Logical Access. (i) controls to enforce and maintain access restrictions for employees, and subcontractors, including encryption of data transmission and encrypted data during remote access sessions; (ii) processes to ensure assignment of unique IDs to each person with computer access; (iii) processes to ensure vendor-supplied defaults for passwords and security parameters are appropriately managed (e.g., changed periodically etc.); (iv) mechanisms to track and log all access to Customer Personal Data by unique ID; (v) mechanisms to encrypt or hash all passwords or otherwise ensure all passwords are not stored unsecured in clear text; and (vi) processes to promptly revoke accesses of inactive accounts or terminated/transferred users.
Appears in 1 contract
Sources: Data Processing Agreement
Logical Access. (i) controls to enforce and maintain access restrictions for employees, and subcontractors, including encryption of data transmission and encrypted data during remote access sessions;
(ii) processes to ensure assignment of unique IDs to each person with computer access;
(iii) processes to ensure vendor-supplied defaults for passwords and security parameters are appropriately managed (e.g., changed periodically etc.);
(iv) mechanisms to track and log all access to Customer Personal Data by unique ID;
(v) mechanisms to encrypt or hash all passwords or otherwise ensure all passwords are not stored unsecured in clear text; and
(vi) processes to promptly immediately revoke accesses of inactive accounts or terminated/transferred users.
Appears in 1 contract
Sources: Data Processing Agreement