Laserfiche WebLink
EXHIBITA <br />STATEMENTOFWORK <br />This Statement of Work (ÐSOWÑ), dated July 25, 2024,is entered into pursuant to the <br />Master Services Agreement (ÐAgreementÑ), dated July 25, 2024,and among Arete Advisors, LLC, <br />a Florida limited liability company having a place of business at 4800 T-Rex Avenue, Suite 350, <br />Boca Raton, FL 33431(ÐAreteÑ), McDonald Hopkins LLC, a law firm having a place of business <br />at 39533 Woodward Avenue, Suite 318, Bloomfield Hills, MI 48304(ÐCounselÑ), as counsel for <br />and on behalf of CIty Of Centerville, having a place of business at 1880 Main Street, Centerville, <br />MN 55038 (ÐClientÑ) (Arete, Counsel, and Client are each a ÐParty,Ñ and collectively the <br />ÐPartiesÑ). All capitalized terms not otherwise defined in this SOW shall be defined as set forth <br />in the Agreement. <br />1.Services. <br />Overview: Arete Advisors will perform forensics investigative services including: <br />Conduct a forensics analysis to determine scope of attack, whether there was <br />exfiltration of data, and assure a clean bill of health. <br />I.Incident Response Support <br />Arete will provide support for the overall Investigation effort including <br />recommendations, validation of measures taken, review of architecture andsecurity <br />controls and malware specific mitigation measures. <br />Provide client updates and coordination. <br />II.Forensics Analysis Artifacts and Malware -Logs <br />Arete will perform analysis on the available email logs consisting of message trace <br />logs, unified audit logs, and exchange logs looking for malicious behavioral patterns, <br />evidence of compromise, indications of financial or wire fraud, rule creation, and <br />evidence of access to and/or exfiltration of sensitive data. <br />Arete will analyze one (1) email instance forevidence of threat actor behavior.This <br />analysis is limited to one (1) M365 Email Tenant (ÐTenant EnvironmentÑ) orone (1) <br />MS Exchange Server (ÐExchange EnvironmentÑ) only. Additional hours are required <br />for analysis of any environment other than Tenant Environment or Exchange <br />Environment. <br />Arete will examine the mailboxes of up to three (3) identified compromised accounts <br />within the Tenant Environment or Exchange Environment for phishing emails and <br />external outbound email transfers. Additional hours arerequired for examination of <br />activity beyond three (3) instances/transfers/ or accounts, including multiple frauds, <br />multiple accounts, or wire transfers. <br />III.OPTIONAL -Report of Findings <br />AreteÓs analysis will include the production of a forensic update presentation and <br />technical appendix to Client and Counsel, if requested by Counsel, containing the <br />findings of the forensics investigation and security validation. <br />Arete will produce a written report for an additional fee, if requested by Counsel. <br /> /ƚƓŅźķĻƓƷźğƌLƓŅƚƩƒğƷźƚƓ <br />tğŭĻ΋Њ <br />www.areteir.com <br /> <br />