Laserfiche WebLink
DOR Contract Number: K1687 <br />2) Network servers <br />a) Access to data stored on hard disks mounted on network servers and made available <br />through shared folders will be restricted to authorized users through the use of access <br />control lists, which will grant access only after the authorized user has authenticated to <br />the network using a unique user ID and complex password, passphrase, or other <br />authentication mechanisms that provide equal or greater security, such as biometrics or <br />smart cards. <br />b) Data on disks mounted to such servers must be located in a secure physical location. <br />c) Servers must be maintained with current anti-malware or anti -virus software. <br />d) Software and operating system security patches on servers must be kept current. <br />3) Backup tapes or backup media <br />a) Partner may archive Revenue data for disaster recovery (DR) or data recovery purposes. <br />b) Backup devices, tapes, or media must be kept in a secure physical location. <br />c) Backup tapes and media must be encrypted. <br />d) When being transported outside of a secure physical location, tapes or media must be <br />under the physical control of Partner staff with authorization to access the data or under <br />the physical control of a secure courier contracted by Partner for transportation purposes. <br />4) Cloud Storage <br />a) Revenue will meet cloud and data requirements in Washington's Standard for Securing <br />Information Technology Assets, OCIO Standard 141.10. <br />b) Revenue and Partner will, at a minimum, meet the following requirements: <br />i. Encrypt the data at rest and in transit. <br />ii. Control access to the cloud environment with a unique user ID and complex password, <br />passphrase, or stronger authentication method such as a physical token or biometrics. <br />iii. Cloud provider data center(s) and systems must be Service Organization Control <br />(SOC) 2 Type II certified. <br />5) All data provided by Revenue shall be stored on a secure environment by city staff. The City <br />will implement these policies to ensure this security: <br />a) Staff will not store or place any Revenue material on any portable devices or portable <br />media (USB devices, CD/DVD, etc.). <br />b) Staff will not email information provided by Revenue to anyone outside of City staff. <br />c) Staff shall only access Revenue information on a City network computer. <br />d) Staff will not save any Revenue reports or data on the hard drive of any City <br />computer. It shall only be stored on a City network. <br />B. Protection of Data in Transit <br />Partner agrees that any retransmission of Revenue data over a network, other than the Partner's <br />internal business network will be encrypted. <br />88 <br />Page 8 of 10 <br />