Laserfiche WebLink
service office; (b) processed at the Agency's call center; and (c) under a Business <br /> Account Agreement when acting as the Business Account Lead Agency. <br /> 7.1.12 Comply with Generally Accepted Accounting Principles (GAAP), methods prescribed by <br /> the Washington State Auditor and business rules established by the Joint Board in <br /> accounting for assets, liabilities, resources and expenditures related to the ORCA <br /> System. <br /> 7.1.13 Allow access to facilities and records and/or conduct annual audits in accordance with <br /> GAAP and Generally Accepted Auditing Standards (GAAS); report audit concerns to the <br /> ROOT. <br /> 7.1.14 Collect, report and pay any taxes applicable to transactions that are processed by the <br /> Agency. Each Agency shall indemnify, defend and hold harmless other Agencies from <br /> claims, judgments and penalties of any kind and for all cost incurred (including attorney <br /> fees) as a result of the Agency's non-compliance with this subsection. <br /> 7.1.15 Agree to address all "user control considerations" identified in the Service Organization <br /> Controls (SOC) diagnostic review performed by an external auditor and implement such <br /> control activities or risk mitigation recommendations made in future external auditor <br /> engagements for the ROOT or SI Contractor. <br /> 7.1.16 Maintain insurance, or if self-insured, adequate reserves to respond to potential issues <br /> that arise through the course of the operation of the ORCA System. Without limiting any <br /> Agency's defense and indemnification obligations under this Agreement, each Agency <br /> shall maintain in force, at all times during the term of this Agreement, a policy or policies <br /> of Commercial General Liability insurance with limits not less than $1 million with <br /> insurance carriers authorized to do business in the state of Washington, which have a <br /> Best's rating of no less than A: VIII. If an Agency is self-insured, or is a member of a self- <br /> insurance pool, a certification of self-insurance covering the activities of the Agency in <br /> the ORCA System shall constitute compliance with this insurance requirement. Upon <br /> request of the Joint Board, each Agency shall submit documentation demonstrating its <br /> compliance with this insurance requirement. <br /> 7.2 Security. <br /> 7.2.1 Adequately manage the security of the Agency's portions of the system, and collectively, <br /> the ORCA System, including (but not limited to)the Payment Card Industry Data Security <br /> Standard (PCI-DSS), as evaluated against the version that is enforceable during the <br /> compliance period being assessed. <br /> 7.2.2 Incorporate and follow best security practices, the applicable standards at the point in <br /> time, in the operation and maintenance of the Agency's respective portions of the ORCA <br /> System. <br /> 7.2.3 Comply with the provisions of business rules and data security policies adopted by the <br /> Joint Board. <br /> 19 <br />