Laserfiche WebLink
11 <br /> • ATTACHMENT 3 <br /> SECURITY STANDARDS <br /> ORCA Business Account Security Best Practices <br /> for University of Washington and Cascadia Community College <br /> delines the <br /> Purpose: The purpose of this O Bu mess Acment is to describe count Website fsecurity and managing ORCA card sttock.ns will <br /> follow when accessing the ORCA <br /> Application Security <br /> Access to the ORCA Business Account Website is restricted to authorized representatives, which are <br /> . the University Transportation Services Director, Transportation Systems Manager, and Sales and <br /> Administration Manager; and the College Director of Finance. For the purposes of this attachment, <br /> these parties will be called Website Users. <br /> The University Transportation Systems Manager and College Director of Finance will establish a valid <br /> user id and password in order to access the ORCA Business Account Website. <br /> Passwords should be changed a minimum of one time per Academic Quarter. <br /> Website Users must keep the University and College user ids and passwords confidential. <br /> Additional Website Users may be permitted if approved by the University Transportation Services <br /> Director or College Director of Finance. <br /> Any changes in user access, i.e. appointed users leaving the employment of the business account, <br /> must be communicated to the Lead Agency Business Account administrator. <br /> Website Users will review security policies and guidelines annually. <br /> Website Users will keep any personally identifiable data confidential and secure. <br /> Website Users should log off the ORCA Business Account Website or lock their screen using a <br /> password protected screen-saver when not at their workstations to prevent unauthorized access. <br /> Physical Security <br /> Undistributed ORCA Cards must be stored in a locked cabinet/drawer during non-business hours. <br /> Access to the ORCA Cards will be limited to staff involved in the distribution of ORCA Cards and sale of <br /> the U-PASS product. <br /> Incident Management <br /> Any security incident or potential incident should be reported immediately to the Lead Agency <br /> Representative, who will follow regional procedures to notify affected Parties. <br /> U-PASS Agreement 85 Pa e 34 of 44 Final, October 2011 <br /> Attachment 3, Security Standards g <br />