Laserfiche WebLink
a <br />Program against all information stored locallY and off-site. Information must be encrypted <br />both in-transit and at rest and apPlied in such a way that it renders data unusable to anyone <br />but authorized Personnel,and the confidential Process'encryption keY or other means to <br />decipher the information is protected from unauthorized access <br />It is compliant with the aPPl icable provisions of the Washington State Office of Washington <br />Technology Solutions (WaTech) policy SEC-01 through SEC-13,Securing Information <br />atrTechnology Assets, available at: <br />ilssets. <br />r It will provide DOH copies of its IT security policies, practices and procedures upon the <br />,.qu"ri of the DOH Chief Information Security Officer' <br />. DOH may atany time conduct an audit of the LHJ's security practices and/or infrastructure to <br />assure compliance with the security requirements of this contract. <br />. It has implemented physical, electronic and administrative safeguards that are consistent with <br />WaTech security standard SEC-01 through SEC-13 and ISB-IT guidelines to-prevent <br />unauthorized u"L"rr, use, modification oidisclosure of DOH Confidentiallnformation in any <br />form. <br />This includes, but is not limited to, restricting access to specifically authorized individuals and <br />services through the use of: <br />o Documented access authorization and change control procedures; <br />o Card key systems that restrict, monitor and log access; <br />o Locked ruik, fo, the storage of servers that contain Confidential Information or use <br />AES encryption (key lengths of 256 bits or greater) to protect confidentialdata at <br />."rt, .tuniurd algoriihms validated by the National Institute of Standards and <br />Technology(NIST)CryptographicAlgorithmValidationProgram(CMVP); <br />o Documefied'patch munug"rn"nt practices that assure all network systems are running <br />"riticairl"urity updates,iitnin 6 days of release when the exploit is in the wild, and <br />within 30 days of release for all others; <br />o Documented anti-virus strategies that assure all systems are running the most current <br />anti-virus signatures within 1 day of release; <br />o Complex puiswords that are sysiematically enforced and password expiration not to <br />exceed l2b days, dependent user authentiiation types as defined in WaTech security <br />standards; <br />o Strong multi-factor authentication mechanisms that assure the identity of individuals <br />who access Conhdential Information; <br />o Account lock-out after 5 failed authentication attempts for a minimum of 15 minutes, <br />orforConfidentiallnformation,untiladministratorreset; <br />oAESencryption(usingkeytengthsl28bitsorgreater)sessionforalldata <br />transmissions, standard algorithms validated by MST CMVP; <br />o Firewall rules and network address translation that isolate database servers from web <br />servers and Public networks; <br />o Regular."ui.* of firewall rules and configurations to assure compliance with <br />authorization and change control procedures; <br />oLogmanagementandintrusiondetectiorr/preventionSystems; <br />o A documented and tested incident response plan <br />Any breach of this clause may result in termination of the contract and the demand for return of all personal <br />information. <br />DOH Contract CLH3263 5 -0 <br />July 2025 <br />rI <br />Page 5 of9