Laserfiche WebLink
B. <br />I <br />(1).Data will not be stored in any consumergrade Cloud solution, unless all of thefollowing <br />conditions are met: <br />(a). Contractor has written procedures in place governing use of the Cloud storage and <br />Contractor attests in writing that all such procedures will be uniformly followed; <br />(b). The Data will be Encrypted while within the Contractor network; <br />(c). The Data will remain Encrypted during transmission to the Cloud; <br />(d).The Data will remain Encrypted at alltimes while residing within the Cloud storage solution; <br />(e).The Contractor will possess a decryption key for the Data, and the decryption key will be <br />possessed only by the Contractor and/or DCyF, <br />(f). The Data will not be downloaded to non-authorized systems, meaning systems that are not <br />on either the DCYF or Contractor networks; <br />(g).The Data will not be decrypted until downloaded onto a computeror porlable devise within <br />the control of an Authorized User and within either the DCYF or Contractor's network; and <br />(h).Access to the cloud storage requires Multi Factor Authentication or Two Step Authentication. <br />(2).Data will not be stored on an Enterprise Cloud storage solution unless either: <br />(a) The Cloud storage provider is treated as any other Sub-Contractor, and agrees in writing toall of the requirements within this exhibit; or <br />(b) The Cloud storage solution used is FedRAMp certified. <br />(3) lf the Data includes protected health information covered by the Health lnsurance portability andAccountability Act (HIPAA), the Cloud. provider must sign a Business Associate Agreement priorto Data being stored in their Cloud solution. <br />Method of Transfer. <br />a. All Data transfers to or from the Contractor shall only be made by using the secure data.wa.govportal provided by the state of Washington with login and hardened paisword security. <br />b. The contractor shall use an encrypted email account for ele ctronic submissions which containConfidential, and Personal lnformation , as defined in the General Terms and Conditionslnformation regarding encrypted email acco unts can be obtained at DCyF's website, located at:d /serv hitd d d <br />System Protection <br />that Data passes: <br />d <br />b <br />To prevent compromise of systems which contain DCyF Data or through which <br />Systems containing Data must have all security patches or hotfixes applied within three (3) monthsof being made available; <br />The contractor will have a method of ensuring that the requisite patches and hotfixes have beenapplied within the required timeframes; <br />c' Systems containing Data shall have an Anti-Malware application, if available, installed; andDepartment of Children, youth & Families <br />2017CF County Program Agreement 6-24-20 <br />Page 15