Laserfiche WebLink
APPENDIX B <br />DATA SECURITY REQUIREMENTS <br />Protection of Data <br />The Information Recipient agrees to store information received under this Agreement (the data) <br />within the United States on one or more of the following media, and to protect it as described <br />below : <br />A. Passwords <br />1. Passwords must always be encrypted. When stored outside of the authentication <br />mechanism, passwo r ds must be in a secured environment that is separate from the data <br />and protected in the same manner as the data . For example passwords stored on mobile <br />devices or portable storage devices must be protected as described under section F. Data <br />storage on mobile devices or portable storage med;a . <br />2. Complex Passwords are : <br />• At least 8 chara cters in length . <br />• Contain at least three of the following character classes: uppercase letters, <br />lowercase letters, numerals, special characters. <br />• Do not contain the user's name, user ID or any form of their full name. <br />• Do not consist of a single complete dictionary word, but can include a passphrase . <br />• Changed at least every 120 days. <br />B. Hard disk drives -Data stored on workstation hard disks : <br />1. The data must be encrypted as described under section F. Data storage on mobile devices <br />or portable storage media. Encryption is not required when Potentially Identifiable <br />Information is stored temporarily on local workstation hard disks. Temporary storage is <br />thirty (30) days or less. <br />2. Access to the data is restricted to authorized users by requiring logon to the local <br />workstation using a unique user ID and Complex Password, or other authentication <br />mechanisms which provide equal or greater security, such as biometrics or smart cards. <br />Accounts must lock after 5 unsuccessful access attempts and remain locked for at least <br />15 minutes, or require administrator reset. <br />Page 20 of 26 <br />09/201(