Attachment D – Agreement that successful Bidder personnel will need to sign after contract award.

Vendor Employee Computer and Network User Agreement

All employees of vendors and Vendors who will accessKansas Department of Health andEnvironment (KDHE) information systems in thenormal course of their work forthe State ofKansas arerequired to sign this VendorEmployee Computer and NetworkUser Agreementdocument and Confidentialityand Access Agreement before accessinganyKDHE computersystem.

  • AllvendorpersonnelshalluseonlyaccountsauthorizedbytheKDHEOfficeofInformationServices(OITS)ChiefInformationOffice(CIO)ordesignee.
/
  • VendorpersonnelshallpromptlynotifytheKDHEOITSCIOordesigneeandtheprogramprojectmanager(dataowner)iftheyhaveanyreasontosuspectabreachofsecurityorpotentialbreachofsecurity.

  • Vendorpersonnelmayaccessonlythoseresourcesforwhichtheyarespecificallyauthorized.
/
  • VendorpersonnelshallpromptlyreportanythingthattheydeemtobeasecurityloopholeorweaknessinthecomputernetworktotheKDHEOITSCIOordesignee.

  • Vendorpersonnelarepersonallyresponsibleforsafeguardingtheiraccountandlog-oninformation.Passwordsshalladheretothepasswordmanagementprocedurefortheapplicablesystem.
/
  • VendorpersonnelmaynotcopyanysoftwarefromanyKDHEcomputersystemforpersonaluse.

  • Passwordsshallneverbedisplayed,printed,orotherwiserecordedinanunsecuredmanner.
/
  • KDHEdatashallnotberemovedfromthepremiseswithoutpriorwrittenapprovalfromtheKDHEOITSCIOordesigneeandthedataowner.

  • VendorpersonnelarenotpermittedtoscripttheiruserIDsandpasswordsforlog-onaccess.
/
  • VendorpersonnelmaynotremovefromtheKDHEpremises,anycomputerhardwareforanyreason,withoutwrittenpermissionfromtheKDHEOITSCIOordesignee.KDHEcomputersystems(servers,desktopandlaptopcomputers)maycontainKDHEinformationordatathatmightbesensitive.

  • Vendorpersonnelarenotpermittedtoallowanotherpersontolog-ontoanycomputerutilizingtheir,ifprovided,personalaccount,noraretheypermittedtoutilizesomeoneelse’saccounttolog-ontoacomputer.Authorizedsystemorserviceaccountsmaybeusedbymultiplepeople.
/
  • Vendorpersonnelshallnotinstalloruseanytypeofencryptiondeviceorsoftwarethathasnotbeenapprovedinwritingbythe KDHEOITSCIOordesignee,foruseontheircomputersystem.

  • Vendorpersonnelmaynotleavetheirworkstationloggedontothenetworkwhileawayfromtheirarea.Vendorpersonnelmayelecttolocktheworkstationratherthanloggingoffwhenleavingforveryshorttimeperiods.
/
  • VendorpersonnelshallnotdeleteordisableanyauthorizedencryptiondeviceorsoftwareprograminstalledonKDHEhardware.

  • Vendorpersonnelshallmaintainalog,leftwiththecomputerand/oremailedtotheKDHEOITSCIOordesignee,ofallsoftwareloadedontoanyKDHEcomputer.ThesoftwaremusthavebeenapprovedinwritingbytheKDHEOITSCIOordesignee.
/
  • VendorpersonnelshallnotattachanydevicetotheKDHEnetworkwithoutwrittenapprovalfromtheKDHEOITSCIOordesignee.

  • Vendorpersonnelshallexecuteonlyapplicationsthatpertaintotheirspecificcontractwork.
/
  • VendorpersonnelshallnotattachanynetworkorphonecablestoanydevicewithoutwrittenapprovalfromtheKDHEOITSCIOordesignee.

  • Vendorpersonnelshallpromptlyreportlog-onproblemsoranyothercomputererrorstotheKDHEOITSCIOordesignee.
/
  • Vendorpersonnelmaynotdisableorbypassanyanti-virusprogram.

  • VendorpersonnelmaynotutilizeKDHEcomputersystemsforanyofthefollowingreasons:
  • Gameplaying;
  • Internetsurfingnotrequiredfortheirworkactivity;
  • Non-relatedworkactivity;or
  • Anyillegalactivity.
  • DownloadingoffilesfromtheInternet.Iffilesareneededforyourwork,contactKDHEpersonnel.
/
  • Vendorpersonnelmaynotremoveordeleteanycomputersoftwarewithoutthe writtenapprovaloftheKDHEOITSCIOordesignee.
  • VendorpersonnelshallnotattempttoobtainordistributeKDHEsystempasswords.
  • Vendorpersonnelshallnotattemptto obtainordistributedoorpasscodestosecuredroomsattheKDHEfacilities.

  • Vendorpersonnelareprohibitedfrominterceptingormonitoringnetworktrafficbyanymeans,includingtheuseofnetworksniffers,unlessauthorizedinwritingbytheKDHEOITSCIOordesignee.
/
  • VendoremployeesmaynotusetheKDHE'semailsystemtosendorreceiveobscene,abusive,sexuallyexplicitlanguageorpictures,orthreateninglanguage.

  • VendorpersonnelmaynotgiveoutanyKDHEcomputerinformationtoanyone.Exception:othervendorpersonnelneedingtheinformationtocompletetasksand who havesignedthisagreement.Informationincludesbutisnotlimitedto:IPaddresses,securityconfigurations,etc.
/
  • VendoremployeesareprohibitedfromcausingtheKDHE,ortheStateofKansastobreakcopyrightlaws.
  • VendorshalldocumenttheemployeewhologgedontoKDHEcomputersystemsifasharedaccountisused.Thiscanbedoneinthevendor’shelpdeskticketsystem.

  • Alldatastorage mediashallbeerasedordestroyedpriortobeingplacedinthetrash.
/
  • Vendorshallnotcreateand/orinstallanybackdoortoanyKDHEinformationsystemstoalloworgainaccessotherthanthroughauthorizedmeans.

  • VendorpersonnelareprohibitedfromcausingtheKDHEortheStateofKansastoincuranyexpensesunlessapprovedinwritingbytheKDHEOITSCIOordesigneeandtheprogramprojectmanager(dataowner
/
  • VendoremployeehasreadandacceptsKDHEInternalDirective7001.0and7002.0.
  • Vendoremployeehasreadand willcomplywithInformationTechnologyPolicy7400A–ComputerSecurityAwarenessandTraining.

Use of any part of the KDHE’s computer network will acknowledge acceptance of the above policies.

Anyvendoremployee whoviolatesanyoftheabovepoliciesshallbesubjecttodisciplinaryaction,includingbutnotlimitedtototalremovalfromtheKDHEproject,assessedfeesfordamages, aswellasbeingsubjecttoKansas’scivilandcriminalliability.DisciplinaryactionmayincludetheKDHErequestingthevendorconsiderdemotion,suspensionandtermination.

______/ ______/ ______
Vendor Name - Printed / Authorizing Employee Name Printed / Date
______
Employee Signature