Annex II — Technical and Organisational Measures
Vendor will adopt and maintain appropriate security measures, including administrative, physical, and technical controls, to protect all Personal Data and all Vendor systems and devices used to process or access Personal Data or systems to which Vendor has authorized access (“Systems”), against unauthorized, accidental or unlawful access, loss, alteration, modification, disclosure, collection, copying, destruction or processing. Vendor shall be responsible for the security of the Personal Data and, to the extent controlled by Vendor, the security of the Systems. Vendor agrees to adhere to the following requirements during the term of the Agreement (inclusive of any ongoing obligations to Fourthwall as may be specified in the Agreement or its Exhibits). To the extent of any conflict between this Annex II and the DPA, the provisions of this Annex II control:
- Physical Controls
- General. Vendor shall maintain procedures to ensure the physical protection of Systems and Personal Data, including information, software, and hardware.
- Access restrictions. Access to Vendor facilities shall be restricted to Vendor personnel who are authorized to have such access. Restricted areas of Vendor facilities, such as server rooms, shall be subject to risk-appropriate access controls, such as by requiring key cards and/or PINs for entry. Vendor shall regularly review audit trails of access to these restricted areas.
- Visitors. Vendor shall identify and log all visitors to Vendor facilities and ensure that visitors to restricted areas are escorted by Vendor personnel at all times.
- Security Monitoring
- Generally. Vendor shall maintain procedures to determine whether any compromise of Systems or Personal Data (e.g. loss or modification of information, software or hardware) has occurred.
- Logging. Local logging must be enabled on all systems and networking devices to capture detailed information such as event source, date, user, timestamp, source addresses, destination addresses, and other useful elements.
- Monitoring. Vendor must analyze Systems for anomalous and suspicious activity to assist in the identification of possible security incidents.
- Data return or deletion. Vendor must return or securely delete or destroy Personal Data, and any copies thereof, at the end of, or at an agreed point in time during the Agreement.
- Personnel
- Confidentiality. Vendor must ensure that all Vendor personnel with access to Personal Data or Systems have signed a confidentiality agreement requiring them to keep Personal Data confidential and prohibiting them from copying or disclosing Personal Data without prior authorization.
- Background Checks. Vendor must perform commercially-reasonable background checks in compliance with all applicable laws on any Vendor personnel that will have access to Personal Data or Systems. No Vendor personnel with access to Personal Data or Systems may have a criminal history involving offenses related to theft, fraud, burglary, bribery, property damage, violence, sexual misconduct, harassment, or securities laws violations.
- Reporting. Vendor shall maintain a clear reporting structure for Vendor personnel to communicate security issues and establish a clear reporting format for any incident or security policy violation.
- Integrity and Availability. Vendor must maintain controls to ensure the integrity and availability of Personal Data and Systems.
- Training and Awareness
- Training. Vendor shall provide training to Vendor users and administrators with access to Systems and Personal Data that covers appropriate role-based topics in methods, procedures, and security.
- Security Awareness. Vendor shall ensure that Vendor personnel with access to Systems and Personal Data are aware of their security responsibilities, and shall disseminate periodic reminders on relevant security issues to such personnel.
- Change Management. Vendor shall maintain documented processes for change management.
- Access Controls. Vendor shall:
- Restrict access to Personal Data and Systems to only those Vendor personnel that require such access to perform the services described in the Agreement, or to facilitate the performance of such services, such as system administrators, consistent with the concepts of least privilege and need-to-know.
- Immediately terminate access privileges to Personal Data and Systems for any Vendor personnel that no longer need such access, and conduct reviews of access lists to ensure that access privileges have been appropriately provisioned and terminated no less than quarterly.
- Maintain an authorization process for user access and privileges that requires that access requests be approved by a different individual than the requester, consistent with the concept of segregation of duties.
- Maintain a list or log of individuals authorized to access Systems and Personal Data, and what their rights and privileges are with respect to such access.
- Enforce complex password requirements and multifactor authentication on all Systems.
- Vulnerability management. Vendor shall:
- Perform (1) automated quarterly vulnerability scans and (2) periodic authenticated vulnerability scanning on all systems storing, processing or transmitting Personal Data, or connected to Systems, to identify all potential vulnerabilities on such system.
- Remediate identified vulnerabilities in a timely, risk-based manner, including timely implementation of all manufacturer- and developer-recommended security updates and patches to operating systems and third-party software storing, processing, or transmitting Personal Data, or otherwise installed on Vendor Systems.
- Penetration testing. Vendor shall perform or engage a qualified third party to perform an annual penetration test on all Vendor Systems that process Personal Data.
- Antivirus. Antivirus and malware protection software with up-to-date definitions and signatures must be maintained and enabled on all Vendor Systems.
- Network security. Vendor shall maintain appropriate network security measures, including but not limited to firewalls to segregate Vendor’s internal networks from the internet, risk-based network segmentation, and intrusion prevention or detection systems to alert Vendor to suspicious network activity.
- Encryption. All Personal Data must be encrypted in transit and at rest using industry-standard encryption algorithms, and in accordance with industry standards for secure key and protocol negotiation and key management.
- Code and application security. To the extent that Vendor develops custom code or applications on Fourthwall’s behalf, Vendor shall perform security testing to ensure that the application or code is secure against (1) the vulnerabilities described in the version of the OWASP Top Ten List available as of the Effective Date, (2) any vulnerabilities described in changes to the OWASP Top Ten List after the Effective Date (within a reasonable time after such changes are initially published), (3) any other vulnerabilities that are identified through industry standard testing, or (4) vulnerabilities reported to Vendor by any third party. The term “OWASP Top Ten List” shall mean the Open Web Application Security Project's Top Ten list (available at https://owasp.org/www-project-top-ten/ or an updated website, as periodically defined by Fourthwall).
- Breach Notification
- Vendor must notify Fourthwall by sending a report to https://vdp.fourthwall.com within 24 hours of discovering any Security Breach.
- The notice to Fourthwall of such Security Breach must include, to the extent known by Vendor:
- The nature of the Security Breach, including, where possible, the categories and types of Personal Data affected and/or the Systems impacted;
- A list of the individuals whose information was contained in Personal Data affected by the Security Breach;
- The likely consequences of the Security Breach;
- Measures taken or proposed to be taken by Vendor to address the Security Breach, including, where appropriate, measures to mitigate its possible adverse effects; and
- Any other information requested by Fourthwall that, in Fourthwall’s reasonable determination, is required to comply with Fourthwall’s obligations under the applicable law.
- To the extent the information required in Section 15.2 is not available at the time Vendor provides notice to Fourthwall, Vendor will provide such information as it becomes available, and in any event at least once each day there is new material information discovered.
- Vendor shall provide reasonable assistance to, and cooperation with, Fourthwall to take measures that in Fourthwall’s reasonable determination, reduce the risk of exposure of the Personal Data involved, or are necessary for Fourthwall to comply with the applicable law with respect to the Security Breach;
- Vendor shall refrain from notifying any Fourthwall customers of the Security Breach without Fourthwall’s written consent unless required by applicable law. Vendor shall not name Fourthwall as an impacted party in connection with the Security Breach in any public statement, regulatory notice, or other third-party notice without Fourthwall’s written consent unless required by applicable law.
- Vendor shall bear the costs (including reasonable attorneys’ fees) associated with Fourthwall’s response to a Security Breach, including without limitation any costs (1) related to investigating and remediating the Security Breach; and (2) of remedying and otherwise mitigating any potential damage or harm from the Security Breach, as reasonably requested by Fourthwall. Vendor will bear these expenses directly where practicable (and will otherwise reimburse Fourthwall within 30 days of receipt of supporting documentation).
- Vendor shall maintain evidence demonstrating that all notifications to Fourthwall required by this Section 15 were made without unreasonable delay.
- Audit and Monitoring.
- Third-Party Audit Report. During the term of the Agreement, Fourthwall reserves the right to request a copy of Vendor’s most recent third-party security audit report (e.g., SOC II Type 2) pertaining to the environment in which Personal Data is stored. If Vendor has not undergone a third-party security audit of the relevant environment in the past 12 months, Fourthwall reserves the right to request other evidence of compliance with this Annex II, including copies of policies and procedures and responses to Fourthwall security questionnaires.
- Audit. During the term of the Agreement, Fourthwall reserves the right to periodically audit the infrastructure designated by Vendor to be used in the provision of Services under the Agreement to ensure compliance with the requirements of this Annex II. Non-intrusive network audits, such as TCP and UDP port scans, may be performed randomly without prior notice.
- Documentation. Fourthwall reserves the right to request documentation to verify Vendor’s compliance with this Annex II.
- Revocation of Processing. If Fourthwall identifies instances of material non-compliance with this Annex II, Fourthwall reserves the right to revoke Vendor’s right to process Personal Data and demand immediate return or deletion of Personal Data.
- Indemnification. Vendor shall indemnify, defend and hold harmless Fourthwall and its officers, directors and employees (the “Fourthwall Indemnitees”) for, from and against any and all Losses (as defined herein) incurred, arising out of, or relating to, any claim, investigation, action, proceeding, allegation or demand made or brought against any Fourthwall Indemnitees arising out of, relating to or based on Vendor’s violation of its obligations under this Annex II. Fourthwall shall provide Vendor with: (i) prompt written notice of any claim requiring indemnification hereunder (but the failure to give such notice shall not relieve Vendor of any of its obligations under this Section except to the extent that Vendor is materially prejudiced thereby); (ii) exclusive control over the defense and settlement of such claim, provided that any settlement will be subject to Fourthwall’s prior written approval; and (iii) at Vendor’s sole cost and expense, proper and full information and assistance requested by Vendor in writing to settle or defend any such claim. In the event that Vendor does not promptly handle such claims, Fourthwall shall have the right to take any and all actions necessary to protect its rights, and Vendor shall reimburse Fourthwall for any costs that Fourthwall incurs. For purposes of this Section, “Losses” means any and all losses, liabilities, damages, demands, claims (including without limitation taxes), suits, proceeding, costs, payments and expenses (including any and all reasonable attorneys’ fees, reasonable costs of investigation, discovery, litigation and settlement, interest and any judgments, fines and penalties), the costs of enforcing any right to indemnification hereunder, and the cost of pursuing any insurance providers.
- Non-Compliance. Any material non-compliance with this Annex II constitutes a material breach of the Agreement and is subject to the penalties for such material breach set forth in the Agreement.