(Insert Company Name) VA MOU ISA Checklist 2017.12.18.xlsx

XLSX spreadsheet 1 MB Posted

Attached to
7A21--VISN 22 POC Middleware Federal contract opportunity
Solicitation number
36C26221Q0044
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 22

View the file

Other files for this federal contract opportunity

Other files attached to 7A21--VISN 22 POC Middleware, newest first.
File Type Posted
lab_52_poc_hl7_spec.docx DOCX document
Appendix C Template 2018.08.08.pdf PDF
VA Handbook 6500.6 Appendix A.pdf PDF
36C26221Q0044 0002 - RFQ Amendment.docx DOCX document
MOU ISA Intake Form Instructions.pdf PDF
MOU ISA Annual Review SharePoint User Guide.pdf PDF
36C26221Q0044 0002_1.docx DOCX document
2020 MOU ISA New Template Brown Bag.pptx PPTX presentation
OIS MOU ISA SOP Final_20191007.pdf PDF
VA MOU ISA Approved Final Template-09092020.docx DOCX document
MOU ISA Review Form-.pdf PDF
(Insert Company Name) VA LAN Extension MOU 2017.12.11 - TEMPLATE.docx DOCX document
(Insert Company Name) VA MOU Appendix A POC List 2017.12.18 - TEMPLATE.docx DOCX document
VA Directive 6500.pdf PDF
RFQ - 36C26221Q0044 v2.docx DOCX document
36C26221Q0044 0001 Amendment.docx DOCX document
36C26221Q0044 0001_1.docx DOCX document
Attachment B - Middleware SOW v2.docx DOCX document
Attachment C - VA Directive 6550.pdf PDF
Attachment A - Schedule.xlsx XLSX spreadsheet
36C26221Q0044.docx DOCX document
Attachment E - Past Performance References.docx DOCX document
Attachment D - VA Handbook 6500.6 Appendix C.pdf PDF
Attachment B - Middleware SOW.docx DOCX document
Show all 24

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

MOU ISA Checklist

Section / CriteriaStatusCommentsRecommendations
General
Instructions in template you are using should state document published on 12/11/17.[Select Status]
The document draft has been renamed to correct naming convention (Company Name) (Facility Code or VA National) MOU ISA - (Working Document)[Select Status]
Template basic instructions text box is deleted from title page.[Select Status]
The title page is correctly completed with VA Organization 1 (must be a VA component).[Select Status]
The title page is correctly completed with Organization 2 (a non-VA entity, confirm it is a contract primary).[Select Status]
Confirm that VA Organization 1 and Organization 2 are not under same approving authority (or else no agreement needed).[Select Status]
The title page has the date documented.[Select Status]
The title page has the version number documented.[Select Status]
Template color key text box is deleted from title page.[Select Status]
The Document Control Change Sheet contains a VA Author and Organization 2 Author.[Select Status]
The Document Control Change Sheet is updated as appropriate according to either Option A or B.[Select Status]
The Document Control Change Sheet entry in the formatting of the example entry.[Select Status]
Acronyms are defined the first time they are mentioned throughout the document.[Select Status]
The same name for VA Organization 1 is used throughout the MOU/ISA.[Select Status]
The same name for Organization 2 is used throughout the MOU/ISA.[Select Status]
Ensure VA Organization 1 System or Informational Asset are correctly filled-in as appropriate throughout the MOU/ISA.[Select Status]
Ensure Organization 2 System or Informational Asset fields are correctly filled-in as appropriate throughout the MOU/ISA.[Select Status]
Confirm no changes to the boilerplate language have been made throughout the document.[Select Status]
For National Agreements, Asset Name / Facility name must be sufficiently vague. Too specific and it is no longer a national agreement.[Select Status]
For cloud connections, VA has the requirement to only use Fed Ramp (FEDRAMP) certified cloud solutions.[Select Status]
Executive Summary
Confirm a high level description of the interconnection is covered in the Executive Summary to include devices and what kind of information is being transferred is included. Should not be more than a few paragraphs.[Select Status]
The basic Purpose and scope of the interconnection is covered in the Executive Summary.[Select Status]
1.1 Introduction
For new agreements, state it is a brand new MOU / ISA and therefore does not supersede any previous MOU/ISAs (Option A Selected).[Select Status]
For Renewals / Updates to Existing Agreements, Insert the date of the original MOU/ISA agreement (Option B Selected). Confirm Date matches Change Log Date.[Select Status]
1.2 Authority
Verify ISO listed all other relevant legislative, regulatory, or policy authorities not included in the template list.[Select Status]
Verify PO listed all authorities to share data not included in the template list.[Select Status]
Content Checklist - Memorandum of Understanding (MOU)
2.1 Background
Modify paragraph to best describe interconnection, replace all [required fields].[Select Status]
Benefits to be derived from the interconnection are included.[Select Status]
Ensure Name of VA Organization 1's System or Information Asset is filled out.[Select Status]
Ensure Function of VA Organization 1 IT system is filled out.[Select Status]
Ensure Location of VA Organization 1 IT System is filled out.[Select Status]
Ensure Description of data being transmitted from VA Organization 1 to Organization 2 is filled in correctly; Include if any PII/PHI or state if no sensitive data is processed. List the relevant data fields.[Select Status]
Ensure the Data Flow Description bring transmitted transmitted from VA Organization 1 to Organization 2 is filled in correctly; including "how" it handled, and Describe if it is collected, transmitted and/or stored.[Select Status]
The FIPS 199 Sensitivity Categorization Level of the VA Organization 1 System.[Select Status]
Ensure Name of Organization 2's System or Information Asset is filled out.[Select Status]
Ensure Function of Organization 2 IT system is filled out.[Select Status]
Ensure Location of Organization 2 IT System is filled out, including street, city, and zip.[Select Status]
Ensure Description of data being transmitted from Organization 2 to VA Organization 1 is filled in correctly; include "what" types are handled and if any PII/PHI is transmitted. List the relevant data fields or state if no sensitive data is processed.[Select Status]
Ensure Description of dataflow bring transmitted transmitted from Organization 2 to VA Organization 1 is filled in correctly; including "how" it is handled.[Select Status]
The FIPS 199 Sensitivity Categorization Level of the Organization 2 System.[Select Status]
2.2.6 Security
If VA owned sensitive data is stored, processed, or transmitted on external system, ensure the recommended verbiage in quotes is included.[Select Status]
If text is included, ensure that text color is changed to black.[Select Status]
Content Checklist - Interconnection Security Agreement (ISA)
3.1.1 System Description
A description of the system and scope is included (this should correlate with section 2.1.).[Select Status]
A description of the interconnection between the 2 systems is included.[Select Status]
3.1.2 System Hardware and Software Requirements
Required hardware to support the interconnection is listed.[Select Status]
All listed hardware requirements must be clearly labeled as "need to be obtained" if not already in place.[Select Status]
Required software to support the interconnection is listed.[Select Status]
All listed software requirements must be clearly labeled as "need to be obtained" if not already in place.[Select Status]
3.2.1 System Security Documentation
Confirm the types of security control reviews are documented for VA Organization 1.[Select Status]
Confirm the frequency of the reviews is discussed for VA Organization 1.[Select Status]
Confirm the date of the last review is discussed for VA Organization 1.[Select Status]
Confirm the types of security control reviews are specified for Organization 2.[Select Status]
Confirm the frequency of the reviews is specified for Organization 2.[Select Status]
Confirm the date of the last review is specified for Organization 2.[Select Status]
3.2.2 General Information/Data Description
Select "one-way" or "two-way" as indicated in the template.[Select Status]
3.2.3 Services Offered
Ensure a listing of the information services offered over the interconnection by each organization, and that each service is briefly described.[Select Status]
3.2.5 Sensitivity Categorization
Verify that a data sensitivity category is documented for the sensitivity of data to be exchanged. I.e. Low, Med, or High. (This should correlate with section 2.1.)[Select Status]
3.2.6 User Community
Ensure Community of users who will access, exchange, and/or receive data across the interconnection is described.[Select Status]
3.2.7 Information Exchange Security
Ensure Organization 2's FIPS 140-2 certificate # is documented.[Select Status]
Confirm that the FIPS 140-2 certificate is active on the NIST website.[Select Status]
3.2.9 Formal Security Policy
Ensure Organization 2's policy name(s) and identifier(s) are specified.[Select Status]
3.2.11 Security Parameters
VA Organization 1's patch management policy is detailed.[Select Status]
VA Organization 1's malware prevention/virus scanning policy is detailed.[Select Status]
VA Organization 1's audit policy is detailed.[Select Status]
VA Organization 1's incident response/security breach notification policy is detailed.[Select Status]
VA Organization 1's user certification, identification, and authentication policy is detailed.[Select Status]
VA Organization 1's password policy is detailed.[Select Status]
VA Organization 1's account management policy is detailed.[Select Status]
VA Organization 1's physical and environmental security policy is detailed.[Select Status]
VA Organization 1's firewall, IDS, and encryption policy is detailed.[Select Status]
VA Organization 1's contingency plans are detailed.[Select Status]
Organization 2's patch management policy is detailed.[Select Status]
Organization 2's malware prevention/virus scanning policy is detailed.[Select Status]
Organization 2's audit policy is detailed.[Select Status]
Organization 2's incident response/security breach notification policy is detailed.[Select Status]
Organization 2's user certification, identification, and authentication policy is detailed.[Select Status]
Organization 2's password policy is detailed.[Select Status]
Organization 2's account management policy is detailed.[Select Status]
Organization 2's physical and environmental security policy is detailed.[Select Status]
Organization 2's firewall, IDS, and encryption policy is detailed.[Select Status]
Organization 2's contingency plans are detailed.[Select Status]
3.3 Topological Drawing
Topological drawing is included.[Select Status]
Topological drawing illustrates the systems described in section 2.1, including all communication paths, circuits, and other components used for the interconnection.[Select Status]
All data flows are clearly showed with arrows as either a one or two way path.[Select Status]
Topological drawing depicts the logical location of all major components (e.g., firewalls, servers, and computer workstations or system components).[Select Status]
If required, mark the top and bottom of each page with an appropriate handling requirement.[Select Status]
Ensure no IP Addresses are included in the drawing.[Select Status]
Diagram clearly shows any VPN Tunnels.[Select Status]
Topological drawing indicates which components are part of VA Organization 1, and which are part of Organization 2 on each end.[Select Status]
Ensure any abbreviations used are labeled in drawing itself or a legend in this section.[Select Status]
4. Duration
Confirm Duration Text matches VA MOU ISA Addendum Section 4 Duration 2016.07.26. (Template 12/11/2017 langauge)[Select Status]
5. Signatory Authority
Confirm authority of signers matches the organization titles (Local by facility staff, Territory level agreements signed by a Territory level ISO, National agreements signed at enterprise level, etc.).[Select Status]
Insert VA Organization 1 System Owner name and title (Note: One Person can be listed and sign for multiple roles).[Select Status]
Insert VA Organization 1 ISSO name and title.[Select Status]
Insert VA Organization 1 Privacy Officer name and title.[Select Status]
Insert VA Organization 1 Privacy Officer Boiler Plate paragraph (if missing).[Select Status]
Insert Organization 2 System Owner and title.[Select Status]
Insert Organization 2 ISO name and title.[Select Status]
Insert Organization 2 Privacy Officer name and title.[Select Status]
Ensure VA Organization 1 System Owner has signed and dated the agreement.[Select Status]
Ensure VA Organization 1 ISSO has signed and dated the agreement.[Select Status]
Ensure VA Organization 1 Privacy Officer has signed and dated the agreement.[Select Status]
Ensure Organization 2 System Owner has signed and dated the agreement.[Select Status]
Ensure Organization 2 ISO has signed and dated the agreement.[Select Status]
Ensure Organization 2 Privacy Officer has signed and dated the agreement.[Select Status]
For National Agreements only, ensure current Signed DOA added as its own page (replace template placeholder after signatories page and prior to Appendix A).CompleteNo Longer Required.
Before Finalizing
All comments / tracked changes have been accepted and/or closed.[Select Status]
Remove all "Draft" watermarks.[Select Status]
Ensure all instructional text (in colors other than black) is deleted and replaced with the appropriate information in accordance with the template.[Select Status]
The document has been spell / grammar checked.[Select Status]
Confirm that page breaks / formatting is clean throughout the agreement.[Select Status]
The Table of Contents is updated as appropriate.[Select Status]
Complete Appendices Tab

ISA/MOU Checklist

ISA/MOU Checklist

ISA/MOU Checklist

ISA/MOU Checklist

ISA/MOU Checklist

Page &P of &N

Page &P of &N

Page &P of &N

Page &P of &N

Page &P of &N

Appendices

Content Checklist - Appendices
Section / CriteriaStatusCommentsRecommendations
Appendix A: Points of Contact
Ensure VA FSS BRD contact information is included in both sections of Appendix A (for National Agreements Only).[Select Status]
Ensure BAA POC information is included (when applicable).[Select Status]
System POC: Ensure list includes signing System Owner.[Select Status]
System POC: Ensure list includes signing ISSO.[Select Status]
System POC: Ensure list includes signing Privacy Officer.[Select Status]
System POC: Ensure list includes a few key technical POCs who understand the system.[Select Status]
System POC: Ensure list includes Document Author listed in Change Log[Select Status]
System POC: Identify name of responsible parties for each system.[Select Status]
System POC: Identify company for each responsible party for each system.[Select Status]
System POC: Identify title for each responsible party for each system (Privacy Officer, Technical staff, System Owner, ISO, etc.).[Select Status]
System POC: Identify office phone for each responsible party for each system.[Select Status]
System POC: Identify email for each responsible party for each system.[Select Status]
Security Incident POC: Ensure VA-CSOC contact information is included (along with * notation).[Select Status]
Security Incident POC: Ensure list includes Primary ISSO.[Select Status]
Security Incident POC: Ensure list includes Backup ISSO.[Select Status]
Security Incident POC: Ensure list includes 24/7 support desk.[Select Status]
Security Incident POC: Ensure list includes Key Technical Staff.[Select Status]
Security Incident POC: Identify name of responsible parties to contact during a security incident for each system.[Select Status]
Security Incident POC: Identify company for each responsible party for each security incident.[Select Status]
Security Incident POC: Identify title for each responsible party for each security incident (Primary ISO, Backup ISO, 24/7 Support Desk, Technical staff, System Owner, etc.).[Select Status]
Security Incident POC: Identify office phone for each responsible party for each security incident.[Select Status]
Security Incident POC: Identify email for each responsible party for each security incident.[Select Status]
Appendix B: Questionnaire – Transmission of VA Sensitive Information Utilizing a System Interconnection
If this is N/A, list as such at top of questionnaire and do not fill in Items 1-7 and/or POC blocks. Delete instruction text from document, ignore next few checklist items and move to Appendix C below.[Select Status]
Fill in Item 1. Describe the sensitive information to be transferred (e.g., clinical images with protected health information; financial information with names and social security numbers; identifiable data collected for research). The data listed should be the same as in section 2.1.[Select Status]
Fill in Item 2. Describe the purpose of the data transfer (e.g., access to clinical images by off-site radiologists; financial information used to generate billing information; subject data to be analyzed under a VA or a non-VA research protocol). Should be the same as what is described in the Executive Summary and/or 2.1 Background.[Select Status]
Fill in Item 3. Identify the non-VA Storage location of the transmitted information (e.g., Medical Center *name* Department of Radiology servers, *Name* Financial Institution servers).[Select Status]
Fill in Item 4. Identify the supporting document(s) describing the transfer of the data to the recipient: (e.g., Contract#, Protocol#, MOU, HIPAA authorization, Data Use Agreement, etc.).[Select Status]
Fill in Item 5. Describe the provisions for the return to VA or destruction of the sensitive information at the completion of the contract, project, clinical application/evaluation, etc., if applicable.[Select Status]
Fill in VA point of contact name, signature, and date signed.[Select Status]
Fill in VA Information System Security Officer name, signature, and date signed.[Select Status]
Appendix C: VA Annual Review Documentation
Confirm latest copy of sheet is present, and complete following 4 steps only if performing an annual review. Otherwise move to Appendix E below.[Select Status]
Identify date of VA annual review filled in if this is now going though an annual review.[Select Status]
The change status of the review field has been filled in if this is now going though an annual review.[Select Status]
Additional comments field has been filled in if this is now going though an annual review.[Select Status]
ISO signature field for annual review present and filled in if this is now going though an annual review.[Select Status]
Confirm MOU/ISA has been reviewed no later than one year after last date on signature (unless new).[Select Status]
Confirm MOU/ISA has been reviewed annually (every year) to determine if interconnection is still required and that there have not been significant changes.[Select Status]
Appendix E: Interconnection Ports and Protocols
Connection Type is documented.[Select Status]
Connection ID# is documented (may be left blank if only a new agreement and still pending ESCCB).[Select Status]
Gateway has been documented (may be left blank if only a new agreement and still pending ESCCB).[Select Status]
Ensure Port and Protocol Table covers all data transmissions shown in section 2.1.[Select Status]
Ensure Port and Protocol Table matches 3.2.2 in terms of it being a one-way or two-way path.[Select Status]
Ensure Port and Protocol Table shows everything from Topological Drawing (Section 3.3).[Select Status]
Port and Protocol table has been completed and completely filled in to include columns for direction, protocol, port, and purpose.[Select Status]
Complete MOU ISA Checklist Tab

ISA/MOU Checklist

ISA/MOU Checklist

ISA/MOU Checklist

ISA/MOU Checklist

ISA/MOU Checklist

Page &P of &N

Page &P of &N

Page &P of &N

Page &P of &N

Page &P of &N

File details come from the government source that posted it. Updated .