Laserfiche WebLink
1.9.1 Provide a climate controlled warehouse space of sufficient size to receive and store a <br />minimum of two months volume of City envelopes and inserts. <br />1.9.2 Provide notification to the City at least 60 business days in advance of the depletion of <br />the existing supply of City documents to allow the City to provide necessary revisions prior to <br />the Contractor's reordering of City supplies. <br />1.10 TASK 10 — SECURITY <br />The Contractor will: <br />1.10.1 Maintain secure control and handling of all City documents in order to prevent access by <br />unauthorized individuals and ensure that procedures are in place to secure physical and digital <br />safety, security and confidentiality of City documents. In addition, the Contractor warrants that <br />all of its employees are bound by strict confidentiality agreements. <br />1. 10.2 Safeguard protected health information and privacy information to satisfy HIPPA and <br />PCI compliance requirements and employ comprehensive Data Loss Prevention (DLP) solutions <br />that protect sensitive data in motion, at rest, and in use. This includes files on servers, databases, <br />desktops, laptops, and email including attachments. The Contractor will ensure that all HPI and <br />sensitive member data storage is encrypted with at least 1024 -bit encryption algorithms and that <br />all Web application access and transmissions are protected with 256 -bit HTTPS /SSL encryption. <br />The Contractor's network and servers will be protected with multi -layer firewall infrastructure <br />with real -time intrusion detection, prevention mechanisms, and periodic vulnerability scan. The <br />Contractor will tightly control access to PHI and sensitive member data and such data will be <br />logged at every level. <br />1.10.3 Utilize digital security cameras to monitor and record activity inside and outside the <br />Contractor's Operations Center. Locate critical servers, workstations and network devices in a <br />secure data center with physical access by the Contractor's authorized personnel controlled by an <br />electronic key system that is a component of the facility security system. The Contractor will <br />ensure that primary components of the information systems located at the Contractor's Data <br />Center are Windows -based servers, storage area network (SAN) devices, firewall and other <br />security systems, network devices, redundant access to the internet, data backup devices, <br />telecommunications devices and infrastructure, redundant power supplies, uninterruptible power <br />and backup generator systems. The Contractor will contain all systems in secure network <br />cabinets accessible only by the Contractor's authorized personnel and authorized staff members <br />of any third -party service provider. In addition, the Contractor will locate network cabinets in a <br />high — security, monitored and environmentally controlled facility, accessible only by authorized <br />personnel. <br />1.10.4 Place discarded documents in locked containers to be shredded by a service on the <br />Contractor's site. <br />1.11 TASK 11 —DISASTER RECOVERY <br />5 <br />