2020 MOU ISA New Template Brown Bag.pptx
PPTX presentation 1 MB Posted
- Attached to
- 7A21--VISN 22 POC Middleware Federal contract opportunity
- Solicitation number
- 36C26221Q0044
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Office of Information Security Information Security Risk Management Business Requirements Division
MOU/ISA New Template cybersecurity Support Requests Deedra A. Jones, Manager Joe DeCoteau, Technical Lead Leigh Zirbel, Technical Lead November 19, 2020
FOR INTERNAL USE ONLY
Hello and thank you for joining us today. My name is Deedra Jones and I am the Manager of the Business Requirements Division, or BRD, under the Office of Information Security, Information Security Risk Management. With me today are Joe DeCoteau and Leigh Zirbel. They are the Technical Leads for the BRD team. We have a few slides to present in order to share some critical information with you and then we will answer any questions you may have. We will open the call for Q&A after the presentation. If you have any questions during the presentation, please enter them in Chat and we will be sure they are all answered.
Next Slide
OIS Releases New MOU/ISA Template
The Department of Veterans Affairs/Office of Information Security/Information Security Risk Management issued a new Memorandum of Understanding (MOU) and Interconnection Security Agreement (ISA) template.
MOU/ISAs are required for authorization whenever VA connects with another information system that VA doesn’t own.
In alignment with NIST 800-47 and VA Handbook 6500, the MOU/ISA must document “security controls/requirements for external information systems that process, store, or transmit VA information.”
FOR INTERNAL USE ONLY Office of Information and Technology
The first subject for today is the new Memorandum Of Understanding/Interconnection Security Agreement, or MOU/ISA template, which was released by OIS via ITOPS bulletin on September 9th, 2020. Per the National Institute of Standards and Technology, or NIST 800-47 document, VA Handbooks 6500 and 6513, MOU/ISA documents are required for the documentation and authorization of connections to information systems that do not share the same authorizing authority. Per VA Handbook 6500, the MOU/ISA must document “security controls and requirements for external information systems that process, store, or transmit VA information.” As a reminder, the Information System Owner, or their designee, is responsible for the MOU/ISA document and its content. It is a system security artifact, just like the Disaster Recovery Plan or Information System Contingency Plan. The system’s Information System Security Officer, or ISSO, is responsible for the security review of the document and ensuring all security requirements have been met.
What Does the New Template Mean for You
FOR INTERNAL USE ONLY Office of Information and Technology With this new MOU/ISA template, the Information System Owner or their designee will:
Use the new MOU/ISA template to document all new external interconnecting systems as required by VA policy.
Update all existing MOU/ISAs signed before December 2017 to the new template.
Update any MOU/ISA with a major change noted in the most recent or prior annual review to the new template.
Document annual reviews on the MOU/ISA Review Form located in the MOU ISA Published Templates and Instructions folder.
So, you may be asking what impact a new MOU/ISA template will have on you. First, it means that all new external connections will be documented using the new template. Second, any existing MOU/ISA document, with the last signature date prior to December 2017, should be updated to the new template. This will be covered in more detail on the next slide. Third, any MOU/ISA noted as needing a major change during the most recent or prior annual reviews, should be moved to the new template. Now Leigh is going to go over the many reasons why MOU/ISAs dated before December 2017 should be updated.
Reasons to Update to the New Template
Outdated Content Requirement for Background Investigations Changes in Federal Laws Sensitive Information (Ports, Protocols, IP Addresses) Connection and Environment Changes MOU/ISA Review Form
FOR INTERNAL USE ONLY Office of Information and Technology
Since releasing the new template, we have had several people ask why an existing MOU/ISA document should be updated. As mentioned earlier, if you have any MOU/ISA documents with the last signature date prior to December 2017, you should update them to the new template. There are several reasons to do so. The biggest reasons are outdated content and updated federal laws.
The older templates have outdated content that has been removed from the new template because it is irrelevant. Older templates contain a lot of contract language that is not applicable to documenting external connections. One example of outdated content is the requirement for background investigations. This information in the older templates is not only inaccurate, but it is information that should be in the contract governing the connection, not in the MOU/ISA document. In the past, the extraneous language in the older template caused numerous vendors to push back and delayed putting an agreement in place.
Stipulations in updated laws and regulations could materially change the requirements for external connection documents. Some older documents contain sensitive information, such as IP addresses. These documents are subject to the Freedom of Information Act and could be released to the public under FOIA. If a person had malicious intent, they could use this information to cause harm to VA IT systems and data.
Finally, the Office of Inspector General has continually cited VA for outdated MOU/ISAs. The OIG auditors review document content for accuracy and have noted findings of outdated and inaccurate information in those older documents.
You will see in the new template that the MOU ISA Review form has changed. This is because Appendix C was removed, and a new document was added to ensure both the Information System Owner and ISSO review and sign. I will now turn it over to Joe and he will provide details about the new template and review form.
Next Slide
MOU/ISA Overview The MOU/ISA has been streamlined in accordance with NIST 800-47 and VA Handbook 6500.
External connections documentation must be accurate. The MOU/ISA tells the story of the external connection.
All color-coded sections must be filled out completely. No edits will be made to the black font text.
Topological Drawing must be included.
Simplified signature section.
Updated Appendices.
New MOU/ISA Review Form.
FOR INTERNAL USE ONLY Office of Information and Technology
Thank you, Leigh. The MOU ISA tells the complete story of the external connection. It includes the justification for the connection and outlines the type of data that is traversing the connection. The new MOU/ISA document was streamlined and authored to comply with NIST 800-47 and VA Handbook 6500.
I will now show you some of the critical sections in the new template, to include the template color key, a sample Topological Drawing, the simplified Signature Section, updated appendices, and the new MOU ISA Review form.
Template Color Key FOR INTERNAL USE ONLY Office of Information and Technology
The new template includes color coded instructions to streamline filling out the document. All black text should remain unchanged. Black text is the approved language for the template to meet the requirements of NIST 800-47 and VA policy. Red text is for the VA organization and VA system name. Purple text is for the vendor organization name and name of the vendor system that is connecting to the VA. Blue text should be replaced with appropriate text and changed to black once the document is complete. Green text is instructional for the writer and gives examples of what information is needed.
VA Boundary Organization 2 Boundary/Network Public Internet VA Firewall/ Router VA System
[XYZ]
Firewall/Router Server Site-to-Site VPN Tunnel Bi-directional/VA Inbound/VA Outbound
TLS/SSL/SFTP/HTTPS
FIPS 140-2 #0000
Component/ Medical device Component/device Technical Support Workstation Legend VA – The Department of Veterans Affairs VA System – [VA System] XYZ – VA System Name
Topological Drawing
Another critical piece of the document is the topology. The Topological Drawing illustrates the systems described in the document. The topology should depict the system boundaries and show details of all communications paths, circuits and other components used for the interconnection. This includes but is not limited to routers, firewalls, servers, VPN tunnels and major components.
Signature Section
The signature process has changed on the new MOU/ISA template. National and Local MOU/ISAs are now only signed by the Authorizing Officials or System Owners. This streamlines the process for signatures and places VA in compliance with NIST requirements for signatures.
Appendix A: Points of Contact
FOR INTERNAL USE ONLY Office of Information and Technology
List of Responsible Parties for Each System List of Responsible Parties to Contact During a Security Incident
List of Responsible Parties to Contact During a Security Incident
A critical piece of the MOU ISA is Appendix A, the Points of Contact list. This appendix should reflect the current system points of contact to include Information System Owner, Privacy Officer, the ISSO and the VA Technical Lead for the connection. Appendix A should also list the responsible parties to contact in the event of a security incident. This appendix should be updated whenever changes occur.
Appendix B:
Definitions of Sensitive Information Types FOR INTERNAL USE ONLY Office of Information and Technology
Appendix B contains a list and definitions of sensitive Information types. This is to assist the Information System Owner with determining the type of information being transmitted. It also helps with deciding if Federal Information Processing Standard, or FIPS 140-2 encryption is required.
New Appendix C:
Interconnection Ports and Protocols FOR INTERNAL USE ONLY Office of Information and Technology
In prior MOU/ISA templates, Appendix C was used for the purpose of recording Annual Reviews of the document. In the new template, Appendix C is for documenting the Interconnection Ports and Protocols. The annual reviews are now recorded on a new form, which I will cover now.
MOU/ISA Review Form
FOR INTERNAL USE ONLY Office of Information and Technology
A new MOU ISA review form was created and is required for use with the new template. The old Appendix C review form will not be used for new MOU/ISA documents. The first two signatures on the new review form are the ISSO and Privacy Officer. They will sign when the MOU ISA document is first authored to certify their initial review. This form will also be used to document all annual reviews going forward. The new form requires the signature of both the Information System Owner and the ISSO in the annual review section. This requirement was added because the Information System Owner is ultimately responsible for the review and accuracy of the external connection document. The MOU ISA Review Form will remain with the MOU/ISA for the life of the document.
MOU/ISA Helpful Links and Resources MOU/ISA templates, appendices, and checklists are located on the MOU ISA Document Site Portal ISRM/BRD MOU/ISA Standard Operating Procedure (SOP) VA Handbook and Directive 6513, Secure External Connections NIST 800-47, Security Guide for Interconnecting Information Technology Systems Department of Veterans Affairs (VA) Handbook 6500, Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program FOR INTERNAL USE ONLY Office of Information and Technology
I’m going to briefly cover the MOU ISA Document site. The other references on this slide, the MOU/ISA SOP, VA Handbook and Directive 6513, NIST 800-47 and VA Handbook 6500 are provided to guide you to successfully complete your MOU ISA documents.
MOU ISA Document Site
FOR INTERNAL USE ONLY Office of Information and Technology
You can navigate to the new MOU/ISA template via the MOU ISA Document Site shown here. The arrows are pointing to the links that provide access to all the resources mentioned on the previous slide, as well as helpful user guides for the entire MOU/ISA document process. To access the new MOU/ISA templates, click on the MOU ISA Templates link.
MOU ISA Published Templates and Instructions
FOR INTERNAL USE ONLY Office of Information and Technology
You will then click on the VA MOU ISA Approved Final Template – 09092020 file to open the template. All MOU/ISA documents that you may need are on this page as well.
Now that we have covered all the highlights of the new MOU/ISA template, I will now turn it over to Leigh to talk about our new Cybersecurity Support Request tool.
Next Slide
OIS/ISRM/BRD
Cybersecurity Support Request Portal FOR INTERNAL USE ONLY Office of Information and Technology Cybersecurity Support Request Portal process is now on VA’s Light Electronic Action Framework, better know as LEAF Moved from SharePoint to LEAF to provide the best possible customer service New form on the LEAF portal provides customers a simplified method for requesting cybersecurity support and ISSO assignment for IT projects and systems OIS/ISRM/BRD Cybersecurity Support Requests Portal
The cybersecurity support request process is now in LEAF! The new Leaf request portal is available to any stakeholder that needs cybersecurity support for new and existing ATOs. The request captures all of the relevant information needed to be able triage and route the request to the correct parties.
LEAF Cybersecurity Support Request Portal
FOR INTERNAL USE ONLY Office of Information and Technology
On the front page of the portal, you can initiate a request by clicking on the New Request button.
Relevant information that will be collected includes whether the system has an ATO, what the VIPR number is if there is one, where the system is housed, such as cloud or data center and detailed information that helps us all understand what type of assistance is needed. Based on the data collected, the LEAF portal allows BRD the ability to assign an ISSO, add a cybersecurity professional from a different division, and also send on to Enterprise Security Operations for their review and assignment.
There is a link to the User Guide on the front page which provides extensive details on how to complete the request form if you need it.
Now back to Deedra.
QUESTIONS?
Again, I would like to thank you all for joining us today. I also want to thank Joe and Leigh for their hard work and dedication to the MOU/ISA process. We will now address any questions in chat that haven’t already been answered and open the call for questions and discussion.
image3.png image4.png image2.png image6.jpeg image7.jpeg image8.png image9.jpeg image10.png image11.png image12.png image13.svg image14.png image15.svg image16.png image17.png image18.png image19.png image20.png image21.png image22.png image23.png image24.png image25.jpeg image26.png image27.png image5.png image28.png image1.png
File details come from the government source that posted it. Updated .