Laserfiche WebLink
Agreement No. ####### <br />AGENCY <br />Page 11 of 14 <br />A. AGENCY agrees to comply with the following requirements to ensure the <br />preservation, security, and integrity of CALTRANS-owned data on portable <br />computing devices and portable electronic storage media: <br />1) Encrypt all CALTRANS-owned data stored on portable computing devices <br />and portable electronic storage media using government -certified Advanced <br />Encryption Standard (AES) cipher algorithm with a 256 -bit or 128 -bit <br />encryption key to protect CALTRANS data stored on every sector of a hard <br />drive, including temp files, cached data, hibernation files, and even unused <br />disk space. <br />2) Data encryption shall use cryptographic technology that has been tested and <br />approved against exacting standards, such as FIPS 140-2 Security <br />Requirements for Cryptographic Modules. <br />3) Encrypt, as described above, all CALTRANS-owned data transmitted from <br />one computing device or storage medium to another. <br />4) Maintain confidentiality of all CALTRANS-owned data by limiting data sharing <br />to those individuals contracted to provide services on behalf of the State, and <br />limit use of State information assets for State purposes only. <br />5) Install and maintain current anti-virus software, security patches, and <br />upgrades on all computing devices used during the course of the FTA. <br />6) Notify the Contract Manager immediately of any actual or attempted violations <br />of security of CALTRANS-owned data, including lost or stolen computing <br />devices, files, or portable electronic storage media containing CALTRANS- <br />owned data. <br />7) Advise the owner of the CALTRANS-owned data, the AGENCY Information <br />Security Officer, and the AGENCY Chief Information Officer of vulnerabilities <br />that may present a threat to the security of CALTRANS-owned data and of <br />specific means of protecting that CALTRANS-owned data. <br />B. To use the CALTRANS-owned data only for State purposes under this FTA. <br />C. To not transfer CALTRANS-owned data to any computing system, mobile device, <br />or desktop computer without first establishing the specifications for information <br />integrity and security as established for the original data file(s). (State <br />Administrative Manual (SAM) section 5335.1 <br />21. Project Close Out <br />A. The FTA Expiration Date refers to the last date for AGENCY to incur valid Project <br />costs or credits and is the date the FTA expires. AGENCY has sixty (60) days <br />after that Expiration Date to make final allowable payments to Project contractors <br />or vendors, prepare the Project Closeout Report, and submit the final invoice to <br />CALTRANS for reimbursement for allowable Project costs. Any unexpended <br />Project funds not invoiced by that sixtieth (60th) day will be reverted and will no <br />