Laserfiche WebLink
(1). Data will not be stored in any consumer grade Cloud solution, unless all of the following <br />conditions are met: <br />(a). Contractor has written procedures in place governing use of the Cloud storage and <br />Contractor attests in writing that all such procedures will be uniformly followed; <br />(b). The Data will be Encrypted while within the Contractor network; <br />(c). The Data will remain Encrypted during transmission to the Cloud; <br />(d). The Data will remain Encrypted at all times while residing within the Cloud storage solution; <br />(e). The Contractor will possess a decryption key for the Data, and the decryption key will be <br />possessed only by the Contractor and/or DCYF; <br />(f). The Data will not be downloaded to non -authorized systems, meaning systems that are not <br />on either the DCYF or Contractor networks; <br />(g). The Data will not be decrypted until downloaded onto a computer or portable devise within <br />the control of an Authorized User and within either the DCYF or Contractor's network; and <br />(h). Access to the cloud storage requires Multi Factor Authentication or Two Step Authentication. <br />(2). Data will not be stored on an Enterprise Cloud storage solution unless either: <br />(a) The Cloud storage provider is treated as any other Sub -Contractor, and agrees in writing to <br />all of the requirements within this exhibit; or <br />(b) The Cloud storage solution used is Fed RAMP certified. <br />(3) If the Data includes protected health information covered by the Health Insurance Portability and <br />Accountability Act (HI PAA), the Cloud provider must sign a Business Associate Agreement prior <br />to Data being stored in their Cloud solution. <br />8. Method of Transfer. <br />a. All Data transfers to or from the Contractor shall only be made by using the secure data.wa.gov <br />portal provided by the state of Washington with login and hardened password security. <br />b. The Contractor shall use an encrypted email account for electronic submissions which contain <br />Confidential, and Personal Information, as defined in the General Terms and Conditions. <br />Information regarding encrypted email accounts can be obtained at DCYF's website, located at: <br />https://www.dcyf.wa.g ov/services/ch ild-welfare-orovid erste ncrypted-ema i I. <br />9. System Protection. To prevent compromise of systems which contain DCYF Data or through which <br />that Data passes: <br />a. Systems containing Data must have all security patches or hotfixes applied within three (3) months <br />of being made available; <br />b. The Contractor will have a method of ensuring that the requisite patches and hotfixes have been <br />applied within the required timeframes; <br />C. Systems containing Data shall have an Anti-Malware application, if available, installed; and <br />Department of Children, Youth & Families <br />2017CF County Program Agreement 6-24-20 <br />Page 15 <br />