Laserfiche WebLink
C. Network server and storage area networks (SAN) <br />1. Access to the data is restricted to authorized users through the use of access control <br />lists which will grant access only after the authorized user has authenticated to the <br />network. <br />2. Authentication must occur using a unique user ID and Complex Password, or other <br />authentication mechanisms which provide equal or greater security, such as <br />biometrics or smart cards. Accounts must lock after 5 unsuccessful access attempts, <br />and remain locked for at least 15 minutes, or require administrator reset. <br />3. The data are located in a secured computer area, which is accessible only by <br />authorized personnel with access controlled through use of a key, card key, or <br />comparable mechanism. <br />4. If the servers or storage area networks are not located in a secured computer area or <br />if the data is classified as Confidential or Restricted it must be encrypted as described <br />under F. Data storage on mobile devices or portable storage media. <br />D. Optical discs (CDs or DVDs) <br />1. Optical discs containing the data must be encrypted as described under F. Data <br />storage on mobile devices or portable storage media. <br />2. When not in use for the purpose of this Agreement, such discs must be locked in a <br />drawer, cabinet or other physically secured container to which only authorized users <br />have the key, combination or mechanism required to access the contents of the <br />container. <br />E. Access over the Internet or the State Governmental Network (SGN). <br />1. When the data is transmitted between DOH and the Information Recipient, access is <br />controlled by the DOH, who will issue authentication credentials. <br />2. Information Recipient will notify DOH immediately whenever: <br />a) An authorized person in possession of such credentials is terminated or <br />otherwise leaves the employ of the Information Recipient; <br />b) Whenever a person's duties change such that the person no longer requires <br />access to perform work for this Contract. <br />3. The data must not be transferred or accessed over the Internet by the Information <br />Recipient in any other manner unless specifically authorized within the terms of the <br />Agreement. <br />Page 21 of 26 <br />09/2017 <br />