or exceeds industry standards and the requirements of this PO; (b) maintain network, system, and application security,
<br /> which includes, but is not limited to, network firewalls, intrusion detection (host and network), annual security testing, and
<br /> improvements or enhancements consistent with evolving industry standards; (c) comply with State and federal rules and
<br /> regulations related to overall security, privacy, confidentiality, integrity, availability, and auditing; (d) provide that security is
<br /> not compromised by unauthorized access to workspaces, computers, networks, software, databases, or other physical or
<br /> electronic environments; (e) promptly report all Incidents, including Incidents that do not result in unauthorized disclosure
<br /> or loss of data integrity, to a designated representative of the OIS; and (f) comply with all rules, policies, procedures, and
<br /> standards issued by the Governor's Office of Information Technology (OIT), including project Iifecycle methodology and
<br /> governance, technical standards, documentation, and other requirements posted at https://oit.colorado.gov/standards-
<br /> policies-guides/technical-standards-policies.Vendor shall not allow remote access to State Records from outside the United
<br /> States, including access by Vendor's employees or agents, without the prior express written consent of OIS. Vendor shall
<br /> communicate any request regarding non-U.S. access to State Records to the State. The State, acting by and through OIS,
<br /> shall have sole discretion to grant or deny any such request.
<br /> N. Accessibility. Vendor shall comply with and the Work Product provided under this PO shall be in compliance with all
<br /> applicable provisions of§§24-85-101, et seq., C.R.S., and the Accessibility Standards for Individuals with a Disability, as
<br /> established by OIT pursuant to Section §24-85-103 (2.5), C.R.S. Vendor shall also comply with all State of Colorado
<br /> technology standards related to technology accessibility and with Level AA of the most current version of the Web Content
<br /> Accessibility Guidelines(WCAG), incorporated in the State of Colorado technology standards.Vendor shall indemnify,save,
<br /> and hold harmless the Indemnified Parties against any and all costs, expenses, claims, damages, liabilities, court awards
<br /> and other amounts (including attorneys' fees and related costs) incurred by any of the Indemnified Parties in relation to
<br /> Vendor's failure to comply with §§24-85-101, et seq., C.R.S., or the Accessibility Standards for Individuals with a Disability
<br /> as established by OIT pursuant to Section §24-85-103 (2.5), C.R.S. The State may require Vendor's compliance to the
<br /> State's Accessibility Standards to be determined by a third party selected by the State to attest to Vendor's Work Product
<br /> and software is in compliance with §§24-85-101, et seq., C.R.S., and the Accessibility Standards for Individuals with a
<br /> Disability as established by OIT pursuant to Section §24-85-103 (2.5), C.R.S.
<br /> Page 8 of 8
<br /> Effective 7/1/2022
<br />
|