Laserfiche WebLink
1 Definitions <br />definitions: <br />EXHIBIT A <br />DATA SECURITY REQUIREMENTS <br />ORGANIZATION OF DATA SECURITY REQUIREMENTS <br />1. Definitions <br />2. Authority <br />3. Scope of Protection <br />4. Data Classification <br />5. Compliance with Laws, Rules, Regulations, and Policy6. Administrative Controls <br />7. Authorization, Authentication, and Access <br />B. Protection of Data <br />9. Method of Transfer <br />10. System Protection <br />1 1. Data Segregation <br />1 2. Confidentiality Protection <br />'13. Data Disposition <br />1 4. Data shared with Subcontractors <br />15. Notification of Compromise or Potential Compromise <br />16. Breach of Data <br />The words and phrases listed below, as used in this Exhibit, shall each have the following <br />a <br />Departmentof Children, Youth & Families <br />2017CF County Program Agreement 6-24-20 <br />b <br />c. <br />"AES" means the Advanced Encryption Standard, a specification of Federal lnformation processing <br />Standards Publications for the encryption of electronic data issued by the National lnstitute of <br />Standards and Technology (http:/invlpubs.nist.gov/nistpubs/FIPS/NIST. F tPS.1 97. pdf). <br />"Authorized Users(s)" means an individual or individuals Wth a busin ess need to access DCYF <br />Confidential lnformation, and who has been authorized to do so. <br />"Cloud storage" means data storage on servers hosted by an entity other than the Contractor and <br />on a network outside the control of the Contractor. Physical storage of data in the cloud typically <br />spans multiple servers and often multiple locations. Cloud storagecan be divided between <br />consumer grade storage for personal files and enterprise grade for companies and governmental <br />entities. Examples of consumer grade storage would include iTunes, Dropbox, Box.com, and manyother entities. Enterprise cloud vendors include Microsoft Azure,Amazon Web Services, and <br />Rackspace. <br />"Confidential lnformation" means information that may be exempt from disclosure to the public orother unauthorized persons under either chapler 42.56 RCW or other state or federal laws. <br />Confidential lnformation includes, but is not limited to, Personal lnformation, agency source code or <br />gbject cod_e, and agency security data. "Confidential lnformation" also includes", buiis not limited to,Category 3 and Category 4 Data as described in section 4 of this Exhibit lexfrUiiA: Data Security- ' <br />Requirements), Personal lnformation, Materials, and Data. The definitjon of "Confidential <br />lnformation" shallalso include the definition described in section 1 (Definitions)of the General <br />Terms and Conditions of this Contract. <br />"Data" means DCYF's records, files, forms, information and other documents in electronic or hardcopy medium. "Data" includes, but is not limited to, Confidential lnformation. <br />d <br />e <br />Page 1 5