Laserfiche WebLink
Cryptography <br />Encryption of relevant data in transit and at rest based on <br />data classification <br />Physical and environmental security <br />Physical access and environmental controls <br />Operations security <br />Procedures, anti -virus, backups, change management, <br />capacity management, logging, vulnerability management <br />Communications security <br />Network controls, network segmentation <br />System acquisition, development <br />System development methodologies, secure coding training, <br />and maintenance <br />security engagement into the project management lifecycle <br />Supplier relationships <br />Review of key third party service organizations to include <br />right to audit and review of SSAE16, PCI and related reports <br />Information security incident <br />Incident management, security investigations, and <br />management <br />eDiscovery capabilities <br />Information security aspects of <br />Formal business continuity and disaster recovery programs <br />business continuity management <br />including periodic testing and business resiliency controls <br />Compliance; with internal <br />PC[-DSS, SSAE16, SOX/404, NIST, Data Protection Laws, data <br />requirements - policies, and with <br />loss prevention controls <br />external requirements - laws <br />In terms of administration and governance, WEX has established a Global Chief Information <br />Security Officer who reports to the Board of Directors Technology Committee and <br />administratively through the Chief Technology Officer. WEX's security function includes <br />Governance, Risk and Compliance, Identity and Access Management, Security Architecture, <br />Security Engineering, and Business Continuity/Disaster Recovery functions. The Security <br />framework is reviewed regularly and updated at least annually to respond to the rapidly evolving <br />threat landscape. <br />WEX has also contracted with a Managed Security Service provider to perform 247 real time <br />threat intelligence, security monitoring, and incident response capabilities. <br />7.5 Data Breached Notification. <br />The WEX Crisis Management Team ensures notification requirements are assessed by the legal <br />and compliance teams and facilitates all required notifications via the appropriate channels to <br />those who may have been impacted by any data breach. <br />7.6 Data Breach and Protocols to protect Agency Information. <br />In the event of a data breach the WEX Crisis Management Team engages immediately to <br />implement the WEX Business Continuity Plan (BCP) to triage the level a potential breach and <br />immediately safeguard all customer, State and/or Purchasing Entity's information. WEX has a BCP <br />for each line of business across our organization, and this plan is customized to meet the unique <br />needs of WEX customers across our organization in a given line of business. The WEX Business <br />MASTER AGREEMENT No. 00819 - FLEET CARD SERVICES PAGE 105 OF 138 <br />