WAC 182-70-430

WAC 182-70-430. WA-APCD infrastructure

Last amended: 2020Year: 2026Length: 116 wordsOfficial source
(1) The data vendor must limit access to the secure site. Personnel allowed access must be based on the principle of least privilege and have an articulable need to know or access the site. (2) The data vendor must conduct annual penetration testing and have specific requirements around the timing of penetration and security testing of infrastructure used to host the WA-APCD by the outside firm. The results of penetration and security testing must be documented and the data vendor must provide the summary results, along with a corrective action plan and remediation timelines, to the authority and the office of the state chief information security officer within thirty calendar days of receipt of the results.
WAC 182-70-430: WAC 182-70-430. WA-APCD infrastructure | Justis AI