Laserfiche WebLink
00081911 Envelope ID;72A91838-BEA1 46FE AGOD-146571 B137804 <br /> I <br /> g. User IN and Password Controls. <br /> I. All users must be Issued a unique username for accessing Pil. <br /> li. Username must be promptly disabled, deleted, or the password changed upon <br /> the transfer or termination of an employee within twenty-four(24) hours. mote: <br /> Twenty-four (24) hours Is defined as one (1)working day. <br /> Ili. Passwords are not to be shared. <br /> iv. Passwords must be at least eight (8) characters. <br /> v, Passwords must be a non-diction aryword. <br /> vi. Passwords must not be stored in readable format on the computer or server. <br /> vii. Passwords must be changed every ninety(90) days or less. <br /> viii. Passwords mast be changed if revealed or compromised. <br /> Ix. Passwords must be composed of characters from at least three (3) of the <br /> following four(4) groups from the standard keyboard: <br /> A. Upper case letters (A-Z) <br /> B. Lower case letters(a-z) <br /> C. Arabic numerals (0-9) <br /> D. Special characters(l,@a,#, etc.) <br /> h, Data Destruction. When no longer needed, all PII must be cleared, purged, or destroyed <br /> consistent with MST SP 800-88, Guidelines for Media Sanitization, such that the PII <br /> cannot be retrieved. <br /> I. System Timeout.The systems providing access to PIE must provide an automatic timeout, <br /> requiring re-authentication of the user session after no more than twenty (20) minutes <br /> of inactivity. <br /> j. Warning Banners. The systems providing access to PH must display a warning banner <br /> stating, at a minimum: <br /> 1. Data is confidential; <br /> ii. Systems are logged; <br /> iii. System use is for business purposes only, by authorized users;and <br /> iv. Users shall log ,off the system immediately if they do not agree with these <br /> requirements. <br /> k. System togging. <br /> 1. The systems which provide access to PH must maintain an automated audit trail <br /> that can identify the user or system process which initiates a request for PH or <br /> alters Pli. <br /> H. The audit trail shall: <br /> A. Be date and time stamped; <br /> 7 <br />