845 Midway Drive Willowbrook, IL 60527 630-789-2525 x223 www. ESPOSYSTEMS.com Websense ESPO intelligent Managed Security Service Provider (imssp) Version 3.1 Monthly service Submitted by: Nick Stricker, CISSP Espo Systems A Division of Espo Corporation 630.789.2525 x223 Nick.Stricker@EspoSystems.com http://www.esposystems.com
Executive Summary Espo Systems is pleased to provide this proposal for ESPO imssp service. This document describes the steps that Espo Systems is proposing to take on your behalf, as well as information about the strength of Espo Systems capabilities and project logistics. Espo Systems believes that these services will position you to take fuller advantage of your Websense Solution and better address matters of current and/or future policy compliance. ESPO imssp ESPO Systems, in its continued effort to build Easy Button solutions that negate the needless complexity of standard security offerings, has created ESPO imssp. Why "i"? ESPO believes the standard Managed Security Service Provider (MSSP) has created a one size fits all model designed for the largest of organizations... with an equally large pricing and opex model. ESPO has added intelligence to this model, thus the imssp acronym, to reduce operational burden and associated costs. ESPO's imssp is a comprehensive offering that when applicable, builds on our established Quick Start Installations and Websense Training expertise to provide our customers with ongoing professional tuning of your Websense Solution. After initial deployment, the ESPO team will monitor incidents on your Websense solution and provide additional policy "fine tuning" for a period of *two months. When you are satisfied that your policies are effectively meeting your corporate objectives, blocking actions will be implemented, and, we will move into the managed portion of our offering. With our imssp subscription service, ESPO will review your deployment during a monthly consultation with a Websense Expert to determine if false positives and/or false negatives exist. You will also receive a monthly report review that will highlight any events that should be addressed from an internal policy perspective. In addition to the monthly policy configuration tweaks, ESPO will review system upgrades or manufacturer recommended software enhancements that could impact your application during your consultation. Minor tuning adjustments will be completed as part of the service, larger projects will be quoted separately and will be subject to customer approval. The ESPO team will make best efforts to assign the same ESPO engineer to your account for the duration of the engagement. ESPO imssp Includes: *TE or DSS Quick Start Installation Review/Tuning of High Severity incidents via monthly sessions Monthly DSS/DLP and email Consultation * For customers that have already deployed their Websense solution, the first two months installation review will not apply.
Scope of Work ESPO Systems is proud to offer our imssp for the Websense family of security solutions. This program provides customer s access to Websense-centric ESPO Engineers that can aid and assist in everything from minor break-fix issues to policy refinement and management to training via our signature Knowledge Transfer Process. imssp is a minimum 6 month engagement designed to bring your Websense security solution to its full potential in your environment. Once the solution has been brought to your target expectations, Phase II will begin. Phase II will, with your approval, lock down your network and include monthly monitoring of your Websense solution. Phase II provides monthly consultation with the customer to highlight recommended changes to the network. These changes can include: *recommended software upgrades or patch implementation, further tuning of security policies, or additional work as recommended by ESPO and deemed necessary by the customer. ESPO will establish a Basecamp Project management page that is fully accessible to you and your staff. The Basecamp tool provides a working document for the customer and ESPO Systems to share common technical documents, measure progress on agreed to objectives, and identify further enhancements the customer may choose to enable. Our mutual objective is to complete the work described in Phase I below over the first 60 days, subject to customer review and permissions to proceed at critical points in the process. Customers will have one-on-one time with a Websense-centric ESPO Engineer. All sessions can be recorded for reference. * Minor tuning adjustments will be completed as part of the service, larger projects, (example: software upgrade) will be quoted separately and will be subject to customer approval. Phase I imssp 2 month objectives: Assistance where appropriate to bring your Websense solution up to your design target Phase II Ongoing Management Services ESPO will monitor your network on a monthly basis, reviewing all Websense related incidents. We will establish a monthly review of this report with you, and our Websense Expert to determine if false positives and/or false negatives exist. You will also receive a copy of this report that will highlight any events that should be addressed from an internal policy perspective. In addition to the monthly policy configuration tweaks, ESPO will review system upgrades or manufacturer recommended software enhancements that could impact your application during your monthly consultation. ESPO recommendations may require additional hours of services not included in the standard imssp offering. These additional hours can be added to the monthly service agreement as noted in the pricing section of this proposal. ESPO engineers will only proceed with recommended changes that have full approval of your staff. Any proposed changes or modifications will be documented in the Basecamp tool associated with the imssp service.
Assumptions This Statement of Work and the project parameters it contains are based on the following assumptions. If an assumption is incomplete, incorrect or becomes incorrect, Espo Systems may change the project s parameters including but not limited to scope, cost or schedule, of the work defined herein. The change management procedure described in this document will be used to manage modifications. Changes to these assumptions may impact the overall timeline, deliverables and costs. 1. The project schedule is highly dependent on the availability of the customer s staff to provide input, review deliverables and provide signoff. 2. The scope and objectives of the project will be jointly managed by the customer and Espo Systems to ensure timely completion of the project. 3. Some services may be performed at Espo Systems location(s). 4. IT resources committed to the engagement will be committed to the degree necessary to complete the project. 5. IT resources will be made available for information gathering and validation, reviews and other input. 6. Once Espo Systems agrees to a start date for the engagement, it is understood that Espo Systems will commit the appropriate engineering resources to be available for the project at that time. Should the customer alter the kickoff time within a period of one week prior to the agreed-upon start date, Espo Systems reserves the right to collect a fee of up to $500, to be determined based on the impact of this change on the calendars of the engineers and other Espo Systems customers. 7. The work will be performed during regular business hours. 8. Initial installation and deployment is already completed whether by customer or by third party. Project Fees All prices listed here represent imssp costs, inclusive of all expenses. You will not receive any billings beyond the amounts cited without an explicit request for additional products or services, and a mutually agreed-upon documented change to the project scope. The terms and prices set forth below are valid until 60 days from the date on the cover of this proposal. Pricing for imssp is quoted for a 6 month engagement, billed at time of purchase. Additional hours of support can be added to address agreed to enhancements, policy tuning or related services to the Websense solution in increments of 8 hours at a cost quoted per increment. Only the services outlined in this Statement of Work are considered deliverables as a part of this project. Espo Systems will be pleased to address any additional services utilizing the option outlined above for adding hours of service for agreed to enhancements to your Websense solution. Payment Terms Espo Systems will issue its invoice for the 6 month service upon order. Customers shall pay such invoice within 30 days of receipt. Any objections to an invoice must be made to Espo Systems within 15 days after the date of the invoice. After the initial 6 month term, this agreement will automatically renew on a 6 month basis on a to be quoted rate. The customer does have the right to terminate the agreement with 30 days notice. Upon termination, Espo Systems will provide the customer a copy of the customer Base Camp data.
Signatures The terms and conditions of sales and services for which Espo Systems, an affiliate of ESPO, is or might become engaged are limited to those contained in this document (which includes its appendices, exhibits and other attachments), as it exists now and as it may be amended in the future, is governed by any such separate agreement (if and for so long as such separate agreement is valid and binding) or those web terms, and references therein to a Statement of Work or a Work Order apply to this document. This document is the proprietary and confidential information of Espo Systems and is effective as of, 20 (or, if left blank, on the date that this document is signed by the last of the parties below to do so). This document can be terminated by either party below without cause by providing to the other party the following number of days advanced written notice: 30 (or, if left blank, 14, or if NA is inserted, this document cannot be so terminated). Project Options Virtual In acknowledgement that the parties below have read and understood each and every provision of this document and agree to be bound hereby, each party has caused this document to be signed and delivered by its respective authorized representative. ESPO Systems Customer (print full legal name) By: By: Name: Name: Title: Title: Date: Date: Mailing Address: 845 Midway Drive Willowbrook, IL 60527 Mailing Address: Internal Use Activity Customer Billing Contact: ATTN: Address:
Appendix A. Change Management Procedures In the event that it becomes necessary to amend this Statement of Work, the change management procedures outlined in this section will apply. The Project Change Request form is included in the Appendix of this Statement of Work. Types of Change Changes to the project may be made for reasons including, but not limited to, the following: Scope of work Specifications of the deliverables Non-functioning or unavailable materials beyond either party s control Unavailable resources beyond either party s control Environmental or architectural impediments not previously identified Change Initiation Either party may initiate a change by completing the Project Change Request form. The initiating party may give the Project Change Request form to the other party s project manager to review and process. Approval In acknowledgement that the parties below have read and understood each and every provision of this document and agree to be bound hereby, each party has caused this document to be signed and delivered by its respective authorized representative. ESPO Systems Customer (print full legal name) By: By: Name: Name: Title: Title: Date: Date: Mailing Address: 845 Midway Drive Willowbrook, IL 60527 Internal Use Activity Mailing Address: Customer Billing Contact: ATTN: Address: