Orange County NC Website
EXHIBIT 2 <br />CentralSquare Access Management Policy <br /> <br /> <br />In order to provide secure, federally compliant connections to agency systems CentralSquare Technologies <br />(“CentralSquare”) requires BeyondTrust or SecureLink as the only approved methodology of connection. BeyondTrust <br />and Securelink provide the necessary remote access in order to service and maintain CentralSquare products while <br />adhering to the Federal Bureau of Investigations Criminal Justice Information Services requirements. Both solutions <br />utilize two-factor authentication Federal Information Processing Standard Publication (“FIPS”) 140-2 validated <br />cryptographic modules and AES encryption in 256-bit strengths. <br /> BeyondTrust and Securelink are addressed in turn via this Access Management Policy; Customers may <br />choose which remote privileged access management solution will be utilized by CentralSquare. <br />BeyondTrust <br /> The BeyondTrust remote support solution may be utilized via escorted session or a jump Customer. As for <br />an escorted session, when an agency needs assistance from CentralSquare, the agency employee requesting <br />assistance will receive verbal or email communication with a session key necessary to enable remote access. If a <br />verbal key is provided, the user enters the session key after visiting https://securesupport.centralsquare.com. <br /> Jump Customers are a Windows service that can be stopped/started to facilitate a support <br />session. Connections made via jump Customer can be active or passive. An active jump Customer is always <br />available. A passive connection is enabled for a specific purpose and then disabled when not used. Regardless of the <br />option selected, CentralSquare’s support team will arrange a BeyondTrust session to establish the jump Customer. <br /> The jump Customer resides on the agency side on the installed device, where an agency administrator can <br />manage. Instructions on how to enable/disable jump Customers can be provided upon request. A sample workflow of <br />a passive jump Customer is provided below: <br />Should an agency require support from CentralSquare, a call would be placed and/or <br />a support ticket opened in the portal on the CentralSquare customer support <br />website. Before accessing the agency’s system and/or environment, the <br />CentralSquare representative would send a notice of connection from the <br />CentralSquare support portal instance. This notice can be sent to the individual at <br />the agency that the CentralSquare representative is working with or other designated <br />contacts as necessary. Upon receipt of the notice of connection, the agency <br />personnel would enable the BeyondTrust jump Customer. The CentralSquare <br />representative would then be admitted to the agency’s system and/or environment <br />to perform the necessary task. Upon completion of the task, the CentralSquare <br />representative sends a notice of disconnection from the CentralSquare support <br />portal instance. Upon receipt of the notice of disconnection, the agency personnel <br />would then disable the BeyondTrust jump Customer. <br />Securelink <br /> Similar to BeyondTrust’s escorted session, Securelink may be utilized via “quick connect”. To enable a quick <br />connect session when an agency needs assistance from CentralSquare, the Agency employee requesting assistance <br />will enter a key code in order to connect for screen sharing on a device. <br /> Similar to the jump Customer methodology, SecureLink may also be utilized via “gatekeeper”. The sample <br />workflow description for a jump Customer provided above is substantially similar to the workflow for gatekeeper. <br />Summation <br /> BeyondTrust and Securelink allow customers the ability to monitor connectivity to the customer’s network and <br />maintain CJIS compliance while enabling CentralSquare to perform the necessary support functions. <br /> <br /> <br />Docusign Envelope ID: 57B8CAEA-5B53-40D6-BBFB-DA6FFEBE77CDDocusign Envelope ID: 8602A585-4937-4651-A46F-B3BF57DB1E26