Exhibit_F-IHS_Rules_of_Behavior.doc

DOC document 197 KB Posted

Attached to
Teleradiology Service, HHCC Federal contract opportunity
Solicitation number
16-247-SOL-00013
Issued by
Department of Health and Human Services Indian Health Service

About this file

Exhibit F-IHS Rules of Behavior for Interconnection Security Agreements

View the file

Other files for this federal contract opportunity

Other files attached to Teleradiology Service, HHCC, newest first.
File Type Posted
Exhibit_A-SF1449_(revised).pdf PDF
Amendment_0002.pdf PDF
Amendment_0001.pdf PDF
Exhibit_A-SF1449.pdf PDF
Exhibit_D-Bus._Partner_Interconnection_Security_Agreement.doc DOC document
Exhibit_B-Wage_Determination.docx DOCX document
Exhibit_E-DataExchangeAgreement.docx DOCX document
Exhibit_C-Tax_Exemption_Letter_2015.pdf PDF
SOW_12.01.15.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

IHS Rules of Behavior for Interconnection Security Agreements

IHS Rules of Behavior for Interconnection Security Agreements

Contents

11.0 Rules of Behavior for ISA

11.1 General

21.2 IHS Resources

21.3 Prohibited Activities

31.4 Reporting

4USER’S SIGNATURE OF RECEIPT OF ISA RULES OF BEHAVIOR

1.0 Rules of Behavior for ISA

The Indian Health Service (IHS) Rules of Behavior provide common rules on the appropriate use of all IHS information and technology resources. This section contains the minimum Rules of Behavior for all Interconnection Security Agreements (ISA), and applies to anyone requesting any type of access to IHS systems.

NOTE: The IHS Rules of Behavior apply only to IHS information and technology resources. Personal computers, to the extent that they do not interact with IHS information and technology resources, are not subject to these rules.

Users who do not comply with the prescribed Rules of Behavior may be subject to disciplinary action. These disciplinary actions are based on the sensitivity of information involved and the number of prior offenses. Suspected security incidents will be reported to the Department of Health and Human Services (DHHS) via the procedures outlined in NIST SP 800-61.

1.1 General

Users shall:

· Complete IHS security awareness training and sign the Receipt of ISA Rules of Behavior before accessing any IHS system, and then on an annual basis thereafter.

· Complete IHS privacy training before accessing sensitive information, and then on an annual basis thereafter.

· Notify the IHS Point of Contact (POC) when access to IHS information and technology resources exceeds what is needed, or is no longer required.

· Report suspected security incidents and work with the IHS Security Team when called upon for assistance.

· Protect personally identifiable information (PII), protected health information (PHI) and other sensitive information by using approved encryption and secure data transfer and sharing processes.

1.2 IHS Resources

Users given access to IHS information and technology resources shall:

· Protect IHS property including equipment, intellectual property, paper and electronic records, software, data, and information/work products from theft, destruction, alteration, or misuse.

· Change IHS passwords a minimum of every 90 days, and do not reuse passwords until at least six other passwords have been used.

· Create IHS passwords with a minimum of eight characters using a combination of alpha, numeric characters with at least one uppercase letter, one lower case letter, and one number. It is recommended, when possible, to use a special character.

· Commit IHS passwords and user identifications (IDs) to memory or store them in a safe place; do not post them or share them.

· Ensure that security features and controls are activated when processing IHS data.

· Ensure that software has been appropriately authorized and is free of malicious code before it is installed or used on IHS systems.

· Dispose of all electronic storage media such as CD-ROMS, memory, diskettes, or other re-writable media and hard copy media in accordance with IHS sanitation and disposal procedures, which includes destroying hard copies of sensitive IHS data by pulping, burning, or cross-cut shredding.

· Use and maintain virus protection software on IHS systems; scan all files including e-mail attachments before opening.

· Sign in and be escorted when present in IHS limited access rooms, such as computer rooms.

· Ensure that IHS systems are current with the latest releases and fixes.

1.3 Prohibited Activities

Users shall:

· Not use network monitoring, cracking, or hacking type tools unless specifically authorized in writing to do so as part of job duties.

· Not use another person’s IHS account or access for any purpose.

· Not knowingly or willingly conceal, remove, mutilate, obliterate, falsify, or destroy IHS information.

· Not use IHS network resources to send or forward chain letters, junk e-mail, inappropriate messages, unapproved newsletters/broadcast messages, or spam.

· Not attempt to break into or introduce malicious code to an IHS electronic device.

· Not use government systems or networks for games, chat rooms, auctions, gambling, and other personal or non-productive use except as permitted by IHS policy.

· Not reconfigure IHS equipment, software, or computers, or circumvent the anti-virus, firewall, and other security controls or safeguards of IHS systems.

· Not transmit or store sensitive IHS information in email or portable devices such as laptops, personal digital assistants (PDA), external disks including CDs/DVDs, zip drives, etc., and universal serial bus (USB) drives or on remote/home systems without authorization and appropriate safeguards such as FIPS 140-2 approved encryption software.

· Not send, retrieve, store, view, display, or print sexually explicit, suggestive text or images, or other offensive material.

1.4 Reporting

Users shall immediately report any of the following to the IHS Incident Response Team (IRT@ihs.gov):

· Any potential, suspected or actual theft or loss of IHS equipment, software or sensitive information.

· Any compromised IHS passwords.

· Unusual or suspicious activity on IHS systems, such as viruses or worms.

USER’S SIGNATURE OF RECEIPT OF ISA RULES OF BEHAVIOR

I certify that I have read the IHS Rules of Behavior for Interconnection Security Agreements in its entirety, and understand and agree to comply with its provisions. I understand that violations of the IHS rules or information security policies and standards may lead to disciplinary action, up to and including removal or debarment from work on IHS contracts or projects; and/or revocation of access to Federal information, information systems, and/or facilities. I understand that exceptions to the IHS Rules must be authorized in advance in writing by the IHS Chief Information Officer (CIO) or his/her designee. I also understand that violation of laws, such as the Privacy Act of 1974, copyright law, and 19 USC 2071, which the IHS Rules draw upon, can result in monetary fines and/or criminal charges that may result in imprisonment.

Signatures:

Employee’s / User’s Signature
Printed Name
Organization
Date

OPTIONAL SIGNATURE

Federal Supervisor, IHS Point of Contact (POC), Contract Officer Technical Representative (COTR), or Project Officer (PO) Signature Printed Name

Date

NOTE: Sign and return this form to your Federal supervisor, IHS Point of Contact (POC), Contract Officer Technical Representative (COTR), or Project Officer (PO). They shall maintain the signed form and may use these forms as part of the annual review process. Make a copy for your records.

April 2009

_1120022968

File details come from the government source that posted it. Updated .