Laserfiche WebLink
Offsite/Cloud Addendum - 2 <br />6.20.23 <br />access City data remotely only as required to provide technical <br />support. <br />6. Encryption: <br />a. Vendor shall encrypt all non-public data in transit regardless of <br />the transit mechanism. <br />b. For engagements where Vendor stores sensitive personally <br />identifiable or otherwise confidential information, this data shall <br />be encrypted at rest. Examples of such information include <br />without limitation: social security number, date of birth, driver’s <br />license number, financial data, federal/state tax information, and <br />hashed passwords. Vendor’s encryption shall be consistent with <br />validated cryptography standards as specified in National <br />Institute of Standards and Technology FIPS140-2, Security <br />Requirements. The key location and other key management <br />details will be agreed to by City and Vendor technical staffs. <br />When Vendor cannot maintain encryption at rest, Vendor <br />must maintain, for the duration of the Agreement, cyber <br />security liability insurance coverage for any loss resulting <br />from a data breach in accordance with Supplier shall <br />procure and maintain insurance as required under cyber <br />liability insurance requirements at: <br />https://www.everettwa.gov/319/Procurement. Additionally, <br />where encryption of data at rest is not possible, Vendor <br />must provide to the City a description of its existing <br />security measures that provide a similar level of protection. <br />7. Breach Notification and Recovery: The City requires public breach <br />notification when citizens’ personally identifiable information is lost or <br />stolen. Additionally, unauthorized access or disclosure of non-public <br />data is considered to be a breach. Vendor will provide notification <br />without unreasonable delay and all communication shall be pre- <br />coordinated with the City. When Vendor or Vendor’s subcontractors <br />are responsible for the loss, Vendor shall bear all costs associated with <br />the investigation, response and recovery from the breach, including <br />without limitation credit monitoring services with a term of at least three <br />years, mailing costs, website, and toll free telephone call center <br />services. The City rejects any limitation on liability that purports to <br />relieve a vendor from its own negligence or to the extent that it <br />purports to creates an obligation on the part of the City or State of <br />Washington to hold a vendor harmless. <br />8. Notification of Legal Requests: Vendor shall notify the City upon <br />receipt of any electronic discovery, litigation holds, discovery searches, <br />and expert testimonies related to, or which in any way might <br />reasonably require access to, the data of the City. Vendor shall not <br />respond to subpoenas, service of process, and other legal requests