS-DOC-08140-5.9.1 H-7 4.01 The CGA must report security violations to the CJIS Systems Officer (CSO) and the Director, FBI, along with indications of actions taken by the CGA and Contractor. 4.02 Security violations can justify termination of the appended agreement. 4.03 Upon notification, the FBI reserves the right to: a. Investigate or decline to investigate any report of unauthorized use; b. Suspend or terminate access and services, including telecommunications links. The FBI will provide the CSO with timely written notice of the suspension. Access and services will be reinstated only after satisfactory assurances have been provided to the FBI by the CGA and Contractor. Upon termination, the Contractor's records containing CHRI must be deleted or returned to the CGA. 5.00 Audit 5.01 The FBI is authorized to perform a final audit of the Contractor's systems after termination of the Security Addendum. 6.00 Scope and Authority 6.01 This Security Addendum does not confer, grant, or authorize any rights, privileges, or obligations on any persons other than the Contractor, CGA, CJA (where applicable), CSA, and FBI. 6.02 The following documents are incorporated by reference and made part of this agreement: (1) the Security Addendum; (2) the NCIC 2000 Operating Manual; (3) the CJIS Security Policy; and (4) Title 28, Code of Federal Regulations, Part 20. The parties are also subject to applicable federal and state laws and regulations. 6.03 The terms set forth in this document do not constitute the sole understanding by and between the parties hereto; rather they augment the provisions of the CJIS Security Policy to provide a minimum basis for the security of the system and contained information and it is understood that there may be terms and conditions of the appended Agreement which impose more stringent requirements upon the Contractor. 6.04 This Security Addendum may only be modified by the FBI, and may not be modified by the parties to the appended Agreement without the consent of the FBI. 6.05 All notices and correspondence shall be forwarded by First Class mail to: Information Security Officer Criminal Justice Information Services Division, FBI 1000 Custer Hollow Road Clarksburg, West Virginia 26306 DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 10/01/2022 CJISD-ITS-DOC-08140-5.9.1 H-8 FEDERAL BUREAU OF INVESTIGATION CRIMINAL JUSTICE INFORMATION SERVICES SECURITY ADDENDUM CERTIFICATION I hereby certify that I am familiar with the contents of (1) the Security Addendum, including its legal authority and purpose; (2) the NCIC Operating Manual; (3) the CJIS Security Policy; and (4) Title 28, Code of Federal Regulations, Part 20, and agree to be bound by their provisions. I recognize that criminal history record information and related data, by its very nature, is sensitive and has potential for great harm if misused. I acknowledge that access to criminal history record information and related data is therefore limited to the purpose(s) for which a government agency has entered into the contract incorporating this Security Addendum. I understand that misuse of the system by, among other things: accessing it without authorization; accessing it by exceeding authorization; accessing it for an improper purpose; using, disseminating or re-disseminating information received as a result of this contract for a purpose other than that envisioned by the contract, may subject me to administrative and criminal penalties. I understand that accessing the system for an appropriate purpose and then using, disseminating or re-disseminating the information received for another purpose other than execution of the contract also constitutes misuse. I further understand that the occurrence of misuse does not depend upon whether or not I receive additional compensation for such authorized activity. Such exposure for misuse includes, but is not limited to, suspension or loss of employment and prosecution for state and federal crimes. _______________________________________ _______________ Printed Name/Signature of Contractor Employee Date ______________________________________ _______________ Printed Name/Signature of Contractor Representative Date ______________________________________ Organization and Title of Contractor Representative DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 5/30/2024 Vice President ANY PROPRIETOR/PARTNER/EXECUTIVEOFFICER/MEMBER EXCLUDED? INSR ADDL SUBRLTRINSDWVD PRODUCER CONTACTNAME: FAXPHONE(A/C, No):(A/C, No, Ext): E-MAILADDRESS: INSURER A : INSURED INSURER B : INSURER C : INSURER D : INSURER E : INSURER F : POLICY NUMBER POLICY EFF POLICY EXPTYPE OF INSURANCE LIMITS(MM/DD/YYYY)(MM/DD/YYYY) AUTOMOBILE LIABILITY UMBRELLA LIAB EXCESS LIAB WORKERS COMPENSATIONAND EMPLOYERS' LIABILITY DESCRIPTION OF OPERATIONS / LOCATIONS / VEHICLES (ACORD 101, Additional Remarks Schedule, may be attached if more space is required) AUTHORIZED REPRESENTATIVE EACH OCCURRENCE $ DAMAGE TO RENTEDCLAIMS-MADE OCCUR $PREMISES (Ea occurrence) MED EXP (Any one person)$ PERSONAL & ADV INJURY $ GEN'L AGGREGATE LIMIT APPLIES PER:GENERAL AGGREGATE $ PRO-POLICY LOC PRODUCTS - COMP/OP AGGJECT OTHER:$ COMBINED SINGLE LIMIT $(Ea accident) ANY AUTO BODILY INJURY (Per person)$ OWNED SCHEDULED BODILY INJURY (Per accident)$AUTOS ONLY AUTOS HIRED NON-OWNED PROPERTY DAMAGE $AUTOS ONLY AUTOS ONLY (Per accident) $ OCCUR EACH OCCURRENCE CLAIMS-MADE AGGREGATE $ DED RETENTION $ PER OTH-STATUTE ER E.L. EACH ACCIDENT E.L. DISEASE - EA EMPLOYEE $ If yes, describe under E.L. DISEASE - POLICY LIMITDESCRIPTION OF OPERATIONS below INSURER(S) AFFORDING COVERAGE NAIC # COMMERCIAL GENERAL LIABILITY Y / N N / A (Mandatory in NH) SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN ACCORDANCE WITH THE POLICY PROVISIONS. THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED. NOTWITHSTANDING ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES. LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER. THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S), AUTHORIZED REPRESENTATIVE OR PRODUCER, AND THE CERTIFICATE HOLDER. IMPORTANT: If the certificate holder is an ADDITIONAL INSURED, the policy(ies) must have ADDITIONAL INSURED provisions or be endorsed. If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy, certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s). COVERAGES CERTIFICATE NUMBER:REVISION NUMBER: CERTIFICATE HOLDER CANCELLATION © 1988-2015 ACORD CORPORATION. All rights reserved.ACORD 25 (2016/03) CERTIFICATE OF LIABILITY INSURANCE DATE (MM/DD/YYYY) $ $ $ $ $ The ACORD name and logo are registered marks of ACORD 5/29/2024 (330) 453-7721 (330) 453-4911 38288 TrustedSec LLC 3485 Southwestern Boulevard Fairlawn, OH 44333 A 1,000,000 X 45SBABB2368 7/1/2023 7/1/2024 1,000,000 10,000 1,000,000 2,000,000 2,000,000 1,000,000A 45SBABB2368 7/1/2023 7/1/2024 5,000,000A 45SBABB2368 7/1/2023 7/1/2024 5,000,000 10,000 A 45WECAY9LEW 6/1/2024 6/1/2025 1,000,000 1,000,000 1,000,000 Orange County, its officers, agents, and employees are Additional Insured with respect to General Liability where required by written contract. Orange County 300 West Tryon Street PO Box 8181 Hillsborough, NC 27278 TRUSTED-01 MROKO Schauer Group, Inc. 200 Market Ave. NSuite 100Canton, OH 44702 insure@schauergroup.com The Hartford Insurance Co. X X X X X X X X X DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 1 October 2013 BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (“Agreement”) is made effective the 29th day of May, 2024, by and between Orange County Government through its Orange County Health Department (“Covered Entity”), and Trustedsec, LLC, (“Business Associate”). Covered Entity and Business Associate may be referred herein individually as a “Party” or collectively as the “Parties”. This Agreement supersedes any previously executed Business Associate Agreement between the Parties. WITNESSETH: WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), Public Law 104-191, as modified by the Health Information Technology for Economic and Clinical Health Act (“HITECH”), Public Law 111-5, known as “the Administrative Simplification provisions,” direct the Department of Health and Human Services to develop standards to protect the security, confidentiality and integrity of health information; and WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and Human Services (“Secretary”) has issued regulations modifying the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as the same may be amended from time to time (the “HIPAA Security and Privacy Rule”); and WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangements, Business Associate may be considered a “Business Associate” of Covered Entity as defined in the HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is detailed below and hereinafter referred to as the “Service Agreement(s)”); and WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in fulfilling its responsibilities under such arrangement; THEREFORE, in consideration of the Parties’ continuing obligations under the Service Agreement, compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this Agreement in order to address the requirements of the HIPAA Security and Privacy Rule and to protect the interests of both Parties. I. DEFINITIONS (a) Service Agreement. Agreement(s) for services affected by this HIPAA Business Associate Agreement, which this Business Associate Agreement shall be attached to, and is (are) hereby incorporated by reference, and which shall be taken and considered as a part of this document the same as if fully set out herein: Trustedsec Services Agreement (b) Catch-all Provision. Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule, 45 CFR Parts 160 and 164, subparts A and E. In the event of an inconsistency between the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as amended, the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are different than those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy Rule, the provisions of this Agreement shall control. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 2 October 2013 (c) Electronic Protected Health Information. Protected Health Information that is transmitted by or maintained in Electronic Media (as defined in the HIPAA Security and Privacy Rule). (d) Protected Health Information. “Protected Health Information” shall have the same meaning as the term in 45 CFR § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity and includes without limitation “Electronic Protected Health Information.” Business Associate acknowledges and agrees that all Protected Health Information that is created or received by Covered Entity and disclosed or made available in any form, including paper record, oral communication, audio recording, and electronic display by Covered Entity or its operating units to Business Associate or is created or received by Business Associate on Covered Entity’s behalf shall be subject to this Agreement. (e) Required by Law. “Required by Law” shall have the same meaning as the term in 45 CFR § 164.103. II. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE (a) Use and Disclosure. Business Associate agrees to fully comply with the requirements under the HIPPA Security and Privacy Rule applicable to Business Associates and not to use or disclose Protected Health Information other than as permitted or required by this Agreement, the Service Agreement or as Required by Law. To the extent Business Associate carries out obligations of Covered Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable provisions of the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered Entity. Business Associate agrees to comply with Covered Entity’s policies regarding the minimum necessary use or disclosure of Protected Health Information. (b) Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of Protected Health Information other than as provided for by this Service Agreement(s), this Agreement or as Required by Law. This includes the implementation physical, technical and administrative safeguards to prevent use or disclosure of Protected Health Information other than as permitted in this Agreement or Required by Law and reasonably and appropriately protect the confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and Privacy Rule. The Business Associate shall maintain appropriate documentation of its compliance with the HIPPA Security and Privacy Rule, including, but not limited to, its policies, procedures, records of training and sanctions of members in its workforce. (c) Assurances. Business Associate agrees to provide Covered Entity with written assurances that any Protected Health Information placed on any type of mobile media, including, but by no means limited to, lap top computers, Ipads and mobile phones, is encrypted in accordance with guidance issued by the Secretary. (d) Agents and Subcontractors. Business Associate shall require any agents, including any subcontractors, to whom it provides Protected Health Information from Covered Entity that is created, received, maintained or transmitted on behalf of Business Associate to agree by written contract with Business Associate to the same (or greater) restrictions, conditions and requirements that apply to Business Associate with respect to such information, and to agree to i mplement reasonable and appropriate safeguards to protect any of such information that is Electronic Protected Health Information. In addition, Business Associate agrees to take reasonable steps to ensure that its employees’ actions or omissions do not cause Business Associate to breach the terms of this Agreement. (e) Mitigation of Breach. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Healt h Information DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 3 October 2013 by Business Associate in violation of the requirements of this Agreement, as well as to provide complete cooperation to Covered Entity should Covered Entity elect to review or investigate such noncompliance or Security Incident. Business Associate shall cooperate in Covered Entity’s breach analysis and/or risk assessment, if requested. Furthermore, Business Associate shall cooperate with Covered Entity in the event that Covered Entity determines that any third parties must be notified of a Breach, provided that Business Associate shall not provide any such notification except at the direction of Covered Entity. (f) Breach Reporting. Business Associate shall report in writing to Covered Entity’s Privacy Officer (see Exhibit A), any use or disclosure of Protected Health Information that is not in compliance with the terms of this Agreement, as well as any Security Incident and any actual or suspected Breach, of which it becomes aware, without unreasonable delay, and in no event later than forty-eight (48) hours of such discovery. For purposes of this Agreement, “Security Incident” means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Such notification shall contain the elements required by 45 C.F.R. § 164.410. (g) Compliance. To the extent applicable, Business Associate will comply with (i) Covered Entity’s Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an Individual’s permission to use or disclose his or her Protected Health Information; and (iii) any restrictions to the use or disclosure of Protected Health Information to which Covered Entity has agreed or is required to agree. (h) Government Access. Business Associate will make its internal practices, books and records available to the Secretary of the Department of Health and Human Services for purposes of determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply with any investigations and compliance reviews, permit access to information, and cooperate with any complaints, as Required by Law. Without unreasonable delay and, in any event, no more than 48 hours of receipt of the request or notification, Business Associate will notify Covered Entity in writing of any request by any governmental entity, or its designee, to review Business assessment of any kind. (i) Electronic Transactions. If Business Associate conducts any Standard Transactions for or on behalf of Covered Entity, Business Associate shall comply with the requirements under the Electronic Transaction Rule. (j) Audit. Business Associate shall permit Covered Entity, in its discretion, to conduct an audit of Business Associate’s compliance with this Agreement, HIPAA, and H ITECH. Such audit may consist of an onsite visit, a series of inquiries that require written responses, or both. Business Associate shall promptly and completely respond to Covered Entity’s requests for information in support of the audit, which shall not be conducted more than once annually except in cases of an actual or reasonably suspected Security Incident or reasonably suspected noncompliance with this Agreement, HIPAA or HITECH. Each Party shall bear its own costs associated with the audit. (k) Identity Theft. Business Associate shall implement Identity Theft Monitoring Policies and Procedures to protect any patient information that may be breached by the Business Associate to the extent applicable under the Federal Trade Commission’s Red Flag Rules. (l) HITECH Compliance. Business Associate shall: A. Not receive, directly or indirectly, any impermissible remuneration in exchange for Protected Health Information or Electronic Protected Health Information, except as permitted by HITECH § 13405(d) or the HIPPA Regulations; B. Comply with the marketing and other restrictions applicable to Business Associates contained in HITECH § 13406 and the HIPPA Regulations; DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 4 October 2013 C. To the extent required under HITECH § 13404, fully comply with the applicable requirements of 45 CFR 164.502(e)(2) for each use and disclosure of Protected Health Information; D. To the extent required under HITECH § 13401, fully comply with 45 CFR §§ 164.308, 164.310, 164.312, and 164.316; E. To the extent required under HITECH §§13401 and 13404, comply with the additional privacy and security requirements that apply to Covered Entities in the same manner and to the same extent as Covered Entity is required to do so; and F. To the extent required under the HIPPA Regulations, comply with the privacy and security requirements that apply to Business Associates. (m) State Privacy Laws. Business Associate shall understand and comply with state privacy laws to the extent that such privacy laws are not preempted by HIPPA or HITECH. III. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE (a) Use of Protected Health Information on Behalf of Covered Entity. Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform functions, activities or services for, or on behalf of, Covered Entity described in the Service Agreement, provided that such use or disclosure would not violate the HIPPA Security and Privacy Rule if it were made by Covered Entity or would not violate the Covered Entities minimum necessary policies. (b) Other Uses of Protected Health Information. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information within its workforce for the proper management and administration of Business Associate not to include Marketing or Commercial Use and to carry out the legal responsibilities of Business Associate; and (c) Third Party Confidentiality. Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that if Business Associate discloses any Protected Health Information to a third party for such purpose, the Business Associate shall enter into a written agreement with such third party requiring the following: A. Disclosure only as Required by Law; or B. Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality, integrity, and or availability of the Protected Health Information has been breached immediately upon becoming aware. (d) Business Associate may provide data aggregation services relating to the health care operations of Covered Entity pursuant to any agreements between the Parties evidencing their business relationship as permitted by 45 CFR § 164.504(e)(2)(i)(B). (e) Other Uses Strictly Limited. Nothing in this Agreement shall permit the Business Associate to share Protected Health Information with Business Associate’s affiliates or contractors except for the purposes of the Service Agreement(s) between the Covered Entity and Business Associate(s) identified in Section I (a) of this Agreement. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 5 October 2013 (f) Covered Entity Authorization for Additional Uses. Any use of Protected Health Information by Business Associate, its affiliate or Contractor, other than those purposes of this Agreement, shall require express written authorization by the Covered Entity, and a Business Associate Agreement or amendment as necessary. Activities which are prohibited include, but are not limited to, Marketing, as defined by 45 CFR § 164.503 or the sharing for Commercial Use or any purpose construed by Covered Entity as Marketing or Commercial Use, even if such sharing would be permitted by federal or state laws. (g) Business Associate may de-identify Protected Health Information only at the specific direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health Information except at the direction of Covered Entity and in compliance with the requirements of the HIPAA Security and Privacy Rule. IV. AVAILABILITY OF PHI (a) Access to Protected Health Information. Business Associate agrees, in the event the Business Associate maintains protected health information in a Designated Record Set, to make available, within ten (10) days of a request by Covered Entity in a time and manner designated by Cove red Entity, Protected Health Information in a Designated Record Set, to Covered Entity or as directed by Covered Entity, to an individual in order to meet the requirements of 45 CFR § 164.524 of the HIPAA Security and Privacy Rule. (b) Amendments to Protected Health Information. In the event that the Business Associate maintains Protected Health Information in a Designated Record Set, Business Associate agrees to make any amendment(s) to Protected Health Information in a designated record set that the Covered Entity directs or agrees to pursuant to the HIPAA Security and Privacy Rule at the request of Covered Entity of an individual, within ten (10) days of receipt of a request from Covered Entity and in the time and manner designated by Covered Entity. (c) Accounting of Disclosures. Business Associate agrees to maintain and make available the information required to provide an accounting of disclosures, as required by 45 CFR § 164.528 of the HIPAA Security and Privacy Rule. Business Associate will comply with Covered Entity’s policy regarding accounting of disclosures. (d) Document Disclosures. In the event an Individual makes a request under this Section of the Agreement directly to Business Associate, Business Associate will notify Covered Entity of such request within three (3) business days and shall cooperate with, and act only at the direction of Covered Entity in responding to such request. V. OBLIGATIONS OF COVERED ENTITY (a) Notice of Privacy Practices. Covered Entity shall provide Business Associate with the notice of privacy practice that Covered Entity produces in accordance with 45 CFR § 164.520, as well as any changes to that notice. (b) Notice of Changes in Individual’s Access or Protected Health Information. Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, is such changes affect Business Associate’s permitted or required uses. (c) Notice of Restriction in Individual’s Access to Protected Health Information. Covered Entity shall notify Business Associate of any restrictions to the use or disclosure of Protected Health Information that Covered Entity has agreed in accordance with 45 CFR § 164.522 to the extent that such restriction may affect Business Associate’s use of Protected Health Information. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 6 October 2013 VI. PERMISSABLE REQUESTS BY COVERED ENTITY Requests Permissible Under HIPAA. Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy or Security Rule. VII. TERMINATION (a) Term. This Agreement shall be effective as of the date first set forth above and shall terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the termination by Covered Entity for cause as provided herein. (b) Termination for Cause. Notwithstanding anything in this Agreement to the contrary, Covered Entity shall have the right to terminate this Agreement and the Service Agreement immediately if Covered Entity determines that Business Associate has or will violated any material term of this Agreement. Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered Entity shall provide an opportunity for Business Associate to cure the breach or end the violation. Covered Entity may terminate this Agreement if Business Associate does not cure the breach or end the violation within the time period specified by Covered Entity. If termination, cure or end of the violation is not feasible, Covered Entity may report the violation to the Secretary. (c) Obligation of Business Associate Upon Termination. At termination of this Agreement, the Service Agreement (or any similar documentation of the business relationship of the Parties), or upon request of Covered Entity, whichever occurs first, Business Associate, shall: A. if feasible, return (in a manner or process approved by the Covered Entity) or destroy all Protected Health Information, regardless of form, including but not limited to paper or electronic format, received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity. Business Associate shall retain no copies of the Protected Health Information. This provision shall also apply to Protected Health Information and other confidential information in the possession of sub- contractors or agents of Business Associate. B. If such return or destruction is not feasible, Business Associate shall (i) retain only that Protected Health Information necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities; (ii) return or destroy the remaining Protected Health Information that the Business Associate still maintains in any form; (iii) extend the protections of this Agreement to the retained Protected Health Information; (iv) limit further uses and disclosures to those purposes that make the return or destruction of the Protected Health Information not feasible; and (v) return or destroy the retained Protected Health Information when it is no longer needed by Business Associate. (d) Survival. This paragraph shall survive the termination of this Agreement and shall apply to Protected Health Information created, maintained, or received by Business Associate and any of its subcontractors. VIII. MISCELLANEOUS (a) Indemnification. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, agents, contractors and agents, against, and in respect of, any and all claims, losses, expenses, costs, damages, obligations, penalties, and liabilities which Covered Entity may incur by reason of Business Associate’s breach of or failure to perform any its obligations pursuant to this DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 7 October 2013 Agreement, including but not limited to any injury or damages arising from any noncompliance with this Agreement or any Security Incident attributable to the negligence of Business Associate, including failure to execute the terms of this Agreement. Further, Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, employees, contractors and agents, against all costs and expenses, including but not limited to, reasonable legal expenses, which are incurred by or on behalf of Business Associate in connection with the defense of such claims. (b) Disclaimer. Covered Entity makes no warranty or representation that compliance by Business Associate with this Agreement, HIPAA, HITECH, or the HIPAA Regulations will be adequate or satisfactory for Business Associate’s own purposes. Business Associate is solely responsible for all decisions made by Business Associate regarding the safeguarding of Protected Health Information. (c) Assistance in Litigation or Administrative Proceedings. Business Associate shall make itself, and any subcontractors, employees, affiliates or agents assisting Business Associate in the performance of its obligations under this Agreement, available to Covered Entity, at no cost to Covered Entity, to testify as witnesses, or otherwise, in the event of litigation or administrative proceedings being commenced against Covered Entity, its directors, officers or employees based upon a claimed violation of HIPAA, HITECH, the HIPAA Regulations, or other laws relating to security and privacy, except where Business Associate or its subcontractor, employee or agent is named adverse party. (d) Survival. The obligations of Business Associate under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the Service Agreement and/or the business relationship of the parties, and shall continue to bind Business Associate, its agents, employees, contractors, successors, and assigns as set forth herein. (e) Ownership of Information. Covered Entity holds all right, title, and interest in and to the Protected Health Information and Business Associate does not hold and will not acquire by virtue of this Agreement or by virtue of providing goods or services to Covered Entity, any right, title, or interest in or to the PHI or any portion thereof. (f) Right to Injunctive Relief. Business Associate expressly acknowledges and agrees that the breach, or threatened breach, by it of any provision of this Agreement may cause Covered Entity to be irreparably harmed and that Covered Entity may not have an adequate remedy at law. Therefore, Business Associate agrees that upon such breach, or threatened breach, Covered Entity will be entitled to seek injunctive relief to prevent Business Associate from commencing or continuing any action constituting such breach without having to post a bond or other security and without having to prove the inadequacy of any other available remedies. Nothing in this paragraph will be deemed to limit or abridge any other remedy available to Covered Entity at law or in equity. Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third parties. (g) Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPSS Regulations. In addition, this Agreement may be amended or modified by the Parties only in writing. (h) Assignment. No Party may assign its respective rights and obligations under this Agreement without the prior written consent of the other Party. (i) Independent Contractor. None of the provisions of this Agreement are intended to create, nor will they be deemed to create any relationship between the Parties other than that of independent parties contracting with each other solely for the purposes of effecting the provisions of this Agreement and any other agreements between the Parties evidencing their business relationship. This Agreement will be governed by the laws of the State of North Carolina. No change, waiver or discharge of any liability or obligation hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing or other obligation, or shall prohibit enforcement of any obligation, on any other occasion. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 8 October 2013 (j) Regulatory References. A reference in this Agreement to a section in HIPAA, HITECH or the HIPAA Regulations means the section as it currently is in effect or as amended. (k) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Regulations. The parties agree that, in the event that any documentation of the arrangement pursuant to which Busi ness Associate provides services to Covered Entity contains provisions relating to the use or disclosure of Protected Health Information that are more restrictive than the provisions of this Agreement, the more restrictive provisions will control. The provisions of this Agreement are intended to establish the minimum requirements regarding Business Associate’s use and disclosure of Protected Health Information. (l) Severability. In the event any part or parts of this Agreement are held to be unenforceable, the remainder of this Agreement will continue in effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails to comply with the then-current requirements of the HIPAA Security and Privacy Rule, such party shall notify the other party in writing. For a period of up to (30) thirty days, the parties shall address in good faith such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after such thirty-day period, a party believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule, then either party has the right to terminate upon written notice to the other party. (m) Notices and Communications. All instructions, notices, consents, demands, or other communications required or contemplated by this Agreement shall be in writing and shall be delivered to the Party at the address below: For Covered Entity: For Business Associate Robert Reynolds Trustedsec, LLC Information Technologies P.O. Box 8181 3485 Southwestern Boulevard Hillsborough NC 27278 Fairlawn, OH 44333 (n) Strict compliance. No failure by any Party to insist upon strict compliance with any terms or provisions of this Agreement, to exercise any option, to enforce any right, or to seek any remedy upon any default of any other Party shall affect, or constitute a waiver of, any Party’s right to insist upon such strict compliance, exercise that option, enforce that right, or seek that remedy with respect to that default or any prior, or contemporaneous, or subsequent default. No custom or practice of the Parties at variance with any provisions of this Agreement shall affect, or constitute a waiver of, any Party’s right to demand strict compliance with all provisions of this Agreement. (o) Governing Law. This Agreement shall be governed and construed in accordance with the laws of the State of North Carolina except to the extent that North Carolina laws have been pre-empted by HIPAA and without giving effect to principals of conflicts of law. Jurisdiction shall be Orange County, North Carolina, for purposes of litigation resulting from disagreements of the Parties for purposes of this Agreement and the Service Agreement(s). (p) E-Verify. Employers and their subcontractors with 25 or more employees as defined in Article 2 of Chapter 64 of the NC General Statutes must comply with E-Verify requirements to contract with governmental units. E-Verify is a Federal program operated by the United States Department of Homeland Security and other federal agencies, or any successor or equivalent program used to verify the work authorization of newly hired employees pursuant to federal law. Where applicable, failure to maintain compliance with the requirements of Article 2 of Chapter 64 of the North Carolina General Statutes shall constitute breach of this Agreement. If applicable, by executing this Agreement, Business Associate affirms that they are in compliance with Article 3 of Chapter 64 if the North Carolina General Statutes. IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 9 October 2013 COVERED ENTITY: BUSINESS ASSOCIATE: By:_________________________________ By:___________________________________ Title:________________________________ Title:__________________________________ DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC 10 October 2013 EXHIBIT A COVERED ENTITY PRIVACY OFFICER CONTACT INFORMATION To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with the terms of this Agreement that might be considered a privacy breach, Business Associate should contact the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident (as defined in the Agreement), Business Associate should contact Melissa Tegeder, or the Security Officer at The Orange County Health Department. DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC ANY PROPRIETOR/PARTNER/EXECUTIVEOFFICER/MEMBER EXCLUDED? INSR ADDL SUBRLTRINSDWVD PRODUCER CONTACTNAME: FAXPHONE(A/C, No):(A/C, No, Ext): E-MAILADDRESS: INSURER A : INSURED INSURER B : INSURER C : INSURER D : INSURER E : INSURER F : POLICY NUMBER POLICY EFF POLICY EXPTYPE OF INSURANCE LIMITS(MM/DD/YYYY)(MM/DD/YYYY) AUTOMOBILE LIABILITY UMBRELLA LIAB EXCESS LIAB WORKERS COMPENSATIONAND EMPLOYERS' LIABILITY DESCRIPTION OF OPERATIONS / LOCATIONS / VEHICLES (ACORD 101, Additional Remarks Schedule, may be attached if more space is required) AUTHORIZED REPRESENTATIVE EACH OCCURRENCE $ DAMAGE TO RENTEDCLAIMS-MADE OCCUR $PREMISES (Ea occurrence) MED EXP (Any one person)$ PERSONAL & ADV INJURY $ GEN'L AGGREGATE LIMIT APPLIES PER:GENERAL AGGREGATE $ PRO-POLICY LOC PRODUCTS - COMP/OP AGGJECT OTHER:$ COMBINED SINGLE LIMIT $(Ea accident) ANY AUTO BODILY INJURY (Per person)$ OWNED SCHEDULED BODILY INJURY (Per accident)$AUTOS ONLY AUTOS HIRED NON-OWNED PROPERTY DAMAGE $AUTOS ONLY AUTOS ONLY (Per accident) $ OCCUR EACH OCCURRENCE CLAIMS-MADE AGGREGATE $ DED RETENTION $ PER OTH-STATUTE ER E.L. EACH ACCIDENT E.L. DISEASE - EA EMPLOYEE $ If yes, describe under E.L. DISEASE - POLICY LIMITDESCRIPTION OF OPERATIONS below INSURER(S) AFFORDING COVERAGE NAIC # COMMERCIAL GENERAL LIABILITY Y / N N / A (Mandatory in NH) SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN ACCORDANCE WITH THE POLICY PROVISIONS. THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED. NOTWITHSTANDING ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES. LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER. THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S), AUTHORIZED REPRESENTATIVE OR PRODUCER, AND THE CERTIFICATE HOLDER. IMPORTANT: If the certificate holder is an ADDITIONAL INSURED, the policy(ies) must have ADDITIONAL INSURED provisions or be endorsed. If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy, certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s). COVERAGES CERTIFICATE NUMBER:REVISION NUMBER: CERTIFICATE HOLDER CANCELLATION © 1988-2015 ACORD CORPORATION. All rights reserved.ACORD 25 (2016/03) CERTIFICATE OF LIABILITY INSURANCE DATE (MM/DD/YYYY) $ $ $ $ $ The ACORD name and logo are registered marks of ACORD 5/30/2024 (330) 453-7721 (330) 453-4911 38288 TrustedSec LLC 3485 Southwestern Boulevard Fairlawn, OH 44333 A 1,000,000 X 45SBABB2368 7/1/2023 7/1/2024 1,000,000 10,000 1,000,000 2,000,000 2,000,000 1,000,000A 45SBABB2368 7/1/2023 7/1/2024 5,000,000A 45SBABB2368 7/1/2023 7/1/2024 5,000,000 10,000 A 45WECAY9LEW 6/1/2024 6/1/2025 1,000,000 1,000,000 1,000,000 B TechE&O/CyberPrimary ESM0839737155 8/15/2023 Occurrence/Aggregate 5,000,000 Orange County, its officers, agents, and employees are Additional Insured with respect to General Liability where required by written contract. Orange County 300 West Tryon Street PO Box 8181 Hillsborough, NC 27278 TRUSTED-01 MROKO Schauer Group, Inc. 200 Market Ave. NSuite 100Canton, OH 44702 insure@schauergroup.com The Hartford Insurance Co. Lloyd's of London X 8/15/2024 X X X X X X X X DocuSign Envelope ID: AFDC1276-5BF5-4129-B1DC-BCD00B65C8BC