36C24818Q9221-001.pdf

PDF 117 KB Posted

Attached to
Circuit Breakers Federal contract opportunity
Solicitation number
36C24818Q9221
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 8

About this file

36C24818Q9221 Attachment A Salient Characteristics.pdf

View the file

Other files for this federal contract opportunity

Other files attached to Circuit Breakers, newest first.
File Type Posted
-14165.docx DOCX document
36C24818Q9221-0002000.docx DOCX document
36C24818Q9221-0001000.docx DOCX document
36C24818Q9221-000.docx DOCX document
36C24818Q9221-003.pdf PDF
36C24818Q9221-002.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment A

Salient Characteristics

Lee County VA Healthcare Center Circuit Breakers Replacement

Brand Name or Equal: GE

A. General

TheDepartmentofVeteranAffairsisseekingcontractorstoprovidereplacementandinstallation
ofbreakersasidentifiedinthisSalientCharacteristics.ThelocationisLeeCountyVAHealthcare
Center,2489DiplomatParkwayEast,CapeCoral,Florida33909.

B. Salient Characteristics

1. (7)‐SKLC3608L4XXGE800AMPCIRCUITBREAKERS(OrEqual).Directreplacementfor
SKLB3608D0800.BenchtestedandcertifiedwithNETAprimaryinjectiontesting.
2. (2)‐SKLC3604L4XXGE400AMPCIRCUITBREAKERS(OrEqual).Directreplacementfor
SKLB3604D0800.BenchtestedandcertifiedwithNETAprimaryinjectiontesting.
3. Thecontractorshallprovideallmanagement,supervision,labor,materials,supplies,tools
andequipment,necessarytocompletethereplacement,andinstallationofthenine
breakersspecifiedaboveattheVALeeCountyHealthcareCenter.
4. ContractorshallprovideinstallationofallbreakersasdirectedbytheVAandworkmustbe
doneafterclinicbusinesshours.

5. Contractor shall provide FLIR thermal imaging of all the newly installed breakers following installation.

6. All material supplied shall be NEW. No used, rebuilt, or refurbished equipment will be accepted.

7. Minimum one‐year warrantee on all items supplied.

CONTRACTOR SECURITY REQUIREMENTS (VA HANDBOOK 6500.6)

1. INFORMATION AND INFORMATION TECHNOLOGY SECURITY REQUIREMENTS

a.Duetothethreatofdatabreach,compromiseorlossofinformationthatresidesoneither
VA‐ownedorContractor‐ownedsystems,andtocomplywithFederallawsandregulations,VAhas
developedanInformationandInformationTechnologySecurityclausetobeusedwhenVA
sensitiveinformationisaccessed,used,stored,generated,transmitted,or
b.exchangedbyandbetweenVAandaContractor,subcontractororathirdpartyinany
format(e.g.,paper,microfiche,electronicormagneticportablemedia).
c.InsolicitationsandcontractswhereVASensitiveInformationorInformationTechnology
willbeaccessedorutilized,theCOshallinserttheclausefoundat852.273‐75,Security
RequirementsforUnclassifiedInformationTechnologyResources.

2. SECURITY REQUIREMENTS FOR UNCLASSIFIED INFORMATION TECHNOLOGY RESOURCES

TheContractor,theirpersonnel,andtheirsubcontractorsshallbesubjecttotheFederallaws,
regulations,standards,andVADirectivesandHandbooksregardinginformationandinformation
systemsecurityasdelineatedinthiscontract

1. GENERAL

Contractors,Contractorpersonnel,subcontractors,andsubcontractorpersonnelshallbesubjectto
thesameFederallaws,regulations,standards,andVADirectivesandHandbooksasVAandVA
personnelregardinginformationandinformationsystemsecurity.

2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

a.AContractor/subcontractorshallrequestlogical(technical)orphysicalaccesstoVA
informationandVAinformationsystemsfortheiremployees,subcontractors,andaffiliatesonlyto
theextentnecessarytoperformtheservicesspecifiedinthecontract,agreement,ortaskorder.
b.Allcontractors,subcontractors,andthird‐partyservicersandassociatesworkingwithVA
informationaresubjecttothesameinvestigativerequirementsasthoseofVAappointeesor
employeeswhohaveaccesstothesametypesofinformation.Thelevelandprocessofbackground
securityinvestigationsforcontractorsmustbeinaccordancewithVADirectiveandHandbook
0710,PersonnelSuitabilityandSecurityProgram.TheOfficeforOperations,Security,and
Preparednessisresponsibleforthesepoliciesandprocedures.
c.Contractpersonnelwhorequireaccesstonationalsecurityprogramsmusthaveavalid
securityclearance.NationalIndustrialSecurityProgram(NISP)wasestablishedbyExecutiveOrder
12829toensurethatclearedU.S.defenseindustrycontractpersonnelsafeguardtheclassified
informationintheirpossessionwhileperformingworkoncontracts,programs,bids,orresearch
anddevelopmentefforts.TheDepartmentofVeteransAffairsdoesnothaveaMemorandumof
AgreementwithDefenseSecurityService(DSS).VerificationofaSecurityClearancemustbe
processedthroughtheSpecialSecurityOfficerlocatedinthePlanningandNationalSecurityService
withintheOfficeofOperations,Security,andPreparedness.
d.CustomsoftwaredevelopmentandoutsourcedoperationsmustbelocatedintheU.S.tothe
maximumextentpractical.Ifsuchservicesareproposedtobeperformedabroadandarenot
disallowedbyotherVApolicyormandates,theContractor/subcontractormuststatewhereallnon‐
U.S.servicesareprovidedanddetailasecurityplan,deemedtobeacceptablebyVA,specificallyto
addressmitigationoftheresultingproblemsofcommunication,control,dataprotection,andso
forth.LocationwithintheU.S.maybeanevaluationfactor.
e.TheContractororsubcontractormustnotifytheContractingOfficerimmediatelywhenan
employeeworkingonaVAsystemorwithaccesstoVAinformationisreassignedorleavesthe
Contractororsubcontractor’semploy.TheContractingOfficermustalsobenotifiedimmediatelyby
theContractororsubcontractorpriortoanunfriendlytermination.

3. VA INFORMATION CUSTODIAL LANGUAGE

a.InformationmadeavailabletotheContractororsubcontractorbyVAfortheperformance
oradministrationofthiscontractorinformationdevelopedbytheContractor/subcontractorin
performanceoradministrationofthecontractshallbeusedonlyforthosepurposesandshallnot
beusedinanyotherwaywithoutthepriorwrittenagreementoftheVA.Thisclauseexpressly
limitstheContractor/subcontractor'srightstousedataasdescribedinRightsinData‐General,
FAR52.227‐14(d)(1).
b.VAinformationshouldnotbeco‐mingled,ifpossible,withanyotherdataonthe
contractors/subcontractor’sinformationsystemsormediastoragesystemsinordertoensureVA
requirementsrelatedtodataprotectionandmediasanitizationcanbemet.Ifco‐minglingmustbe
allowedtomeettherequirementsofthebusinessneed,theContractormustensurethatVA’s
informationisreturnedtotheVAordestroyedinaccordancewithVA’ssanitizationrequirements.
VAreservestherighttoconductonsiteinspectionsofContractorandsubcontractorITresourcesto
ensuredatasecuritycontrols,separationofdataandjobduties,anddestruction/mediasanitization
proceduresareincompliancewithVAdirectiverequirements.
c.Priortoterminationorcompletionofthiscontract,Contractor/subcontractormustnot
destroyinformationreceivedfromVA,orgathered/createdbytheContractorinthecourseof
performingthiscontractwithoutpriorwrittenapprovalbytheVA.Anydatadestructiondoneon
behalfofVAbyaContractor/subcontractormustbedoneinaccordancewithNationalArchivesand
RecordsAdministration(NARA)requirementsasoutlinedinVADirective6300,Recordsand
InformationManagement(orsubsequentrevisionsthereto)anditsHandbook6300.1Records
ManagementProcedures,applicableVARecordsControlSchedules,andVAHandbook6500.1,
ElectronicMediaSanitization(orsubsequentrevisionsthereto).Self‐certificationbytheContractor
thatthedatadestructionrequirementsabovehavebeenmetmustbesenttotheVAContracting
Officerwithin30daysofterminationofthecontract.
d.TheContractor/subcontractormustreceive,gather,store,backup,maintain,use,disclose
anddisposeofVAinformationonlyincompliancewiththetermsofthecontractandapplicable
FederalandVAinformationconfidentialityandsecuritylaws,regulationsandpolicies.IfFederalor
VAinformationconfidentialityandsecuritylaws,regulationsandpoliciesbecomeapplicabletothe
VAinformationorinformationsystemsafterexecutionofthecontract,orifNISTissuesorupdates
applicableFIPSorSpecialPublications(SP)afterexecutionofthiscontract,thepartiesagreeto
negotiateingoodfaithtoimplementtheinformationconfidentialityandsecuritylaws,regulations
andpoliciesinthiscontract.
e.TheContractor/subcontractorshallnotmakecopiesofVAinformationexceptasauthorized
andnecessarytoperformthetermsoftheagreementortopreserveelectronicinformationstored
onContractor/subcontractorelectronicstoragemediaforrestorationincaseanyelectronic
equipmentordatausedbytheContractor/subcontractorneedstoberestoredtoanoperatingstate.
Ifcopiesaremadeforrestorationpurposes,aftertherestorationiscomplete,thecopiesmustbe
appropriatelydestroyed.
f.IfVAdeterminesthattheContractorhasviolatedanyoftheinformationconfidentiality,
privacy,andsecurityprovisionsofthecontract,itshallbesufficientgroundsforVAtowithhold
paymenttotheContractororthirdpartyorterminatethecontractfordefaultorterminatefor
causeunderFederalAcquisitionRegulation(FAR)part12.
g.IfaVHAcontractisterminatedforcause,theassociatedBAAmustalsobeterminatedand
appropriateactionstakeninaccordancewithVHAHandbook1600.01,BusinessAssociate
Agreements.Absentanagreementtouseordiscloseprotectedhealthinformation,thereisno
businessassociaterelationship.
h.TheContractor/subcontractormuststore,transport,ortransmitVAsensitiveinformation
inanencryptedform,usingVA‐approvedencryptiontoolsthatare,ataminimum,FIPS140‐2

validated.

i.TheContractor/subcontractor’sfirewallandWebservicessecuritycontrols,ifapplicable,
shallmeetorexceedVA’sminimumrequirements.VAConfigurationGuidelinesareavailableupon

request.

j.ExceptforusesanddisclosuresofVAinformationauthorizedbythiscontractfor
performanceofthecontract,theContractor/subcontractormayuseanddiscloseVAinformation
onlyintwoothersituations:(i)inresponsetoaqualifyingorderofacourtofcompetent
jurisdiction,or(ii)withVA’spriorwrittenapproval.TheContractor/subcontractormustreferall
requestsfor,demandsforproductionof,orinquiriesabout,VAinformationandinformation
systemstotheVAcontractingofficerforresponse.
k.Notwithstandingtheprovisionabove,theContractor/subcontractorshallnotreleaseVA
recordsprotectedbyTitle38U.S.C.5705,confidentialityofmedicalqualityassurancerecords
and/orTitle38U.S.C.7332,confidentialityofcertainhealthrecordspertainingtodrugaddiction,
sicklecellanemia,alcoholismoralcoholabuse,orinfectionwithhumanimmunodeficiencyvirus.If
theContractor/subcontractorisinreceiptofacourtorderorotherrequestsfortheabove‐
mentionedinformation,thatContractor/subcontractorshallimmediatelyrefersuchcourtordersor
otherrequeststotheVAcontractingofficerforresponse.
l.Forservicethatinvolvesthestorage,generating,transmitting,orexchangingofVAsensitive
informationbutdoesnotrequireC&AoranMOU‐ISAforsysteminterconnection,the
Contractor/subcontractormustcompleteaContractorSecurityControlAssessment(CSCA)ona
yearlybasisandprovideittotheCOR.

4. INFORMATION SYSTEM DESIGN AND DEVELOPMENT

a.InformationsystemsthataredesignedordevelopedfororonbehalfofVAatnon‐VA
facilitiesshallcomplywithallVAdirectivesdevelopedinaccordancewithFISMA,HIPAA,NIST,and
relatedVAsecurityandprivacycontrolrequirementsforFederalinformationsystems.This
includesstandardsfortheprotectionofelectronicPHI,outlinedin45C.F.R.Part164,SubpartC,
informationandsystemsecuritycategorizationleveldesignationsinaccordancewithFIPS199and
FIPS200withimplementationofallbaselinesecuritycontrolscommensuratewiththeFIPS199
systemsecuritycategorization(referenceAppendixBofVAHandbook6500,VAInformation
SecurityProgram).DuringthedevelopmentcycleaPrivacyImpactAssessment(PIA)mustbe
completed,providedtotheCOR,andapprovedbytheVAPrivacyServiceinaccordancewith
Directive6507,VAPrivacyImpactAssessment(orsubsequentrevisionsthereto).
b.TheContractor/subcontractorshallcertifytotheCORthatapplicationsarefullyfunctional
andoperatecorrectlyasintendedonsystemsusingtheVAFederalDesktopCoreConfiguration
(FDCC),andthecommonsecurityconfigurationguidelinesprovidedbyNISTortheVA.This
includesInternetExplorer7configuredtooperateonWindowsXPandVistA(inProtectedModeon
VistA)andfutureversions,asrequired.
c.Thestandardinstallation,operation,maintenance,updating,andpatchingofsoftwareshall
notaltertheconfigurationsettingsfromtheVAapprovedandFDCCconfiguration.Information
technologystaffmustalsousetheWindowsInstallerServiceforinstallationtothedefault“program
files”directoryandsilentlyinstallanduninstall.
d.Applicationsdesignedfornormalendusersshallruninthestandardusercontextwithout
elevatedsystemadministrationprivileges.
e.Thesecuritycontrolsmustbedesigned,developed,approvedbyVA,andimplementedin
accordancewiththeprovisionsofVAsecuritysystemdevelopmentlifecycleasoutlinedinNIST
SpecialPublication800‐37,GuideforApplyingtheRiskManagementFrameworktoFederal
InformationSystems,VAHandbook6500,InformationSecurityProgramandVAHandbook6500.5,
IncorporatingSecurityandPrivacyinSystemDevelopmentLifecycle(orsubsequentrevisions

thereto).

f.TheContractor/subcontractorisrequiredtodesign,develop,oroperateaSystemof
RecordsNotice(SOR)onindividualstoaccomplishanagencyfunctionsubjecttothePrivacyActof
1974,(asamended),PublicLaw93‐579,December31,1974(5U.S.C.552a)andapplicableagency
regulations.ViolationofthePrivacyActmayinvolvetheimpositionofcriminalandcivilpenalties.

g. The Contractor/subcontractor agrees to:

(1)ComplywiththePrivacyActof1974(theAct)andtheagencyrulesandregulationsissued
undertheActinthedesign,development,oroperationofanysystemofrecordsonindividualsto
accomplishanagencyfunctionwhenthecontractspecificallyidentifies:

(a) The Systems of Records (SOR); and

(b) The design, development, or operation work that the Contractor/subcontractor is to perform;

(2)IncludethePrivacyActnotificationcontainedinthiscontractineverysolicitationand
resultingsubcontractandineverysubcontractawardedwithoutasolicitation,whenthework
statementintheproposedsubcontractrequirestheredesign,development,oroperationofaSOR
onindividualsthatissubjecttothePrivacyAct;and
(3)IncludethisPrivacyActclause,includingthissubparagraph(3),inallsubcontractsawarded
underthiscontractwhichrequiresthedesign,development,oroperationofsuchaSOR.
h.IntheeventofviolationsoftheAct,acivilactionmaybebroughtagainsttheagency
involvedwhentheviolationconcernsthedesign,development,oroperationofaSORonindividuals
toaccomplishanagencyfunction,andcriminalpenaltiesmaybeimposedupontheofficersor
employeesoftheagencywhentheviolationconcernstheoperationofaSORonindividualsto
accomplishanagencyfunction.ForpurposesoftheAct,whenthecontractisfortheoperationofa
SORonindividualstoaccomplishanagencyfunction,theContractor/subcontractorisconsideredto
beanemployeeoftheagency.
(1)“OperationofaSystemofRecords”meansperformanceofanyoftheactivitiesassociated
withmaintainingtheSOR,includingthecollection,use,maintenance,anddisseminationofrecords.
(2)“Record”meansanyitem,collection,orgroupingofinformationaboutanindividualthatis
maintainedbyanagency,including,butnotlimitedto,education,financialtransactions,medical
history,andcriminaloremploymenthistoryandcontainstheperson’sname,oridentifying
number,symbol,oranyotheridentifyingparticularassignedtotheindividual,suchasafingerprint
orvoiceprint,oraphotograph.
(3)“SystemofRecords”meansagroupofanyrecordsunderthecontrolofanyagencyfrom
whichinformationisretrievedbythenameoftheindividualorbysomeidentifyingnumber,
symbol,orotheridentifyingparticularassignedtotheindividual.
i.Thevendorshallensurethesecurityofallprocuredordevelopedsystemsandtechnologies,
includingtheirsubcomponents(hereinafterreferredtoas“Systems”),throughoutthelifeofthis
contractandanyextension,warranty,ormaintenanceperiods.Thisincludes,butisnotlimitedto
workarounds,patches,hotfixes,upgrades,andanyphysicalcomponents(hereafterreferredtoas
SecurityFixes)whichmaybenecessarytofixallsecurityvulnerabilitiespublishedorknowntothe
vendoranywhereintheSystems,includingOperatingSystemsandfirmware.Thevendorshall
ensurethatSecurityFixesshallnotnegativelyimpacttheSystems.
j.ThevendorshallnotifyVAwithin24hoursofthediscoveryordisclosureofsuccessful
exploitsofthevulnerabilitywhichcancompromisethesecurityoftheSystems(includingthe
confidentialityorintegrityofitsdataandoperations,ortheavailabilityofthesystem).Suchissues
shallberemediatedasquicklyasispractical,butinnoeventlongerthan14days.
k.WhentheSecurityFixesinvolveinstallingthirdpartypatches(suchasMicrosoftOSpatches
orAdobeAcrobat),thevendorwillprovidewrittennoticetotheVAthatthepatchhasbeen
validatedasnotaffectingtheSystemswithin10workingdays.Whenthevendorisresponsiblefor
operationsormaintenanceoftheSystems,theyshallapplytheSecurityFixeswithin14days.
l.Allothervulnerabilitiesshallberemediatedasspecifiedinthisparagraphinatimely
mannerbasedonrisk,butwithin60daysofdiscoveryordisclosure.Exceptionstothisparagraph
(e.g.fortheconvenienceofVA)shallonlybegrantedwithapprovalofthecontractingofficerand
theVAAssistantSecretaryforOfficeofInformationandTechnology.

5. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE

a.Forinformationsystemsthatarehosted,operated,maintained,orusedonbehalfofVAat
non‐VAfacilities,contractors/subcontractorsarefullyresponsibleandaccountableforensuring
compliancewithallHIPAA,PrivacyAct,FISMA,NIST,FIPS,andVAsecurityandprivacydirectives
andhandbooks.Thisincludesconductingcompliantriskassessments,routinevulnerability
scanning,systempatchingandchangemanagementprocedures,andthecompletionofan
acceptablecontingencyplanforeachsystem.TheContractor’ssecuritycontrolproceduresmustbe
equivalent,tothoseproceduresusedtosecureVAsystems.APrivacyImpactAssessment(PIA)
mustalsobeprovidedtotheCORandapprovedbyVAPrivacyServicepriortooperational
approval.AllexternalInternetconnectionstoVA’snetworkinvolvingVAinformationmustbe
reviewedandapprovedbyVApriortoimplementation.
b.Adequatesecuritycontrolsforcollecting,processing,transmitting,andstoringofPersonally
IdentifiableInformation(PII),asdeterminedbytheVAPrivacyService,mustbeinplace,tested,
andapprovedbyVApriortohosting,operation,maintenance,oruseoftheinformationsystem,or
systemsbyoronbehalfofVA.ThesesecuritycontrolsaretobeassessedandstatedwithinthePIA
andifthesecontrolsaredeterminednottobeinplace,orinadequate,aPlanofActionand
Milestones(POA&M)mustbesubmittedandapprovedpriortothecollectionofPII.
c.Outsourcing(Contractorfacility,ContractorequipmentorContractorstaff)ofsystemsor
networkoperations,telecommunicationsservices,orothermanagedservicesrequirescertification
andaccreditation(authorization)(C&A)oftheContractor’ssystemsinaccordancewithVA
Handbook6500.3,CertificationandAccreditationand/ortheVAOCSCertificationProgramOffice.
Government‐owned(governmentfacilityorgovernmentequipment)Contractor‐operatedsystems,
thirdpartyorbusinesspartnernetworksrequirememorandumsofunderstandingand
interconnectionagreements(MOU‐ISA)whichdetailwhatdatatypesareshared,whohasaccess,
andtheappropriatelevelofsecuritycontrolsforallsystemsconnectedtoVAnetworks.
d.TheContractor/subcontractor’ssystemmustadheretoallFISMA,FIPS,andNISTstandards
relatedtotheannualFISMAsecuritycontrolsassessmentandreviewandupdatethePIA.Any
deficienciesnotedduringthisassessmentmustbeprovidedtotheVAcontractingofficerandthe
ISOforentryintoVA’sPOA&Mmanagementprocess.TheContractor/subcontractormustuseVA’s
POA&Mprocesstodocumentplannedremedialactionstoaddressanydeficienciesininformation
securitypolicies,procedures,andpractices,andthecompletionofthoseactivities.Security
deficienciesmustbecorrectedwithinthetimeframesapprovedbythegovernment.
Contractor/subcontractorproceduresaresubjecttoperiodic,unannouncedassessmentsbyVA
officials,includingtheVAOfficeofInspectorGeneral.Thephysicalsecurityaspectsassociatedwith
Contractor/subcontractoractivitiesmustalsobesubjecttosuchassessments.Ifmajorchangesto
thesystemoccurthatmayaffecttheprivacyorsecurityofthedataorthesystem,theC&Aofthe
systemmayneedtobereviewed,retestedandre‐authorizedperVAHandbook6500.3.Thismay
requirereviewingandupdatingallofthedocumentation(PIA,SystemSecurityPlan,Contingency
Plan).TheCertificationProgramOfficecanprovideguidanceonwhetheranewC&Awouldbe

necessary.

e.TheContractor/subcontractormustconductanannualself‐assessmentonallsystemsand
outsourcedservicesasrequired.Bothhardcopyandelectroniccopiesoftheassessmentmustbe
providedtotheCOR.Thegovernmentreservestherighttoconductsuchanassessmentusing
governmentpersonneloranotherContractor/subcontractor.TheContractor/subcontractormust
takeappropriateandtimelyaction(thiscanbespecifiedinthecontract)tocorrectormitigateany
weaknessesdiscoveredduringsuchtesting,generallyatnoadditionalcost.
f.VAprohibitstheinstallationanduseofpersonally‐ownedorContractor/subcontractor‐
ownedequipmentorsoftwareonVA’snetwork.Ifnon‐VAownedequipmentmustbeusedtofulfill
therequirementsofacontract,itmustbestatedintheserviceagreement,SOWorcontract.Allof
thesecuritycontrolsrequiredforgovernmentfurnishedequipment(GFE)mustbeutilizedin
approvedotherequipment(OE)andmustbefundedbytheowneroftheequipment.Allremote
systemsmustbeequippedwith,anduse,aVA‐approvedantivirus(AV)softwareandapersonal
(host‐basedorenclavebased)firewallthatisconfiguredwithaVA‐approvedconfiguration.
Softwaremustbekeptcurrent,includingallcriticalupdatesandpatches.OwnersofapprovedOE
areresponsibleforprovidingandmaintainingtheanti‐viralsoftwareandthefirewallonthenon‐
VAownedOE.
g.Allelectronicstoragemediausedonnon‐VAleasedornon‐VAownedITequipmentthatis
usedtostore,process,oraccessVAinformationmustbehandledinadherencewithVAHandbook
6500.1,ElectronicMediaSanitizationupon:(i)completionorterminationofthecontractor(ii)
disposalorreturnoftheITequipmentbytheContractor/subcontractororanypersonactingon
behalfoftheContractor/subcontractor,whicheverisearlier.Media(harddrives,opticaldisks,CDs,
back‐uptapes,etc.)usedbythecontractors/subcontractorsthatcontainVAinformationmustbe
returnedtotheVAforsanitizationordestructionortheContractor/subcontractormustself‐certify
thatthemediahasbeendisposedofper6500.1requirements.Thismustbecompletedwithin30
daysofterminationofthecontract.
h.Bio‐Medicaldevicesandotherequipmentorsystemscontainingmedia(harddrives,optical
disks,etc.)withVAsensitiveinformationmustnotbereturnedtothevendorattheendoflease,for
trade‐in,orotherpurposes.Theoptionsare:

a. Vendor must accept the system without the drive;

b.VA’sinitialmedicaldevicepurchaseincludesasparedrivewhichmustbeinstalledinplace
oftheoriginaldriveattimeofturn‐in;or
c.VAmustreimbursethecompanyformediaatareasonableopenmarketreplacementcostat
timeofpurchase.
d.Duetothehighlyspecializedandsometimesproprietaryhardwareandsoftwareassociated
withmedicalequipment/systems,ifitisnotpossiblefortheVAtoretaintheharddrive,then;
(1)TheequipmentvendormusthaveanexistingBAAifthedevicebeingtradedinhassensitive
informationstoredonitandharddrive(s)fromthesystemarebeingreturnedphysicallyintact;

and

(2)Anyfixedharddriveonthedevicemustbenon‐destructivelysanitizedtothegreatest
extentpossiblewithoutnegativelyimpactingsystemoperation.Selectiveclearingdowntopatient
datafolderlevelisrecommendedusingVAapprovedandvalidatedoverwriting
technologies/methods/tools.Applicablemediasanitizationspecificationsneedtobepre‐approved
anddescribedinthepurchaseorderorcontract.
(3)AstatementneedstobesignedbytheDirector(SystemOwner)thatstatesthatthedrive
couldnotberemovedandthat(a)and(b)controlsaboveareinplaceandcompleted.TheISOneeds
tomaintainthedocumentation.

6. SECURITY INCIDENT INVESTIGATION

a.Theterm“securityincident”meansaneventthathas,orcouldhave,resultedin
unauthorizedaccessto,lossordamagetoVAassets,orsensitiveinformation,oranactionthat
breachesVAsecurityprocedures.TheContractor/subcontractorshallimmediatelynotifytheCOR
andsimultaneously,thedesignatedISOandPrivacyOfficerforthecontractofanyknownor
suspectedsecurity/privacyincidents,oranyunauthorizeddisclosureofsensitiveinformation,
includingthatcontainedinsystem(s)towhichtheContractor/subcontractorhasaccess.
b.TotheextentknownbytheContractor/subcontractor,theContractor/subcontractor’s
noticetoVAshallidentifytheinformationinvolved,thecircumstancessurroundingtheincident
(includingtowhom,how,when,andwheretheVAinformationorassetswereplacedatriskor
compromised),andanyotherinformationthattheContractor/subcontractorconsidersrelevant.
c.Withrespecttounsecuredprotectedhealthinformation,thebusinessassociateisdeemed
tohavediscoveredadatabreachwhenthebusinessassociatekneworshouldhaveknownofa
breachofsuchinformation.Upondiscovery,thebusinessassociatemustnotifythecoveredentity
ofthebreach.Notificationsneedtobemadeinaccordancewiththeexecutedbusinessassociate

agreement.

d.Ininstancesoftheftorbreak‐inorothercriminalactivity,theContractor/subcontractor
mustconcurrentlyreporttheincidenttotheappropriatelawenforcemententity(orentities)of
jurisdiction,includingtheVAOIGandSecurityandLawEnforcement.TheContractor,its
employees,anditssubcontractorsandtheiremployeesshallcooperatewithVAandanylaw
enforcementauthorityresponsiblefortheinvestigationandprosecutionofanypossiblecriminal
lawviolation(s)associatedwithanyincident.TheContractor/subcontractorshallcooperatewith
VAinanycivillitigationtorecoverVAinformation,obtainmonetaryorothercompensationfroma
thirdpartyfordamagesarisingfromanyincident,orobtaininjunctivereliefagainstanythirdparty
arisingfrom,orrelatedto,theincident.

7. LIQUIDATED DAMAGES FOR DATA BREACH

a.Consistentwiththerequirementsof38U.S.C.§5725,acontractmayrequireaccessto
sensitivepersonalinformation.Ifso,theContractorisliabletoVAforliquidateddamagesinthe
eventofadatabreachorprivacyincidentinvolvinganySPItheContractor/subcontractor
processesormaintainsunderthiscontract.However,itisthepolicyofVAtoforegocollectionof
liquidateddamagesintheeventthecontractorprovidespaymentofactualdamagesinanamount
determinedtobeadequatebytheagency.
b.TheContractor/subcontractorshallprovidenoticetoVAofa“securityincident”assetforth
intheSecurityIncidentInvestigationsectionabove.Uponsuchnotification,VAmustsecurefroma
non‐DepartmententityortheVAOfficeofInspectorGeneralanindependentriskanalysisofthe
databreachtodeterminethelevelofriskassociatedwiththedatabreachforthepotentialmisuse
ofanysensitivepersonalinformationinvolvedinthedatabreach.Theterm'databreach'meansthe
loss,theft,orotherunauthorizedaccess,oranyaccessotherthanthatincidentaltothescopeof
employment,todatacontainingsensitivepersonalinformation,inelectronicorprintedform,that
resultsinthepotentialcompromiseoftheconfidentialityorintegrityofthedata.Contractorshall
fullycooperatewiththeentityperformingtheriskanalysis.Failuretocooperatemaybedeemeda
materialbreachandgroundsforcontracttermination.
c.Eachriskanalysisshalladdressallrelevantinformationconcerningthedatabreach,
includingthefollowing:

(1) Nature of the event (loss, theft, unauthorized access);

(2) Description of the event, including:

(a) date of occurrence;

(b)dataelementsinvolved,includinganyPII,suchasfullname,socialsecuritynumber,dateof
birth,homeaddress,accountnumber,disabilitycode;(3)Numberofindividualsaffectedor
potentiallyaffected;

(3) Names of individuals or groups affected or potentially affected;

(4)Easeoflogicaldataaccesstothelost,stolenorimproperlyaccesseddatainlightofthe
degreeofprotectionforthedata,e.g.,unencrypted,plaintext;

(5) Amount of time the data has been out of VA control;

(6)Thelikelihoodthatthesensitivepersonalinformationwillorhasbeencompromised(made
accessibletoandusablebyunauthorizedpersons);

(7) Known misuses of data containing sensitive personal information, if any;

(8) Assessment of the potential harm to the affected individuals;

(9)Databreachanalysisasoutlinedin6500.2Handbook,ManagementofSecurityandPrivacy
Incidents,asappropriate;and
(10)Whethercreditprotectionservicesmayassistrecordsubjectsinavoidingormitigatingthe
resultsofidentitytheftbasedonthesensitivepersonalinformationthatmayhavebeen

compromised.

d.Basedonthedeterminationsoftheindependentriskanalysis,theContractorshallbe
responsibleforpayingtotheVAliquidateddamagesintheamountof$37.50peraffectedindividual
tocoverthecostofprovidingcreditprotectionservicestoaffectedindividualsconsistingofthe

following:

(1) Notification;

(2)Oneyearofcreditmonitoringservicesconsistingofautomaticdailymonitoringofatleast3
relevantcreditbureaureports;

(3) Data breach analysis;

(4)Fraudresolutionservices,includingwritingdisputeletters,initiatingfraudalertsandcredit
freezes,toassistaffectedindividualstobringmatterstoresolution;

(5) One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and

(6)Necessarylegalexpensesthesubjectsmayincurtorepairfalsifiedordamagedcredit
records,histories,orfinancialaffairs.

8. SECURITY CONTROLS COMPLIANCE TESTING

Onaperiodicbasis,VA,includingtheOfficeofInspectorGeneral,reservestherighttoevaluateany
orallofthesecuritycontrolsandprivacypracticesimplementedbytheContractorunderthe
clausescontainedwithinthecontract.With10working‐days’notice,attherequestofthe
government,theContractormustfullycooperateandassistinagovernment‐sponsoredsecurity
controlsassessmentateachlocationwhereinVAinformationisprocessedorstored,orinformation
systemsaredeveloped,operated,maintained,orusedonbehalfofVA,includingthoseinitiatedby
theOfficeofInspectorGeneral.Thegovernmentmayconductasecuritycontrolassessmenton
shorternotice(toincludeunannouncedassessments)asdeterminedbyVAintheeventofa
securityincidentoratanyothertime.

9. TRAINING

a.AllContractoremployeesandsubcontractoremployeesrequiringaccesstoVAinformation
andVAinformationsystemsshallcompletethefollowingbeforebeinggrantedaccesstoVA
informationanditssystems:
(1)Signandacknowledge(eithermanuallyorelectronically)understandingofand
responsibilitiesforcompliancewiththeContractorRulesofBehavior,AppendixErelatingtoaccess
toVAinformationandinformationsystems;
(2)SuccessfullycompletetheVACyberSecurityAwarenessandRulesofBehaviortrainingand
annuallycompleterequiredsecuritytraining;
(3)SuccessfullycompletetheappropriateVAprivacytrainingandannuallycompleterequired
privacytraining;and
(4)Successfullycompleteanyadditionalcybersecurityorprivacytraining,asrequiredforVA
personnelwithequivalentinformationsystemaccess[tobedefinedbytheVAprogramofficialand
providedtothecontractingofficerforinclusioninthesolicitationdocument–e.g.,anyrole‐based
informationsecuritytrainingrequiredinaccordancewithNISTSpecialPublication800‐16,
InformationTechnologySecurityTrainingRequirements.]
b.TheContractorshallprovidetothecontractingofficerand/ortheCORacopyofthetraining
certificatesandcertificationofsigningtheContractorRulesofBehaviorforeachapplicable
employeewithin1weekoftheinitiationofthecontractandannuallythereafter,asrequired.
c.FailuretocompletethemandatoryannualtrainingandsigntheRulesofBehaviorannually,
withinthetimeframerequired,isgroundsforsuspensionorterminationofallphysicalor
electronicaccessprivilegesandremovalfromworkonthecontractuntilsuchtimeasthetraining
anddocumentsarecomplete.

File details come from the government source that posted it.