Laserfiche WebLink
Company ID Number:32855 Client Company ID Number:385743 <br />8. The Web Services E-Verify Employer Agent acknowledges that if its system enhancements are not <br />completed to the satisfaction of DHS or its assignees within six months from the date DHS notifies the Web <br />Services User of the system update, then the Web Services User's E-Verify account may be suspended, and <br />support for previous releases of E-Verify may no longer be available to the Web Services User. The Web <br />Services E-Verify Employer Agent also acknowledges that DHS may suspend the Web Services User's <br />account after the six-month period has elapsed. <br />9. The Web Services E-Verify Employer Agent agrees to incorporate error handling logic into its development <br />or software to accommodate and act in a timely fashion should an error code be returned. <br />10. The Web Services E-Verify Employer Agent agrees to complete the technical requirements testing which is <br />confirmed upon receiving approval of test data and connectivity between the Web Services E-Verify <br />Employer Agent and DHS. <br />11. DHS will not reimburse any Web Services E-Verify Employer Agent or software developer who has expended <br />resources in the development or maintenance of a Web Services interface if that party is unable, or <br />becomes unable, to meet any of the requirements set forth in this MOU. <br />12. Housing, development, infrastructure, maintenance, and testing of the Web Services applications may take <br />place outside the United States and its territories, but testing must be conducted to ensure that the code is <br />correct and secure. <br />13. If the Web Services E-Verify Employer Agent includes an electronic Form I-9 as part of its interface, then it <br />must comply with the standards for electronic retention of Form I-9 found in 8 CFR 274a.2(e). <br />B. INFORMATION SECURITY REQUIREMENTS <br />Web Services E-Verify Employer Agents performing verification services under this MOU must ensure that <br />information that is shared between the Web Services E-Verify Employer Agent and DHS is appropriately protected <br />comparable to the protection provided when the information is within the DHS environment [OMB Circular A-130 <br />Appendix III]. <br />To achieve this level of information security, the Web Services E-Verify Employer Agent agrees to institute the <br />following procedures: <br />1. Conduct periodic assessments of risk, including the magnitude of harm that could result from the <br />unauthorized access, use, disclosure, disruption, modification, or destruction of information and information <br />systems that support the operations and assets of the DHS, SSA, and the Web ServicesE-Verify Employer <br />Agent and its clients; <br />2. Develop policies and procedures that are based on risk assessments, cost-effectively reduce information <br />security risks to an acceptable level, and ensure that information security is addressed throughout the life <br />cycle of each organizational information system; <br />3. Implement subordinate plans for providing adequate information security for networks, facilities, information <br />systems, or groups of information systems, as appropriate; <br />4. Conduct security awareness training to inform the Web Services E-Verify Employer Agent's personnel <br />(including contractors and other users of information systems that support the operations and assets of the <br />organization) of the information security risks associated with their activities and their responsibilities in <br />complying with organizational policies and procedures designed to reduce these risks; <br />5. Develop periodic testing and evaluation of the effectiveness of information security policies, procedures, <br />practices, and security controls to be performed with a frequency depending on risk, but no less than once <br />per year; <br />6. Develop a process for planning, implementing, evaluating, and documenting remedial actions to address <br />any deficiencies in the information security policies, procedures, and practices of the organization; <br />7. Implement procedures for detecting, reporting, and responding to security incidents; <br />8. Create plans and procedures to ensure continuity of operations for information systems that support the <br />operations and assets of the organization; <br />9. In information -sharing environments, the information owner is responsible for establishing the rules for <br />appropriate use and protection of the subject information and retains that responsibility even when the <br />information is shared with or provided to other organizations [NIST SP 800-37]. <br />10. DHS reserves the right to restrict Web Services calls from certain IP addresses. <br />11. DHS reserves the right to audit the Web Services E-Verify Employer Agent's application. <br />12. Web Services E-Verify Employer Agents and Software Developers agree to cooperate willingly with the DHS <br />assessment of information security and privacy practices used by the company to develop and maintain the <br />Page 10 of 17 I E-Verify MOU for Employers Using a Web Services Employer Agent I Revision Date 06/01/13 <br />