Laserfiche WebLink
Company ID Number:32855 <br />� ram■ ■■ �`''�':. ;"°-';M�� <br />�.. <br />Client Company ID Number:385743 <br />8. The Web Services E-Verify Employer Agent acknowledges that if Its system enhancements are not <br />completed to the satisfaction of DHS or Its assignees within six months from the date DHS notifies the Web <br />Services User of the system update, then the Web Services User's E-Verify account may be suspended, and <br />support for previous releases of E-Verify may no longer be available to the Web Services User. The Web <br />Services E-Verify Employer Agent also acknowledges that DHS may suspend the Web Services User's <br />account after the six-month period has elapsed. <br />9. The Web Services E-Verify Employer Agent agrees to Incorporate error handling logic Into Its development <br />or software to accommodate and act In a timely fashion should an error code be returned. <br />10. The Web Services E-Verify Employer Agent agrees to complete the technical requirements testing which Is <br />confirmed upon receiving approval of test data and connectivity between the Web Services E-Verify <br />Employer Agent and DHS. <br />11. DHS will not reimburse any Web Services E-Verify Employer Agent or software developer who has expended <br />resources In the development or maintenance of a Web Services intertace If that party Is unable, or <br />becomes unable, to meet any of the requirements set forth in this MOU. <br />12. Housing, development, Infrastructure, maintenance, and testing of the Web Services applications may take <br />place outside the United States and Its territories, but testing must be conducted to ensure that the code is <br />correct and secure. <br />13. If the <br />Web Services E-Verify Employer Agent Includes an <br />electronic <br />Form I-9 <br />as part of Its interface, then it <br />must <br />comply with the standards for electronic retention <br />of Form I-9 <br />found <br />in <br />8 CFR 274a.2(e). <br />B. INFORMATION SECURITY REQUIREMENTS <br />Web Services E-Verify Employer Agents performing verification services under this MOU must ensure that <br />information that Is shared between the Web Services E-Verify Employer Agent and DHS is appropriately protected <br />comparable to the protection provided when the Information Is within the DHS environment [OMB Circular A-130 <br />Appendix III]. <br />To achieve this level of <br />information security, <br />the Web Services E-Verify <br />Employer Agent agrees to Institute the <br />following procedures: <br />1. Conduct periodic assessments of risk, including the magnitude of harm that could result from the <br />unauthorized access, use, disclosure, disruption, modification, or destruction of Information and Information <br />systems that support the operations and assets of the DHS, SSA, and the Web ServlcesE-Verify Employer <br />Agent and Its clients; <br />2. Develop pollcles and procedures that are based on risk assessments, cost-effectively reduce information <br />security risks to an acceptable level, and ensure that information security Is addressed throughout the I(fe <br />cycle of each organizational Information system; <br />3. Implement subordinate plans for providing adequate information security for networks, facilities, information <br />systems, or groups of information systems, as appropriate; <br />4. Conduct security awareness training to Inform the Web Services E-Verity Employer Agent's personnel <br />(including contractors and other users of Information systems that support the operations and assets of the <br />organization) of the Information security risks associated with their activities and their responsibilities in <br />complying with organizational pollcles and procedures designed to reduce these risks; <br />5. Develop periodic testing and evaluation of the effectiveness of Information security pollcles, procedures, <br />practices, and security controls to be pertormed with a frequency depending on risk, but no less than once <br />per year; <br />6. Develop a process for planning, Implementing, evaluating, and documenting remedial actions to address <br />any deficiencies in the Information security policies, procedures, and practices of the organization; <br />7. Implement procedures for detecting, reporting, and responding to security incidents; <br />S. Create plans and procedures to ensure continuity of operations for information systems that support the <br />operations and assets of the organization; <br />9. In Information -sharing environments, the Information owner is responsible for establishing the rules for <br />appropriate use and protection of the subject Information and retains that responsibility even when the <br />information Is shared with or provided to other organizations [NIST SP 800-37]. <br />10. DHS reserves the right to restrict Web Services calls from certain IP addresses. <br />11. DHS reserves the right to audit the Web Services E-Verify Employer Agent's application. <br />12. Web Services E-Verify Employer Agents and Software Developers agree to cooperate willingly with the DHS <br />assessment of Information security and privacy practices used by the company to develop and maintain the <br />Page 10 of 17 I E-Verify MOU for Employers Using a Web Services Employer Agen[ 1 Revision Date OG/OS/13 <br />