Laserfiche WebLink
WSP Contract No.TRACS00259 <br />For External Use Only: <br />Attachment A: <br />Statement of Work for <br />Data Security Requirements <br />g. Electronic Records at Rest. <br />If there is a need for Records to be stored on any of the Recipient's devices, the Agency <br />must assure unauthorized access cannot take place, including but not limited to session <br />locks with password protection when the computer is on and left unattended. Records <br />stored on non-WSP equipment must be encrypted utilizing FIPS 140-2 certified encryption <br />software as required by Section J(iv) below. <br />h. Authentication of User Identity. <br />i. Authentication from inside a WSP facility for the Agency staff to access internal LAN <br />and computer systems requires User ID and password. <br />ii. Authentication for the Agency staff from a location outside of a WSP facility requires <br />strong authentication (e.g., digital certificates, hardware, tokens, biometrics, etc.). <br />L Records Recovery. <br />-__ If either -Party -experiences -loss -of the Records or equipment obtained or maintained <br />pursuant to this Agreement, that Party shall promptly provide written notification to the other <br />Party's Contract Manager. <br />j. Systems Management: <br />The Agency shall ensure all systems, including portable systems, are maintained with all <br />best security practices equal to WSP's including but not limited to: <br />i. Install and maintain commercially available antivirus program <br />ii. Maintain current levels of security patches on operating systems <br />iii. Utilize firewalls <br />iv. Utilize FIPS 140-2 certified encryption software with proper configurations <br />V. Maintain physically secure areas for information systems <br />vi. Monitor logs <br />vii. Utilize an established incident plan <br />viii. Report incidents involving WSP Data <br />TraCS Data Sharing Agreement Approved by AGO 02/04/2026 Page 12 of 14 <br />