Laserfiche WebLink
Security Policies and Procedures <br />F. Policy <br />Virtru will not knowingly accept any confidential information belonging to third <br />parties until that information is reviewed against our protections and the appropriate <br />agreements put into place and signed by the information owner. The agreements <br />should include all requirements for controls over the third -party information and the <br />processes to be followed. <br />IX. Rules by Data Classification <br />A. Public/unclassified data <br />This type of information does not require special marking or storage, except to ensure <br />that it is available when needed. It does need to be kept safe from unauthorized <br />modification. <br />B. Private/internal data <br />Access is granted on a need -to -know basis, as authorized by the manager of the user of <br />the information. Some types of jobs are automatically granted access to data in this <br />class. <br />Paper products and backup media containing this type of information must be stored <br />and handled in a secure manner. This includes: <br />Printing this class of information only to a known printers located in secure <br />areas on secure networks. <br />2. Encrypting or physically securing backup media <br />3. Keeping paper copies of information locked or otherwise secured <br />This class of information is not released to anyone outside Virtru without a <br />non -disclosure agreement, a Business Associate Subcontractor Agreement, and/or <br />without the approval of the information owner. Private/Internal use information must <br />not be transmitted across any unsecured outside network or path without proper <br />controls. This means encryption for files and emails or secured packaging for paper <br />copies. <br />C. Confidential or protected data <br />Access to this type of information is on a need -to -know basis, as approved by the ISO or <br />information owner. <br />This class of information is not released to anyone outside the Company without a <br />non -disclosure agreement and without the approval of the information owner. <br />Rev.2015.8.6 <br />22 <br />