Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policy, Securing Information Technology Assets, available at ▇▇▇▇://▇▇▇.▇▇.▇▇▇/ocio. It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH IT Security Officer. DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. It has implemented physical, electronic and administrative safeguards that are consistent with ISB IT security standards and guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: Documented access authorization and change control procedures; Card key systems that restrict, monitor and log access; Locked racks for the storage of servers that contain Confidential Information or AES encryption (128bit or stronger) to protect confidential data at rest; Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; Complex passwords that are systematically enforced and expire at least every 180 days; Strong (Two Factor) authentication mechanisms that assure the identity of individuals who access Confidential Information; Account lock-out after 5 failed authentication attempts for a minimum of 20 minutes, or for Confidential Information, until administrator reset; AES encrypted (128bit or stronger) sessions for all data transmissions. Firewall rules and network address translation that isolate database servers from web servers and public networks; Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; Log management and intrusion detection/prevention systems; A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 5 contracts
Sources: Contract Agreement, Data Sharing Agreement, Contract Agreement
Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policyOfficer (OCIO) policy 141, Securing Information Technology Assets, available at at: ▇▇▇▇▇://▇▇▇▇.▇▇.▇▇▇/ocio/policy/securing-information-technology-assets. It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH IT Chief Information Security Officer. DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. It has implemented physical, electronic and administrative safeguards that are consistent with OCIO security standard 141.10 and ISB IT security standards and guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: o Documented access authorization and change control procedures; o Card key systems that restrict, monitor and log access; o Locked racks for the storage of servers that contain Confidential Information or use AES encryption (128bit key lengths of 256 bits or strongergreater) to protect confidential data at rest, standard algorithms validated by the National Institute of Standards and Technology (NIST) Cryptographic Algorithm Validation Program (CMVP); o Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; o Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; o Complex passwords that are systematically enforced and expire at least every 180 password expiration not to exceed 120 days, dependent user authentication types as defined in OCIO security standards; o Strong (Two Factor) multi-factor authentication mechanisms that assure the identity of individuals who access Confidential Information; o Account lock-out after 5 failed authentication attempts for a minimum of 20 15 minutes, or for Confidential Information, until administrator reset; o AES encrypted encryption (128bit using key lengths 128 bits or strongergreater) sessions session for all data transmissions. , standard algorithms validated by NIST CMVP; o Firewall rules and network address translation that isolate database servers from web servers and public networks; o Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; o Log management and intrusion detection/prevention systems; o A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 4 contracts
Sources: Contract Agreement, Contract Agreement, Contract Agreement
Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policy, Securing Information Technology Assets, available at ▇▇▇▇://▇▇▇.▇▇.▇▇▇/ocio. It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH IT Security Officer. DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. It has implemented physical, electronic and administrative safeguards that are consistent with ISB IT security standards and guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: Documented access authorization and change control procedures; Card key systems that restrict, monitor and log access; Locked racks for the storage of servers that contain Confidential Information or AES encryption (128bit or stronger) to protect confidential data at rest; Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; Documented anti-virus strategies that assure all systems are running the most current anti-anti- virus signatures within 1 day of release; Complex passwords that are systematically enforced and expire at least every 180 days; Strong (Two Factor) authentication mechanisms that assure the identity of individuals who access Confidential Information; Account lock-out after 5 failed authentication attempts for a minimum of 20 minutes, or for Confidential Information, until administrator reset; AES encrypted (128bit or stronger) sessions for all data transmissions. Firewall rules and network address translation that isolate database servers from web servers and public networks; Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; Log management and intrusion detection/prevention systems; A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 2 contracts
Sources: Contract Agreement, Contract Agreement
Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: • It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policy, Securing Information Technology Assets, available at ▇▇▇▇://▇▇▇.▇▇.▇▇▇/ocio. /ocio • It will provide DOH copies of its IT security policies, practices practices, and procedures upon the request of the DOH IT Security Officer. Officer • DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. contract • It has implemented physical, electronic electronic, and administrative safeguards that are consistent with ISB WA OCIO and WaTech IT security standards and guidelines to prevent unauthorized access, use, modification modification, or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: • Documented access authorization and change control procedures; procedure • Card key systems that restrict, monitor and log access; access • Locked racks for the storage of servers that contain Confidential Information or AES encryption (128bit or stronger) to protect confidential data at rest; rest • Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; others • Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; release • Complex passwords that are systematically enforced and expire at least every 180 days; Strong days • ▇▇▇▇▇▇ (Two Factor) authentication mechanisms that assure the identity of individuals who access Confidential Information; Information • Account lock-out after 5 failed authentication attempts for a minimum of 20 minutes, or for Confidential Information, until administrator reset; reset • AES encrypted (128bit or stronger) sessions for all data transmissions. transmissions • Firewall rules and network address translation that isolate database servers from web servers and public networks; networks • Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; procedures • Log management and intrusion detection/prevention systems; systems • A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 2 contracts
Sources: Purchase Order, Purchase Order Terms and Conditions
Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policy, Securing Information Technology Assets, available at ▇▇▇▇▇://▇▇▇▇.▇▇.▇▇▇/ocio. /policy/securing-information-technology-assets-standards It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH IT Security Officer. DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. It has implemented physical, electronic and administrative safeguards that are consistent with ISB OCIO IT security standards and guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: Documented access authorization and change control procedures; Card key systems that restrict, monitor and log access; Locked racks for the storage of servers that contain Confidential Information or AES encryption (128bit or stronger) to protect confidential data at rest; Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; Complex passwords that are systematically enforced and expire at least every 180 days; Strong (Two Factor) authentication mechanisms that assure the identity of individuals who access Confidential Information; Account lock-out after 5 failed authentication attempts for a minimum of 20 minutes, or for Confidential Information, until administrator reset; AES encrypted (128bit or stronger) sessions for all data transmissions. Firewall rules and network address translation that isolate database servers from web servers and public networks; Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; Log management and intrusion detection/prevention systems; A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 1 contract
Sources: Contract Agreement
Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policy, Securing Information Technology Assets, available at ▇▇▇▇▇://▇▇▇▇.▇▇.▇▇▇/ocio. /policy/securing-information-technology-assets-standards It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH IT Security Officer. DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. It has implemented physical, electronic and administrative safeguards that are consistent with ISB OCIO IT security standards and guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: Documented access authorization and change control procedures; Card key systems that restrict, monitor and log access; Locked racks for the storage of servers that contain Confidential Information or AES encryption (128bit 128 bit or stronger) to protect confidential data at rest; Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; Complex passwords that are systematically enforced and expire at least every 180 days; Strong (Two Factor) authentication mechanisms that assure the identity of individuals who access Confidential Information; Account lock-out after 5 failed authentication attempts for a minimum of 20 minutes, or for Confidential Information, until administrator reset; AES encrypted (128bit 128 bit or stronger) sessions for all data transmissions. Firewall rules and network address translation that isolate database servers from web servers and public networks; Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; Log management and intrusion detection/prevention systems; A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 1 contract
Sources: Contract
Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policy, Securing Information Technology Assets, available at ▇▇▇▇▇://▇▇▇▇.▇▇.▇▇▇/ocio. /policy/securing-information-technology-assets-standards It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH IT Security Officer. DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. It has implemented physical, electronic and administrative safeguards that are consistent with ISB IT security standards and guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: Documented access authorization and change control procedures; Card key systems that restrict, monitor and log access; Locked racks for the storage of servers that contain Confidential Information or AES encryption (128bit or stronger) to protect confidential data at rest; Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; Complex passwords that are systematically enforced and expire at least every 180 days; Strong (Two Factor) authentication mechanisms that assure the identity of individuals who access Confidential Information; Account lock-out after 5 failed authentication attempts for a minimum of 20 minutes, or for Confidential Information, until administrator reset; AES encrypted (128bit or stronger) sessions for all data transmissions. Firewall rules and network address translation that isolate database servers from web servers and public networks; Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; Log management and intrusion detection/prevention systems; A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 1 contract
Sources: Consultation Agreement
Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policyOfficer (OCIO) policy 141, Securing Information Technology Assets, available at at: ▇▇▇▇▇://▇▇▇▇.▇▇.▇▇▇/ocio/policy/securing-information-technology- assets. It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH IT Chief Information Security Officer. DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. It has implemented physical, electronic and administrative safeguards that are consistent with OCIO security standard 141.10 and ISB IT security standards and guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: o Documented access authorization and change control procedures; o Card key systems that restrict, monitor and log access; o Locked racks for the storage of servers that contain Confidential Information or use AES encryption (128bit key lengths of 256 bits or strongergreater) to protect confidential data at rest, standard algorithms validated by the National Institute of Standards and Technology (NIST) Cryptographic Algorithm Validation Program (CMVP); o Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; o Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; o Complex passwords that are systematically enforced and expire at least every 180 password expiration not to exceed 120 days, dependent user authentication types as defined in OCIO security standards; o Strong (Two Factor) multi-factor authentication mechanisms that assure the identity of individuals who access Confidential Information; o Account lock-out after 5 failed authentication attempts for a minimum of 20 15 minutes, or for Confidential Information, until administrator reset; o AES encrypted encryption (128bit using key lengths 128 bits or strongergreater) sessions session for all data transmissions. , standard algorithms validated by NIST CMVP; o Firewall rules and network address translation that isolate database servers from web servers and public networks; o Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; o Log management and intrusion detection/prevention systems; o A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 1 contract
Sources: Sample Contract
Security of Information. Unless otherwise specifically authorized by the DOH IT Security Officer, Contractor receiving confidential information under this contract assures that: • It is compliant with the applicable provisions of the Washington State Office of the Chief Information Officer’s policyOfficer (OCIO) policy 141, Securing Information Technology Assets, available at at: ▇▇▇▇▇://▇▇▇▇.▇▇.▇▇▇/ocio/policy/securing-information-technology-assets. • It will provide DOH copies of its IT security policies, practices and procedures upon the request of the DOH IT Chief Information Security Officer. • DOH may at any time conduct an audit of the Contractor’s security practices and/or infrastructure to assure compliance with the security requirements of this contract. • It has implemented physical, electronic and administrative safeguards that are consistent with OCIO security standard 141.10 and ISB IT security standards and guidelines to prevent unauthorized access, use, modification or disclosure of DOH Confidential Information in any form. This includes, but is not limited to, restricting access to specifically authorized individuals and services through the use of: o Documented access authorization and change control procedures; o Card key systems that restrict, monitor and log access; o Locked racks for the storage of servers that contain Confidential Information or use AES encryption (128bit key lengths of 256 bits or strongergreater) to protect confidential data at rest, standard algorithms validated by the National Institute of Standards and Technology (NIST) Cryptographic Algorithm Validation Program (CMVP); o Documented patch management practices that assure all network systems are running critical security updates within 6 days of release when the exploit is in the wild, and within 30 days of release for all others; o Documented anti-virus strategies that assure all systems are running the most current anti-virus signatures within 1 day of release; o Complex passwords that are systematically enforced and expire at least every 180 password expiration not to exceed 120 days, dependent user authentication types as defined in OCIO security standards; o Strong (Two Factor) multi-factor authentication mechanisms that assure the identity of individuals who access Confidential Information; o Account lock-out after 5 failed authentication attempts for a minimum of 20 15 minutes, or for Confidential Information, until administrator reset; o AES encrypted encryption (128bit using key lengths 128 bits or strongergreater) sessions session for all data transmissions. , standard algorithms validated by NIST CMVP; o Firewall rules and network address translation that isolate database servers from web servers and public networks; o Regular review of firewall rules and configurations to assure compliance with authorization and change control procedures; o Log management and intrusion detection/prevention systems; o A documented and tested incident response plan Any breach of this clause may result in termination of the contract and the demand for return of all personal information.
Appears in 1 contract
Sources: Contract Agreement