Laserfiche WebLink
EXHIBIT A <br />DATA SECURITY REQUIREMENTS <br />ORGANIZATION OF DATA SECURITY REQUIREMENTS <br />1. Definitions <br />2. Authority <br />3. Scope of Protection <br />4. Data Classification <br />5. Compliance with Laws, Rules, Regulations, and Policy <br />6. Administrative Controls <br />7. Authorization, Authentication, and Access <br />8. Protection of Data <br />9. Method of Transfer <br />10. System Protection <br />11. Data Segregation <br />12. Confidentiality Protection <br />13. Data Disposition <br />14. Data shared with Subcontractors <br />15. Notification of Compromise or Potential Compromise <br />16. Breach of Data <br />Definitions. Thewords and phrases listed below, as used in this Exhibit, shall each have the following <br />definitions: <br />a. "AES" means the Advanced Encryption Standard, a specification of Federal Information Processing <br />Standards Publications for the encryption of electronic data issued by the National Institute of <br />Standards and Technology (http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197.pdf). <br />b. "Authorized Users(s)" means an individual or individuals with a business need to access DCYF <br />Confidential Information, and who has been authorized to do so. <br />c. "Cloud storage" means data storage on servers hosted by an entity other than the Contractor and <br />on a network outside the control of the Contractor. Physical storage of data in the cloud typically <br />spans multiple servers and often multiple locations. Cloud storage can be divided between <br />consumer grade storage for personal files and enterprise grade for companies and governmental <br />entities. Examples of consumer grade storage would include iTunes, Dropbox, Boxcom, and many <br />other entities. Enterprise cloud vendors include Microsoft Azure, Amazon Web Services, and <br />Rackspace. <br />d. "Confidential Information" means information that may be exempt from disclosure to the public or <br />other unauthorized persons under either chapter42.56 RCW or other state or federal laws. <br />Confidential Information includes, but is not limited to, Personal Information, agency source code or <br />object code, and agency security data. "Confidential Information" also includes, but is not limited to, <br />Category 3 and Category 4 Data as described in section 4 of this Exhibit (Exhibit A: Data Security <br />Requirements), Personal Information, Materials, and Data. The definition of "Confidential <br />Information" shall also include the definition described in section 1 (Definitions) of the General <br />Terms and Conditions of this Contract. <br />e. "Data' means DCYF's records, files, forms, information and other documents in electronic or hard <br />copy medium. "Data" includes, but is not limited to, Confidential Information. <br />Department of Children, Youth & Families <br />2017CF County Program Agreement 6-24-20 Page 15 <br />