GPS » Topics » Security Incident Response Team (SIRT) Service Levels

This excerpt taken from the GPS 10-Q filed Jun 9, 2009.

Security Incident Response Team (SIRT) Service Levels

The Service Levels for the evaluation of security vulnerability alerts are defined below. Failure to meet any of the Service Levels set forth below shall be a Service Level Default.

 

Service Levels

  

Definition

  

Floor

Service Level

  

Expected

Service Level

  

Window

  

Service Level

Type as of

Effective Date

Security Vulnerability Evaluation Measurement period starts when a ticket is opened after an alert is received    Evaluate security vulnerability alerts and categorize.    *    *    Monthly    *

 

 

* Certain information on this page has been omitted and filed separately with the Commission. Confidential treatment has been requested with respect to the omitted portions.

 

Exhibit B.1    Gap/IBM Confidential and Proprietary Information    B - 23


LOGO

 

This excerpt taken from the GPS 10-K filed Mar 28, 2006.

Security Incident Response Team (SIRT) Service Levels

The Service Levels for the evaluation of security vulnerability alerts and necessary patch implementations are defined below. Failure to meet any of the Service Levels set forth below shall be a Service Level Default.

 

Service Levels

  

Definition

  

Data Source

  

Floor
Service Level

  

Expected
Service Level

  

Window

  

Service Level
Type as of
Effective Date

Security Vulnerability Evaluation Measurement period starts when a ticket is opened after an alert is received    Evaluate security vulnerability alerts and categorize.   

*

  

*

  

*

  

Monthly

  

*

Critical Patches, Known exploit in the environment Measurement period starts when a ticket is opened, and ends when the patch is available for distribution within the infrastructure    Stage for distribution of a patch to address a vulnerability or known problem to which an exploit exists and is present in the Gap IT Environment.   

*

  

*

  

*

  

Monthly

  

*

Critical Patches, Known exploit outside the environment    Stage for distribution of a patch to address a vulnerability or known problem to which an exploit exists but is not yet present in the Gap IT environment.   

*

  

*

  

*

  

Monthly

  

*

Critical Patches, No known exploit    Apply a patch to address a vulnerability or known problem to which no exploits are currently known.   

*

  

*

  

*

  

Monthly

  

*

 


* Certain information on this page has been omitted and filed separately with the Commission. Confidential treatment has been requested with respect to the omitted portions.

 

Exhibit B.1

   Gap/IBM Confidential and Proprietary Information        B - 19


LOGO

 

EXCERPTS ON THIS PAGE:

10-Q
Jun 9, 2009
10-K
Mar 28, 2006
Wikinvest © 2006, 2007, 2008, 2009, 2010, 2011, 2012. Use of this site is subject to express Terms of Service, Privacy Policy, and Disclaimer. By continuing past this page, you agree to abide by these terms. Any information provided by Wikinvest, including but not limited to company data, competitors, business analysis, market share, sales revenues and other operating metrics, earnings call analysis, conference call transcripts, industry information, or price targets should not be construed as research, trading tips or recommendations, or investment advice and is provided with no warrants as to its accuracy. Stock market data, including US and International equity symbols, stock quotes, share prices, earnings ratios, and other fundamental data is provided by data partners. Stock market quotes delayed at least 15 minutes for NASDAQ, 20 mins for NYSE and AMEX. Market data by Xignite. See data providers for more details. Company names, products, services and branding cited herein may be trademarks or registered trademarks of their respective owners. The use of trademarks or service marks of another is not a representation that the other is affiliated with, sponsors, is sponsored by, endorses, or is endorsed by Wikinvest.
Powered by MediaWiki