Laserfiche WebLink
L2 <br />C. Administrative Safeguards <br />SSA and the Reporter will restrict access to the data received under this agreement to <br />only those authorized employees, officials, and contractors ("personnel") who need it to <br />perform their official duties in connection with the uses of the data authorized in this <br />agreement. Further, SSA and the Reporter will advise all personnel who will have access <br />to the data received under this agreement of the confidential nature of the data, the <br />safeguards required to protect the data, and the civil and criminal sanctions for <br />noncompliance contained in the applicable Federal laws. <br />D. Physical Safeguards <br />SSA and the Reporter will store the data received under this agreement in an area that is <br />physically and technologically secure from access by unauthorized persons during duty <br />hours as well as nonduty hours or when not in use (e.g., door locks, card keys, biometric <br />identifiers). Only authorized personnel will transport the data received. SSA and the <br />Reporter will establish appropriate safeguards determined by a risk-based assessment of <br />the circumstances involved. <br />E. Technical Safeguards <br />SSA and the Reporter will process the data received under this agreement under the <br />immediate supervision and control of authorized personnel in a manner that will protect <br />the confidentiality ofthe data, so that unauthorized persons cannot retrieve any data by <br />computer, remote terminal, or other means. Systems personnel must enter personal <br />identification numbers when accessing data on the agencies' systems. SSA and the <br />Reporter will strictly limit authorizationto those electronic data areas necessary for the <br />authorized analyst to perform his or her official duties. <br />F. Application of Policy and Procedures <br />SSA and the Reporter will adopt policies and procedures to ensure that the parties use the <br />information contained in their respective records or obtained from each other solely as <br />provided in this agreement. SSA and the Reporter will comply with these guidelines and <br />any subsequent revisions. <br />G. Onsite Inspection <br />SSA has the right to monitor the Reporter's compliance with FISMA and other security <br />and safeguarding requirements in applicable laws, regulations, and directives. SSA has <br />the right to make onsite inspections for auditing compliance, if necessary, for the duration <br />or any extension of this agreement. <br />IX. Records Usage, Duplication, Redisclosure <br />A. Reporter's Responsibilities