Oracle Clud Enterprise Hsting and Delivery Plicies Statement f Changes Versin 1.5, 6/01/2015 This dcument utlines changes made t the Oracle Clud Enterprise Hsting and Delivery Plicies dated December 1, 2014, and reflected in the Oracle Clud Enterprise Hsting and Delivery Plicies dated June 1, 2015: Sectin 1: Versin 1.5, June 1, 2015... 2 Sectin 2: Versin 1.4, December 1, 2014... 3 Sectin 3: Versin 1.3, Nvember 1, 2014... 4 Sectin 4: Versin 1.3, June 1, 2014... 4 Sectin 5: Versin 1.2, December 1, 2013... 6 Sectin 6: Versin 1.1, June 7, 2013... 7 Sectin 7: Versin 1.0, December 1, 2012... 7 1
Sectin 1: Versin 1.5, June 1, 2015 This sectin describes the changes made t the Oracle Clud Enterprise Hsting and Delivery Plicies dated December 1, 2014, and reflected in the Oracle Clud Enterprise Hsting and Delivery Plicies dated June 1, 2015. 1.1 Rewrded language t imprve clarity related t encryptin technlgy in use fr Clud Service access. 1.2 Segregatin in Netwrks (Sectin 1.2) Rewrded language t imprve clarity. 1.3 Netwrk Bandwidth and Latency (Sectin 1.4) Rewrded language t imprve clarity. 1.4 Security Related Maintenance (Sectin 1.11) 1.5 Rewrded language t imprve clarity. Security Incident Respnse (Sectin 1.12.5) Changed security incident respnse time frm three business days t 72 hurs. 1.6 Regulatry Cmpliance (Sectin 1.13) Remved the reference t RightNw PCI Certified Clud Platfrm Clud Service. 1.7 Sftware Upgrades and Updates (Sectin 5.2.1) Remved language related t supprting multiple sftware versins 1.8 New Versin Evaluatin (Sectin 5.2.2) Remved sectin custmers t evaluate new sftware versins 1.9 End f Life (Previus Sectin 5.2.3, new Sectin 5.2.2) Rewrded language t imprve clarity. 1.10 Oracle Respnsys Marketing Platfrm Clud Service (Appendix A) Remved mdificatins t Sectin 2.7 Oracle Clud Services Backup Strategy 1.11 Oracle TOA Technlgies Clud Service (Appendix B) Renamed the service t "Oracle Field Service Clud Service 1.12.1 Data Prtectin Rewrded language t imprve clarity 2
Sectin 2: Versin 1.4, December 1, 2014 This sectin describes the changes made t the Oracle Clud Enterprise Hsting and Delivery Plicies dated Nvember 1, 2014, and reflected in the Oracle Clud Enterprise Hsting and Delivery Plicies dated December 1, 2014. 2.1 Oracle Clud Services Backup Strategy (Sectin 2.7) Updated data retentin perid t a minimum f 60 days. 2.2 Sftware Upgrades and Updates (Sectin 5.2.1) Clarified the rle f the Supprt prtal with respect t GA release ntificatins. 2.3 Oracle TOA Technlgies Clud Service (Appendix B) Remved mdificatins t Sectin 2.7 Oracle Clud Services Backup Strategy. Added mdificatins fr ETAwrkfrce. 3
Sectin 3: Versin 1.3, Nvember 1, 2014 3.1 Oracle TOA Technlgies Clud Service (new Appendix B) Inserted Appendix B t include language specific t Oracle TOA Technlgies Clud Service Inserted language t specify that RTO fr ETAdirect Prfessinal is 5 hurs and fr ETAdirect Enterprise is 4 hurs (Sectin 3.3.1) Mdified the fllwing sectins: User Encryptin fr External Cnnectins (Sectin 1.1) Oracle Clud Services Backup Strategy (Sectin 2.7) The fllwing sectins are nt applicable: Physical Media in Transit (Sectin 1.12.2) Data Center Migratins (5.1.3) 3.2 Changed the reference My Oracle Supprt prtal t Clud Custmer Supprt Prtal designated by Oracle fr the specific service rdered (e.g., the My Oracle Supprt prtal) (thrughut the whle plicies dcument) Sectin 4: Versin 1.3, June 1, 2014 This sectin describes the changes made t the Oracle Clud Enterprise Hsting and Delivery Plicies dated December 1, 2013, and reflected in the Oracle Clud Enterprise Hsting and Delivery Plicies dated June 1, 2014. 4.1 Remved the use f verarching terms such as all and fully when discussing Oracle s cmmitments (thrughut the whle Plicies dcument) 4.2 Overview and Table f Cntents Extended ur cmmitment f n material reductin in service by plicy changes t Clud Security Plicies 4.3 Oracle Clud Security Plicy (Sectin 1) Rewrded language fr imprved clarity 4.4 Regulatry Cmpliance (Sectin 1.13) Remved references t IEC (Internatinal Electrtechnical Cmmissin) Changed ISO27001:2005 t ISO27001:2013, as frm July 2014, Oracle Clud service will start t align with ISO 27001:2013 Mdified language related t health, credit card, and persnal infrmatin fr imprved clarify 4.5 Oracle Sftware Security Assurance (new Sectin 1.14) Inserted this new sectin 4.6 Redundant MEP Infrastructure (Sectin 2.2) Changed sectin title t Redundant Pwer 4.7 Oracle Clud Services Backup Strategy (Sectin 2.7) Added language t indicate that: Backups are retained nline and ffline fr a perid f up t 13 mnths Oracle may assist Custmer t restre data n an exceptin basis and subject t written apprval 4.8 Scpe (Sectin 3.1) Remved references t PaaS service and scial media services 4
Changed references frm DR Plans t a DR Plan fr Clud Services 4.9 Recvery Time Objective (Sectin 3.3.1) and Recvery Pint Objective (Sectin 3.3.2) Rewrded language fr imprved clarity 4.10 Disaster Recvery Plans (Sectin 3.6) Changed sectin title t Disaster Recvery Plan Objectives 4.11 Definitin f Availability and Unplanned Dwntime (Sectin 4.3) Rewrded language fr imprved clarity 4.12 Oracle Clud Change Management and Maintenance (Sectin 5.1) Updated scheduled maintenance perid t: typically nce a mnth, initiating at apprximately 20:00 data center lcal time and typically lasting up t 10 hurs Reference t MOS article fr change maintenance perid exceptins Mdified language fr clarity 4.13 Emergency Maintenance (Sectin 5.1.1) Added wrding that Oracle will wrk t prvide 24 hurs prir ntice fr emergency maintenance 4.14 Supprt Perid (Sectin 6.1.2) Rewrded language fr imprved clarity 4.15 Terminatin f Clud Services (Sectin 7.1.1) Rewrded language fr imprved clarity 4.16 Terminatin f Trial Envirnment (ld Sectin 7.1.2) Remved sectin as Trial service is nt gverned by Hsting and Delivery Plicies 4.17 Custmer Assistance at Terminatin (ld Sectin 7.1.4, new Sectin 7.1.3) Rewrded language fr imprved clarity 4.18 Oracle Respnsys Marketing Platfrm Clud Service (new Appendix A) Inserted this new appendix fr Respnsys Marketing Platfrm Clud Service: Added Target System Availability Level 99.9% Added RTO 30 minutes, RPO 15 minutes Carved ut Enterprise Hsting and Delivery Plicies sectins nt applicable t Respnsys Clud Service Segregatin in Netwrks (Sectin 1.2) Netwrk Access Cntrl (Sectin 1.3) Netwrk Cntrls (Sectin 1.6.1) Redundant Netwrk Infrastructure (Sectin 2.3) Oracle Clud Services Backup Strategy (Sectin 2.7) 5
Sectin 5: Versin 1.2, December 1, 2013 This sectin describes the changes made t the Oracle Clud Enterprise Hsting and Delivery Plicies dated June 7, 2012, and reflected in the Oracle Clud Enterprise Hsting and Delivery Plicies dated December 1, 2013. 5.1 User Encryptin fr External Cnnectins (Sectin 1.1) Rewrded language t imprve clarity. 5.2 Security Related Maintenance (Sectin 1.11) Inserted new sectin describing the change management prcess fr security patch bundles. 5.3 Security Incident Respnse (Sectin 1.12.5) Included language t indicate that any misapprpriatin f Custmer data will be reprted t Custmer within 3 business days f determining that the data has been misapprpriated. 5.4 Data Privacy (Sectin 1.12.6) Rewrded language t imprve clarity. 5.5 Regulatry Cmpliance (Sectin 1.13) Included language t indicate that Oracle s internal cntrls are subject t peridic 3 rd party SSAE/ISAE audits and custmers may request a cpy f published audit reprts. Clarified that custmers shuld nt prvide Oracle with any health, payment card, r ther sensitive persnal infrmatin unless the apprpriate bligatins are in the Ordering Dcument. 5.6 Oracle Clud Services Backup Strategy (Sectin 2.7) Remved references t tape/disk and replaced it with mre generic terms. Rewrded language t imprve clarity. 5.7 Definitin f Availability and Unplanned Dwntime (Sectin 4.3) Added 3 rd party sftware cmpnents t Unplanned Dwntime exclusins. 5.8 Reprting f Availability (Sectin 4.4.1) Included language that gives custmers the ptin t lg a Service Request t request availability metrics if the Clud Service availability metrics is nt available n the custmer ntificatins prtal. 5.9 Oracle Clud Change Management Plicy (Sectin 5) Remved references t distinct change management windws fr applicatin upgrades, cre system maintenance, and rutine infrastructure maintenance. Increased ntificatin perid fr majr maintenance changes frm tw weeks t up t 60 days. 5.10 Security Practices fr Oracle Clud Supprt (Sectin 6.3) Deleted sectin t eliminate redundancy. 5.11 Secure Data Transfers (Sectin 7.1.5) Remved specific descriptin f file extract methd t supprt terminatin. Renamed Sectin frm Secure File Transfers. 5.12 Exprtable Data (Sectin 7.3) Remved references t full exprt 5.13 Change Maintenance Perids fr Oracle Tale Recruitment Clud Services (Appendix A) Remved entire appendix as change maintenance fr Tale is cvered in Sectin 5 Oracle Clud Change Management Plicy. 6
Sectin 6: Versin 1.1, June 7, 2013 This sectin describes the changes made t the Oracle Clud SaaS Enterprise Hsting and Delivery Plicies dated December 1, 2012, and reflected in the Oracle Clud Enterprise Hsting and Delivery Plicies dated June 7, 2013. 6.1 Dcument Name Renamed the dcument t Oracle Clud Enterprise Hsting and Delivery Plicies. 6.2 Versin Cntrl Added Versin Cntrl t the dcument. 6.3 User Encryptin fr External Cnnectins (Sectin 1.1) Changed the statement SSL encryptin technlgy is standard fr Oracle Clud Service access t SSL encryptin technlgy is available fr Oracle Clud Service access. 6.4 Netwrk Vulnerability Assessments (Sectin 1.6.3) Remved the wrd practively frm the statement Oracle Clud Services utilize netwrk vulnerability assessment tls t practively identify security threats and vulnerabilities. 6.5 Anti-Virus Cntrls (Sectin 1.6.4.1) Inserted this sectin. 6.6 Security Incident Respnse (Sectin 1.8.5) Re-wrded the secnd sentence. 6.7 Oracle Clud Services Backup Strategy (Sectin 2.7) Remved the wrd dedicated frm the statement Oracle peridically makes backups f Oracle Clud data in all envirnments included in the Custmer s rdering dcument using backup infrastructure. 6.8 Disaster Recvery Plans (Sectin 3.6) Remved the wrd nrmal thrughut the sectin. 6.9 Custmer Mnitring & Testing Tls (Sectin 4.5.2) Remved the statement Exceptins t this are the Oracle Database Clud Service and Oracle Java Clud Service r if therwise expressly permitted in the rdering dcument. 6.10 Majr Maintenance Changes (Sectin 5.1.6) Updated this sectin t clarify that majr maintenance changes wuld be targeted t ccur at the same time as either the cre system maintenance r the applicatin upgrade windw with a tw (2) week prir ntice f the anticipated unavailability. 6.11 Oracle Clud Suspensin and Terminatin Plicies (Sectin 7.1.1) Clarified that fr a perid f up t 60 days after the terminatin r expiratin f prductin services, the custmer will be able t retrieve an exprt file f custmer data frm custmer s prductin envirnment. Updated the secnd sentence f the last paragraph. Sectin 7: Versin 1.0, December 1, 2012 The December 1, 2012 versin f the Oracle Clud SaaS Enterprise Hsting and Delivery Plicies was the initial release f this dcument. 7