(Insert Company Name) VA MOU ISA Checklist 2017.12.18.xlsx
XLSX spreadsheet 1 MB Posted
- Attached to
- 7A21--VISN 22 POC Middleware Federal contract opportunity
- Solicitation number
- 36C26221Q0044
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
MOU ISA Checklist
| Section / Criteria | Status | Comments | Recommendations |
| General | |||
| Instructions in template you are using should state document published on 12/11/17. | [Select Status] | ||
| The document draft has been renamed to correct naming convention (Company Name) (Facility Code or VA National) MOU ISA - (Working Document) | [Select Status] | ||
| Template basic instructions text box is deleted from title page. | [Select Status] | ||
| The title page is correctly completed with VA Organization 1 (must be a VA component). | [Select Status] | ||
| The title page is correctly completed with Organization 2 (a non-VA entity, confirm it is a contract primary). | [Select Status] | ||
| Confirm that VA Organization 1 and Organization 2 are not under same approving authority (or else no agreement needed). | [Select Status] | ||
| The title page has the date documented. | [Select Status] | ||
| The title page has the version number documented. | [Select Status] | ||
| Template color key text box is deleted from title page. | [Select Status] | ||
| The Document Control Change Sheet contains a VA Author and Organization 2 Author. | [Select Status] | ||
| The Document Control Change Sheet is updated as appropriate according to either Option A or B. | [Select Status] | ||
| The Document Control Change Sheet entry in the formatting of the example entry. | [Select Status] | ||
| Acronyms are defined the first time they are mentioned throughout the document. | [Select Status] | ||
| The same name for VA Organization 1 is used throughout the MOU/ISA. | [Select Status] | ||
| The same name for Organization 2 is used throughout the MOU/ISA. | [Select Status] | ||
| Ensure VA Organization 1 System or Informational Asset are correctly filled-in as appropriate throughout the MOU/ISA. | [Select Status] | ||
| Ensure Organization 2 System or Informational Asset fields are correctly filled-in as appropriate throughout the MOU/ISA. | [Select Status] | ||
| Confirm no changes to the boilerplate language have been made throughout the document. | [Select Status] | ||
| For National Agreements, Asset Name / Facility name must be sufficiently vague. Too specific and it is no longer a national agreement. | [Select Status] | ||
| For cloud connections, VA has the requirement to only use Fed Ramp (FEDRAMP) certified cloud solutions. | [Select Status] | ||
| Executive Summary | |||
| Confirm a high level description of the interconnection is covered in the Executive Summary to include devices and what kind of information is being transferred is included. Should not be more than a few paragraphs. | [Select Status] | ||
| The basic Purpose and scope of the interconnection is covered in the Executive Summary. | [Select Status] | ||
| 1.1 Introduction | |||
| For new agreements, state it is a brand new MOU / ISA and therefore does not supersede any previous MOU/ISAs (Option A Selected). | [Select Status] | ||
| For Renewals / Updates to Existing Agreements, Insert the date of the original MOU/ISA agreement (Option B Selected). Confirm Date matches Change Log Date. | [Select Status] | ||
| 1.2 Authority | |||
| Verify ISO listed all other relevant legislative, regulatory, or policy authorities not included in the template list. | [Select Status] | ||
| Verify PO listed all authorities to share data not included in the template list. | [Select Status] | ||
| Content Checklist - Memorandum of Understanding (MOU) | |||
| 2.1 Background | |||
| Modify paragraph to best describe interconnection, replace all [required fields]. | [Select Status] | ||
| Benefits to be derived from the interconnection are included. | [Select Status] | ||
| Ensure Name of VA Organization 1's System or Information Asset is filled out. | [Select Status] | ||
| Ensure Function of VA Organization 1 IT system is filled out. | [Select Status] | ||
| Ensure Location of VA Organization 1 IT System is filled out. | [Select Status] | ||
| Ensure Description of data being transmitted from VA Organization 1 to Organization 2 is filled in correctly; Include if any PII/PHI or state if no sensitive data is processed. List the relevant data fields. | [Select Status] | ||
| Ensure the Data Flow Description bring transmitted transmitted from VA Organization 1 to Organization 2 is filled in correctly; including "how" it handled, and Describe if it is collected, transmitted and/or stored. | [Select Status] | ||
| The FIPS 199 Sensitivity Categorization Level of the VA Organization 1 System. | [Select Status] | ||
| Ensure Name of Organization 2's System or Information Asset is filled out. | [Select Status] | ||
| Ensure Function of Organization 2 IT system is filled out. | [Select Status] | ||
| Ensure Location of Organization 2 IT System is filled out, including street, city, and zip. | [Select Status] | ||
| Ensure Description of data being transmitted from Organization 2 to VA Organization 1 is filled in correctly; include "what" types are handled and if any PII/PHI is transmitted. List the relevant data fields or state if no sensitive data is processed. | [Select Status] | ||
| Ensure Description of dataflow bring transmitted transmitted from Organization 2 to VA Organization 1 is filled in correctly; including "how" it is handled. | [Select Status] | ||
| The FIPS 199 Sensitivity Categorization Level of the Organization 2 System. | [Select Status] | ||
| 2.2.6 Security | |||
| If VA owned sensitive data is stored, processed, or transmitted on external system, ensure the recommended verbiage in quotes is included. | [Select Status] | ||
| If text is included, ensure that text color is changed to black. | [Select Status] | ||
| Content Checklist - Interconnection Security Agreement (ISA) | |||
| 3.1.1 System Description | |||
| A description of the system and scope is included (this should correlate with section 2.1.). | [Select Status] | ||
| A description of the interconnection between the 2 systems is included. | [Select Status] | ||
| 3.1.2 System Hardware and Software Requirements | |||
| Required hardware to support the interconnection is listed. | [Select Status] | ||
| All listed hardware requirements must be clearly labeled as "need to be obtained" if not already in place. | [Select Status] | ||
| Required software to support the interconnection is listed. | [Select Status] | ||
| All listed software requirements must be clearly labeled as "need to be obtained" if not already in place. | [Select Status] | ||
| 3.2.1 System Security Documentation | |||
| Confirm the types of security control reviews are documented for VA Organization 1. | [Select Status] | ||
| Confirm the frequency of the reviews is discussed for VA Organization 1. | [Select Status] | ||
| Confirm the date of the last review is discussed for VA Organization 1. | [Select Status] | ||
| Confirm the types of security control reviews are specified for Organization 2. | [Select Status] | ||
| Confirm the frequency of the reviews is specified for Organization 2. | [Select Status] | ||
| Confirm the date of the last review is specified for Organization 2. | [Select Status] | ||
| 3.2.2 General Information/Data Description | |||
| Select "one-way" or "two-way" as indicated in the template. | [Select Status] | ||
| 3.2.3 Services Offered | |||
| Ensure a listing of the information services offered over the interconnection by each organization, and that each service is briefly described. | [Select Status] | ||
| 3.2.5 Sensitivity Categorization | |||
| Verify that a data sensitivity category is documented for the sensitivity of data to be exchanged. I.e. Low, Med, or High. (This should correlate with section 2.1.) | [Select Status] | ||
| 3.2.6 User Community | |||
| Ensure Community of users who will access, exchange, and/or receive data across the interconnection is described. | [Select Status] | ||
| 3.2.7 Information Exchange Security | |||
| Ensure Organization 2's FIPS 140-2 certificate # is documented. | [Select Status] | ||
| Confirm that the FIPS 140-2 certificate is active on the NIST website. | [Select Status] | ||
| 3.2.9 Formal Security Policy | |||
| Ensure Organization 2's policy name(s) and identifier(s) are specified. | [Select Status] | ||
| 3.2.11 Security Parameters | |||
| VA Organization 1's patch management policy is detailed. | [Select Status] | ||
| VA Organization 1's malware prevention/virus scanning policy is detailed. | [Select Status] | ||
| VA Organization 1's audit policy is detailed. | [Select Status] | ||
| VA Organization 1's incident response/security breach notification policy is detailed. | [Select Status] | ||
| VA Organization 1's user certification, identification, and authentication policy is detailed. | [Select Status] | ||
| VA Organization 1's password policy is detailed. | [Select Status] | ||
| VA Organization 1's account management policy is detailed. | [Select Status] | ||
| VA Organization 1's physical and environmental security policy is detailed. | [Select Status] | ||
| VA Organization 1's firewall, IDS, and encryption policy is detailed. | [Select Status] | ||
| VA Organization 1's contingency plans are detailed. | [Select Status] | ||
| Organization 2's patch management policy is detailed. | [Select Status] | ||
| Organization 2's malware prevention/virus scanning policy is detailed. | [Select Status] | ||
| Organization 2's audit policy is detailed. | [Select Status] | ||
| Organization 2's incident response/security breach notification policy is detailed. | [Select Status] | ||
| Organization 2's user certification, identification, and authentication policy is detailed. | [Select Status] | ||
| Organization 2's password policy is detailed. | [Select Status] | ||
| Organization 2's account management policy is detailed. | [Select Status] | ||
| Organization 2's physical and environmental security policy is detailed. | [Select Status] | ||
| Organization 2's firewall, IDS, and encryption policy is detailed. | [Select Status] | ||
| Organization 2's contingency plans are detailed. | [Select Status] | ||
| 3.3 Topological Drawing | |||
| Topological drawing is included. | [Select Status] | ||
| Topological drawing illustrates the systems described in section 2.1, including all communication paths, circuits, and other components used for the interconnection. | [Select Status] | ||
| All data flows are clearly showed with arrows as either a one or two way path. | [Select Status] | ||
| Topological drawing depicts the logical location of all major components (e.g., firewalls, servers, and computer workstations or system components). | [Select Status] | ||
| If required, mark the top and bottom of each page with an appropriate handling requirement. | [Select Status] | ||
| Ensure no IP Addresses are included in the drawing. | [Select Status] | ||
| Diagram clearly shows any VPN Tunnels. | [Select Status] | ||
| Topological drawing indicates which components are part of VA Organization 1, and which are part of Organization 2 on each end. | [Select Status] | ||
| Ensure any abbreviations used are labeled in drawing itself or a legend in this section. | [Select Status] | ||
| 4. Duration | |||
| Confirm Duration Text matches VA MOU ISA Addendum Section 4 Duration 2016.07.26. (Template 12/11/2017 langauge) | [Select Status] | ||
| 5. Signatory Authority | |||
| Confirm authority of signers matches the organization titles (Local by facility staff, Territory level agreements signed by a Territory level ISO, National agreements signed at enterprise level, etc.). | [Select Status] | ||
| Insert VA Organization 1 System Owner name and title (Note: One Person can be listed and sign for multiple roles). | [Select Status] | ||
| Insert VA Organization 1 ISSO name and title. | [Select Status] | ||
| Insert VA Organization 1 Privacy Officer name and title. | [Select Status] | ||
| Insert VA Organization 1 Privacy Officer Boiler Plate paragraph (if missing). | [Select Status] | ||
| Insert Organization 2 System Owner and title. | [Select Status] | ||
| Insert Organization 2 ISO name and title. | [Select Status] | ||
| Insert Organization 2 Privacy Officer name and title. | [Select Status] | ||
| Ensure VA Organization 1 System Owner has signed and dated the agreement. | [Select Status] | ||
| Ensure VA Organization 1 ISSO has signed and dated the agreement. | [Select Status] | ||
| Ensure VA Organization 1 Privacy Officer has signed and dated the agreement. | [Select Status] | ||
| Ensure Organization 2 System Owner has signed and dated the agreement. | [Select Status] | ||
| Ensure Organization 2 ISO has signed and dated the agreement. | [Select Status] | ||
| Ensure Organization 2 Privacy Officer has signed and dated the agreement. | [Select Status] | ||
| For National Agreements only, ensure current Signed DOA added as its own page (replace template placeholder after signatories page and prior to Appendix A). | Complete | No Longer Required. | |
| Before Finalizing | |||
| All comments / tracked changes have been accepted and/or closed. | [Select Status] | ||
| Remove all "Draft" watermarks. | [Select Status] | ||
| Ensure all instructional text (in colors other than black) is deleted and replaced with the appropriate information in accordance with the template. | [Select Status] | ||
| The document has been spell / grammar checked. | [Select Status] | ||
| Confirm that page breaks / formatting is clean throughout the agreement. | [Select Status] | ||
| The Table of Contents is updated as appropriate. | [Select Status] | ||
| Complete Appendices Tab |
ISA/MOU Checklist
ISA/MOU Checklist
ISA/MOU Checklist
ISA/MOU Checklist
ISA/MOU Checklist
Page &P of &N
Page &P of &N
Page &P of &N
Page &P of &N
Page &P of &N
Appendices
| Content Checklist - Appendices | |||
| Section / Criteria | Status | Comments | Recommendations |
| Appendix A: Points of Contact | |||
| Ensure VA FSS BRD contact information is included in both sections of Appendix A (for National Agreements Only). | [Select Status] | ||
| Ensure BAA POC information is included (when applicable). | [Select Status] | ||
| System POC: Ensure list includes signing System Owner. | [Select Status] | ||
| System POC: Ensure list includes signing ISSO. | [Select Status] | ||
| System POC: Ensure list includes signing Privacy Officer. | [Select Status] | ||
| System POC: Ensure list includes a few key technical POCs who understand the system. | [Select Status] | ||
| System POC: Ensure list includes Document Author listed in Change Log | [Select Status] | ||
| System POC: Identify name of responsible parties for each system. | [Select Status] | ||
| System POC: Identify company for each responsible party for each system. | [Select Status] | ||
| System POC: Identify title for each responsible party for each system (Privacy Officer, Technical staff, System Owner, ISO, etc.). | [Select Status] | ||
| System POC: Identify office phone for each responsible party for each system. | [Select Status] | ||
| System POC: Identify email for each responsible party for each system. | [Select Status] | ||
| Security Incident POC: Ensure VA-CSOC contact information is included (along with * notation). | [Select Status] | ||
| Security Incident POC: Ensure list includes Primary ISSO. | [Select Status] | ||
| Security Incident POC: Ensure list includes Backup ISSO. | [Select Status] | ||
| Security Incident POC: Ensure list includes 24/7 support desk. | [Select Status] | ||
| Security Incident POC: Ensure list includes Key Technical Staff. | [Select Status] | ||
| Security Incident POC: Identify name of responsible parties to contact during a security incident for each system. | [Select Status] | ||
| Security Incident POC: Identify company for each responsible party for each security incident. | [Select Status] | ||
| Security Incident POC: Identify title for each responsible party for each security incident (Primary ISO, Backup ISO, 24/7 Support Desk, Technical staff, System Owner, etc.). | [Select Status] | ||
| Security Incident POC: Identify office phone for each responsible party for each security incident. | [Select Status] | ||
| Security Incident POC: Identify email for each responsible party for each security incident. | [Select Status] | ||
| Appendix B: Questionnaire – Transmission of VA Sensitive Information Utilizing a System Interconnection | |||
| If this is N/A, list as such at top of questionnaire and do not fill in Items 1-7 and/or POC blocks. Delete instruction text from document, ignore next few checklist items and move to Appendix C below. | [Select Status] | ||
| Fill in Item 1. Describe the sensitive information to be transferred (e.g., clinical images with protected health information; financial information with names and social security numbers; identifiable data collected for research). The data listed should be the same as in section 2.1. | [Select Status] | ||
| Fill in Item 2. Describe the purpose of the data transfer (e.g., access to clinical images by off-site radiologists; financial information used to generate billing information; subject data to be analyzed under a VA or a non-VA research protocol). Should be the same as what is described in the Executive Summary and/or 2.1 Background. | [Select Status] | ||
| Fill in Item 3. Identify the non-VA Storage location of the transmitted information (e.g., Medical Center *name* Department of Radiology servers, *Name* Financial Institution servers). | [Select Status] | ||
| Fill in Item 4. Identify the supporting document(s) describing the transfer of the data to the recipient: (e.g., Contract#, Protocol#, MOU, HIPAA authorization, Data Use Agreement, etc.). | [Select Status] | ||
| Fill in Item 5. Describe the provisions for the return to VA or destruction of the sensitive information at the completion of the contract, project, clinical application/evaluation, etc., if applicable. | [Select Status] | ||
| Fill in VA point of contact name, signature, and date signed. | [Select Status] | ||
| Fill in VA Information System Security Officer name, signature, and date signed. | [Select Status] | ||
| Appendix C: VA Annual Review Documentation | |||
| Confirm latest copy of sheet is present, and complete following 4 steps only if performing an annual review. Otherwise move to Appendix E below. | [Select Status] | ||
| Identify date of VA annual review filled in if this is now going though an annual review. | [Select Status] | ||
| The change status of the review field has been filled in if this is now going though an annual review. | [Select Status] | ||
| Additional comments field has been filled in if this is now going though an annual review. | [Select Status] | ||
| ISO signature field for annual review present and filled in if this is now going though an annual review. | [Select Status] | ||
| Confirm MOU/ISA has been reviewed no later than one year after last date on signature (unless new). | [Select Status] | ||
| Confirm MOU/ISA has been reviewed annually (every year) to determine if interconnection is still required and that there have not been significant changes. | [Select Status] | ||
| Appendix E: Interconnection Ports and Protocols | |||
| Connection Type is documented. | [Select Status] | ||
| Connection ID# is documented (may be left blank if only a new agreement and still pending ESCCB). | [Select Status] | ||
| Gateway has been documented (may be left blank if only a new agreement and still pending ESCCB). | [Select Status] | ||
| Ensure Port and Protocol Table covers all data transmissions shown in section 2.1. | [Select Status] | ||
| Ensure Port and Protocol Table matches 3.2.2 in terms of it being a one-way or two-way path. | [Select Status] | ||
| Ensure Port and Protocol Table shows everything from Topological Drawing (Section 3.3). | [Select Status] | ||
| Port and Protocol table has been completed and completely filled in to include columns for direction, protocol, port, and purpose. | [Select Status] | ||
| Complete MOU ISA Checklist Tab |
ISA/MOU Checklist
ISA/MOU Checklist
ISA/MOU Checklist
ISA/MOU Checklist
ISA/MOU Checklist
Page &P of &N
Page &P of &N
Page &P of &N
Page &P of &N
Page &P of &N
File details come from the government source that posted it. Updated .