Laserfiche WebLink
Incident Response <br />WEX has an incident response policy, standard, and procedure that is reviewed, approved, and <br />tested yearly. Procedures contain: incident handling, incident detection and analysis, incident <br />categorization, incident analysis, incident documentation, incident prioritization, incident <br />notification, containment, eradication, and recovery, evidence gathering and handling, identifying <br />the attackers, eradication and recovery, and post -incident activity using collected incident data. <br />Subcontractors <br />The WEX Legal Department, in conjunction with Procurement, performs contract review for <br />service providers and has standard legal language in all contracts that address our security <br />requirements and expectations of subcontractors. <br />7.8 Securing and preventing unauthorized disclosure, misuse, alteration, or destruction of confidential <br />information. <br />WEX employees multiple levels of security with our contractors depending on the level of access <br />they require. WEX prevents unauthorized disclosure, misuse, alteration or destruction of <br />confidential information by utilizing the security protocols and proprietary technological <br />advantages described above for both WEX and our Contractors. See responses in 7.1, 7.5, 7.6, 7.7 <br />and 15.4 for more detail. <br />7.9 Disaster recovery plan (i.e. data breaches, system errors and resolution plans, timeframe for data <br />restoration, backup in case of power failure, etc.). <br />WEX's Organizational Resilience Program Overview was created to provide clients with <br />information identifying and defining the resiliency roles and responsibilities of WEX and our <br />clients in the event operations are impacted due to disruption or disaster. WEX employs multiple <br />call center locations across the country to ensure a given event in one area or region will not <br />render another in operable. The same goes for WEX's authorizer that validates and approves <br />transactions. Both are on separate power grids and housed in multiple locations across the <br />country. In addition to some of these basic precautions, see our business continuity plan: <br />Overview <br />The WEX Business Continuity Plan includes well—defined and documented procedures, designed <br />to respond to unforeseen events. WEX utilizes a step-by-step, standardized incident management <br />process that ensures all requirements relating to proper response, escalation, notification and <br />resolution of a disruption of any type are met. The WEX BCP utilizes the ISO 22301 framework and <br />is integrated with WEX physical and information security, and risk management systems. The WEX <br />BCP adopts a process approach for establishing, implementing, operating, monitoring, reviewing, <br />maintaining, and improving the organization's organizational resilience management system. <br />Review Policy <br />Oversight of business continuity planning is assigned to the Director, Organizational Resilience <br />who ensures that plan updates are completed and that the plan is tested and remains current and <br />relevant. <br />MASTER AGREEMENT No. 00819 - FLEET CARD SERVICES PAGE 108 OF 138 <br />