MOU ISA Annual Review SharePoint User Guide.pdf
PDF 468 KB Posted
- Attached to
- 7A21--VISN 22 POC Middleware Federal contract opportunity
- Solicitation number
- 36C26221Q0044
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
INFORMATION SECURITY RISK
MANAGEMENT/(ISRM)
BUSINESS REQUIREMENTS DIVISION (BRD)
MOU/ISA Annual Review Instructions
Version 2.0
09/25/2020
Department of Veterans Affairs: OIS/ISRM/BRD 09/25/2020
2 | P a g e
Document Change Control
Version Release Date Summary of
Changes Reviewer(s) Signature
1.0 9/1/2018 Updated Dan LaBrecque //s//
2.0 9/18/2020 Update to new Review Form and cleaned up instructions
Joe DeCoteau- BRD Team Lead/Leigh Zirbel-BRD Team Lead
//s//
Table of Contents
1 Overview
2 Purpose
3 Objective
4 Procedure
1 Overview
A Memorandum of Understanding (MOU) and Interconnection Security Agreement (ISA) are required for the authorization of connections to information systems that do not share the same Authorizing Official. Department of Veteran Affairs (VA) Handbook 6500, Risk Management Framework for VA Information Systems-Tier 3: VA Information Security Program, states that the MOU/ISA is required to document security controls for external information systems that process, store, or transmit VA information. Federal security regulations and policies require the documentation of security controls for interconnecting systems to ensure the confidentiality, integrity, and availability of networks and data.
3 | P a g e
2 Purpose
Per VA Handbook 6500, MOU/ISA documents must be reviewed at least annually by the Information System Owner (ISO) and Information System Security Officer (ISSO) for systems within the area they are assigned responsibility for. The information outlined in this user guide is to assist ISOs and ISSOs with completing the annual review requirement.
3 Objective
This document provides step-by-step instructions for ISOs and ISSOs to record the annual review of MOU/ISAs prior to one year from the last signature date on the document as required by VA policy.
4 Procedure
1. Confirm all MOU ISAs for the facilities or systems you are responsible for are listed in the master record.
a. Click here for the MOU ISA Master Record.
b. To find documents, you can filter by your GRC Code, Title, Facility or use the “Find an item” search box. If you need any assistance with this step, contact , contact OITITOPSSOESOMOUISAREQUESTS@va.gov.
https://vaww.portal2.va.gov/sites/infosecurity/FY15CRISPAudit/CRISPRemediationContract/WorkSite/Lists/Enterprise_MOUISA_Tracker/Active%20Agreements.aspx mailto:OITITOPSSOESOMOUISAREQUESTS@va.gov
4 | P a g e
c. Entries with “Document Status” set to active or renewal should be included in the annual review.
d. Notify BRD of missing MOU/ISA documents via email.
e. Open the MOU ISA record by clicking on the link.
2. Locate any prior Annual Reviews:
a. Once you open the document in the Master Record as noted above, scroll down to the bottom of the page. Here you will see all the annual reviews completed for that MOU ISA, including the one that is pending for the current year.
mailto:OITITOPSSOESOMOUISAREQUESTS@va.gov
5 | P a g e
3. To complete your Annual Review(s):
a. Open the link to the current year’s annual review form (located in the automated email received) or use the steps above.
4. The MOU ISA annual review SharePoint form will open:
6 | P a g e
5. At the top of the form, you will see the MOU ISA Details section. Verify the listed VA
Sponsor/System Owner is correct. Should you need to update this section please click on the address book icon:
6. Once you verify and/or update the VA Sponsor/System Owner, scroll down and ensure the Connection Category is correct. Change as necessary.
7. Once you have reviewed the System Owner and Connection Category, select the date and document status.
7 | P a g e
8. The choices for “Document Status” and example reasonings are:
• No Longer needed – If the agreement is no longer needed, click “Document Status” and set to “Agreement No Longer Needed”. Fill in the two question boxes that appear and provide justification for why it is no longer needed. Inform BRD whether the connection has been fully decommissioned or not. No attachments are required.
• Major changes needed – Changes to the body of the document are required and the document is likely to fail an IG audit in its current state.
• Examples of major changes include:
o Interconnection is not correctly described o Sections of the document are missing o The MOU ISA template is out of date o A change to the authorization boundary o Configuration changes or changes to the data being transferred o A change from unidirectional to bidirectional o A change from a site-to-site (S2S) Virtual Private Network (VPN) tunnel to a
Secure Socket Layer (SSL) connection.
• Minor changes needed – Appendix updates such as a POC update, Port/Protocol update, and/or minor issues such as formatting/spelling/desired re-wording, etc.
• No changes needed – The interconnection has not changed, and the document is fully compliant.
• New – The document has never been fully signed and executed.
• Signed this year – The document was fully signed and executed, but the last signature date is within one (1) year of the annual review.
9. Attach the finalized document(s) for review. BRD will only certify the review if:
a. The fully signed and executed agreement is attached.
b. The MOU ISA Review Form is fully filled out, to include the Document Status and notes specifying what needs to be updated (if applicable). A blank copy of the MOU ISA Review Form can be found here.
c. MOU ISA Review Form is signed.
d. Save the MOU ISA Review Form using the following naming convention:
(Company Name) (VA Entity Name) (MOU Type) (Date) (Annual Review)
• Company Name – (Business Partner, External entity, etc.)
• VA Entity Name – (GRC Code, VISN Number, or for Nationals just “VA”)
• MOU Type – (“MOU ISA”)
• Completed review date – (YYYY.MM.DD)
• Annual Review
• Example:
https://dvagov.sharepoint.com/:b:/r/sites/OITISRMECSD/Shared%20Documents/MOU%20ISA%20Published%20Templates%20and%20Instructions/MOU%20ISA%20Review%20Form.pdf?csf=1&web=1
8 | P a g e
e. Click here to attach a file:
f. Certify that the review is complete and ready for BRD to verify the request.
g. Enter any notes you may have regarding the document:
9 | P a g e
h. Click the Submit button:
i. BRD will review the submission to confirm everything is in order.
*If a BRD analyst responds back, please provide whatever information they request to move forward and close it out.
*If you receive confirmation that the review has closed, the review sheet has been published and is available in the Master Record.
j. The last step is to follow the “Additional Action” instructions in the confirmation e-mail. If an agreement is missing or major changes cannot be completed within 15 days:
*Ensure a Plan of Action and Milestone (POAM) is entered for a 90-day extension in GRC for the following controls: CA-3.1, AC-20.1, SA-9.1 and SA- 9.E02 per the POAM Management Guide.
*Coordinate with the Information System Owner (or Area Manager if applicable) and VA business owner to complete the MOU/ISA.
More MOU ISA related resources and contact information can be found at the MOU ISA Document Site https://vaww.portal2.va.gov/sites/infosecurity/FY15CRISPAudit/CRISPRemediationContract/WorkSite/SitePages/MOU-ISA_Version2.aspx https://vaww.portal2.va.gov/sites/infosecurity/FY15CRISPAudit/CRISPRemediationContract/WorkSite/SitePages/MOU-ISA_Version2.aspx https://vaww.portal2.va.gov/sites/infosecurity/FY15CRISPAudit/CRISPRemediationContract/WorkSite/SitePages/MOU-ISA_Version2.aspx
File details come from the government source that posted it. Updated .