Laserfiche WebLink
Security Policies and Procedures <br />Confidential or Protected information must not be transmitted across any unsecured <br />outside network or path without proper controls. This means encryption for files and <br />emails, or secured packaging for paper copies. <br />Paper products and backup media containing this type of information must be stored <br />and handled in a secure manner. This includes: <br />1. Printing this class of information only to a known, secure printer <br />2. Encrypting and physically securing backup media <br />3. Keeping paper copies of information locked or otherwise secured <br />D. Managing data sources <br />The key to managing Virtru's business' media and documents is to first consider the <br />source of the information, then the media type. Virtru's media and documents <br />containing Protected Information (PHI, CJIS, or other) require protection from <br />inception through disposition. Regardless of the owner relationship, the Company will <br />be cognizant of the following Media Types: <br />1. Hard Copy: paper printouts, printer and facsimile ribbons, drums, etc. <br />2. Electronic: the bits and bytes contained on hard drives, flash drives, phones and <br />tablets. <br />E. Retention of media <br />Retention: The length of time documentation and/or information is retained according <br />to the level of confidentiality and to the business continuity requirements. System/ <br />information owners should consult with the ISO to ensure compliance with the record <br />retention regulations. <br />Virtru's hard copy record retention policy is as follows: <br />We will digitize and encrypt these records for secure storage on the Synology NAS, <br />which will be backed up to AWS Glacier. <br />Virtru's electronic record retention policy is as follows: <br />1. Agent of Record letters and Letters of Authorization requests are held for no <br />less than ninety (90) days <br />2. New Business Group documents are held for no less than ninety (90) days <br />3. General documents are held for no less than ninety (90) days <br />4. Banking statements are held for seven (7) years <br />5. Workforce member records are held for seven (7) years <br />Rev.2015.8.6 <br />23 <br />