D.11 VA HANDBOOK 6500.6 CONTRACT RULES OF BEHAVIOR.pdf

PDF 208 KB Posted

Attached to
Q201--Amendment to answer questions Federal contract opportunity
Solicitation number
36C25722R0015
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 17

About this file

This document contains the Contractor Rules of Behavior for access to Department of Veterans Affairs information systems and resources under a federal contract. The Rules of Behavior outline acceptable and unacceptable uses of VA systems and data, including requirements for protecting passwords, encryption, and reporting security incidents. Contractors must agree to comply with VA security directives and only use approved software. Remote access is limited and dual network connections are prohibited without approval. Subcontracting does not release the prime contractor from adhering to these security terms.

View the file

Other files for this federal contract opportunity

Other files attached to Q201--Amendment to answer questions, newest first.
File Type Posted
36C25722R0015 0007.docx DOCX document
36C25722R0015 0006.docx DOCX document
Quality Assurance Surveillance Plan - DENTON Final 072622.docx DOCX document
PWS DENTON CBOC FINAL July 26 2022.docx DOCX document
36C25722R0015 0005.docx DOCX document
36C25722R0015 0004.docx DOCX document
36C25722R0015 0003.docx DOCX document
36C25722R0015 0002.docx DOCX document
D.05 RIGHT AND RESPONSIBILITIES OF VA PATIENTS.pdf PDF
D.09 Past Performance Questionnaire.pdf PDF
D.21 PROPER USE OF EMAIL MEMO 01-02-2018.pdf PDF
D.31 Radiology and Denton CBOC Service Agreement.pdf PDF
D.33 VISN NO SHOW POLICY.pdf PDF
D.35 PHARMACY SERVICE POLICY _ PROCEDURE NO.ADM-12 ANTICOAGULATION.pdf PDF
D.37 VHA Directive 1660.03 COI.pdf PDF
D.06 SUICIDE PREVENTION ASSESSMENT AND MANAGEMENT.pdf PDF
D.12 WAGE DETERMINATION NO. 2015-5227 REV 17 MARCH 15 2022.pdf PDF
D.14 VHA T-21 IMPLEMENTATION GUIDE.pdf PDF
D.18 VHA DIRECTIVE 2009-031 IMPROVING SAFETY IN THE USE OF MEDICAL EQUIPMENT.pdf PDF
D.30 VANTHCS MEMO 11-14.pdf PDF
36C25722R0015 0001.pdf PDF
D.03 ORGANIZATIONAL CONFLICT OF INTEREST.pdf PDF
D.08 PAST PERFORMANCE REFERENCES.pdf PDF
D.28 HT-ops-manual.pdf PDF
D.27 VANTHCS BREAST CANCER SCREENING PROCESS.pdf PDF
D.34 Path and Lab Manual - 02-2020.pdf PDF
D.15 VHA HANDBOOK 1101.11 COORDINATED CARE FOR TRAVELING VETERANS.pdf PDF
D.17 VHA HANDBOOK 1006.02 SITE CLASSIFICATIONS AND DEFINTIONS.pdf PDF
D.19 WORKLOAD HISTORY PROJECTIONS UPDATED 31 MAR 2020.pdf PDF
D.23 VANTVHCS SOP 114-12 RADIOLOGY QUALITY CONTROL.pdf PDF
D.29 VHA Directive 1608.pdf PDF
D.02 IMMIGRATION CERTIFICATION.pdf PDF
D.16 VHA Handbook 1101.10 Patient Aligned Care Team (PACT).pdf PDF
D.24 VHA DIRECTIVE 1608 COMPREHENSIVE ENVIRONMENT OF CARE PROGRAM.pdf PDF
D.36 Medical Staff ByLaws.pdf PDF
D.01 FINAL QASP V17 Denton CBOC North TX VANCS.pdf PDF
D.07 ANCILLARY AND POINT OF CARE TESTING.pdf PDF
D.13 VHA HANDBOOK 1605.02 MINIMUM NECESSARY STANDARD FOR PROTECTED HEALTH INFORMATION.pdf PDF
D.25 VANTHCS ANTICOAGULATION POLICY.pdf PDF
D.04 DOCUMENT SCANNING POLICY.pdf PDF
D.10 GOVERNMENT PROVIDED EQUIPMENT.pdf PDF
D.20 CLINIC BASED TELEHEALTH OPERATIONS MAUNAL.pdf PDF
D.22 NTVHCS SOP COMMUICATION TEST RESULTS TO PROVIDERS AND PATIENTS.pdf PDF
D.26 FY19 SES ADDENDUM VERSION 2.01.pdf PDF
D.32 Podiatry Service Agreement.pdf PDF
36C25722R0015 0001.docx DOCX document
Organizational Conflict of Interest.docx DOCX document
D.9 Past Performance Questionnaire.docx DOCX document
Wage Deter.pdf PDF
36C25722R0015_2.docx DOCX document
Show all 50

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

MARCH 12, 2010 VA HANDBOOK 6500.6

APPENDIX D

CONTRACTOR RULES OF BEHAVIOR

This User Agreement contains rights and authorizations regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the Department of

Veterans Affairs (VA). This User Agreement covers my access to all VA data whether electronic or hard copy

("Data"), VA information systems and resources ("Systems"), and VA sites ("Sites"). This User Agreement incorporates Rules of Behavior for using VA, and other information systems and resources under the contract.

1. GENERAL TERMS AND CONDITIONS FOR ALL ACTIONS AND ACTIVITIES UNDER

THE CONTRACT:

a. I understand and agree that I have no reasonable expectation of privacy in accessing or using any VA, or other

Federal Government information systems.

b. I consent to reviews and actions by the Office of Information & Technology (OI&T) staff designated and authorized by the VA Chief Information Officer (CIO) and to the VA OIG regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA. These actions may include monitoring, recording, copying, inspecting, restricting access, blocking, tracking, and disclosing to all authorized OI&T, VA, and law enforcement personnel as directed by the VA CIO without my prior consent or notification.

c. I consent to reviews and actions by authorized VA systems administrators and Information Security Officers solely for protection of the VA infrastructure, including, but not limited to monitoring, recording, auditing, inspecting, investigating, restricting access, blocking, tracking, disclosing to authorized personnel, or any other authorized actions by all authorized OI&T, VA, and law enforcement personnel.

d. I understand and accept that unauthorized attempts or acts to access, upload, change, or delete information on

Federal Government systems; modify Federal government systems; deny access to Federal government systems;

accrue resources for unauthorized use on Federal government systems; or otherwise misuse Federal government systems or resources are prohibited.

e. I understand that such unauthorized attempts or acts are subject to action that may result in criminal, civil, or administrative penalties. This includes penalties for violations of Federal laws including, but not limited to, 18

U.S.C. §1030 (fraud and related activity in connection with computers) and 18 U.S.C. §2701 (unlawful access to stored communications).

f. I agree that OI&T staff, in the course of obtaining access to information or systems on my behalf for performance under the contract, may provide information about me including, but not limited to, appropriate unique personal identifiers such as date of birth and social security number to other system administrators, Information Security Officers (ISOs), or other authorized staff without further notifying me or obtaining additional written or verbal permission from me.

g. I understand I must comply with VA’s security and data privacy directives and handbooks. I understand that copies of those directives and handbooks can be obtained from the Contracting Officer's Technical

Representative (COTR). If the contractor believes the policies and guidance provided by the COTR is a material unilateral change to the contract, the contractor must elevate such concerns to the Contracting Officer for resolution.

h. I will report suspected or identified information security/privacy incidents to the COTR and to the local ISO or Privacy Officer as appropriate.

D.11 RFP: 36C25722R0015

2. GENERAL RULES OF BEHAVIOR

a. Rules of Behavior are part of a comprehensive program to provide complete information security. These rules establish standards of behavior in recognition of the fact that knowledgeable users are the foundation of a successful security program. Users must understand that taking personal responsibility for the security of their computer and the information it contains is an essential part of their job.

b. The following rules apply to all VA contractors. I agree to:

(1) Follow established procedures for requesting, accessing, and closing user accounts and access. I will not request or obtain access beyond what is normally granted to users or by what is outlined in the contract.

(2) Use only systems, software, databases, and data which I am authorized to use, including any copyright restrictions.

(3) I will not use other equipment (OE) (non-contractor owned) for the storage, transfer, or processing of VA sensitive information without a VA CIO approved waiver, unless it has been reviewed and approved by local management and is included in the language of the contract. If authorized to use OE

IT equipment, I must ensure that the system meets all applicable 6500 Handbook requirements for OE.

(4) Not use my position of trust and access rights to exploit system controls or access information for any reason other than in the performance of the contract.

(5) Not attempt to override or disable security, technical, or management controls unless expressly permitted to do so as an explicit requirement under the contract or at the direction of the COTR or ISO.

If I am allowed or required to have a local administrator account on a government-owned computer, that local administrative account does not confer me unrestricted access or use, nor the authority to bypass security or other controls except as expressly permitted by the VA CIO or CIO's designee.

(6) Contractors’ use of systems, information, or sites is strictly limited to fulfill the terms of the contract.

I understand no personal use is authorized. I will only use other Federal government information systems as expressly authorized by the terms of those systems. I accept that the restrictions under ethics regulations and criminal law still apply.

(7) Grant access to systems and information only to those who have an official need to know.

(8) Protect passwords from access by other individuals.

(9) Create and change passwords in accordance with VA Handbook 6500 on systems and any devices protecting VA information as well as the rules of behavior and security settings for the particular system in question.

(10) Protect information and systems from unauthorized disclosure, use, modification, or destruction. I will only use encryption that is FIPS 140-2 validated to safeguard VA sensitive information, both safeguarding VA sensitive information in storage and in transit regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA.

(11) Follow VA Handbook 6500.1, Electronic Media Sanitization to protect VA information. I will contact the COTR for policies and guidance on complying with this requirement and will follow the

COTR's orders.

(12) Ensure that the COTR has previously approved VA information for public dissemination, including e-mail communications outside of the VA as appropriate. I will not make any unauthorized disclosure of any VA sensitive information through the use of any means of communication including but not limited to e-mail, instant messaging, online chat, and web bulletin boards or logs.

(13) Not host, set up, administer, or run an Internet server related to my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA unless explicitly authorized under the contract or in writing by the COTR.

(14) Protect government property from theft, destruction, or misuse. I will follow VA directives and handbooks on handling Federal government IT equipment, information, and systems. I will not take VA sensitive information from the workplace without authorization from the COTR.

(15) Only use anti-virus software, antispyware, and firewall/intrusion detection software authorized by

VA. I will contact the COTR for policies and guidance on complying with this requirement and will follow the COTR's orders regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with VA.

(16) Not disable or degrade the standard anti-virus software, antispyware, and/or firewall/intrusion detection software on the computer I use to access and use information assets or resources associated with my performance of services under the contract terms with VA. I will report anti-virus, antispyware, firewall or intrusion detection software errors, or significant alert messages to the COTR.

(17) Understand that restoration of service of any VA system is a concern of all users of the system.

(18) Complete required information security and privacy training, and complete required training for the particular systems to which I require access.

3. ADDITIONAL CONDITIONS FOR USE OF NON- VA INFORMATION TECHNOLOGY

RESOURCES

a. When required to complete work under the contract, I will directly connect to the VA network whenever possible. If a direct connection to the VA network is not possible, then I will use VA approved remote access software and services.

b. Remote access to non-public VA information technology resources is prohibited from publicly-available IT computers, such as remotely connecting to the internal VA network from computers in a public library.

c. I will not have both a VA network line and any kind of non-VA network line including a wireless network card, modem with phone line, or other network device physically connected to my computer at the same time, unless the dual connection is explicitly authorized by the COTR.

d. I understand that I may not obviate or evade my responsibility to adhere to VA security requirements by subcontracting any work under any given contract or agreement with VA, and that any subcontractor(s) I engage shall likewise be bound by the same security requirements and penalties for violating the same.

4. STATEMENT ON LITIGATION

This User Agreement does not and should not be relied upon to create any other right or benefit, substantive or procedural, enforceable by law, by a party to litigation with the United States Government.

5. ACKNOWLEDGEMENT AND ACCEPTANCE

I acknowledge receipt of this User Agreement. I understand and accept all terms and conditions of this User

Agreement, and I will comply with the terms and conditions of this agreement and any additional VA warning banners, directives, handbooks, notices, or directions regarding access to or use of information systems or information. The terms and conditions of this document do not supersede the terms and conditions of the signatory’s employer and VA.

Print or type your full name Signature

Last 4 digits of SSN Date

Office Phone Position Title

Contractor’s Company Name

Please complete and return the original signed document to the COTR within the timeframe stated in the terms of the contract.

File details come from the government source that posted it. Updated .