SECURITY EXHIBIT

    1. LOGICAL ACCESS CONTROL
      1. Access
        1. Riskonnect denies all access to information systems and resources by default. Access is granted by request for specific business purposes, and in accordance with the principles of least privilege and separation of duties. Riskonnect controls the use of administrative privileges by tracking, preventing, and correcting the use, assignment, and configuration of administrative privileges on computers, networks, and applications through a formal access recertification process.
        2. Riskonnect maintains appropriate usage restrictions and configuration/connection requirements for information systems (including wireless) access, which requires prior authorization for access to the systems prior to allowing such connections. All access to Riskonnect’s information systems and resources requires management approval.
        3. Riskonnect maintains appropriate usage restrictions, configuration/connection requirements, and implementation guidance for organization-controlled mobile devices, and authorizes (as described above) the connection of mobile devices to organizational information systems.
      2. Account Management. Riskonnect configures its information systems and resources to enforce access control policies and standards and requires or forces users to log out after a pre-determined amount of inactivity.
    2. AWARENESS AND TRAINING
      1. Security Awareness Training
        1. Riskonnect maintains, regularly reviews, documents, and administers security awareness training for all of Riskonnect’s personnel.
        2. Training is administered as part of the new hire onboarding process and annually thereafter.
    3. AUDIT AND ACCOUNTABILITY
      1. Audit Logs. Riskonnect’s information systems will generate audit logs containing the type of event, the date and time of the event, the location of the event, the source of the event, the outcome of and response to the event, and the individual(s) associated with the event, and reasonably provide such information that is relevant to the Customer’s specific application upon request.
      2. System Logging and Review
        1. Riskonnect’s information systems protect audit information, including audit records, audit settings, audit reports, and audit tools from unauthorized access, modification, and deletion. Audit information must be backed up onto a physically different system or system component than the system or component being audited. Riskonnect’s information systems implement cryptographic protection to ensure the integrity of audit information and enforce the principles of separation of duties and least privilege in the review, analysis, and reporting of audit records.
        2. Riskonnect retains audit logs to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.
        3. Depending on the relevant hosting environment in which the Riskonnect Application will reside, and Customer Data will be processed, and as detailed in the applicable Product Schedule, such hosting environment will (a) be subject to an annual SOC2 Type2 audit (except for Active Risk and Ventiv applications) and (b) have achieved ISO 27001 certification. Additionally, as part of the annual SOC2 Type2 audit or ISO 27001 certification process, Riskonnect engages a qualified third party to conduct an audit of, and perform penetration testing on, the subject hosting environment. In lieu of authorizing Customer to conduct its own audit or penetration testing of the subject hosting environment (but subject to a requirement under applicable law for Customer to have such audit conducted) , Riskonnect makes available, on demand to its customers : (1) as applicable, a copy of its latest SOC 2 Type2 report and/or a copy of its latest ISO 27001 certificate; and (2) a summary of the related annual penetration testing results. Finally, Riskonnect will respond to additional Customer information security questionnaires so long as such questionnaires are (i) submitted to Riskonnect not more than once per twelve (12) month time period and (ii) limited to using either the SIG Lite or CAIQ format.
    4. SECURITY ASSESSMENT AND AUTHORIZATION
      1. Security Authorization. Riskonnect assigns a senior-level executive or manager as the authorizing official for the information systems, ensures that such official authorizes the information systems for processing before commencing operations, and periodically updates the security authorization as needed.
      2. Continuous Monitoring. Riskonnect maintains a Data Loss Prevention (“DLP”) strategy to prevent data exfiltration, mitigate the effects of exfiltrated data, and ensure the privacy and integrity of sensitive information. Riskonnect maintains a continuous monitoring program that includes establishing metrics to be monitored, the frequency for monitoring, response actions to address the results of such analysis, and reporting the security status of the Riskonnect information system to the appropriate personnel.
    5. CONFIGURATION MANAGEMENT
      1. Information System Component Inventory. Riskonnect develops, documents, and regularly updates an inventory of information system components. Riskonnect detects, tracks, and restricts all hardware devices on its non-public networks so that only authorized devices are given access, and detects, tracks, and restricts all software on such networks so that only authorized software is installed.
      2. Configuration Management Plan. Riskonnect establishes and implements a configuration management plan, employing the principle of least functionality. Riskonnect establishes, implements, and actively tracks, corrects, and reports on the security configuration of network infrastructure devices using a rigorous configuration management and change control process that are reasonably designed to prevent attackers from exploiting vulnerable services and settings. The configuration management plan addresses roles and responsibilities and flaw remediation, as well as defines detailed processes and procedures for how configuration management is used to support Riskonnect’s system development lifecycle. The plan describes how to move changes through the system, how to update baselines and configuration settings, how to maintain system component inventories, and how to control development, test, and operational environments.
      3. Baseline Configuration and Hardening. Riskonnect develops, documents, and maintains current baseline configuration and hardening requirements for Riskonnect’s information systems. Baseline configurations and hardening requirements are reviewed and updated regularly and as part of information system component installations and updates. Security compliance assessments are performed on new servers and applications prior to migration into production and repeated periodically based on risk to ensure compliance with Riskonnect’s system hardening requirements. Riskonnect retains previous versions of baseline configurations of the information systems to support rollback and maintains a baseline configuration for information system development and test environments that are managed separately from the operational baseline configuration.
      4. Configuration Change Control. Riskonnect establishes and implements a formal change control process designed to prevent unauthorized changes and documents all changes to network infrastructure. Riskonnect tests, validates, and documents changes to the information systems before implementing the changes on the operational systems, and requires that an information security representative be a member of the configuration change control team.
    6. CONTINGENCY PLANNING
      1. Contingency Plan. Riskonnect develops a contingency plan for the information systems, which identifies essential business missions/functions and associated contingency requirements, provides recovery objectives and restoration responses, addresses contingency roles and responsibilities, addresses maintaining essential business functions in the event of system disruption or failure, and addresses full system restoration without deterioration of the security safeguards in place. The contingency plan is regularly reviewed and updated at least annually, and as needed to address changes in the threat environment.
      2. Information System Backup and Alternate Storage Site. Riskonnect conducts backups of user-level information, system-level information, and system documentation including security-related documentation. Riskonnect maintains alternate storage locations permitting storage and prompt retrieval of information system backup information. Storage of information system backups are protected with information security safeguards of an equivalent strength to that of the primary system and storage site.
      3. Information System Recovery and Reconstitution. Riskonnect promptly provides for the recovery and reconstitution of information systems to a state of normal operation after disruption, compromise, or failure. This recovery plan includes transaction-based recovery, and protects backup and restoration hardware, software, and firmware.
    7. IDENTIFICATION AND AUTHENTICATION
      1. Unique Identification. Riskonnect’s information systems uniquely identify and authenticate both organizational and non-organizational users and/or processes acting on behalf of users, such that all user activity can be traced back to the individual(s) who performed the activity. Riskonnect’s systems employ industry standard encryption for all authentication mechanisms, provide for federated identity capabilities, and implement replay-resistant authentication mechanisms. Information systems implement multifactor authentication for network and local access to both privileged and non-privileged accounts.
      2. Non-Repudiation.  Riskonnect’s information systems enforce non-repudiation such that the validity and authenticity of an action or task cannot be disputed, including creating and/or changing information, sending and receiving messages, approving information, signing contracts, and approving procurement requests.
      3. Device Identification and Authentication. Devices attempting to access Riskonnect’s network are uniquely identified and authenticated via a Network Access Control system (or other comparable means) prior to establishing a network connection.
      4. Authentication Management. Riskonnect manages information system credentials/authenticators using industry best practices. Riskonnect takes into consideration the type of authentication (e.g., hardware token-based, PKI-based, password-based, biometric-based, etc.) and applies additional security controls as appropriate.
    8. INCIDENT RESPONSE
      1. Incident Response Program. Riskonnect maintains a written incident response program that addresses cybersecurity event preparation, detection, analysis, containment, eradication, and recovery. This program includes procedures that describe: (i) roles and responsibilities of the incident response team; (ii) communication requirements with internal and external partners; (iii) plans to detect, respond to, and contain common incident categories; (iv) methods to preserve evidence, maintain chain of custody, and perform forensic analysis; (v) coordination of recovery processes; (vi) follow-up processes; and (vii) reporting to ensure critical details of incidents are tracked and lessons learned are incorporated into ongoing response procedures, training, and testing. The incident response program includes coordinating incident handling activities involving supply chain events with other organizations involved in the supply chain. The incident response program is reviewed and updated at least annually.
      2. Incident Handling. If Riskonnect discovers or is notified of any security incident that impacts or may impact Customer Data and/or systems, Riskonnect will promptly: (i) investigate the security incident; (ii) remediate, mitigate, or mitigate and remediate, the risk to the Customer Data or systems and other effects of the security incident; (iii) preserve all related records and other evidence; and (iv) implement a plan to prevent such a security incident from reoccurring.
      3. Incident Notification. If Riskonnect discovers or is notified of any security incident, Riskonnect will immediately notify Customer thereof in writing, but no later than seventy two (72) hours from the time Riskonnect becomes aware of a security incident, including disclosing (i) the date, time, and cause of the incident if known; (ii) the Customer Data and/or systems that were exposed or reasonably believed to have been exposed; and (iii) whether nonpublic personally identifiable information was accessed.
      4. Reporting. Riskonnect will provide Customer with a written report on the outcome of its investigation including any risk to Customer Data and/or systems and the corrective action Riskonnect has taken to respond to the security incident.
    9. MAINTENANCE
      1. Nonlocal Maintenance. Riskonnect: (i) approves, documents, and monitors nonlocal maintenance and diagnostic activities; (ii) allows the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the information system; (iii) requires multifactor authentication to establish nonlocal maintenance and diagnostic sessions via external network connections; (iv) maintains records for nonlocal maintenance and diagnostic activities; and (v) terminates session and network connections when nonlocal maintenance is completed. Riskonnect protects nonlocal maintenance sessions by employing replay-resistant authenticators and separating the maintenance sessions from other network sessions by either physically or logically separated communication paths based on encryption.
      2. Timely Maintenance. Riskonnect approves, obtains, and documents the maintenance, support, and repair of information systems and information system components in a timely manner following system or component failure. Riskonnect performs preventative maintenance on critical information system components at regular intervals, or as needed, to ensure that they are in operating condition. Security controls potentially impacted during maintenance or repair activities are inspected for proper function post-activity. Riskonnect promptly applies software patches, updates, and code fixes, when available.
    10. MEDIA PROTECTION
      1. Media Use. Riskonnect employs both technical and non-technical safeguards to restrict the use of removable media and portable storage devices.
      2. Media Storage. Riskonnect physically controls and securely stores both digital and non-digital media and protects information system media until such media are destroyed or sanitized using secure data destruction techniques. Riskonnect restricts access to media storage areas and maintains access logs for both successful and unsuccessful access attempts.
      3. Media Transport. Riskonnect: (i) protects and controls information system media during transport outside of controlled areas using physical and technical safeguards; (ii) maintains accountability for information system media during transport outside of controlled areas; (iii) documents activities associated with the transport of information system media; and (iv) restricts the activities associated with information system media to authorized personnel. Information systems implement cryptographic mechanisms to protect the confidentiality and integrity of information stored on digital media during transport outside of controlled areas.
      4. Media Sanitization. Riskonnect sanitizes information system media prior to disposal, release from organizational control, or release for reuse in accordance with organizational policies, employing sanitation mechanisms with the strength and integrity commensurate with the security category or classification of the information. Riskonnect: (i) reviews and approves media to be sanitized to ensure effectiveness and compliance with records-retention policies and (ii) tracks and documents the media sanitation process, including personnel who handled such media, and verifies that that sanitation of the media was effective prior to disposal. The information systems, system components, and system devices are capable of being purged/wiped remotely to protect data obtained by unauthorized individuals.
    11. PHYSICAL AND ENVIRONMENTAL PROTECTION
      1. Physical Access Control. Riskonnect: (i) enforces physical access authorizations at facility entrance/exit points by verifying individual access authorizations before granting access to the facility; (ii) maintains physical access audit logs for entry/exit points; and (iii) uses security safeguards to control access of such facilities, including the use of security guards (only at data processing facilities where the Customer Data is stored) and physical access control devices (e.g., alarms, card swipe, keypads).
      2. Location of Information System Components. Riskonnect positions information system components within the facility to minimize potential damage from environmental hazards (e.g., flooding, fire, tornados, earthquakes, hurricanes, vandalism, acts of terrorism, electromagnetic pulse, electrical interference, etc.) as well as physical hazards, including the opportunity for unauthorized access.
    12. PLANNING
      1. Information Security Architecture. Riskonnect maintains information security architecture for the information systems that includes an architectural description, the placement/allocation of security functionality (including security controls), security-related information for external interfaces, information being exchanged across the interfaces, and the protection mechanisms associated with each interface. The information security architecture is reviewed and updated regularly to reflect updates in the enterprise architecture, external impacts, and industry practices.
    13. PERSONNEL SECURITY
      1. Personnel Screening. Riskonnect screens individuals prior to authorizing access to Riskonnect’s information systems Screening includes (but may not be limited to, depending on location) identity verification, criminal screening and education verification.  Riskonnect personnel are required to self report any conviction of a felony, theft, or crimes of mistrust during their time of employment within 30 days of conviction.
      2. Personnel Termination. Upon termination, Riskonnect promptly: (i) disables the individual’s information system access; (ii) terminates/revokes any authenticators/credentials associated with the individual; (iii) conducts exit interviews that include information security topics; (iv) retrieves all security-related organizational information system-related property (e.g., hardware authentication tokens, system administration technical manuals, keys, identification cards, building passes, etc.); and (v) retains access to organizational information and information systems formerly controlled by terminated individual.
    14. RISK ASSESSMENT
      1. Risk Assessment. Riskonnect: (i) conducts a risk assessment, including the likelihood and magnitude of harm, from the unauthorized access, use, disclosure, disruption, modification, or destruction of the information systems and the information they process, store, or transmit; (ii) documents and reviews the risk assessment results; and (iii) updates the risk assessment at least annually, and whenever there are significant changes to the information system or environment of operation (e.g. the identification of new threats and vulnerabilities).
      2. Vulnerability Scanning. Riskonnect: (i) scans for vulnerabilities in the hosted application at least annually and when new vulnerabilities potentially affecting the system/applications are identified; (ii) employs vulnerability scanning tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for enumerating platforms, software flaws, and improper configurations, formatting checklists and test procedures, and measuring vulnerability impact ; (iii) analyzes vulnerability scan reports and results from security control assessments; (iv) remediates vulnerabilities in accordance with organizational risk assessment; (v) shares information from the vulnerability scanning and security control assessments with appropriate personnel to help eliminate similar vulnerabilities in other information systems; and (vi) employs periodic external vulnerability scanning and annual penetration testing to assess the overall strength of Riskonnect’s defenses (technology, processes, and employees). Upon Customer’s written request, Riskonnect will deliver to Customer a summary of the results of the most recent external penetration tests and application security assessments.
    15. SYSTEM DEVELOPMENT LIFE-CYCLE
      1. Riskonnect manages information systems using industry standard System Development Life Cycle (“SDLC”) that incorporates information security considerations, defines and documents information security roles and responsibilities throughout the SDLC, identifies individuals having such roles or responsibilities, and integrates Riskonnect’s information security risk management process into SDLC activities.
    16. SUPPLY CHAIN RISK MANAGEMENT
      1. Riskonnect (i) protects against supply chain threats to the information systems, components, or service by employing security safeguards as part of a comprehensive information security strategy, including the use of secure acquisition strategies, contract, tools, and procurement methods for purchasing of information systems, components, and services from suppliers; (ii) conducts supplier reviews prior to engaging into a contractual agreement to acquire information systems, components, or services; (iii) maintains security safeguards to limit harm from potential adversaries targeting the organizational supply chain; and (iv) conducts assessments of the information systems, components, or services prior to selection, acceptance, or update in scope of engagement.
    17. SYSTEMS AND COMMUNICATIONS PROTECTION
      1. Boundary Protection. Riskonnect (i) monitors and controls communications at the external boundaries and at key internal boundaries of the organizational system; (ii) implements sub-networks for publicly accessible system components that are physically or logically separated from internal networks; (iii) limits the number of external network connections; and (iv) employs a deny by default, permit by exception policy for network communication traffic for both inbound and outbound communications. The Riskonnect Service, connects to external networks or information systems, only through managed interfaces. Riskonnect manages the ongoing operational use of ports, protocols, and services on networked devices to minimize windows of vulnerability available to attackers.
      2. Transmission Confidentiality and Integrity. Information systems protect the confidentiality and integrity of transmitted information through both physical and logical means, including employing protected distribution procedures and limiting access to peripherals (e.g., servers, computers, printers, scanners, facsimile machines), and through the use of encryption.
    18. SYSTEM AND INFORMATION SYSTEM INTEGRITY
      1. Flaw Remediation. Riskonnect: (i) identifies, reports, and corrects information system flaws; (ii) tests software and firmware updates for effectiveness and potential side effects before installation; and (iii) installs security-relevant software and firmware updates, including patches, service packs, hot fixes, and anti-virus signatures, once they are available. Riskonnect centrally manages the flaw remediation process, which measures the time between flaw identification and flaw remediation and establishes a process for taking corrective actions.
      2. Malicious Code Protection. Riskonnect: (i) employs malicious code protection mechanisms at information system exit and entry points (including web browsers and email) to detect and eradicate malicious code; (ii) updates malicious code protection mechanisms whenever new releases are available and maintains organizational configuration management policy and procedures for managing such updates; (iii) configures malicious code protection mechanisms to perform periodic scans of the information systems; (iv) blocks, quarantines, or both, malicious code and maintains systems that send alerts to system administrator(s) in response to malicious code detection; and (v) addresses the receipt of false positives during malicious code detection and eradication, as well as all resulting potential impact on the availability of the information systems.
      3. Information System Monitoring. Riskonnect: (i) monitors the information systems to detect attacks and indicators of potential attacks, and unauthorized local, network, and remote connections and identifies unauthorized use of the information system; (ii) deploys monitoring devices strategically within the information system and at ad hoc locations within the system; (iii) protects information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion; (iv) heightens monitoring activity when increased risk to organizational operations, assets, individuals, other organizations, or the nation is indicated; (v) obtains legal opinion with regard to information system monitoring activities in accordance with applicable laws, Executive Orders, directives, policies, or regulations; and (vi) provides information system monitoring information to appropriate personnel as needed.