Laserfiche WebLink
DocuSign Envelope ID: 62955F1D-7A37-4CB0-A8D8-2BA7ADB5515E <br />notify EXCHANGE staff immediately whenever an authorized person in possession of such <br />credentials is terminated or otherwise leaves the employ of the contractor and whenever a <br />user's duties change such that the user no longer requires access to perform work for this <br />Contract. <br />h. Data storage on portable devices or media. <br />(1) EXCHANGE Data shall not be stored by the Contractor on portable devices or media <br />unless specifically authorized within the Special Terms and Conditions of the contract. If <br />so authorized, the Data shall be given the following protections: <br />(a) Encrypt the Data with a key length of at least 128 bits using an industry standard <br />algorithm (e.g., AES, Twofish, RC6, etc.) <br />(b) Control access to devices with a unique user ID and password or stronger <br />authentication method such as a physical token or biometrics. <br />(c) Manually lock devices whenever they are left unattended and set devices to lock <br />automatically after a period of inactivity, if this feature is available. Maximum <br />period of inactivity is 20 minutes. <br />Physically protect the portable device(s) and/or media by <br />(d) Keeping them in locked storage when not in use <br />(e) Using check-in/check-out procedures when they are shared, and <br />(f) Taking frequent inventories <br />(2) When being transported outside of a secure area, portable devices and media with <br />confidential EXCHANGE Data must be under the physical control of contractor staff with <br />authorization to access the Data. <br />(3) Portable devices include any small computing device that can be transported. They <br />include, but are not limited to; handhelds/PDAs/phones, Ultramobile PCs, flash memory <br />devices (e.g. USB flash drives, personal media players), and laptop/notebook/tablet <br />computers. <br />(4) Portable media includes any Data storage that can be detached or removed from a <br />computer and transported. They include, but are not limited to; optical media (e.g. CDs, <br />DVDs), magnetic media (e.g. floppy disks, tape, Zip or Jaz disks), USB drives, or flash <br />media (e.g. CompactFlash, SD, MMC). <br />4. Data Segregation. <br />a. EXCHANGE Data must be segregated or otherwise distinguishable from non -EXCHANGE <br />Data. This is to ensure that when no longer needed by the contractor, all EXCHANGE Data <br />can be identified for return or destruction. It also aids in determining whether EXCHANGE <br />Data has or may have been compromised in the event of a security breach. <br />b. EXCHANGE Data will be kept on media (e.g. hard disk, optical disc, tape, etc.) which will <br />contain no non-HBE Data. Or, <br />c. HBE Data will be stored in a logical container on electronic media, such as a partition or <br />folder dedicated to HBE Data. Or, <br />HBE-349 YNHS Exhibit D — Data Security Requirements Page 26 of 41 <br />