PAKISTAN CLOUD FIRST POLICY 10.2 Contracts with CSP The relevant Cloud Office will issue guidelines for the execution of cloud computing contracts between PSE and CSP. These guidelines will cover (but are not limited to) the following areas: - 10.2.1 Service Level Agreements (SLA) SLA are undertakings that are binding on the CSP on the service level. Among other things, they stipulate penalties for the CSP if the contractual undertakings are not fulfilled. They are particularly important with regards to clauses on security (vulnerability scanning, patching and change management, quality control checks, certification requirements, etc) and data protection (retention period, exercise of rights of data subjects, availability of processing, etc.). The provisioning of cloud solutions by CSP shall be governed by SLA by specifying and clarifying performance expectations and establishing accountability. The SLA shall relate to the provisions in the contract regarding incentives, penalties, escalation procedures, disaster recovery and business continuity, and contract cancellation for the protection of customers in the event the CSP fails to meet the required level of performance. PSE shall closely monitor the CSP compliance with key SLA provisions among others on the following aspects: a. b. c. d. e. f. Availability and timeliness of services; Confidentiality and integrity of data; Change control; Security standards compliance, including vulnerability and penetration management; Business continuity including disaster recovery and contingency plans; and Help Desk Support. 10.2.2 Interoperability Requirements PSE shall require interoperability of the components of cloud infrastructure to work together to achieve the intended result based on international standards. The components may come from different sources including public and private cloud implementations. The components shall be replaceable by new or different components from different CSP and continue to work, to facilitate the exchange of data between systems. 10.2.3 Migration between Cloud Service Providers PSE may decide to change / migrate between CSP for a variety of reasons. Their initial migration to the cloud must facilitate future migration between platforms. This can be enabled by defining technology standards in their procurement processes. If PSE build their infrastructure using standard and widely available components, this will facilitate the migration of their data to the cloud and between CSP. PSE shall consider the necessity of migrating potentially large quantities of data to launch a service, and the ability to increase the scale if necessary. CAO will be available to facilitate in recommending models and roll out plans for PSE to follow for cloud adoption and migration between CSP. 10.2.4 Data Ownership PSE will have full ownership of their data. They will decide how and where their data is stored and managed. Data kept on the cloud remains the property of the PSE irrespective of who owns, manages, or operates the cloud. PSE has the right to access, retrieve, modify or delete the data irrespective of the physical location of the cloud. It also has the right to approve, deny or revoke access to the data by third parties. Page 14 of 21

Select target paragraph3