Laserfiche WebLink
5. Paper documents. Any paper records must be protected by storing the records in <br /> a secure area accessible only to authorized individuals. When not in use, such <br /> records must be stored in a locked container,such as a file cabinet,locking drawer, <br /> or safe,to which only authorized persons have access. <br /> 6. Portable Devices. Within this Agreement, portable devices include, but are not <br /> limited to handhelds/PDAs, Ultramobile PCs, flash memory devices (e.g., USB <br /> flash drives, personal media players),portable hard disks, and laptop/notebook <br /> computers. Portable media includes,but is not limited to optical media(e.g.,CD's, <br /> DVD's,Blu-Rays),magnetic media(e.g.,floppy disks,Zip or Jaz disks or drives), <br /> and flash media(e.g.,Compact Flash,SD Card,MMC). <br /> Requestor shall not store WADOC Data on portable devices or portable media <br /> unless specifically authorized within this Agreement. If so authorized, the <br /> Requestor shall: <br /> a. Encrypt the data with a FIPS approved cryptographic algorithm. <br /> b. Control access to devices with a unique user ID and password or stronger <br /> authentication method such as a physical token or biometrics. <br /> c. Manually lock devices whenever they are left unattended and set devices to <br /> lock automatically after a period of inactivity, if this feature is available. <br /> Maximum period of inactivity is twenty(20)minutes. <br /> d. Physically protect the portable device(s) and/or media by keeping them in <br /> locked storage when unused; using check-in/check-out procedures when <br /> device or other media is being shared;taking frequent inventories of media, <br /> and access to media by users. <br /> e. When being transported outside of a secure area,portable devices and media <br /> with confidential WADOC Data must be under the physical control of <br /> Requestor's staff with authorization to access the data. <br /> B. SAFEGUARDS AGAINST UNAUTHORIZED USE AND RE-DISCLOSURE OF DATA. <br /> Requestor shall exercise due care to protect all data from unauthorized physical and <br /> electronic access. Both parties shall establish and implement the following minimum <br /> physical, electronic, and managerial safeguards for maintaining the confidentiality of <br /> information provided by either party pursuant to this Agreement: <br /> 1. Access to information provided by WADOC will be restricted to only those <br /> authorized staff, officials, and agents of the parties who need it to perform their <br /> official duties in the performance of the work requiring access to the information <br /> as detailed in this Agreement and/or contract which this Agreement concerns. <br /> Washington State K12798 Page 4 of 9 <br /> Department of Corrections Attachment A <br />