Laserfiche WebLink
DocuSign Envelope ID: 94D165AB-F367-4157-8526-77F15FF93CD8 <br />ATTACHMENT B - Data Security Requirements <br />1. Data Classification <br />The classification of the data shared is considered: <br />❑ Category 1 — Public Information <br />❑ Category 2 — Sensitive Information <br />® Category 3 — Confidential Information <br />❑ Category 4 — Confidential Information Requiring Special Handling <br />2. Access Security <br />Access to the Data will be restricted to authorized users by requiring a login using a unique user ID and <br />complex password or other authentication mechanism which provides equal or greater security. Passwords <br />must be changed on a periodic basis and the sharing of user ID and passwords is strictly prohibited. <br />3. Data Storage <br />Agent agrees that any and all Data will be stored, processed, and maintained solely on designated computing <br />equipment and that at no time will Data be processed on or transferred to any portable storage medium. <br />4. Data Transmission <br />Agent agrees that any and all electronic transmissions or exchanges of system and application data with DOL <br />and/or any other parties expressly designated by DOL shall take place via secure means. Data that is <br />transferred by and/or resides on assigned DOL equipment is considered secure. <br />5. Distribution of Data <br />Agent shall ensure no Data of any kind shall be transmitted, exchanged, or otherwise passed to other <br />contractors/vendors or interested parties except on a case-by-case basis as specifically agreed to in writing <br />by DOL. Agent further agrees not to release, outside their control, screen prints or other printed documents <br />that are not designated for the customer. All hard copies not necessary for business use must be destroyed <br />as referenced in the Data Disposal section. <br />6. Data Disposal <br />Unless otherwise specified in the Agreement, Agent agrees that upon termination of this Agreement it shall <br />erase, destroy, and render unrecoverable all DOL data and certify in writing that these actions have been <br />completed within 30 days of the termination of this Agreement or within 7 days of the request of an agent of <br />DOL, whichever shall come first. At a minimum, media sanitization is to be performed according to the <br />standards enumerated by NIST SP 800-88 Guidelines for Media Sanitization. <br />7. Security Breach Notification <br />Agent agrees to comply with all applicable laws that require the notification of individuals in the event of <br />unauthorized release of DOL data or other event requiring notification. In the event of a breach of any of <br />Agent's security obligations, or other event requiring notification under applicable law, Agent agrees to the <br />following: <br />a) Notify DOL by telephone and e-mail of such an event within 24 hours of discovery: <br />DOL Help Desk, phone: (360) 902-0111; email: hlbhelp@dol.wa.gov <br />b) Assume responsibility for costs and for cooperating with DOL on all matters necessary for informing all <br />such individuals, as directed by DOL, and in accordance with applicable state and federal laws. <br />c) Mitigate the risk of loss and comply with any notification or other requirements imposed by law or DOL. <br />WA State Department of Licensing Page 22 of 26 DOL Reference # K6984 <br />Version: January 2020 Attachment B — Data Security Requirements County Reference # V01901 <br />