Product Specific Terms – Beyond MSSP - Managed SOC
1. Supplier Obligations
As applicable based on the Supported Sources, the Supplier shall:
1.1
Fine Tuning Phase
(a)
From the Services Start Date for the Fine Tuning Phase the Service Level Agreement does not apply while the Security Alerts are fine tuned;
(b)
work with Customer to reduce the number of False Positives and critical alerts during the Fine Tunning Phase;
1.2
Reactive Support
(a)
respond to Security Incidents raised by a Customer Named Contact in accordance with the Service Level Agreement;
(b)
reclassify the priority of a Security Incident raised by the Customer where incorrectly prioritised by the Customer;
(c)
track and report Security Incidents raised by the Customer activities in the Supplier Support Portal;
1.3
24/7 Managed Detection & Response
(a)
continuously detect, investigate and provide context around Security Threats;
(b)
monitor the Supported Sources 24/7 to detect and identify Security Threats which may be raised as Security Alerts;
(c)
respond to Security Threats and Security Alerts with Recommended Remediation Guidance;
(d)
notify the Customer within the relevant Response Time SLA of an on-going Security Incident;
1.4
Google SecOps Platform Management
(a)
proactively support Google SecOps SIEM data source integrations, onboarding and fine-tuning of the platform;
(b)
design, implement, integrate and fine-tune the Google SecOps SOAR automation playbooks for new and existing detection use-cases;
1.5
Threat Modelling and Use Case Designing
(a)
create and share threat-centric use cases using the latest threat intelligence across the Supported Services;
1.6
Threat Intelligence Enrichment
(a)
proactively enhance managed detection and response capabilities by enriching ingested data with enterprise-grade and open-source threat intelligence sources specific to the customer's industry;
(b)
develop custom threat hunting rules by analysing complex, non-atomic threat intelligence data to uncover new and sophisticated threats that may bypass predefined detection mechanisms;
1.7
Compliance Scanning
(a)
proactively scan the Customer Public Cloud environments against Centre for Internet Security (“CIS”) benchmarks;
(b)
share a monthly report defining CIS benchmark findings;
1.8
KPIs & Reporting
(a)
provide monthly reporting that summarise KPI performance, trends, and key findings across relevant Key Metrics, as agreed with the Customer from time to time;
1.9
EDR Operations
(a)
proactively monitor and fine tune the Customer’s Endpoint Protection Platform (“EPP”) or Endpoint Detection and Response Solution (“EDR”), ensuring the tools are updated to deliver operational value;
(b)
take action in the Customer EDR / EPP once approval has been granted by the Customer.
2. Customer Obligations
The Customer shall:
2.1
have an active Google SecOps SOAR and SIEM platform licence (“Google SecOps Platform”) in place for the Supported Sources, either purchased via the Supplier or purchased elsewhere;
2.2
deploy the necessary Agents and Configurations to enable the Supplier to onboard SIEM data sources;
2.3
provide the necessary level of delegated access to the Customer Google SecOps Platform to the Supplier;
2.4
manage and operate the Customer EDR / EPP service, if applicable;
2.5
provide the necessary level of delegated access to the Customer EDR/EPP service to the Supplier, if applicable;
2.6
remedy any Security Threats and Security Incidents discovered during the onboarding and Fine Tuning Phase within 1 month of the Fine Tuning Phase concluding. Any Security Threats and Security Incidents that remain unaddressed after 1 month will be muted by the Supplier and will not be covered under the Managed Security Services; and
2.7
remedy all Security Threats and Security Incidents using the Recommended Remediation Guidance provided by the Supplier.
3. General
3.1
Unless otherwise set out in the relevant Ordering Document, the Supplier shall invoice the Customer on the Effective Date.
3.2
The Supplier may increase the Charges annually. This increase will be based on the preceding month's announced inflation rate (either ONS CPI (Consumer Price Index) for contracts with Qodea Limited/Qodea Technology Limited, or ECB HICP (Harmonised Index of Consumer Prices) for contracts with Cloud Technology Solutions Nederlands B.V./Appsbroker Europe GmbH), plus an additional 5%. If the applicable inflation rate is negative, only the 5% additional charge will apply.
3.3
The relevant Order Form shall auto-renew at the end of the relevant Term, for 12 month periods (“Renewal Term”) at the Supplier’s then current pricing unless either party gives at least 30 days prior written notice of non-renewal prior to the end of the relevant Term or Renewal Term.
4. Definitions
4.1 The following definitions apply in these Product Specific Terms:
Agents and Configurations:
means including but not limited to installing new agents, creating API keys or credentials and altering firewall & network configurations to facilitate log collection.
Change Request:
means a request for consultancy, or to make an impactful change to the Supported Sources, that requires risk analysis, planned outage, further approval and or planning / coordination between the Customer and Supplier.
False Positive or FP:
means a Security Alert that is triggered based on a Security Threat that is benign.
Fine Tuning Phase:
means as defined in the Ordering Document.
Google SecOps SIEM:
means a cloud native security information and event management (“SIEM”) solution, enables users to collect and analyse security telemetry from across their enterprise to power detection, investigation, and remediation of threats.
Google SecOps SOAR:
means a cloud native security, orchestration, automation and response (“SOAR”) solution, empowers security teams to respond to cyber threats in minutes. SecOps SOAR fuses a unique threat-centric approach, powerful playbook automation, and context-rich investigation.
Key Metrics:
means as set out in Schedule 1.
MDR:
means managed detection and response.
Protocol-Specific Logs:
means including but not limited to: DNS, HTTP, SMB, FTP
Public Attack Surface:
means the points of entry and vulnerabilities an attacker can exploit to infiltrate a network or a system from the internet.
Public Cloud:
means Google Cloud Platform (“GCP”), Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”).
Recommended Remediation Guidance:
means the steps required by the Customer to resolve a Security Threat or Security Incident.
SecOps Threat Intelligence Platform:
means a cloud native insight platform providing visibility into the global threat landscape
Security Alert:
means an automated or manual notification made to make the Supplier or the Customer aware of a Security Threat or Security Incident that poses an active risk to the Customer’s environment. Security Alerts classified as informational or informative are out of scope unless correlated with additional alerts of higher severities.
Security Incident:
means a Security Threat or group of Security Threats that pose an active risk to the Customer’s environment and requires active management until resolution.
Security Threat:
means a notification of a log event that has the potential to become a Security Incident if it is not addressed.
Service Level Agreement or SLA:
| Priority Level | Description | Response Time | Availability | Available Support Channels* |
|---|---|---|---|---|
| P1 | Immediate risk including suspected or high probability of system compromise | 30 minutes | 24/7 | Phone outside of Business Hours. Support Portal or Email during Business Hours. |
| P2 | High risk of increased attack activity including high priority events that may require further investigation by the Customer | 2 Hours | Business Hours | Support Portal, Email or Phone during Business Hours |
| P3 | Low risk indicates the need for increased vigilance in monitoring and will be used to keep Customer informed about potentially hostile activity. | 1 Business Day | Business Hours | Support Portal, Email or Phone during Business Hours |
| P4 | Change Requests and Service Requests | 2 Business Days | Business Hours | Support Portal or Email |
*Available Support Channels
| Support Portal | https://support.qodea.com |
| mdr@qodea.com | |
| Phone | 01793 391477 |
Service Request:
means a request to make a low impact change to the Supported Sources, that does not require any risk analysis or further approval.
Supported Sources:
means as defined in the Ordering Document.
Schedule 1 - Key Metrics
| KPI | Definition |
|---|---|
| Total Number of Security Alerts | The total number of Security Alerts |
| Mean time to Acknowledge (MTTA) | The average amount of time it takes for the Supplier to acknowledge a Security Alert before investigation occurs. |
| Mean time to Resolution (MTTR) | The average time it takes to completely resolve a Security Incident once it has been detected. This includes root cause analysis, deployment of configuration changes or fixes and any recovery actions required. |
| Alerts / Use Cases | The total number of alerts in relation to the respective SIEM use cases provided by the Supplier |
| Alerts / SOAR Playbooks | The total number of alerts in relation to the respective SOAR playbooks provided by the Supplier |
| Event Quality | The number of resources with parsing-errors |
| Resolved Alerts | The total number of resolved alerts |
| True Positives | The number of True Positive alerts |
| False Positives | The number of False Positive alerts |
| Compliance Audit Results | The results of compliance audits, including the number of non-compliant items identified, number of assets with incompliances, number of assets violating PCI, GDPR etc. the severity of the non compliance, and the time to remediate non-compliant items |
| Severity Distribution | The distribution of vulnerabilities by severity level, such as critical, high, medium, and low |
| Incident Resolution Time | The amount of time it takes the incident response team to get from investigation to recovery |