2021/05/03 CyberwareSoftwareDistributors, LLC Risk Assessment and Penetration TestDocosign Envelope lDr CF481587-64D9-45E0-9854-419FF0347878 lssuc Datc: May 3,2021 Statement of Work Risk Assessmcnt and Penetrati()n Test For City of Menifec, California 0rrltci):5 CD DocuSign Envelope lD: CF481587-64D9-45E0-9854-B.t9FFO347B7B CD l. Exccutivc Summary cybcrSoftwarcDistributors. LLC shall providc an .rganization rvitlc risk asscssmcnt and penetration tesls with a delined scope.'l-hese services are an evalualion ol'lhe currenl. security posturc on the dcfincd targcts in thc sco;rc in ordcr to gathcr a hasclinc for thc currcnt sccuriry at thc city of Mcnifcc. ln thc ca:;c ofa pcnctration tcst bcing rcquircd allcr a risk asscssmcnt. cybe rSo I'twareDistributon. LI-c will evaluate the rarEet l'rum an "attacker's." penipective. and will cvaluatc findings by exploiting any vulncrabilitics found. The objeclive of these assessnrenls and tesls are to provicle knowleilge ol' rernediation for the customer with respcct to its ability to prescrvc the confidcntiality, inrcgrity and availabitity ofrhe infonnation maintuincd by and used by its origination. cybcrSotfuarcDistributors, LLC will assess and test the use ofsecurity controls to sccure sen-sitive dala. 2. Services Overview This project shall includc 2 consultants for the time period of 6 rvccks remotcly to pro'ide the organization wide risk assessmcnt and pcnctration tests with thc riefined scope- cybcrSoliwarcDistribulors. LLC will providc tools, knowledge. and cxpcrlisc ro cxccutc thc asscssmcnts and tcsls on thc customcr dcsignatcd targcts. cybcrsoltwarcDistributors, LLC can operate with as little or as much knowledge ofthe targets as desired by the customcr contact, with lhe exceptions of required knowledge as delined by the scope. CyberSoftwareDistributors. LLC will assess the targets and artempt to comprornise any dcsignatcd targcls known vulncrabilitics with thc conscnr ollhc city ol'Mcnilcc. An additional scrvice ofsocial cnginccring will hc pcrfbrmcd on contacts dcfincd by thc city of Mcnifcc. Thc risk assessments and penetration tests will be perftrrmed using the tbllowing methodology: l. Enumeration - Once CyberSoftwarcl)istnbutors, LLC begins thc project with The City of Mcnifeel CyberSoftwarcDistributors, LLC will connect to the netu'ork using the ! irtual private network prol idcd by the customer. Once connccted, CyberSoftrvareDistributors, LLC wilt run a variety of inlbrmation gathering tools in ordcr to enumerate computen and devices connected to the networks in question. 2. Vulnerebility Mapping end Penetration Te;ting - Any targets designated will be scanned for vulnerahilitics using a widc !.aricty oftools and tcchniqucs. Thc toots and tcchniqucs uscd will be consistcnr wirh cument industry trcnds rcgarding exploitation of vulnerabiliries. (iybersoftrvareDistributors, LL(. will attempt to lind the wcakest links that can bc cxploitcd and attcmpt to gain funhcr acccss with conscnt from thc City of Menifee. CyberSoftwareDistributors. Ll,C will ancmpt to penetrate thes€ targcts up to an including the point where sensitive data can bc accessed. 3. Report of Risk Assessment and Penetration 'l'est -'fhroughout thc risk asscssmcnts and or pcnctration tcsts. CybcrsoftwarcDistributors. LLC will do('umcnt and rccord cach stBp o[Lhe process. CyberSo{lwareDistributors, I-l-C will provide a repo of the risk asscssmcnts and dcfincd pcnctration rcsrs which will includc data ohtaincd from thc 'czrulldo 'tuourcldrxr 'uSrscp 'puelslcpun 'cz,(lpuu ol scrSolopoqlcr[ 8ur1;nsuor ucao:d Surzrpln aJr^las luarussoss-e lsrJ Jpr,r\ uort8zlueSro uE lJnpuoJ ll!/\{ J'l-l'srolnqulsr(JJlE,rl.losrJq,(J srafeuzred pue 3u;r;r4 g 'luauluo.lrAUa rno{ 1oa-ge ot s)rUed pJzr.rolllnp .ro pozuoqlnerm ,{q slsu ;1e ctuururlc:ou .{.11ucpt -tcqlrcu ueo scJl^rJs csaql 'crntsod ,Qunocs Jno,{ J.{oJdrur fuur 'lusodord slrlt ql!,n cJuBpJo])B ur pcpr^oJd sB 'seJr^Jcs oscql Jo cJuprruoJJcd aqt reql ee.rie pue puetsl)pun ealru:61 9o &t3 aqt puu J-l-l 'srotnqu1slqrlpmgog:cqf 3 I 'I1alu.rtdos paJro^ur puu palorrb oq llerls lBsodord srql rapun salruas Euruorsr.ro;d qtllr'r uorlJarruoJ ul JnJur lauuosJed Jll 'srotnql4slcJare,r,rgoSraq,(3 (sasuadxa ry 1alr.r1 ' 3 c) 'sasuadxc ssamsng pJuprmls 'JJets rauolsnr qlr,n Suqaeu e puepe lo '3lts Jrruolsnc u lrsll ro uo lro,r uuol.rad ot lc^BJ1 ot lauuosJad .;11 'srolnqr:lslCeE^\toSJaq^J pa.trnba: as3rua613o &tJ aqlJl uodn paalSe u..g aneq slueua?ueue r:qto ssalun J-l l 'slotnqqslgalemuosrag{J le pcllrf,Jxa cq lp^\ Iro^\ ll? puu sllec ocualc.luocclol Sulsn pclcnpuoJ cq 1l^\ s8unJotu ruotua8e8uc aql lBql mrEE c{ruc1411o i(I.] aqt pue -)'l'l 'srotnqulsr0crp^1go5.lcq{3 - scsucdxE g 'ccJrucnlJo ,{1r3 cql ,(q cpr,rord cq ;pm sccrruc5 Jo ^Ja^rlcp ctcldruor ol aoJrucl^.lo {1r-l oqt ,,(q porrnbor sa;ucdxa SuruleJ,| puu ,{lr,trlcouuoc 'erp^\uos 'rr9/r\preq ;euorlrppu .{uy 'Jl'I 's.tolnqLuslca.remrjoSraq,(3 ,{q pa1:r.n1as sloot Sursn yo,tr Jtll tu:o3rcd ;pm Jl'l r$olnqulsrqcremljog:cq,(3 - scsuxlxq Su4quuq luculccrfly I 'uttl:q paqLrlsap srrlAl:s pur? lzsodo-rd srql ul pcqrjrscp s1se13r,r suorlcldu:oc Suunp cdocs cql utqtr,^/\ scJr?\los to slo8ru; ,{uujo suogdnr.rclur .ro.; clqrsuodscr lou st -.ll.l 'srolnqutsrCJ-rEA\lloslcq{J .pclqestp SurqoJd c^ttf,rulsop {tr,r ual) alqrsp:J sr uorlduslp J3rlles lsuouualulun 'pauuoy:d fureq s1sal puc lueurssessp cqlJo arntuu ol anp leqt puBlsrJpun ccJrur6Jo {lr3 Jrll pue J'Il 'solnqusl(Je&^iuosrsq^l .l suopdurnssy .9 'e^oq8 peqrJJssp se uodo: paltslJp e st rlgpro^rtrp rql':Jqeu8rs lreluol go s,(eJr g1 urqlr,n luoru:?e8ua:q1 roJ elep UEls eql oururrclcp XFuro[ JJrm aa3rueyl jo ,qtJ crll pue J'Il 'slolnqutsroarsm{osraq^J 'a1ep uorla;duro: arllJo laa,tr 1 urtpr,tr papr,ro:d Eutaq poda.r l?utl p qlr^{ .alagduror o1 slee,tr 9 ,{laruurrxordde rlsr llr,rr p:luUf,p sgs:r1 uorlu:;:ruld pus lulussissp Isl-r Jpl^r uoqezrueiro :rq1_ JlnpJqJs tuJuJSsSuS '€ 'sBurpuq csct11 .go ,{ue o1 pal?lel sE 'J3Jruey{.lo ,{1r3 aqt :o.y peluaulnJop aq ItA1 uotlprpeua..r patsaiBns ,{uc ',(lleuoqrppy godor pouoqu:rurJro3e l{l ,{rollll olllsts oi-}luJ}i\l Jqt qtl,rl tJJu osle lll,rr gSJ'ts:t uollelrucd cqt loJ tuJsuof, uc,r13 sctro scrlrlrquJouln^ f,suJl Jo uorlelroldxc aql pue'serllrq"Jaugn,l flurpreiar uotlprlJo-lur (un pue.ado:rs aql ur slafl.ru1 paur;ap o3 A/A/reolj6 t g-rgg6-0f9,-6O19-1.99 !Btl3 :Ol edota^uf u6rSn.oO Docusign Envelope lD: CF481587-64D9-45E0-9854-B19FFO347B7B CD and/ or recollrmend renrediation to secure targels. The scale ol'the service lbr lhe custonrer is dclincd by thc following paramctcrs. Tablc l: Scrvcr Paramctcrs Virnral Privare Nenvork Testin cybersoliwareDistriburors. LLC will conduct thc asscssrnent and/ or penetration tests whEn nceded rcmotcly. CybcrSn{lwareDisrribuk)rs, LLC u,ill provide all rcquircd material and supply all labor required to gathcr rcquircd data to product rhc rcport output. wc will requirc rninirual assistancc to cstablish conrmunicati,n rvith you network aside from the required credcntials. Duc to thc naturc ofrisk asscssmcnts and pcrctration tcsring, wc anlicipatc thc work will takc approxirnately 6 u,eeks to cornplete. Table 2: Pricing Approximately every week, during the enlagenrenr, cybe rSoft*.areDistriburors, LLC persunnel shall meet with the city of Mcuifcc pcrsorurcl to give a prcscntation to rcvicrv any findings. answcr qucstions. and discuss next steps for the ftrllorving wcok, As these pertain to thc dcfined "pruject checkpoints." Additionallv. success criteria shall be tlehned tluring these meelings which will he the actions CybcrSoftwarcDistriburors. LLC will necd to take to be comprchcnsivc. At thc conclusion of this project. cybcrSotlwareDistributors, LLC shall givc a prcsentation to rhe city of Menilbe personnel to reviEw the deliverablcs. answer questions. and plovidc dirccrion firr ncxt step action itcms and suggcstcd rcmediation. 6. Cuslomcr Assistancc Rcquircd lll ordcr to optimizc thc clTcctivcncss of CybcrSoftwarcl)istrihutors, 1-l-C rcd tcanr nrcrnbcrs, rhc customer needs to provide access to systcrns- services, contraclors and crnployccs. lb pcrlbnn the work specified in this statenrenr ofwork. CyberSoftwarcDistribu(onr w.illrequire the folbwing from thc customcr: Corn oncrr1s Amount Scrvcrs ll Swirchus xlln tcl 20 or morc I ircwalls 5 Public IP Addrcsscs 5 Social lt)ccnll End int Softwarc Anal SIS int rvith software solutionsI I Virtual Privare Nerwork Price Risk Asscssmcnt and Dcfincd pcnctration Tcsts $ I 0.950 Approximatcly 50 contacts Work ltem DocuSrgn Envelope lDr CF481587-64D9,45E0-9854-B19FFO347B7B Acccss to rclcvant pcrconncI Rclevanl rccords and documcntalion A primary poinl of contact Coordination of cvcnts with customcr tcam mcmtrcrs Non-l)isclosurc Agrccmcnl and othcr agrccmcnts as nccdcd 7. Dclivcrablcs cybcrSoftwarcDistributors, LLC will conduct thc organization widc risk asscssmcnt and pcnch-ation tests as described in this proposal. Upon completion. CybersoftwareDistributors shall provide a report containing deliverables as indicated in table j below. Trble 3: Engagement Deliverables The report \'\'illcontain docurnen(ed and detaileil linrJings as a resuh olperlornring lhese services and willconvcy CybcrSofnrarcDistrihutors. L[-C's opinion ofhow bcst to rcnrcdv vulncrabi litics liorn a vcndor-ncutral pcrspcetivc. Thc architccturc and vulncrability maps will contain rhc mapping oftargcts and nctworks as defincd in the scope and as a resull of performing these services. -Ihis will convey CyberSoRwareDistriburors. LLC's findings in a visual [orrn. 8. Payment Tcrms custorncr agrecs to pay 507n ofthe overall price upon cxccution ofthis sow; the rernaining 50% shall be due and payablc wirhin rhirlv (30)days after receipr ofa final invoice ll.orn Cybersoftu'areDisrributors, issued upon completion of the project. 9. Penetration Testlng Service Agreement All scnioes dcscribcd within this statctncnt of work arc subjcct ro tcmrs and conditions of the CyberSoft wareDistributors" LLC's consulting agreemenr and specilically. CybcrSoftwarcDistriburors, tiability is limitcd as dcscribcd in Attachmcnt A. 10. Fi,xccution I0.1. Exccution of Strtemcnt of Work Plcasc sign and providc any additional intbnnation listcd bclow and rctum to CyberSoftwarcDistributor s. LLC along with signed relared dtrcuments and infonnation as dcscribcd in scction 6 within fi ftccn ( l5) days liom reccipt in ordcr to cxcculc this statcmcnt ol' work. CD Evcnt Deliverables Rc Elcctronic Findi DocumcntArchirccturc and Vulncrabilit Elcctronicall Gcncrated Visualizations Docusrgn Envelope lD: CF481587,64D9-45E0 9854-B19FFO34787B CybcrSoftu'a rcDis LLC CD Citv of Mcnifcc, California (*Customcr") Signalu re Altied Ortiz alure .\rnrando Villa Printcd Namc Printcd Namc g/oslutr Date Address: 545 Third Strcet, #267 Monumcnt, CO 80132 Date Address: 29E44 Haun Drivc Menifcc, CA 92586 10.2. Penetration Testing Service Agreement This Statement of Work incorpxrrates by ret'erence the CyberSoftwareDistribut,rs, LLC Penetration Testing Sen'iccs Agreement (the "Agrccment") (scc Attachrncnt A). 10.3. Expiration of Statement of Work This estirnate deemed null and void ilrrot signed by the Customer and received by CybcrSoftwarcDistributors, LLC rvithin thirty (10) days of thc datc sct firrth on thc covcr pagc. BllC Ot edota^uf u6rSnroO DocuSign Envelope lD CF481587-64D9-45E0-9854,819FF0347878 agrccs that CSD may deliver such updates or notifications to Customer as part ofthe Service and Custorner shall receive and install thern rs required. 4.2 Rcstrictions. Custorner agrecs that Cuslomer shall not place anv data on lhc Target Systems crr Allected Systems that: (a) inliinges on the intellectual propcrly rights ol'any third partv or any rights ol' puhlicity or privacy; (b) violatcs any law, statuc. ordinancc or rcgulation (including rvithout limitation thc laws and rcgulations govcming cxpoll control, unlair conlpcririon. antidiscriminal ion or talsc advertising): (c) is defarnatory. trade libelous. unlawlirlly thrcatening or unlawlully harassing; (d) is obsccnc. child pornographic or indcccnt; (c) crcatcs or causcs an), viruscs, Trojan horscs. worms. tintc homhs. cancclbot\ or orhcr conlputcr programnring rrrutincs that arc intcndcd to darnagc, dctrinrentally intcrl'crc with- surrcptitiously intcrccpt or cxpl'opliatc any systeln. dirta or personal inlbrmation: (t') creates or causes siluations or environrnents where any failurc or timc dclays of. or crrors or inaccuracics in. the contcnt. data or infornration on the Target Systerns or Atlecled Systems or any systems ofany third party could lead ro dcath, personal injury. or scvele physical or environmenral damage: (g) crcates or causcs any damages. corruption, loss. interl'erences, security intnrsions or any failulc oIany systcnts irr f'ustor:rer's control, possession. or business operations. or any systems ofany drird-parr_v. Custotncr acknowlcdgcs that CSD is not rcsponsible or liablc in any way tbr any data prr,rvidcd by ('ustomer and has no duty to pre-scrcen such data. However, CSD reserves the right at all timcs to dctcnrlinc whcthcr data is appropriatc and in compliancc witlr this Agrccmcnt, and may prc-scrccn, nrovc, rcli.rsc, modily and/or rcmovc data at any timc, without prior noticc and in its solc discrction, il'sr.rch datu is lound to be in violation of this Agreenrent o[ any kno',r,n laws- or is othcrwisc ohjcctionablc. .1.3 Confidcntialitv. Customcr agrecs to hold conlldcntial all CSD Confidcntial Intbmration in its possession or to which it has access under this Agrcenrcnt or as a rcsull ofthc provision ofthe Services, exercising the sanre degree of ciue that 0 reasonable and carel'ul conrpany would exercise with similar data of its own. Customer will limit access to CSD Confidcntial Inlbmratiol only to employees and contractors rvirlr a need to know such CSD Contidcutial Intbrmation. provided that any such pcrsons arc bound by thc same confidentiality plovisions as undeI this Agrccmcn[. "('SD Conlidcntial Infbrrlation" mcans CSD's computer systcms, mcthodologies. and any othcr aspect ofthe Scrvicc that a rcasonablc pcrson would dccrr contidcntial. Thc panics acknowlcdgc Cuslorncr is a public cntity and thcrctbrc is sub.icct to thc Calilirrnia Public Recolds Act. Any disclosure ol'inlbrnration pursuant to that Act will not be brcach of Customcr's rcsponsibilitics undcr tlris Scction. 5. As pan of llrc provision ol'thc Scrvicc. ccrtain solirvare- such as a rvcb brorvscr and PI)l'rcadcr or othcr officc applications nray nccd t., bc installcd on custonrcr's systcnr. and custonlcr nray bc rcquirud tc, halc a uscfiraolc and passworcl trr a wchsirc ro acccss scrvisc R(ports. Subjcct to lhe lernrs and condittttns ol'this Agreernenl, CSD grants to Custorlet'a lirlited. non-exclusive, non-translcmblc liccnsc undcr CSD's copyrights [o usc thc Scrvicc Rcporrs dclivcry systcm as spccilically allowcd by CSI) solcly in conncctions with cSD's provision of thc Scn,icc. All rights not specifically grantcd to Customer herein are expressly reserved by CSD. 8.2 1.1sc Restrictions customcr agrees not to: (a) modiff, arLapt. alter, translate, or create derivative works fionr the Service. the Serrlice Reports. or the Service Reports <Ielivery system; (b) rnerge thc Serwice Reports with other infonnellion in a rnanner that lails to attribute the content of tlre Service Rcport to CSD or that may othcnvise creatc confusion with rcspect to thc soul.cc of thc infonnation conlaincd in thc Scn,icc Rcport; (c) subliccnsc, lcasc, rcnt, loan, or othcrwisc transl'er thc Scrv'icc or scn'ise Rcporls to any third pafiy; (d) rclerse engineer. decornpile. disasscnrblc, or othcrtr.isc attcmpt to dcri\c or cop) or sharc thc sourcc coclq or copyrightctl information containcd in thc Scr'icc Rcpon.. 1c1 usc thc scrvicc or scrvicc Rcports to proccss data or provido any scrvicc burcau activity for any third parly: or (t) othcrwisc usc thc scrvicc. or. use or copy the Service Reporls, except as expressly allowed under this Seclion 8. 9. Warranty and Disclaimer CSD's sole and exclusivc wananty is that the Servicc provided undcr this Agrccnlcnt shall bc pertbrnred ln contbrrnity with the standard practices ill the industry and applicable law. Notu'ithstanding the forcgoing, thc security mechanisnrs implemented by ('SD have inherent limitations and Customer is solely responsible for determining that this mechanism sutlciently lDccts Customcr's security and opcrational needs. It is Customer's responsibility to rnaintain appropriate altenlate backup ol'Customel content. inlbn]lation, data. bLrsiness operations, anrj Targct SystcrDs, as wcll as p()tcct anv associatcd systcms lhat nray be aflcctcd by thc Scrvicc. CUSTOMER UNDERSTANDS AND ACREES I'HAT. EXCEPT FOR THE EXPRESS WARRANTY PROVIDED ABOVE. THIl SI]RVICI: IS PROVIDI]D ON AN "AS IS'' AND 'AS AVAILABLE- BASIS. CSD AND ITS AFt ILIATES. SUBSIDI;\RIES, OFFICERS, DIRECTORS, EMPLOYEF]S, AGF]NTS, PARTNI]RS AND LICLNSORS [XPRLSSLY DISCLN IM ALL WARRANTIES OF ANY KIND. WHETHER EXPRESS OR IMPI-IED. INCLUDING BUT NOT LlMlTllD TO THI lMPl ll]D WAIIRAN-l ll:S Ol' MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE. AND NON- INFRINCEMENT. IN PARTICUL,{R. CSD AND ITS AFFILIATES, SUBSIDIARIES, OFFICERS, DIRECTORS. IIMPLOYLtTS, ACENTS, PARTNIRS AND LICENSORS MAKE l Docusign Envelope lD: CF481587-64D9-45E0-9854-819FF0347878 NO WARRANTY TTLAT (I) THE SERVICE WILL MEET CUSTOMER'S REQUIREMENTS: (II) ('USTOMER'S USI OF l'HE SERVIC'E WILL BE TIMIIL\'. LTNINTIRRUPTID, SECURE OR ERRoR-FREE; (UI) ANY INF()RMATI()N oBTAINED BY CUST()MER AS A RESULT OF Tl IE SERVI('E WILL tsE ACCURATE OR RELIABLEi AND (lv) ANY DIFICTS OR ERRORS THNT MAY OCCUR AS A RESULT OF TIII SERVIC]E WILL BE (.oRRE('TED, 10. Limitation ol' Liability CT]S'I'OMI]R I,XPRLSSt-Y IJNDI]RSTANDS AND AGRII]S THNT IN NO EVINT WILL CSD AND ITS AFFILIATES, SUBSIDIARIES, oFFJ(:F]RS, I)IRI.]CI'oRS. I--MPI-OYIiI,S, AGENTS, PARTNERS AND LICENSORS BL, LIABLL, I.OR ANY DIRECT, INDIRECT, INCIDENTAL. SPECtAL. CONSEQUENTIAL OR EXEMpI,ARy DAMAGES. INCLT.'DtNG. BUT NOT LIMITE[, TO, DAMACIIS FOR LOSS OF PROFITS. GOODWILL, USI:, I)ATA. COST ()F PROCI,IREMENT ()F SUBSTITUTE (;(X)DS 0R SERVICES. OR oTHER INTANGIBLE LOSSES (EVEN IF CSD IIAS I]EEN AD\-ISEI] OT TIIE POSSIBILITY OF SUC]H DAMAGES). RESULTING FROM ANY CLAIM OR CAUSE OF ACTION UNDER THtS ACREEMENT OR ANY SOW. (]SD AND ITS AFFILIATES. SUBSIDIARII]S. OFfICBRS. DIRECTORS. EMPLOYL,ES. AGENTS. PARTNtsRS AND LICBNSORS ALSO SIIALL NOT I IAVE ANY LIABILITY FOR ANY PROCRAMS OR DATA USED WITI I TIII] SERVICE. INCLUDING WITHOUT LIMITNTION AN}'LOSS OF PROCRAMS OR DATA OF ANY KIND ()R'THE CoSTS OF RECOVERING SUCH DATA. CSD'S T0TAL CUMULATIVb LlAtslLll Y IN CONNECTIO\ wlTl I l lllS AGREbM1INT AND TllL StrRVICtl AND SERVICT: RIPOR IS. WHETHF.R lN CONTRACT OR TOI{1- OR OTHllRWISll, Wll-l- NOl- IXCtillD $200,000.00. This lirniLdtion ol-liabiliLy does not apply to cxtcr)l alry damagcs arc covcrcd by tl]c insurancc policics rcquircd by this Agrccmcnt. In ordcr tbr the lirnitarion ol liability s!'1 lbrth in this Scction l0 to apply. CSD shall providc Custorncr u,ilh a signed, written statement fiorn an authorized representative of the relevant insuruncc carricr(s) that insurance covcragc is dcnicd or unavailablc lbr any clainr or cause olaclion in conncction with this Agreement, the Sen icc, and/or the Servicc Rcponls). I l. Indemnilication Customcr agrccs to dcf'cnd, indcmnity and hold ('SD. its al'tiliatcs, subsidiaries, directors. officcrs. cmployccs. aScrts. partncrs. c()ntractors. and liccnsors (thc "CSD lnderrrnitccs") lrannlcss fiorn anv clainr or dcrnand, including rcasonablc altomcys' fccs. tnadc by a third party. relating to or arising lionr: (a) any data Custouror stores, subnlits, Posts, transrnils, ol'otherwise nrakcs availahlc that may bc affcctcd lry lhc Sclvicc: (l)) f'ustorncr's usc ofthc Scrvicc; (c) atly violation hy Customcr olthis Agrccnrcnt; (d) any action takcn by CSD as part of its invcstigation of a suspcctcd violation ol this Agrecrncnt r.rr as u rcsu lt of its find ing e'r- dt'cision tlrat a violation of this Agreement has occurred; (e) Custonrer's violal,ion ol'any lights ol'arrother; (l) Custontcr's actual or allcgcd gross ncgligcncc, willlul nrisconduct, violatiotl of law, failurc to l'nccl thc security obligatiuus rcquircd by thc Agrccrncnt, r'iolation ofthc CSD Acceptablc Usagc Policy' or violation of Scction 12.8 (Export Control) of this Agreement; or (g) any usage olCustomer's 6 L tlu :)q plno^l sJiPttlsp fuelJllotu tlalq/$ lo.l qsl ol urpq alqpfidiurr ':rtnlp:rnrrur rlnlrJsrro. Ilt^r (suo[Julscu xsn) Z'g uollc.s-lo q]siJg piuclErJtlt Jo l?rUJB Fue tcql ,OSJJo UotlBulloJut X.[lar.rdo.rd puu slerJas rpert alqpnlt:^ ultuo: slrodag aJtruaq puc eJr ]aS aql leql saipal,noulre rru.rotsllJ a^llElnuJnJ ale luaur:c.riy stql lapun s.tpaurel pue s1qfir.r .saryed aq-1. .S5ipiuiIIJ t.t I 'r;qurrlddu sR'eru.ro.lrleJ',{tuno;):rprs-ro.,'1 ur :!-ltnoJ lB.lJpJ-l -lo cl8ls Jrlt ur tqfino.rq Cq llEqS lUOtuCOJflv stql ol poltrlJJ uou:ru ,(uy .s:ldtrurrd .\\nl.l0 slllUuol slt ol :lusJaleJ lnoqlur\ truloltlru lo ilrls :rqlJo s^\n1 oL;t ,(q p:rru:r,roi aq 11tru ltriruiil8v slqJ -nn5[FjE-mpTExlrEaI6D .t.t I ',4uud :aqro cqt ol ssorppc \1au aql-lo arnou usllrJ,'' fiur,,r3 ,t'q }^s..rppr? srr atuuqc (eur Kped.raqrrl .Jauoos sJnJJo .ra^aqJrq.h 'enoqu purnb.:rr sc lrpur Jql ul p:rllsodap iurlq rcgc s^ep sseursnq (C) e:ql .Jr"ur Jo .sE. arll nr'ro ldracar uodn c/\rlraJla aq 1r^\ pue.OSJ,{q pauruuclap sE ssatppr Brnpuodsaxo; laqx) ro ljoiA..lo tueu.ralEls aql ut polBltput s? .lo a:nlerr8rs s..{uBd qJns qtpxueq quo] Irs (sr)ssatppE aql lD fuBd reqlo aql o! (ldteJ:l.Io tuau:8pc1,trou1te s:leJrpul luql luardrra: uo:.1 asuodse.r lrpurJ qIA\ lo pJlrrlunsop pue pruuguoo tdtosil pl_,:u) ;reur:r .{q :o .(p:rtserrh.-r.r ldrom: urnlr: pue predcld tSulsod)'lr,rx piJclslEcJ Jo pcgrpce ;(q '( xsJ ) -llrursJuJ JluoJlrclc,(q ,:cunor ,(q gulir:r,r ur pe.re^tlap 3q tsnu lurutoaJiv stql tepun slp^o.tddp puc sluesuoJ .ssJtlou Ilv T55il6N z.! | .1uotu.-rc-t3y sttp Ltt pcptao.td sB i-tucru3itnhoJ ,ttllelrucplluoc ctues cr;t ol lcclqns ane ^Jgl lcrlrl popr,rord 'crr^.tJS Jtll.lo l.red Xuu.ro 11e ur:o1.rcd o1 vcpr,rold aot.r:cs,{ued pltql o:!-n (eu OSJ pto^ pue llnu 3q lll.\t 3uro3:ro-1 arll-Io uounlot^ ut trJsupll .ro luaruufirsse prtdural;e _raqqo ,{,ry -u,r,1.r..,er1 tlrns ,{rm,;o yed se uorlnuuo-.1ul luuuJprluoJ s.r lotsnJ lo.lsur,,{ ,{etu gg3 pup ,ssaulsnq Jo clBs e Jo uorlezrueEJocJ ,reJodJoJ e Jo ued se uzd ur Jo iloq/ ur l.aulcc:8y iqt uSrssu iluo,{sur Cs,) 'pro^ pull ;1nu rq ;1r.m luloia.ro.l f,r.ll.lo uollplor^ ut JJ-lsupJt .ro luauruFrsse peldur:11u{uy 'lursuoo ur11rr,u rorrd s.OSJ tnoqlrA\ {Ied p:rqt {ue ot (suod.U e.rAlas lo aJl^_.ri!S oqt ot lrxlscr rJlr.* )-Jsua,l s.JauolsnJ BulpnJJur) luoruaetEy srql:apun slqfu s.raruolsnJ Jo ,{ue 'ast,ruor{lo Jo ^\tslJo uorlgJodo (q laJsugrt .to u8rss[ lou {?ru Jaruolsn) ttrarm;mv I ;l snoauBllors!l{l .fI Vlq-lqtA ur rtuo.t lrssluctuc:rnbcr Jr[srrsur Jrrl lcJrx lur.rs os.)'lucrucc:sv srql rJprrn c]r^Jis .{ue SuruurScq c:t5og JJUBJnSU I .zl 'plJrlqll/t\ ^lqeuosrslun cq lou (utu qrrq,^l .lucstroJ s.Jcru()lsn.) lnoqlt,tl utrEIJ orl.t Jlltas lou ^Errr csJ .r.uru lJ IIJO csucJop cql ul uorlEJCd0OJput a--ru pls tssp .lo.J s-lsanbrl ,lq"uosuc.l s.csJ rllt.$ ,{;druor 1"^nUl lauol:\^tlJ ..rautolsnJ ol p:rlerrunuuoo iltdurord aq lsnur put? CSJ ol rilurolsnJ ,{g pred luun Surpuulslno ureur lI,\1. 693 ot rlc1efed soJ-I lle pue'pcldof,]E aq lou llt^\ o:ncleur ea:o; -;o tutelc ,{ue utorl suotle8tlqo lelJupur] laaur o1 (lr1rqeur s.lJtrolsn.) teqt se8pcl,$ou{3u r3r.uo1sn11 qgj ,(q pauttx-tclJp ast:$J}I}o sn ro'sesnns ro 's:JuJrn:rJo 'slu:A: p:uoltust[aJoJs q]ns.(q pasne:r st:ln1tr.-;.to r(elrp q:rns;r trrauraa:Ey ;rrp .yo ged iue .ro 11u uuo.;t:rd ot :rn1re; .ro Xe;ep ,(ua ttto:-; f,utllns:r: :rf;rurep ro ssol ,{ue;o lunoJJc aqt uo.t1t1tt1ell Xrre:nltl lou JII/( q53 '{;leuotttppy suoda1 af,l^Jcs ro ef,r^ies Jr{tlo uorsrAoJd i'-,OSJ sJlBdull qclq,tl sstroJPulq alqrssod.raqo ,{un -to 's.tapttojd ,(1rp1n1o slJB'sl.relle 1st-lorta1 'suotsoldx:'s5.lu'sJ.lsestp le.truBu'poCJo sll[ 'uottrlltxll lnoqtrm Surprrlcul 'CSJ ^q pcuruuctJp se'OSf .to lo{uot Jqt puo,{Jq sJstlst lo's5atlarn3f,o 'sluc,rr (q pcsnef, srrnlreJ.ro s,{e1ap.{ue r<5 r;cltsuods.i rq lou ll!,r^ (lS.)'5lndt6 mxf.l / tl 'lre.LrJ puc:r:uo., lln-l ur anurluor 1pm suorst,ro.rd flurutuutai aql pue .rlsl alqeJrldde rapun alqrssod 1u:rrxo rsolnorS oq1 o1 uorsr,rord qlnslo sJ^rla:\lqo lql qstldtltorl0 ol ptltldlslul pue p:rEupqr c<1 ;1r,,n uorsr,ro:tl qons clqEorreJuiun st luotucc:8y srql jo uotst,,,o:d {ue JI -Fij]lq?l5Ls 9 t- | 'uors^Ef, lo Jeqlo,(ue uo ur'trsr,to-rd q)ns.lo .ro uorsr,ro.rd r:rqlo .(us .ro :r,rrelt P pruli:lp iq lou lpm uorserao ,luo uo luauroorSy srql go uorsr,rord ^us JJlo.fuc ol emlle-l Jo lJ,\tem (uy '3uqum ul )q lsnu sJJ^re,r llV rc,riEfr'E g1 'puoq c lsod oy poou aqt tnoqlr^ Jarle.r qJns- ol pallrlua sr CSJ pue qis:rq qrns lo.l fperuc.r alrrrdoldde ue sr 3erla: Jlu.)unfur tul1l puB ',(pruro] :lunbapuur A1g1re0lJ6 t S-t986,0f9,-6019-109 tgtl3 :Ot edola^uf u6rSncoO ll OocuSign Envelope lD: CF481587-64D9-45E0-9854-B19FFO34787B Erhibit A Insurance Requirenrents l3elbrc bcginning any Scrvioc under this Agrccment, CSD, at its own cost and cxpcnsc.shall procure tnaintain the types and arnounts ol'insurance listed below anil prov i<Je C'ertilicatesof Insurancc' indicating that CSI) has obtaincd or cutrcntly nraintains insurancc that lnccts thcrequircnrents of this Section and which is satistactor.v, in all respects. to cusronrer. CSD shall maintain thc insurancc policics rcqurred hv this scction rhroughout thc tcrm of this AgrccmcntcSD shall not allow any subcontractor, consultant, or othcr agcnt to cornmcncc Scrvicc on anysubcolrLract trrrtil CiSD has obtained all insurarce required herein lbr the srbcon t ractor( s) anriprovidcd cvidcncc thcrcof to Custolncr. Vcrification of thc rcquircd insurancc shall bc subrlittc4 and made part ol'this Agrcement prior to execution. c SD acknowredges the insurance poricy must cover inter-insured suits hctwecn Customer rnd other insurcds. l.l Workers' Compensation. CSD shall. at its sole cost and cxpense, mainlainStatutory worke.s' Compensation rnsurancc and Enrployer's Liability rnsurancc tor any antlall persons employed directry o' indircctly by CSD pursuant to lho pro\isions ol'thecalifomia [abor codc Stanrtory workcrs' compcnsation r*surance a.d Enrproycr.sLiability Insurancc shall be pr.vided rvith li,rits .f oor lcss rhan oNE MILLIONDOLLARS (S I _00(.).000.00) pcr accidcnt, ONE MILLION DOLLARS (S t.000,0(X).(X))discasc pcr cmploycc, and oNE MlLLroN DoLt-.^RS (s tliscasc pcr.policy. In thc altcnrati'c, csD rnay rcly on a scl'-insurancc program r.o rncct thosc rcquircmcnrs, buronlv il thc prograln ol'scll--insurancc cornplics lirliy rtith thc provisions ot rhc Calilorrria Labor Code. Detertnination of rvhr-thcr a sel t'-insrrra nce prograrn rneets the standanls ol'theCalifonria Labor Codc shall bc solcly in thc discrction of rhc Contract Admilistrator. Thc insurcr. if insurancc is p'ovidcd, or cSD" if a prograrn of scll'-insurancc is providud, shall w'aive all righLs ol'subro-tation against ( ustonrcr arrd its ol-ficr,.rs, oflicials, e'rnployccs. andauthorizcd voluntccrs tbr loss arising ttonr thc Scrvicc pertbnncd undcr this Agrccmcnt. L2 Commc ial Gcncral and A tornobilc Liabilitv lnsLrrancc. a. General requiremcnts. CSD, at its own cost and expense, shall tDaintain cornmercial general an<J automobilc liability insurance tbr the tenli ot this Agrccmcnr in an amounr nor lcss than ONE MILLION DOLLARS 1$ 1,0()0,000.00) pcr occurcnse. combinsd single linrit coverage. fbr risks ass.ciated with the sc.vicc contcmplatcd by this Agrccmcnt. TWO MILLION DOLLARS (52,000.000.00) gcucr.al aggrcgatc. and TWO MIt.LION DOLLARS (S2,000,000.0O) prducts./r;o,rplctcrJ opcrari.rrs aggregate, II'a Conrnrercial General t.iabiliry lnsumnceoran Auronrobile Liability lnsurtnce fornr or othcr form rvith a gcncral aggrcgatc linrit is uscd, cithcr thc gcncral aggrcgatc linrit shall apply separately to the Servicc ro be perlbrnrcd under thrs Agrecrncnt oi the gcneral aggrcgatc limit shall lrc at lcast twicc thc rcquircd occurrcucc limit. Such covcragc shall includc btrt shall not r-L lirnilcd to, protcction agairrst clainrs arisirrg tiorn bodily and pcrsorral injury. including tleath resulting thereliorn. and darnage to propertv resulting lionr the Scrvicc contcmplatcd under this Agrcenrcnt. including thc usc of hircd. orvncd. and non- olvned automobiles. I Docusign Envelope lD CF481587-64D9-45E0-9854-419FF0347878 c. Additional rcquircnrcnts. Lach ofthc tirllowing shall bc includcd in the insurancc covcragc or added as a ccltillcd cndorscrnent to thc policy: i. The insurance shall cover on an occurrence or an accident hasis. and not on a claims-madc basis. ii. Any failurc of CSD to comply with rcporring provisions of thc policy shall not atl'cct covcragc providcd to Custonrcr and its ofticcrs, cmployccs. agcnts. and voluntecrs. a. (jcncral requircrncrrts. CSD. at its own cost and cxpcnsc- shall nraintain for thc pcriod covcrcd by this Agrccmcnt prot'cssional liability insurance lbr licensed prol'essionals pellbrnring the Scrvice pursuant lo this Agreenrent in an anrount no[ lcss than ONE MILLION DOLLARS ($1,(XX).000) covcring thc liccnscd profcssionals' enors and ornissions. Any deductible or sell--insured rctention shall be shown on thc Ccrtilicatc. II' thc dcductiblc or scll-insurcd rctcntiolr cxcccds TWIINTY-FIVll Tl IOUSANI) l)Ot,LARS ($25.000). it rlust bc approvcd by Cuslonrcr. b. Claims-rnadc limitations. Thc tbllowi ng provisions shall apply il' (he prolessional liability coverage is written on a claims-rnade lbrnl i. The retroactive dale of the policy must be slrou'n and tuust bc uo later than thc comnrcnccmcnt olthc Scrvicc. ii. lnsurancc must be maintained and evidence of insurance mnst be provided for at least tive (5) years aficr the exp.ilation or tcnnination of this Agreement or completion of the Servicc. so lollg as commercially availablc at rcasonablc r.rtcs. iii. [t covcragc is cancelcd or not rsnuwcd and it is not tcplacccl with another claints-ntade policv lbnn with a retroaclive date that Precedes the Fl'l'ective Datc of this Agrcclncnl, CSD nrust pro\ idc cxlcndcd rcPofiing covcra8c for a nlinimum ol' five (5) years altcr the expilation or termination of lhis Agreemcnt ol thc conrpletitrn of the Scrvice. Such conlinuation covcragc may bc providcd by orrc trfthc tirllowing: (l)rcncrval of thL' cxisting policy: (2) an cxtcndcd lrporting pcriod cndorscmcnt: or (l) lcplaccrncnt insurance with a retroactive date no later than the conrrnencentcnt ol'the Sen ice r.rnder this Agrccmcnt. Custonrcr shall havc thc right to cxcrcisc, at CSD's solc cost and cxpcllsc. any cxtended reporting provisions ofthe policy, ifCSD cancels or does not rcnew lhe covetage. l0 b. Il'linirnunr scopc of coverage. Conrrrrereial genclal covcragc shall bc at loast as broad as Irtsuraucc Scrviccs Offlce Commcrcial (icncral Liability occun'crlcc tbmr CG 0001 . Autonrobilc covcragc shall be at least as broad as lnsurancc Scrvices Olllcc Autornobile Liability lbrnr ('A 0001 C'ode 2, E. and 9. No endoruernent shall be attachetJ lirniting thc covcragc. l.l Protessiorrirl[.iabilitylnsurance. II llDqeq uo Jo ,{q p3ttrio}lJd acr^JcS sqlJo lno Sursl]e ,(lrllqurl :8ur^\olloJ erp-Io qsuo ol l:]cdsf,J tllr^1 sp!.Insnl lPUOllIppt? sP p:Ja^Or aq llPtls sleelunlo^ PeTlJOqlnP puo ':-lu:8n ':.-eei(oldrua 'sJirrt+-ro slr p[r? ]i(uolslrJ t:)Ul?.rlsur ^rprur-rd :pirnsur ir,irorlrPpv 'pisEi.r)r.Il sr uor]llilJj pcrnsur-,flis ro :)lqrl]npop oqt (t) ro:pc)npcJ JJe scJrlod pcrnbiJ cq)J(} ,(ue10 s1rur1 crlt (Z):pcl8uruJcl sr scrcrlod cJuBjnsur pa:rnbe-r aql jo iue ( I ) :Jr s,{cp iurl:o,tr (01 ) u:l urqlrm .raulolsnJ ol alrlou ua11r:..n epr,ro.rd llEqs (JS.) c.J?lJ^oJ lo uou?llJauBJ lo ui lorlcnpcu lo JJ[oN I f o\^.1Jo llcqcq u0 ro ^q suorlBJsdo palalduror pue fiuroffuo .;o 1no Sursrru ,{p1rqrr1 .ro.; parnsur lr?uorlrppp ur sE pasJOpuc iq lsnru.riurotsuJ 9tiSa6 VJ ';rr.lttrirhl 'pcod ullnl I t?lJ6a 'i.r,+rui!\.Jo AItJ .sr uotrpllJJul?J .lo ctrrloN pue scuarnsul Jo scleJuruc.) 'stuaurJsJopuc pojnsul Isuortlppv loJ ssolppr] PUU aurPu eql CIN .tYuISNld:uactNSl\l -{:rou)1.'Iir ::-urrr,roJ1o3 rql apnlcur lsnuj cf,uLlnsul Jo 3lctulual aqt JIDqrq slr uo 5i8Jo^oJ purq ol ieJnsur leql ^q paTrJoqlne uos.rad eJo arnl8tr8rs oql ,{oqs lleqs slueu.rasJopue peuruet puD sarirlod-lo sardoi IIV sluauesropua llu -Io satdoo pel]tUar .toldnrof, irtpnl:)ur ,sat.rlod llB-Io s.irdoi parlrLreJ elelduroJ snlBls parnsur leuorlrppe 3ur1uel8 affunfue; (tr1od.ro tueuaslopua P:rnsul luuourPpB 'eruelnsol Jo s:lPrljrutJ qlr..rr r:ulolsuJ qsrultu sqs cs] 'luauraet3v srttt lcptrr 3Jt^JcS Jtll futrtrtt8-rq <.r1 .ror:4 5Ee:c,rr.>c 3rr uoptcgr..rd (l 'ErrxoJllsJ ur pallrupr? pup lln:V usrll ss:l ou.lo Autlt?l .s^ls-rg I rlltAt sJJtns^ut qll^ pa:c1d aq ot sf uoUJrS srql ,{q prlnbJl cJuernsul IIV 'arrfsurTo-fil'qoibtrv- 'u slucttrcrrlDcx scrJrlod liY g l 'luculcsrSv \^I"ll ol luBnsJnd scr 4urcs Jo iJueuJo-uad cql Jo Jnut^ ,{q ,{ edold io s^uos-trd lo uos.tJd ,{un ,(q plululsns s:lf,putsp Jo sJ nlut ulot-l flutllnstl '.l.r^;toslsqA\ .txttplpqt .(ue jo s.r,Srzurnp Jo 'surrBJJ 'slrns IIE puE KUB 'Elep Jo JolluoJ ro 'uorsstrusueJl .Surlsoq os,) uro.r.; iurstje rl)l2"rq rrI?P c-lo luno:rre uo 'sasuadxa pue s-lsoii fiurpnltur 'ptn1 Jo nlvu ,{uo-10 ,ftrpqell uor-; sac,(o1dua puE 'stua3u 'sJcJlllo slr 'Ja{uotsllJ 'ssJluuurl ploq prc J^es.,&ruruapul .puaJcp llsqs (]Sl 'rucurc:8y srql jo uorsrrord laqlo (uo 3u tpuolsqlt.,r\toN .q '.rr:,{ auo.;o poued urnurrrrrur r? lo-, lenpt^tpur pJlaa.llp {up.ro.l Sur.rolruotu llpJ.rJ Jil-l alqelrB^p Jlsru osle ggcqs,{:rr1od.1:tuBllsur ;rt1t 'uorleuuo.;ur leuos.rod s-3^Jo^ul qf,uclq uluP stJl ltlc^c Jtlt uI PUe rJruolsnl plre CSJ -ro suotlu8rlqo uorlu3urlol.l lJc fruqaetu flurpnlrul 'qJualq etup u-lo luana :ql ur rsuodsa: alerpeurul uB'.rJruolsnJ lo qSJ Jql ol lsor tnoqll,^ 'cpl^ojd lll.{\ tBql'3re3Jr33e 000'000'ts pue rlucJnf,ro tcd 000.000.1$ uary ssal lou.lo slrurrl (1rlqel1 u lrututur qlt,rt '(sllnpoid atunlnsut luele,rrlrba lo e:lunJt.ts^Ul ,ftr-rne:r5 pue Arlqprl rJq^J urplull7ur puP :)-lll]:rs llpqs CSJ .,{ltlui .{u[d-pllqt e qffnorql ulcpjo a'urlsoq oqt:o; opr,ro:d lo lzlep tsorl lll^\ CS.).luJ^. cqt ul .p oaUt.tnslrI ^lrjn.ros puf, AltlrquTrcqlj v I 'luaurcl:3y srql J3pun e)r^lrs aqlJo luauaJucrutuoJ Jqt o; .lor:d .rctuolsn.l ol pirllrtuqns:q tsnu sluauarrnlra: 8u1uod:.r ullzl:'! :ql 3o ,{do:l V .^t A1A1r€0ll6LA-1986-019',6O19-lBgLgrlC :Ot adota^uf uOrSncoO DocuSiqn Envelope lD: CF481587,64D9-45E0-9854,819FF0347878 uctihles of csD. including the insured's gencral supcrvision of cSD: protlucts and cr.rmplcterJopcralions of ('SD, as applicablc; prcrnises ownctl, o,ccupied, or uscd by CSD antlautonrobilcs owned, leascd, ,r used by cSD in thc course of providing the Scrvioc purcuantto this Agreenrert. The coverage shall contain no special linritarions on the icope ol-protcction alfordcd to Custonrcr or its officcrs, cmployccs, agcnts, ,r authorizcd voluntccrs_ Thc insurance provided to Clustolncr as an ailditional insurcd ntust apply on a prinrary an.l n()r]-colltributory basis rvith rcspcct t() any insurancc ()r sclf-insurancc pnrgraflr maintaincd by (iustomcr. Additional insurcd sratus shall continuc lor onc ( l) ycar aftcr thc cxpirarion or termination ol'this Agreernent or conrpletron ol the Service. A cc(iljcd endorsenrent rrrus( bc attachcd to all policics statillg that covcragc is prinrary insurarrcc with rcspcct to custonrcr and its ofJrcers, officials. emplovees, and voluntcers- and that no insurancc ol selt'-insurance maintaincd by customcr shall bc called upon to contributc ro a loss undcr thc covcragc. c Lrrcd a CSD shail obtain thc' rvlittcn appro'" al ofCustotner lbr the self-insuled rctentions and tlcductibles bcltrrc beginning tnv oI the Service. Durins the term ol- this Agreernent. only upon tl.re pr.ior express r,",ritterr authorizatiou of Customer, cSD rnay incrcasc such deductiblcs or scltrinsurcd rctentionswith respect (o Customcr, its ofticers. employces. agents. and voluntccls. customcr may condition approval of atr incrcasc in rlcductiblc or sclt'-insr.rr ccl rctentiotr lcvcls with a tcrluircrncnt that CSD prucurc a bontl guarantccing paynlcnt of losscs and rclatcd in\ csligations. clairn adrninislrat ion, antl dcl'cnsc cxpcnscs that is siltisl-actory in all rcspccts to cach ol thcrn. Sultontractors tlSll shall includc all subconrractors as insLrrcds undl-r its policies or shall f'urnish s.parate eertilicatcs antl certitled endorsemenrs tbr each suhcontractor. All covcragcs for subcontractors shall hc subjcct to all of thc rcquircnrcnts statcd hcrcin. g. Variarion. Custorner lnay, but is nol lequited to, approve in writing a varialion in thc lbrc-qoing insurancc rcquirements. upon a determinalion that thc coYcragc. scopc, limits. and tbms of such insurancc are either not conurcrcially available, or that Customer's interests are othe$,ise tully protected. 1.6 Rernedies. In addition to any other rernedies at larv or equily Custorner nray have if CSD fails to provide or maitrtain any insurancc policies or policy cndorsements to the extcnt and within the tirne herein rcquired. custorner may- al its sole option. exercise anv ol'thc lbllorvirrg .crrrcdiss, whiclr ar!'altctrrativcs (u othsr rsmcdics ('uslomcr may havc and arc not thc sxclusivs rcrnctly litrr CSD's brsach: a. Obtairr such insurancc and dcduct and rcrain thc amount ol thc premiums lbr such insurance liotn any sums due under this Agreentent; b. Order CSD to srop work under this Agrcetnent or withhold any paymcnt that bccomcs duc to CSD hcrcundcr, or both stop work and withhold any payment. until CSD demonstrates compliance witlr rhe requirements hcreofi and/or c. Tcrnrinate tlris Agr-cerncnt. il Docusign Envelope lD CF481 587-64D9-45E0 9854 819FF0347878 r3