The file's text, extracted by GovTribe without its formatting.
Exhibit 1.1 (Definitions) Solicitation No. 5400028075
Managed Cloud Services
Exhibit 1.1 Definitions
Solicitation No. 5400028075
Exhibit 1.1 DefinitionsWhen used in this Contract with initial capital letters, the terms listed in this Exhibit shall have the meanings set forth herein.
Acceptance or Accepted
The determination, in the State’s reasonable discretion and in accordance with Exhibit 1.4 (General Provisions), Section 2.5 Acceptance, confirmed in writing by the State, that Software, Equipment, Systems, and/or other Deliverables are in Compliance, in accordance with Exhibit 1.4 (General Provisions), Section 11.4.3 Developed Materials Compliance and the Services Management Manual (SMM) or other criteria agreed to in writing by the Parties.
Acceptance Criteria
The criteria that Service Provider must confirm have been met prior to submitting a Deliverable for Acceptance by the State. Acceptance Criteria include: (i) any mutually agreed written criteria identified as Acceptance Criteria, (ii) Compliance, (iii) for all Software and System deliverables that process data, such item successfully integrates with all other Services, Software, Equipment, Systems, and other resources and is fully documented such that the anticipated end user can utilize the functionality of such Deliverable in the manner and for the purpose intended and that reasonable knowledgeable professionals can understand, maintain, support, and modify such Deliverable in accordance with its intended use.
Acceptance Review Period
Has the meaning given in Exhibit 1.4 (General Provisions), Section 2.5.4 Acceptance Review Period provided that any provision of written notice alerting the State that a Milestone Deliverable is complete and ready for review that is submitted outside a Business Day shall be considered to be submitted for the purpose of the State’s internal review, on the Business Day immediately following the day on which such notice was submitted.
| Action Plan or Corrective Action Plan (CAP) |
| A written plan detailing measures to be taken to correct a deficiency or resolve an identified problem. |
Acquired Items
Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Indemnification – Intellectual Property.
| Addendum |
| A modification of the Solicitation issued by the State. |
| Admin |
| Means the South Carolina Department of Administration. |
| Affiliate |
| With respect to an Entity, any other Entity that directly or indirectly Controls, is Controlled by, or is under common Control with that Entity at the time in question. |
| API |
| Application Program Interface. |
| Applications and Applications Software |
| All software programs and programming (and all modifications, replacements, Upgrades, enhancements, documentation, materials, media, on-line help documentation and tools related thereto) that perform user or Customer-related information processing functions or support day-to-day operations (including the supporting documentation, media, online help facilities, and tutorials), or otherwise used in the provision of Services by Service Provider. Applications include all such programs and programming in use or required to be used as of the Commencement Date. Applications also include all such programs and programming developed and/or introduced by or for the State or Service Provider during the Term. Applications do not include the Management Tools, utilities, or Operating Software or Systems Software used to deliver Applications. |
| Application Instance |
| An Application Instance is an operating instance of an Application running in production with its own unique process ID. |
| Assessment Notice Date |
| Means the date on which the State notifies the Service Provider that that the Security Assessment concludes that the security program does not meet or exceed the Standards of Due Care as set forth in Exhibit 2.1.1 (Managed Cloud Services Statement of Work – State Agencies) and Exhibit 2.1.2 (Managed Cloud Services Statement of Work – Other Government Entities) Section 5.8 Security Assessments. |
| Assistance Event |
| Means any termination (in whole or in part) under, or the expiration of, the Contract, or the discontinuance of the provision of the Services (in whole or in part) in respect of any Customer. |
| At-Risk Amount |
| For any month during the Term, the percent (%) of the Service Level Program Revenue Earned Amount, which is the maximum amount that the Service Provider will have at risk for Service Level Credits as set forth in Exhibit 3.1 (Service Level and Deliverable Matrix). |
| Audit Period |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 7.7 Audit Rights. |
| Authority |
| Has the meaning given in Solicitation Document (Managed Cloud Services), Article I. Mandatory Contract Clauses. |
| Authorized User(s) |
| Unless otherwise indicated, the officers, directors, employees, contractors, agents, Customers, State technical staff, or any other person(s) designated by State to receive or use the Systems or Services provided by Service Provider. |
| Availability or Available |
| The period for which the full functionality of a Service component is ready for use by Authorized Users and is not degraded in any material respect. |
| Availability Management |
| Means processes to ensure Services are available as contemplated by the Contract, including new or modified IT service management methodologies and tools, as well as technology modifications or upgrades of IT infrastructure systems and components. |
| Benchmarker, Benchmarking |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 8.4 Benchmarking Reviews. |
| Billing Month |
| Has the meaning given in Exhibit 4.0 (Business Model). |
| Business Continuity Plan |
| Means a collection of procedures and information which is developed, compiled, and maintained in readiness for use in the event of an emergency or disaster. |
| Business Continuity Services |
| Means the overall enterprise plans and specific activities of each Customer and/or Service Provider that are intended to enable continued business operations in the event of any unforeseen interruption (e.g., plans and activities to move a department to a new location in the event of a disruption). |
| Business Day |
| Means as defined in SC Procurement Code [11-35-310(4)]. |
| Business Hours |
| The Customer’s business hours are 8:30 am to 5:00 pm EST, Monday – Friday, except State and federal holidays. |
| CAB |
| See “Change Advisory Board”. |
| Call |
| A contact (including by telephone, voicemail, electronic mail, fax, automated tool, or web request) to Service Provider reporting a problem, requesting assistance or Services, or asking a question pertaining to the Services, as well as automated alerts and other problems and Service notifications communicated to Service Provider. |
| CAP Failure Credit |
| Has the meaning given in Exhibit 3.0 (Performance Model). |
| Capacity Management |
| Means the processes responsible for ensuring that the elements that collectively make up the Service can deliver the identified capacity in a cost effective and timely manner. |
| Change(s) |
| Any addition, modification, alteration, or deletion to (i) any installed and supported IT Equipment or Software components, or (ii) the policies, procedures, or documentation on how Services are performed. This includes all production, test, and development system Equipment and Software, any management and support tools and utilities deployed in the IT environment, all associated documentation, as well as the methodologies used to manage and support delivery of the Services. |
Changes may arise reactively in response to Incidents or Problems or externally imposed requirements (e.g., legislative Changes), or proactively from attempts to (i) seek greater efficiency or effectiveness in the provision or delivery of Services; (ii) reflect business initiatives; or (iii) implement programs, Projects, or service improvement initiatives.
Changes must be approved by the State, through the Change Management process, prior to implementation.
| Change Advisory Board (CAB) |
| The representative group that is responsible for assessing from both a business and technical viewpoint all high impact request for Change. |
| Change Control Procedures |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 7.5 Change Control. |
| Change Management or Change Management Process |
| The processes relating to planning and performing all Changes in Customer's IT environment pertaining to the Services, including Changes to individual components and coordination of Changes across all components. The Change Management Processes will support and include checkpoints to determine any potential or required Change Control procedures. |
| Charges |
| Means the fees defined in Exhibit 4.0 (Business Model). |
| CJIS |
| Criminal Justice Information System. |
| Clearing |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security – Safeguarding Requirements. |
| Cloud Service Provider (CSP) |
| Computing services offered by third-party providers of scalable and elastic IT-enabled capabilities, provided as a service to external customers using Internet technologies. Also referred to as hyperscale cloud providers, providers may include, but are not limited to Amazon Web Services, Microsoft Azure, Google Cloud, IBM Cloud, etc. |
| CMDB |
| Configuration Management Database. |
| Commencement Date |
| The date the Parties agree upon, in writing, as the date on which Service Provider begins providing the Services to the first Customer. |
| Commercial Off-The-Shelf (COTS) |
| Services, Equipment, and/or Software, as applicable, that is readily available to the public from a Third Party that is not an Affiliate of a Party. |
| Compliance (also Comply) |
| With respect to Deliverables, fulfilling the requirements of the specifications, the Acceptance Criteria, the Contract, and all other applicable operational and/or functional requirements. |
| Compromise |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security – Definitions. |
| Confidential Information |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 9.1.1 Confidential Information. |
| Configuration as Code (CaC) |
| Configuration as Code (CaC) is an approach to managing and provisioning computer infrastructure and configurations using machine-readable code or scripts, rather than manual configuration processes. It involves defining and maintaining system configurations, software deployments, and infrastructure resources as code, which can be version-controlled, automated, and easily reproduced. |
| Configuration Item (CI) |
| Any component part of Services that is (or is to be) under the control of Configuration Management and therefore subject to formal Change Control. |
| Configuration Management |
| The process of identifying and defining the functional and physical characteristics of any Equipment or Software in the Service recipient environment, controlling any modifications to any Configuration Item (CI) characteristics throughout their life cycle, tracking, recording, and updating any CMDB as a result of any Changes, and reporting on the status of and verifying the completeness, accuracy, and currency of CI data. |
| Configuration Management Database (CMDB) |
| A System that contains details regarding the Software, Equipment, and Systems that are used in the provision and management of Services, including information that relates to the maintenance, movement and problems experienced with such Software, Equipment, and Systems. |
| Contract |
| Has the meaning given in Solicitation Document (Managed Cloud Services), Article I. Mandatory Contract Clauses. |
| Contract Change(s) |
| Means any change to any provision of the Contract, in accordance with the applicable process. |
| Contract Performance Incentive (CPI) |
| The Service Provider’s proposed initiatives to create value in areas that are not already identified and required in the Contract. Contract Performance Incentives are outcome-based performance incentives that are designed to reward innovation investments that create value that is shared between the Service Provider and the State. |
| Contract Records |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 7.7 Audit Rights. |
| Contract Year |
| Each twelve (12) month period commencing each July and ending each June during the Term. If any Contract Year is less than twelve (12) months (“Stub Period”), the rights and obligations under this Contract that are calculated on a Contract Year basis will be proportionately adjusted for such shorter period. |
| Contractor |
| See “Service Provider”. |
| Control (also Controlled, Controlling) |
| (a) the legal, beneficial, or equitable ownership, directly or indirectly, of (i) at least fifty percent (50%) of the aggregate of all voting equity interests in an Entity, or (ii) equity interests having the right to at least fifty percent (50%) of the profits of an Entity or, in the event of dissolution, to at least fifty percent (50%) of the assets of an Entity; (b) the right to appoint, directly or indirectly, a majority of the board of directors; (c) the right to Control, directly or indirectly, the management or direction of the Entity by contract or corporate governance document; or (d) in the case of a partnership, the holding by an Entity (or one (1) of its Affiliates) of the position of sole general partner. |
| Control Deficiency |
| Has the meaning given in Section 7.5 SOC 2 Reports of Exhibit 1.4 (General Provisions). |
| Controlled Penetration Tests |
| Means a type of Assessment that tests the vulnerability of Systems to unauthorized external interventions or improper uses. |
| Corrective Action Plan (CAP) |
| Means a written action plan prepared by Service Provider that (i) clearly identifies the applicable problem or failure, (ii) describes the desired situation going forward, and (iii) sets forth the specific steps that shall be taken to solve the identified problem or correct the identified failure. |
| Cover Page |
| Has the meaning given in Solicitation Document (Managed Cloud Services), Article I. Mandatory Contract Clauses. |
| Crisis |
| Any situation that is threatening or could threaten to harm people or property, seriously interrupt business, significantly damage reputation and/or negatively impact the bottom line. |
| Critical Deliverables |
| Means the One-Time Deliverables and Recurring Deliverables that have associated Deliverable Credits payable to State in the event Service Provider fails to successfully and timely complete such Deliverables as identified in Exhibit 3.1 (Service Level and Deliverable Matrix). |
| Critical Service Level |
| Any Service Level designated as "critical" by State in Exhibit 3.1 (Service Level and Deliverable Matrix), and with respect to which State may become entitled to receive Service Level Credits as a result of Service Provider's failure to satisfy the associated Service Level standards. |
| Critical Uptime |
| Means the aggregate number of minutes in the specified period(s) in the applicable Measurement Window during which a defined Service component is required to be Available. Unless otherwise specified in the Contract, the Service Management Manual, or the CMDB, Critical Uptime equals the total number of minutes in the Measurement Window. A defined Service component is not required to be Available during Scheduled Downtime. |
| CSS |
| Cascading Style Sheet. |
| Customer |
| Means the State in its capacity as a recipient of the Services and State Agencies, Other Government Entities, organizations or entities that receive services through this contract under oversight and governance of the State. |
| Data |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security – Definitions. |
| Deliverable |
| All Materials, processes, inventions, Work Products, and information that Service Provider develops for or on behalf of the State, in whole or in part, solely or jointly with others, including all intermediate and partial versions thereof in whatever medium fixed or embodied, and any and all documentation relating thereto, including any code (including source and object), scripts, APIs, interfaces, menus, structures, operational instructions, text, graphics, animation, audio or digital video components, specifications, data, reports, schematics, research, configurations, flow charts, knowledge bases, notes, outlines, formulae, training materials, documentation, manuals, processes, algorithms and the like created in connection therewith, whether or not protected by copyright, patent, trademark law, or any similar intellectual property law and all materials developed or created by Service Provider for the State under Statements of Work. |
| Deliverable Charges |
| Has the meaning given in Exhibit 4.0 (Business Model). |
| Deliverable Credits |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 5.3 Deliverable Credits. |
| Depositor |
| Has the meaning given in Attachment B (Form of Source Code Escrow) to the Contract. |
| Deposit Materials |
| Has the meaning given in Attachment B (Form of Source Code Escrow) to the Contract. |
| Derivative Work(s) |
| Work based on one (1) or more preexisting works, including a condensation, transformation, translation, modification, expansion, or adaptation, that, if prepared without authorization of the owner of the copyright of such preexisting work, would constitute a copyright infringement under applicable Laws, but excluding the preexisting work. |
| Designated State Representative |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 8.1.1 Designated State Representative. |
| Developed Material(s) |
| Any new Materials or any modifications, enhancements, improvements, Upgrades, or Derivative Works of such Materials that are developed pursuant to the Contract and paid for by the State under the Contract. Developed Materials does not include any underlying Service Provider or Third-Party Owned Materials. |
| Development and Testing |
| A software development process that involves synchronized application of a broad spectrum of defect prevention and detection strategies in order to reduce software development risks, time, and costs. |
| Development or Development Environment |
| The Systems environment in which Software and databases are initially designed and created. Customers may have more than one Development Environment. |
| Development Tool |
| All software programs and programming (and all modifications, replacements, upgrades, enhancements, documentation, materials, and media related thereto) that are used in the development, testing, deployment, and maintenance of Software. Development Tools shall include all such programs and programming in use or required to be used as of the Commencement Date. Development Tools also shall include all such programs and programming developed and/or introduced by or for the State during the Term. |
| DevOps |
| A set of software development practices that combine software development (Dev) and information technology operations (Ops) to shorten the systems development life cycle while delivering features, fixes, and updates frequently in close alignment with business objectives. |
| DIS |
| Division of Information Security. |
| Disaster |
| Means (a) a sudden, unplanned calamitous event causing great damage or loss; (b) any event that creates an inability on an organizations part to provide critical business functions for some predetermined period of time; (c) in the business environment, any event that creates an inability on an organization's part to provide the critical business functions for some predetermined period of time; (d) the period when company management decides to divert from normal production responses (in total or in part) and exercises its disaster recovery plan; and (e) typically signifies the beginning of a move from a primary to an alternate location. |
| Disaster Recovery (DR) Services |
| The process of following specific advance arrangements and procedures in response to a Disaster, resumption of the critical business functions within a predetermined period of time, minimizing the amount of loss, and repairing or replacing the damaged facilities as soon as possible. Disaster Recovery Services include support and coordination with the Business Continuity Services. |
| Disaster Recovery Plan (DRP) |
| The plan to execute Disaster Recovery Services. |
| Disaster Recovery Test Plan |
| Consists of the plan and schedule to test the Disaster Recovery Plan. |
| Document Repository |
| A repository to store and manage all State Managed Security Services documentation, including the Service Management Manuals, knowledge bases of Services, known errors and workarounds, training content, Frequently Asked Questions, and similar documentation for the Service Provider’s organization as well as from other Service Providers as specified by State. |
| DTO |
| Division of Technology Operations. |
| DTO Administrative Fee |
| Has the meaning given in Managed Cloud Services Solicitation, Section G.4 DTO Services Administrative Services Fee. |
| Earnback |
| Means the methodology used to determine the potential return of a Service Level Credit as described in Exhibit 3.0 (Performance Model). |
| Effective Date |
| Means the first day of the contract as specified on the final Statement of Award. |
| Electronic PHI or ePHI |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 9.3 State Personal Data. |
| Enhancement |
| Means the introduction of a change that modifies or adds functionality to an existing Application. Enhancements include Major Enhancements and Minor Enhancements. |
| Entity(ies) |
| A governmental body, agency, unit, or division (including those categories described in the definition of Customer), corporation, partnership, joint venture, trust, limited liability company, limited liability partnership, association, or other organization or entity. |
| Equipment |
| Means the computer, telecommunications, and facility-related hardware, equipment, and peripherals (and all modifications, replacements, Upgrades, enhancements, documentation, materials, and media related thereto) that are used in connection with the Services by Service Provider. |
| Equipment Leases |
| Means all leasing arrangements whereby the State, Service Provider, or any State Contractor leases Equipment as of the Effective Date which shall be used by Service Provider to perform the Services after the Effective Date. Equipment Leases shall include all such leasing arrangements entered into by or for the State, any State Contractor, or Service Provider during the Term. |
| Escrow Agent |
| Has the meaning given in Attachment B (Form of Source Code Escrow) to the Contract. |
| Escrow Agreement |
| Has the meaning given in Attachment B (Form of Source Code Escrow) to the Contract. |
| Escrow Agreement Effective Date |
| Has the meaning given in Attachment B (Form of Source Code Escrow) to the Contract. |
| Expected Service Level |
| Means the desired level of performance as set forth in Exhibit 3.2 (Service Level Definitions) with respect to each Service Level. |
| Expected Service Level Default |
| Service Provider's level of performance for a particular Key Service Level fails to meet the applicable Expected Service Level (but does not fail to meet the applicable Minimum Service Level), as specified in Exhibit 3.0 (Performance Model), and has failed to meet such Expected Service Level for four (4) or more occurrences in any rolling twelve (12) month period. |
| Extraordinary Event |
| Has the meaning given in Exhibit 4.0 (Business Model). |
| Facility(ies) |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 4.1 Service Facilities. |
| FAQ(s) |
| Frequently Asked Question(s) |
| Federal Tax Information (FTI) |
| Any Federal tax information, including without limitation, and tax return-derived information received from the IRS. |
| Fixed Charge |
| A set amount paid for work or a service and is independent of a time and effort required to produce the identified deliverable. |
| Freedom of Information Act |
| South Carolina Freedom of Information Act, S.C. Code Ann. Section 30-4-10, et seq. |
| Full Time Equivalent (FTE) |
| A level of effort, excluding vacation, holidays, training, administrative and other non-productive time (but including a reasonable amount of additional work outside normal business hours), equivalent to that which would be provided by one person working full time for one year. Unless otherwise agreed, one FTE is assumed to be 1,920 productive hours per year. Without the State's prior written approval, one dedicated individual's total work effort cannot amount to more than one FTE. |
| Governance Committee |
| Has the meaning given in Exhibit 1.2 (Governance Model). |
| Governance Escalation Event |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 8.3 Governance Escalation Event. |
| Government Information |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security - Definitions. |
| GRC |
| Governance, Risk, and Compliance. |
| High Availability / Fault Tolerant |
| High Availability refers to a failover feature to ensure availability during device or component interruptions. |
Fault Tolerant refers to a system having the built-in capability to provide continue, correct execution of its assigned function in the presence of a hardware and/or software fault.
| HIPAA |
| Health Insurance Portability and Accountability Act. |
| HIPAA Privacy Rule (45 CFR Parts 160 and 164, Subparts A and E) |
| The national standards protecting individuals’ medical records and other protected health information and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically. The Rule requires appropriate safeguards to protect the privacy of protected health information and sets limits and conditions on the uses and disclosures that may be made of such information without patient authorization. The Rule also gives patient’s rights over their health information, including rights to examine and obtain a copy of their health records, and to request corrections. |
| HIPAA Security Rule (45 CFR Parts 160 and 164, Subparts A and E) |
| The national standard protecting individuals’ electronic protected health information that is created, received, used, or maintained by a covered entity. The HIPAA Security Rule requires appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information. |
| IaaS |
| See “Infrastructure as a Services”. |
| IaC |
| See “Infrastructure as Code”. |
| Impact |
| Has the meaning given in Exhibit 3.0 (Performance Model), Section 19 Priority Levels - Introduction. |
| In Writing, Writing, or Written |
| Has the meaning given in Solicitation Document (Managed Cloud Services), Article I. Mandatory Contract Clauses. |
| Incident |
| An event which is not part of the standard operation of a service, and which causes or may cause disruption to or a reduction in the quality of services and State productivity. |
| Incident Management |
| Means process with the primary goal to restore normal Service operations as quickly as possible and minimize the adverse impact on business operations, thus ensuring that the best achievable levels of service quality and availability are maintained. Normal service operation is defined here as Service operation within Service Level limits. |
| Incident Management System |
| Means an automated system used to track the status of Incident Records defined and maintained by Service Desk personnel. |
| Incident Record |
| Means the information captured by Service Desk personnel about an Incident. |
| Incumbent Service Provider |
| The vendor and their Subcontractors currently providing cloud services to the State, as well as the State team performing in-scope Services. |
| Information |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security - Definitions. |
| Information Custodian |
| Entity responsible for being a steward of State Data and ensuring that the data is classified, used, and protected appropriately. |
| Information Security Configuration Controls (ISCC) |
| Information Security Configuration Controls (ISCC) refer to specific measures and settings established to secure the configuration of IT systems, networks, and software. ISCCs are designed to minimize security vulnerabilities by enforcing predefined configurations that align with security policies and best practices. These controls help prevent unauthorized access, data breaches, and other security risks associated with misconfigurations. |
| Information System |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security - Definitions. |
| Information Technology Infrastructure Library (ITIL) |
| A world-wide recognized best-practice framework for the management and delivery of IT services throughout their full lifecycle. |
| Infrastructure (also IT Infrastructure) |
| The entire portfolio of Equipment, System Software, and Network components required for the integrated provision and operation of State IT systems and Applications. |
| Infrastructure as Code (IaC) |
| Defining of, provisioning, deployment, management, and auditing resources and applications through code in lieu of manual procedures. |
| Infrastructure as a Service (IaaS) |
| The capability provided to provision processing, storage, networks, and other fundamental computing resources where the Customer is able to deploy and run arbitrary software, which can include operating systems and applications. The Customer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, and deployed applications; and possibly limited control of select networking components (e.g., host firewalls). |
| Initial Term |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Term of Contract – Effective Date / Initial Contract Period. |
| In-Scope |
| Those Services or resources that are the subject of Service Provider's obligations under the Contract. |
| Intrusion |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security – Safeguarding Requirements. |
| IP Rights |
| Means all rights in and to United States and foreign (i) patents, patent disclosures, and inventions (whether patentable or not), (ii) trademarks, service marks, trade dress, trade names, logos, corporate names, and domain names, and other similar designations of source or origin, together with the goodwill symbolized by any of the foregoing, (iii) copyrights and works of authorship (whether copyrightable or not), including computer programs, and rights in data and databases, (iv) trade secrets, know-how, and other confidential information, and (v) all other intellectual property rights, in each case whether registered or unregistered, and including all registrations and applications for, and renewals or extensions of, such rights, and all similar or equivalent rights or forms of protection in any part of the world. |
| IRS |
| Internal Revenue Service. |
| ISO |
| International Organization for Standards. |
| ITIL |
| See “Information Technology Infrastructure Library”. |
| IT Service Continuity Management (ITSCM) |
| Means the process of ensuring that identified IT Services will be available during abnormal situations. It typically involves a detailed assessment of the business risk of key IT services being lost and then identifies countermeasures and plans to prevent - or recover from - identified contingencies. |
| IT Service Management (ITSM) |
| The entirety of activities – directed by policies, organized, and structured in processes and supporting procedures — that are performed by an organization or part of an organization to plan, deliver, operate, and control IT services offered to customers. |
| IT Technology Plan and Roadmap |
| Has the meaning given in Exhibit 2.1.1 (Managed Cloud Services Statement of Work – State Agencies), Section 3.10 Technology Roadmap and Exhibit 2.1.2 (Managed Cloud Services Statement of Work – Other Government Agencies), Section 3.11 Technology Roadmap and its associated Exhibits and Attachments. |
| ITSCM |
| Information Technology Service Continuity Management. |
| Key Personnel |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 6.1 Key Personnel. |
| Key Service Level |
| Means those Service Levels for which no Service Level Credit is payable and are described in Exhibit 3.0 (Performance Model). |
| Knowledge Database |
| Means a repository of information used in provision of the Services; inclusive of the Known Error Database. |
| Known Error |
| Means a Problem where the root cause is known and a temporary Workaround or permanent alternative has been identified. |
| Known Error Database |
| Means a repository for all data on the CIs, symptoms, and resolution or circumvention actions relating to all known errors. |
| Laws |
| All federal, state, and local laws, statutes, ordinances, regulations, rules, executive orders, circulars, opinions, interpretive letters, and other official releases of or by any government, or any authority, department, or agency thereof. |
| Level 1 Support |
| Support that is provided as the entry point for inquiries or problem reports from Authorized Users. If Level 1 personnel cannot resolve the inquiry or problem, the inquiry or problem is directed to the appropriate Level 2 personnel or a Third Party for resolution. |
| Level 2 Support |
| Support that serves as a consolidation point for inquiries and problems between Level 1 and Level 3. If Level 2 personnel cannot resolve the inquiry or problem, the inquiry or problem is directed to the appropriate Level 3 personnel or a Third Party for resolution. |
| Level 3 Support |
| Support provided by the personnel or Third Party that is most knowledgeable about the underlying problem or question and that is utilized when efforts to resolve the problem or question by Level 1 and Level 2 Support have failed or are bypassed. Inquiries or problems are usually reported by Level 1 or Level 2 Support personnel but may be initiated directly by Authorized Users or the Service Provider. This also includes working directly with OEM and Software manufacturer regarding major incidents or problems that require advanced Services. |
| LDAP |
| Lightweight Directory Access Protocol; application protocol for accessing and maintaining distributed information services over an Internet Protocol (IP) network. |
| LMS |
| Learning Management System. |
| Losses |
| All losses, liabilities, damages (including punitive and exemplary damages), fines, penalties, settlements, judgments, interest, and claims (including taxes), in each case that a court finally awards to a third party or which are otherwise included in the amount payable to a third party and all related costs and expenses (including reasonable legal fees and disbursements and costs of investigation, litigation, experts, settlement, judgment, interest, and penalties), as incurred. |
| Maintenance Period |
| See “Scheduled Downtime”. |
| Major Incident |
| The highest category of impact for an Incident. A Major Incident results in significant disruption to business operations. |
| Major Release |
| A new version of Software that includes changes to the architecture and/or adds new features and functionality in addition to the original functional characteristics of the preceding Software release. These releases are usually identified by full integer changes in the numbering, such as from "7.0" to "8.0," but may be identified by the industry as a major release without the accompanying integer change. |
| Malicious Code |
| Means (i) any code, program, or sub-program whose knowing or intended purpose is to damage or interfere with the operation of the computer system containing the code, program, or sub-program, or to halt, disable, or interfere with the operation of the Software, code, program, or sub- program, itself, or (ii) any device, method, or token that permits any person to circumvent the normal security of the Software or the system containing the code. |
| Malware |
| Software that is specifically designed to disrupt, damage, or gain unauthorized access to a computer system (for clarity, Malware also includes Ransomware). |
| Management Tools |
| All items used by Services Provider to deliver and manage the Services, including but not limited to software products and tools, code, scripts, bots, automation, and any and all methods, processes, inventions, machines, compositions, know-how, and show-how related thereto (and all modifications, replacements, Upgrades, improvements, enhancements, documentation, materials, and media related thereto). Management Tools shall include all such products and tools in use or required to be used as of the Commencement Date, including those set forth in Exhibit 3.2 (Service Level Definitions), those as to which the license, maintenance, or support costs as required by Exhibit 4.2 (Financial Responsibility Matrix), and those as to which Service Provider received reasonable notice and/or access prior to the Commencement Date. Management Tools also shall include all such products and tools selected and/or developed by or for the State or Service Provider during the Term. |
| Master Security Baseline Configuration (MSBC) |
| A standardized and predefined set of security settings and configurations for computer systems, networks, or software applications. MSBCs serve as a foundational security framework that organizations can use as a starting point to secure their IT assets, ensuring consistent and well-defined security controls are in place. |
| Materials |
| All algorithms, APIs, apparatus, circuit designs and assemblies, databases and data collections, designs, diagrams, documentation, drawings, flow charts, formulae, ideas and inventions (whether or not patentable or reduced to practice), know-how, literary works or other works of authorship, materials, marketing and development plans, marks (including brand names, product names, logos, and slogans), methods, models, network configurations and architectures, procedures, processes, protocols, schematics, Software code (in any form including source code and executable or object code), specifications, subroutines, techniques, tools, uniform resource identifiers, user interfaces, web sites, works of authorship, and other forms of technology and intellectual property; and all modifications, replacements, upgrades, enhancements, improvements, methodologies, tools, documentation, materials, and media related thereto. |
| Measurement Window |
| The time during, or frequency by which a Service Level shall be measured. The Measurement Window will exclude approved scheduled maintenance. |
| Media |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security – Safeguarding Requirements. |
| Middleware |
| Software that facilitates interactions and integration between and among two (2) or more separate Software programs, Systems, or platforms. |
| Minimum Compliant Item |
| Has the meaning given in Exhibit 3.0 (Performance Model). |
| Minimum Service Level |
| Means the minimum level of performance set forth in Exhibit 3.2 (Service Level Definitions) with respect to each Service Level. |
| Minimum Service Level Default |
| The Service Provider's level of performance for a particular Critical Service Level fails to meet the applicable Minimum Service Level at any time. |
| Minor Release |
| A revision of a specification that may add or enhance functionality, fix bugs, and make other changes from the previous revision, but the changes have minimal impact, if any, on backward compatibility. These releases are usually identified by an incremental change to the number after the decimal point, such as from "7.1" to "7.2". |
| Monthly Charges |
| The total Charges earned by Service Provider in any calendar month for Services (excluding Pass-Through Expenses, Out-of-Pocket Expenses, and Service Taxes). |
| Monthly Invoice |
| Has the meaning given in Exhibit 4.0 (Business Model). |
| Monthly Productive Hours Worked |
| With respect to any month and any Service Provider Personnel, the number of productive hours worked by such Service Provider Personnel, excluding non-productive time (e.g., commuting time, vacation, holidays, training unrelated to the Services, education, marketing, administrative staff meetings, medical leave, and military leave). |
| “N” Release Level |
| Means the current release level of any Software product. |
| N-1 or N-n |
| Means NVP or N-Version Programming which are a method of designating program level or program currency. For example, N-1 means that the program or software in place is one (1) release level less than the now-current version of that product. |
| Network |
| Collectively, WAN, LAN, and other communication or transport networks. |
| Network Topology |
| The arrangement in which the nodes or interfaces to the Network are connected. |
| New Service(s) |
| Services requested by the State (i) that are materially different from the Services, (ii) that require materially different levels of effort or resources from Service Provider to provide the Services, and (iii) which are not required for Service Provider to meet the Service Levels. |
For the avoidance of doubt, New Services shall not include (i) increases in the volume of Services for which there is an associated charging methodology, or (ii) the disaggregation of an existing service from a functional service area.
| NIST |
| National Institute of Standards and Technology. |
| Noncompliance |
| Each instance that the Software, Equipment, Systems, or other Deliverable or milestone fails to meet its Acceptance Criteria or is otherwise deficient in State’s reasonable discretion (in accordance with the Service Management Manual or other criteria agreed by the Parties, to the extent applicable). |
| OEM |
| Original Equipment Manufacturer. |
| Offeror |
| Any individual, partnership, or corporation submitting a Response. Unless the Contract clearly indicates otherwise, all terms and conditions of the Contract that refer to Offeror apply with equal force to Service Provider. |
| Office of Technology and Information Services (OTIS) |
| The Admin Office of Technology and Information Services (OTIS) oversees the state’s federated model for implementing, enhancing, and protecting information technology (IT) resources and the utilization of IT shared services across agencies. |
| Offshore |
| Refers to an operational location of Service not within one of the fifty (50) United States, or within or directly adjacent to the Continental US. For Managed Security Services, all work must be performed within the continental US. |
| One-Time Critical Deliverables |
| Those Deliverables that are non-recurring that have associated Deliverable Credits payable to Admin in the event Service Provider fails to successfully and timely complete such Deliverables. |
| Onshore |
| Refers to an operational location of Service within the Continental United States of America. |
| Onsite |
| Refers to physical presence at a location of Service delivery. |
| Open Web Application Security Project (OWASP) |
| OWASP seeks to educate developers, designers, architects, and business owners about the risks associated with the most common web application security vulnerabilities. OWASP supports both open source and commercial security products. |
| Operating Software |
| Means all software programs and programming (and all modifications, replacements, Upgrades, enhancements, documentation, materials, and media related thereto) that perform tasks basic to the functioning of the Equipment and are required to operate the Applications Software or otherwise support the provision of Services by the Service Provider including any systems utilities software. |
| Other Government Entity |
| Any South Carolina local or state organization that is not officially part of the State Agencies included in the 2025 – 2026 Appropriations Act, Part 1B, Section 117.107. Or, not included as State Agencies in subsequent years and similar sections. |
| Out-of-Pocket Expenses |
| Reasonable, demonstrable, and actual expenses due and payable to a Third Party by Service Provider that are approved in advance by State and for which Service Provider is entitled to be reimbursed by State under the Contract. Out-of-Pocket Expenses shall not include Service Provider’s overhead costs (or allocations thereof), general and/or administrative expenses or other markups. Out-of-Pocket Expenses shall be calculated at Service Provider’s actual incremental expense and shall be net of all rebates and allowances. |
| Outage(s) |
| A condition such that a System, Service, Application, Equipment, or network component is not Available or is substantially not Available and is impacting normal business operations. |
| PaaS |
| See Platform as a Service. |
| Page Two |
| Has the meaning given in Solicitation Document (Managed Cloud Services), Article I. Mandatory Contract Clauses. |
| Party(ies) |
| Has the meaning given in the recitals to the Contract. |
| Pass-Through Expense(s) |
| The Service Provider expenses listed in Exhibit 4.0 (Business Model) which the State has agreed to pay directly or reimburse to Service Provider on an Out-of-Pocket Expenses basis. |
| Payment Deliverables |
| Those Deliverables that have associated payments due to the Service Provider after the State’s approval of such Deliverables. Payment will be provided in accordance with the Contract. |
| PCI |
| Payment Card Industry. |
| PCI DSS |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 9.3 State Personal Data. |
| Performance Testing |
| A level of software testing in which software functions, systems, and components are combined and tested evaluate compliance to defined requirements, business needs, policies, and standards to determine how a system will perform in terms of responsiveness and stability under a defined workload. |
| Phishing |
| A type of cyberattack that uses email, phone, or text to entice individuals into providing personal or sensitive information, ranging from passwords, credit card information, and social security numbers to details about a person or organization. |
| PII |
| Personally Identifiable Information. |
| PIR |
| Post Implementation Review. |
| Platform as a Service |
| The capability to deploy onto the cloud infrastructure Customer-created or acquired applications created using programming languages, libraries, services, and tools supported by the provider. The Customer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting. |
| PMO |
| Project Management Office. |
| POE |
| Proof of Entitlement. |
| Portal |
| The online Internet site providing access and links to Services and other applications |
| Pool Percentages Available for Allocation |
| Means a percent (%) of the At-Risk Amount as indicated in Exhibit 3.1 (Service Level and Deliverable Matrix), on the Service Levels tab(s). Each service tower will have its own Pool Percentage Available for Allocation. |
| PPM |
| Program and Project Management. |
| Pre-Commencement |
| Period between the Effective Date and the Commencement Date of the Contract. |
| Priority |
| Measurement of urgency and impact and is used to determine the order of importance of an incident, problem, change, or service request relative to other incidents, problems, changes, and service requests. |
| Priority Level 1 |
| Has the meaning given in Exhibit 3.0 (Performance Model). |
| Priority Level 2 |
| Has the meaning given in Exhibit 3.0 (Performance Model). |
| Priority Level 3 |
| Has the meaning given in Exhibit 3.0 (Performance Model). |
| Priority Level 4 |
| Has the meaning given in Exhibit 3.0 (Performance Model). |
| Pre-Commencement |
| Period between the Effective Date and the Commencement Date of the Contract. |
| Problem(s) |
| An underlying cause of one (1) or more Incidents. A Problem is labeled a “Known Error” when the root cause is known and a temporary workaround or permanent solution has been identified. |
| Problem Management |
| The process of tracking and managing all problems arising in the State’s environment and resolving those problems arising from or related to the Services. |
| Procurement Officer |
| Has the meaning given in Solicitation Document (Managed Cloud Services), Article I. Mandatory Contract Clauses. |
| Production or Production Environment |
| The system environment in which an organization's data processing is accomplished. This environment contains Customer's business data and has the highest level of security and availability of all environments (includes training and other Production-like environments). |
| Project(s) |
| In accordance with Exhibit 1.4 (General Provisions), Section 2.6 Projects and Exhibit 4.0 (Business Model), means a discrete unit of work that does not recur on a regular or periodic basis that: (i) has a defined start and end date with documented Deliverables and acceptance criteria; (ii) has been requested and approved by the State; (iii) is not an inherent, necessary or customary part of the day-to-day (i.e., regular, not daily) Services described in the Transition Plan(s), a Project Schedule, or the Contract; (iv) is not required to be performed by Service Provider to meet the existing Service Levels (other than Service Levels related to Project performance); (v) may consist of or include work that would otherwise be treated as New Services; and (vi) is not otherwise part of the Services. |
| Project Work Order |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 2.6 Projects. |
| Proposal |
| Has the meaning given to “Offeror” in Solicitation Document (Managed Cloud Services), Section L.2 Instructions to Offerors. |
| Protected Health Information (PHI) |
| Has the meaning given in Exhibit 1.4 (General Provisions), Section 9.3 State Personal Data. |
| Public Information |
| Has the meaning given in Attachment I.4 (Negotiated Terms and Conditions), Information Security - Definitions. |
| QA/QC |
| Quality Assurance/Quality Control. |
| Quality Assurance (QA) |
| The actions, planned and performed, to provide confidence that all processes, Systems, Equipment, Software, and components that influence the quality of the Services are working as expected individually and collectively. |
| Rate Card |
| A listing of hourly personnel pricing rates as documented in Exhibit 4.1 (Pricing Structure). |
| Receiving Party |
| Has the meaning given in Exhibit 1.4 (General Provisions), Article 9 State Data and Other Confidential Information. |
| Recovery Point Objective (RPO) |
| The recovery point objectives, as designated in Exhibit 2.1.1 (Managed Cloud Services Statement of Work – State Agencies) and Exhibit 2.1.2 (Managed Cloud Services Statement of Work – Other Government Entities), Section 4.12 IT Service Continuity Management, expressed as the acceptable amount of data loss measured in time prior to an event that has been declared as a disaster. |
| Recovery Time Objective (RTO) |
This is the start of the file's text. The full file is on GovTribe.