Exhibit_D-Bus._Partner_Interconnection_Security_Agreement.doc

DOC document 299 KB Posted

Attached to
Teleradiology Service, HHCC Federal contract opportunity
Solicitation number
16-247-SOL-00013
Issued by
Department of Health and Human Services Indian Health Service

About this file

Exhibit D-Business Partner Interconnection Security Agreement

View the file

Other files for this federal contract opportunity

Other files attached to Teleradiology Service, HHCC, newest first.
File Type Posted
Exhibit_A-SF1449_(revised).pdf PDF
Amendment_0002.pdf PDF
Exhibit_A-SF1449.pdf PDF
Amendment_0001.pdf PDF
Exhibit_F-IHS_Rules_of_Behavior.doc DOC document
Exhibit_C-Tax_Exemption_Letter_2015.pdf PDF
SOW_12.01.15.docx DOCX document
Exhibit_B-Wage_Determination.docx DOCX document
Exhibit_E-DataExchangeAgreement.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Release Notes

Indian Health Service

Business Partner

Interconnection Security Agreement <<Insert Area/Facility>> and <<Partner Organization>>

DIS-Template-10-01 <<Month Year>>

CONTROLLED UNCLASSIFIED INFORMATION

This information is intended for IHS use only. Disclosure may cause harm to IHS. Access is provided by request only and is not available via the organization's Intranet. This document contains information that may be exempt from public release under the Freedom of Information Act (FOIA) (5 U.S.C. 552).

Document Information

SUPERSEDES

· Interconnection Security Agreement Form F06-27, March 2006

· Business Partner Interconnection Security Agreement Template 09-01, May 2009 Table of Contents 11.0 Purpose

12.0 Authority

23.0 Scope

24.0 Statement of Requirements and Systems Description

24.1 General Information and Data Description

34.2 Services Offered

35.0 Information and Network Descriptions

35.1 IHS Network

45.2 Partner Organization Network

65.3 Network Diagram(s)

65.4 Area/Site Connections

66.0 Security Responsibilities: Network, Personnel, and User Security

76.1 User Community

86.2 Commitment to Protect Personally Identifiable Information and Protected Health Information

96.3 Rules of Behavior

96.4 Training and Awareness

96.5 Security Documentation

106.6 Personnel Access Changes

106.7 Incident Response and Reporting

116.8 Disasters and Other Contingencies

116.9 New Interconnections and Modifications

117.0 Compliance

118.0 Cost Considerations

129.0 Timelines

1210.0 Limitation of Liability

1311.0 Signatures

1412.0 Attachment A: Information Security POC’s

1513.0 Attachment B: Network Diagram(s)

1614.0 Attachment C: Area/Site Connections

1715.0 Appendix A: References

1816.0 Appendix B: Review Log

1816.1 Second Year Review

1916.2 Third Year Review

1916.3

2017.0 Appendix C: IHS Incident Reporting Form

2218.0 Glossary

1.0 Purpose

The purpose of this Interconnection Security Agreement (ISA) is to establish procedures for mutual cooperation and coordination between the Indian Health Service (IHS), an agency of the United States Department of Health and Human Services (HHS), and <<Partner Organization>>, to identify and implement information security safeguards and responsibilities required for the establishment of an interconnection between the IHS network and <<Partner Organization>>’s network. This ISA is intended to minimize security risks and ensure the confidentiality, integrity, and availability (CIA) of both IHS information as well as the information that is owned by <<Partner Organization>> that has a network interconnection with IHS information. This ISA documents interconnection arrangements and information security (IS) responsibilities for both parties, outlines security safeguards, provides technical and operational security requirements, and specifies the business and legal requirements for the information systems and networks being interconnected (hereafter known as “both parties”). This ISA authorizes mutual permission to connect both parties and establishes a commitment to protect data that is exchanged between the networks or processed and stored on systems that reside on the network. Through this ISA, both parties shall minimize the susceptibility of their connected systems and networks to IS risks and aid in mitigation and recovery from IS incidents.

2.0 Authority

IHS is responsible for implementing and administering an information security program, including the use of this ISA, to protect its information resources in compliance with applicable public laws, Federal regulations, and Executive Orders, including but not limited to the Federal Information Security Management Act of 2002 (FISMA); the Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources, dated November 28, 2000; the Health Information Technology for Economic and Clinical Health Act (HITECH); and the Health Insurance Portability and Accountability Act of 1996 (HIPAA); OMB Memorandum 07-16 Safeguarding Against and Responding to the Breach of Personally Identifiable Information; OMB Memorandum; OMB Memorandum 09-29 FY 2009 Reporting Instructions for FISMA and Agency Privacy Management; and shall comply with the security required by the Federal Acquisition Regulation (FAR) clause 52.239-1, Privacy or Security Safeguards. This ISA was developed in compliance with Federal policy, including NIST Special Publication (SP) 800-47 Security Guide for Interconnecting Information Technology Systems. NIST SP 800-47 states: “A system that is approved by an ISA for interconnection with one organization’s system shall meet the protection requirements equal to, or greater than, those implemented by the other organization’s system.” These guidelines establish the IS measures that shall be taken to protect the connected systems, networks and shared data. IHS IT managers and IS personnel shall comply with the NIST guidelines in managing the process of interconnecting information systems and networks.

The ISA shall be governed and construed in accordance with Federal law of the United States. In the event of a conflict between the ISA and applicable Federal law, Federal law shall prevail. Furthermore, nothing in this ISA shall be construed to authorize <<Partner Organization>> to act outside of the scope of any Federal law. If any term or condition of this ISA becomes invalid or unenforceable, such term or provision shall in no way affect the validity of enforceability of any other term or provision contained herein.

3.0 Scope

The scope of this ISA is based on the following, but not limited to:

· Interconnection between IHS information system and the <<Partner Organization>>.

· Existing and future users, including employees from both parties, contractors and subcontractors at any tier; and other federally and non-federally-funded users managing, engineering, accessing, or utilizing the Partner Organization Network.

· Related network components belonging to both parties, such as hosts, routers, and switches; IT devices that assist in managing security such as firewalls, intrusion detection systems, and vulnerability scanning tools; desktop workstations; servers; and major applications that are associated with the network connection between both parties.

4.0 Statement of Requirements and Systems Description

This ISA governs the relationship between IHS and <<Partner Organization>> regarding <<Partner Organization>>’s connection to and use of the IHS’ network, systems, and information.

4.1 General Information and Data Description

<<Insert a description of the information and data that will be made available, exchanged, or passed one way or both directions by the interconnection of both parties. Include the following information:

· The requirement for the interconnection, including the benefits derived.

· The names of the systems being interconnected.

· If <<Partner Organization>> will create, receive, view or otherwise have access to IHS Protected Health Information (PHI)

· The agency name or organization that initiated the requirement. If the requirement is generated by a higher level agency or organization, indicate the name of the organization and the individual, if appropriate, that requested the interconnection.>>

4.2 Services Offered

IHS Shall:

· Provide the Partner Organization Point of Contact support via the IHS Help Desk. (Available 6 A.M. MST-6 P.M. MST, Monday-Friday, at 1-888-830-7280. The after-hours contact number is available during non-duty hours at the above number.)

· Provide installation, configuration, and maintenance of IHS edge router(s) with interfaces to multiple IHS core and edge routers.

· <<Insert additional IHS services that are being agreed to as part of the agreement.>>

<<Partner Organization>> Shall:

· <<Insert Partner Organization IT Help Desk Information regarding operating times, process, and contact information.>>

· <<Insert any additional Partner Organization responsibilities or services being offered as part of this agreement.>>

5.0 Information and Network Descriptions

5.1 IHS Network

Organization: IHS

Function: <<Insert IHS’s Network Function as related to this Interconnection>> Location: <<Insert IHS physical site(s) location as related to this Interconnection>> Description <<Insert description of data that will be made available, exchanged or passed across the interconnection. Include the Sensitivity or Classification level.>> Based on Federal Information Processing Standards (FIPS) Publication 199 (http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf), the information handled by the interconnection and the system security level for IHS is:

Information Category
Level
Security Level
<<Enter the Information Category>>
<<Enter High, Medium, or Low>>

Overall Security Level Designation for IHS: <<Insert highest level for this interconnection from the table above.>>

5.2 Partner Organization Network

Organization: <<Partner Organization>> Function: <<Insert Partner Organization Network Function as related to this Interconnection.>> Location: <<Insert Partner Organization physical site(s) location as related to this Interconnection.>>

Description <<Insert description of data that will be made available, exchanged or passed across the interconnection. Include the Sensitivity or Classification level.>>

Based on FIPS Publication 199 (http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf), the following table is provided to assist the partner in determining the information security categorization of the information being shared or exchanged by the interconnection.

Security Objective
Low
Moderate
High

Confidentiality

Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information

[44 USC, SEC. 3542]

The unauthorized disclosure of information could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
The unauthorized disclosure of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
The unauthorized disclosure of information could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.

Integrity

Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.

[44 USC, SEC. 3542]

The modification or destruction of information could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
The modification or destruction of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
The modification or destruction of information could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.

Availability

Ensuring timely and reliable access to and use of information.

[44 USC, SEC. 3542]

The disruption of access to or use of information or an information system could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
The disruption of access to or use of information or an information system could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
The disruption of access to or use of information or an information system could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.

As determined from the table above, please enter the highest security level for the partner’s shared or exchanged information affected by this interconnection into the boxes below.

Information Category
Level
Security Level
<<Enter the Information Category>>
<<Enter High, Medium, or Low>>

Note: For assistance completing this section, contact the IHS ISA Coordinator.

Overall Security Level Designation for <<Partner Organization>>: <<Insert highest level for this interconnection from the table above.>>

5.3 Network Diagram(s)

Attachment B of this ISA shall include a topological drawing that illustrates the interconnectivity between both parties, including all components (e.g., firewalls, routers, switches, hubs, servers, encryption devices, and computer work stations). If applicable, both parties shall provide IP Addresses for all components identified on the topological drawing. Both parties shall notify each other of any requirements such as additional router connections or increases in volume associated with this ISA.

5.4 Area/Site Connections

Attachment C of this ISA shall include a list of all IHS Areas and Sites interconnecting with <<Partner Organization>>. If applicable, <<Partner Organization>> shall list the effective dates of the interconnections.

6.0 Security Responsibilities: Network, Personnel, and User Security

Both parties shall:

· Maintain a level of security that is commensurate with the risk and magnitude of the harm that could result from the loss, misuse, disclosure, or modification of the information contained on the system with the highest sensitivity levels.

· Subject to applicable statutes and regulations, including the Freedom of Information Act, agree that the terms and conditions (any proprietary information) of this ISA shall not be disclosed to any third party outside of the Government without the prior written consent of the other party.

· Adhere to all HHS and IHS IS policies, procedures and guidelines in the execution of this interconnection. The IHS Information Systems Security Officer (ISSO) or ISA Coordinator shall provide appropriate IHS security policies to the partner at the onset of this agreement. IHS policy is located at: http://www.ihs.gov/PublicInfo/Publications/IHSManual/Parts_index.cfm#Part8.

· Designate a technical lead for their respective network and provide POC information to facilitate direct contacts between technical leads to support the management and operation of the interconnection.

· Maintain open lines of communication between POCs at both the managerial and technical levels to ensure the successful management and operation of the interconnection.

· Inform their counterpart promptly of any change in technical POC or interconnections.

· Submit to other designated POC any proposed changes to either the network or the interconnecting medium accompanied with a business justification for the change.

· Report planned technical changes to the network architecture that affect the interconnection through the designated POCs as appropriate.

· Conduct a risk assessment based on any new network architecture affecting this ISA; and modify and re-sign the ISA within one month prior to the implementation.

· Where feasible, ensure this interconnection is isolated from all other customer/business processes.

· Notify the respective POCs when a user’s access and/or this interconnection are no longer required.

IHS shall:

· Designate an IHS ISSO or ISA Coordinator to serve as liaison between both parties and assist the partner in assuring that its IS controls meet or exceed IHS and federal requirements.

· Configure the IHS network perimeter firewall in accordance with IHS, HHS, federal guidelines, and industry best practices.

· Install a firewall between the perimeter (demarcation point) of the Partner’s network and the IHS network, if deemed necessary by the IHS CISO.

<<Partner Organization>> shall:

· Designate an IS POC who shall act on behalf of the partner and communicate all IS issues involving the interconnection via the IHS ISSO or ISA Coordinator.

· Maintain and make available to IHS upon request a list of all partner subnets connected to IHS’ network, and periodically update the information on each owner, physical location, IP Address, host’s name, hardware, operating system version, and applications.

Attachment A contains a listing of responsible parties for each side of the interconnection.

6.1 User Community

Both parties shall:

· Ensure that all employees, contractors, and other authorized users with access to the IHS network and information systems and the Partner Organization and the data sent and received from either organization are not security risks and meet the security and privacy requirements of the Office of Management and Budget (OMB) at http://www.whitehouse.gov/omb/ and the Department of Health and Human Services (DHHS) Personnel Security/Suitability Program at http://www.hhs.gov/ohr/manual/98_1.pdf. For more information, contact the Federal Contract Officer or Project Officer assigned to this interconnection.

· Enforce the following IS best practices:

· Least Privilege: Only authorizing access to the minimal amount of resources required for a function.

· Separation of Duties: A basic control that prevents or detects errors and irregularities by assigning responsibility for initiating transactions, recording transactions and custody of assets to separate individuals.

· Role-Based Security: Access controls to perform certain operations (‘permissions’) are assigned to specific roles.

6.2 Commitment to Protect Personally Identifiable Information and Protected Health Information Both Parties shall:

· Not release, publish, or disclose information to unauthorized personnel and shall protect such information in accordance with provisions of the laws cited in Section 2.0 and Appendix A and any other pertinent laws and regulations governing the adequate safeguard of federal information and information systems.

· Ensure that information used, stored, or transmitted is protected commensurate with the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of the information. FIPS Publication 200 and associated NIST Special Publications, including NIST SP 800-53, shall be used to determine required controls according to the information categorization defined in section 5.2. FIPS 140-2 validated cryptographic modules shall be used when such controls are required.

<<Partner Organization>> shall ensure that each of the employees of <<Partner Organization>> or subcontractors for this organization who may have access to IHS information and information systems comply with the security required by Federal Acquisitions Regulation (FAR) clause 52.239-1, Privacy or Security Safeguards and with IHS Information Security policies, standards and procedures. IHS IT policy is located at: http://www.ihs.gov/PublicInfo/Publications/IHSManual/Parts_index.cfm#Part8.

6.3 Rules of Behavior

Both parties shall ensure that all users with access to IHS networks, information and information systems, the <<Partner Organization>> network and any data received as part of this interconnection shall adhere to all current IHS Rules of Behavior for Interconnection Security Agreements (ROB). All users, including employees, contractors, subcontractors, and other authorized users must sign the ROB upon enactment of this ISA and then annually thereafter. <<Partner Organization>> shall store the signed ROBs, and provide copies of all signed ROBs to an IHS POC.

6.4 Training and Awareness

Both parties shall have all users, including employees, contractors, subcontractors, and other authorized users complete the IHS Information Systems Security awareness training upon enactment of this ISA and then annually thereafter at: http://www.isa.ihs.gov/ <<Partner Organization>> shall provide the IHS Project Officer or designee with the name of each user and the date each user completes initial and annual security awareness training.

6.5 Security Documentation

Both parties shall ensure that security is planned for, documented, and integrated into the System Life-Cycle from the IT system’s initiation to the system’s disposal for any systems that are part of this interconnection agreement. See NIST SP 800-37 Guide for Security Authorization of Federal Information Systems: A Security Life Cycle Approach.

IHS shall review the IHS System Security Plans (SSP) for its systems annually and update as required by NIST SP 800-18 Guide for Developing Security Plans for Federal Information Systems.

<<Partner Organization>> shall:

· Maintain an SSP on the systems affected by this interconnection agreement and update whenever there is a major modification to those systems. The SSP shall be compliant with the NIST SP 800-18.

· Make accessible to IHS all IS program documents related to systems affected by this interconnection.

6.6 Personnel Access Changes

<<Partner Organization>> shall provide notification to IHS via the ISSO or ISA Coordinator of any changes to user profiles, including users who resign or change job responsibilities, within 3 working days of change. This will assure access is removed or maintained accurately on IHS systems and is in accordance with Federal guidelines.

IHS shall provide similar notification to partner if IHS has users accessing partner’s systems as part of this interconnection.

6.7 Incident Response and Reporting

Both parties shall:

· Handle and report any security incident within the organization’s network or subnets within the scope of this ISA that could have an impact on the other as part of this interconnection.

· Submit incident reports within one thirty (30) minutes to the IHS Incident Response Team at IRT@ihs.gov and/or to the IHS Help Desk. (Available 6 A.M. MST-6 P.M. MST, Monday-Friday, at 1-888-830-7280. The after hours contact number is available during non-duty hours at the above number.) The IHS Incident Reporting Form is found in Appendix C.

· Notify the IHS Incident Response Team and/or the IHS Help Desk within thirty (30) minutes of discovery for any breach of IHS protected health information including unauthorized use or disclosure.

· The IHS Incident Response Team (IRT) will assist IHS and its partners with all incidents and breaches of protected health information. Reporting incidents and breaches will allow each party to determine if steps need to be taken to determine whether its network is at risk, has been compromised and to take appropriate security precautions.

· Block inbound and outbound access for any IHS or partner information systems on the subnets within the scope of this ISA that are sources of unauthorized access attempts, or the subject of any security events, such as malware, until the risk is remediated.

· Disseminate critical intrusion detection alerts to respective counterparts for all subnets within the scope of this ISA.

· Share information system event or audit records/logs to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity to enable the actions of those inappropriate uses to be uniquely traced to the source for potential accountability and legal purposes only.

6.8 Disasters and Other Contingencies

Both parties shall immediately notify their designated counterparts as defined in this ISA in the event of a disaster or other contingency that disrupts normal operation of one or both of the connected networks. IHS POC shall notify appropriate personnel on the IHS side of the connection.

IHS shall maintain appropriate system contingency plans in accordance with Federal regulations.

6.9 New Interconnections and Modifications

· New interconnections between IHS and <<Partner Organization>> are prohibited unless expressly agreed upon in a modification to this ISA signed by both parties.

· If any personnel changes occur involving the POCs listed in this ISA, the terms of this ISA shall remain in full force and effect, unless formally modified by both parties. Any modifications that change the security posture to this ISA shall be in writing and agreed upon and approved in writing by both parties or their designees.

7.0 Compliance

Non-compliance with the terms of this ISA by either party may lead to termination of the interconnection. IHS may block network access for <<Partner Organization>> if <<Partner Organization>> does not implement reasonable precautions to prevent the risk of security incidents spreading to IHS’ network. IHS is authorized to audit the security of <<Partner Organization>>’s network periodically by requesting <<Partner Organization>> to provide documentation of compliance with the security requirements of this ISA. <<Partner Organization>> shall provide IHS access to its IT resources impacted by this ISA for purposes of audits.

8.0 Cost Considerations

Both parties agree to be responsible for their own systems and costs of the interconnecting mechanisms and/or media. No financial commitments to reimburse the other party shall be made without the written concurrence of both parties. Modifications to either system that are necessary to support the interconnection are the responsibility of the respective system/network owners’ organization. This ISA does not authorize, require, or preclude any transfer of funds without the written agreement of both parties.

9.0 Timelines

This ISA shall become effective upon the signatures of the parties involved and remains in effect until terminated by either party. This ISA is subject to annual review in accordance with federal directive and must be reauthorized when there is a modification to the security posture or at a minimum every three years. If one or both parties wish to terminate this agreement, they may do so upon thirty (30) days written notice. In an event of a security incident or suspected incident, IHS has the right to immediately terminate the connection and will provide notification of such to the Partner POC prior to termination, if emergency warrants the delay or within 24 hours after disconnection.

10.0 Limitation of Liability

Except to the extent covered by the Federal Tort Claims Act, IHS shall not be liable to <<Partner Organization>>, or any other person for any indirect, special, incidental, or consequential damages of any character including, without limitation, damages for loss of goodwill, work stoppage, computer failure or malfunction, or any and all other commercial damages or losses, even if such party shall have been informed of the possibility of such damages.

11.0 Signatures

Both parties agree to work together to ensure the joint security of the connected networks and the data they store, process, and transmit, as specified in this ISA. Each party certifies that its respective network is designed, managed, and operated in compliance with all relevant federal laws, regulations, and policies. Each party also certifies that its respective network has been certified and accredited in accordance with NIST guidance and as mandated in the Federal Information Security Management Act of 2002.

We agree to the terms and conditions of this ISA.

IHS Management POC <<Partner Organization>> Management POC

(Name)

(Signature) (Date)

IHS Security POC <<Partner Organization>> Information Security POC

12.0 Attachment A: Information Security POC’s

<<Partner Organization>> Responsibilities

<<Partner Organization>> shall designate an information security Point of Contact (POC), who shall communicate all information security issues involving <<Partner Organization>> to the IHS via the IHS Security POC. The <<Partner Organization>> POC shall be the <<Partner Organization>> ISSO or another information security official who shall be responsible for implementing and managing <<Partner Organization>>’s information security program and ensuring that <<Partner Organization>> information security controls meet or exceed IHS requirements.

IHS Security POC:

Address:

Work Phone:

Fax:

E-mail:

24x7 contact number:

IHS Technical POC:

Address:

Work Phone:

Fax:

E-mail:

<<Partner Organization>> Security POC:

Title:

Address:

Work Phone:

Fax:

E-mail:

24x7 contact number:

<<Partner Organization>> Technical POC:

Title:

Address:

Work Phone:

Fax:

E-mail:

13.0 Attachment B: Network Diagram(s)

14.0 Attachment C: Area/Site Connections

IHS Area/Site Interconnected
Date Connected
Currently Connected?

15.0 Appendix A: References

This ISA was developed in accordance with, but not limited to, the following laws, policies, and regulations:

· Indian Health Manual Part 8, Chapter 12, http://www.ihs.gov/PublicInfo/Publications/IHSManual/Part8/pt8chapt12/pt8chapt12.htm ;

· Indian Health Service Information Security Program SOPs, http://home.ihs.gov/ITSC-CIO/security/secpgm/index.cfm

· HHS information security policies and procedures, http://www.hhs.gov/read/irmpolicy.

· Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), Title XIII, Subtitle D of the American Reinvestment and Recovery Act of 2009, Pub. L. No. 111-5, 123 Stat. 115 (2009) (“ARRA”),

· Office of Management and Budget Memorandums:

· 07-16 Safeguarding Against and Responding to the Breach of Personally Identifiable Information; OMB Memorandum, http://www.whitehouse.gov/omb/assets/omb/memoranda/fy2007/m07-16.pdf

· 09-29 FY 2009 Reporting Instructions for FISMA and Agency Privacy Management, http://www.whitehouse.gov/omb/assets/memoranda_fy2009/m09-29.pdf

· National Institute of Standards and Technology (NIST) (http://csrc.nist.gov):

· Federal Information Processing Standards (FIPS) Publications

· Special Publications (SP)

· Draft Special Publications (SP)

· Federal Continuity Directive (FCD), FCD 1, Federal Executive Branch Continuity of Operations, November 6, 2007, http://www.fema.gov/pdf/about/offices/fcd1.pdf.

· Presidential Decision Directives (PDD) (http://www.loc.gov/rr/news/directives.html):

· PDD 67, Enduring Constitutional Government and Continuity of Government Operations, October 21, 1998.

· Homeland Security Presidential Directive/HSPD-7, Critical Infrastructure Identification, Prioritization, and Protection, December 17, 2003.

· All relevant Public Laws.

16.0 Appendix B: Review Log

The Partner Interconnection Security Agreement is valid for three years, but must be reviewed every year to document any relevant modifications and ensure that appropriate security measures are in place.

16.1 Second Year Review

Both parties have reviewed this agreement and reaffirm that the information is still current unless otherwise noted in the comments section below.

We reaffirm the terms and conditions of this Partner Interconnection Security Agreement.

Comments: <<Document any relevant changes to this agreement>>

IHS Management POC <<Partner Organization>> Management POC

<<Partner Organization>> Information Security POC

(Signature) (Date) (Signature) (Date)

Note: All users must complete the IHS Information Security Awareness Training and sign the IHS Rules of Behavior for Interconnection Security Agreements initially and annually thereafter.

16.2 Third Year Review

Both parties have reviewed this agreement and reaffirm that the information is still current unless otherwise noted in the comments section below.

We reaffirm the terms and conditions of this Partner Interconnection Security Agreement.

Comments: <<Document any relevant changes to this agreement>>

IHS Management POC <<Partner Organization>> Management POC

<<Partner Organization>> Information Security POC

(Signature) (Date) (Signature) (Date)

Note: All users must complete the IHS Information Security Awareness Training and sign the IHS Rules of Behavior for Interconnection Security Agreements initially and annually thereafter.

17.0 Appendix C: IHS Incident Reporting Form

Important: Initial notification must be exclusively made to the IHS Incident Response Team (IRT) no later than 30 minutes from discovery. All incidents must also have a resolution completed.

Contact the IHS IRT: E-mail: IRT@ihs.gov; Business Hours: 505-750-3302. After Hours: 1-888-830-7280 OIT Help Desk. Emergency IRT Contact: 505-803-9582 Check One: FORMCHECKBOX Incident Notification FORMCHECKBOX Update FORMCHECKBOX Resolution

IR Primary Handler:

Does the incident involve Personally Identifiable Information (PII)? FORMCHECKBOX Yes FORMCHECKBOX No (if yes, complete PII box) Key Information

Date/Time of Incident Discovery:

Date/Time Incident Occurred:

Facility name:

Discoverer of incident:

Contact person and contact information:

Alternate contact and contact information:

<Describe the roles of the people involved, be it contractors, government employees, etc.>

<Number of individuals impacted/estimated to be impacted>

<List people to keep notified of incident and people who should NOT be notified>

Incident Summary

<High level summary of incident elaborating on key information above>

Detailed Incident Description

<Detailed description of incident. Please include time stamps>

Incident Mitigation

<Detailed description of steps taken with time stamps>

<Detailed description of follow-on actions to be taken>

Personally Identifiable Information (PII)

<What type of PII>

<Who owned the PII>

<Number of individuals impacted/estimated to be impacted>

18.0 Glossary

See online glossary on IHS OIT/Security Web Page (http://security.ihs.gov/SecGlos.cfm) Type your organization’s name here, using the Organization style. Press <Ctrl>+A, then press the F9 key and all instances of partner organization will be replaced with your partner organization’s name.

� “Information” is defined as “any knowledge that can be communicated or documentary material, regardless of its physical form or characteristics, that is owned by, produced by, or for, or is under the control of the United States Government (Executive Order 12958)

� “Network Interconnection” is defined as “the direct connection of two or more IT networks for the purpose of sharing data and other information resources.” (This is based on the definition of system interconnection in NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems).

� “Protected Health Information” is defined as “individually identifiable health information that is transmitted or maintained in any form or medium, including electronic information.” 45 CFR 160.103.

� “Personally Identifiable Information” is defined as “Any information about an individual maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and information which can be used to distinguish or trace an individual's identity, such as their name, SSN, date and place of birth, mother’s maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual”. OMB Memorandum 06-19.

� “Incident” is defined as “a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.” NIST Special Publication 800-61

� “Breach” is defined as the suspected or confirmed “unauthorized acquisition, access, use, or disclosure of Protected Health Information [or Personally Identifiable Information] which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information”. Section 13400 of the HITECH Act.

ii RPMS/3M( Lab Electronic Signature modification Version 5.2 June 2001

Installation Guide / Release Notes

File details come from the government source that posted it. Updated .