OIS MOU ISA SOP Final_20191007.pdf

PDF 282 KB Posted

Attached to
7A21--VISN 22 POC Middleware Federal contract opportunity
Solicitation number
36C26221Q0044
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 22

View the file

Other files for this federal contract opportunity

Other files attached to 7A21--VISN 22 POC Middleware, newest first.
File Type Posted
(Insert Company Name) VA MOU Appendix A POC List 2017.12.18 - TEMPLATE.docx DOCX document
VA Directive 6500.pdf PDF
lab_52_poc_hl7_spec.docx DOCX document
Appendix C Template 2018.08.08.pdf PDF
VA Handbook 6500.6 Appendix A.pdf PDF
36C26221Q0044 0002 - RFQ Amendment.docx DOCX document
MOU ISA Intake Form Instructions.pdf PDF
MOU ISA Annual Review SharePoint User Guide.pdf PDF
(Insert Company Name) VA MOU ISA Checklist 2017.12.18.xlsx XLSX spreadsheet
36C26221Q0044 0002_1.docx DOCX document
2020 MOU ISA New Template Brown Bag.pptx PPTX presentation
VA MOU ISA Approved Final Template-09092020.docx DOCX document
MOU ISA Review Form-.pdf PDF
(Insert Company Name) VA LAN Extension MOU 2017.12.11 - TEMPLATE.docx DOCX document
RFQ - 36C26221Q0044 v2.docx DOCX document
36C26221Q0044 0001 Amendment.docx DOCX document
36C26221Q0044 0001_1.docx DOCX document
Attachment B - Middleware SOW v2.docx DOCX document
Attachment E - Past Performance References.docx DOCX document
Attachment D - VA Handbook 6500.6 Appendix C.pdf PDF
Attachment B - Middleware SOW.docx DOCX document
Attachment C - VA Directive 6550.pdf PDF
Attachment A - Schedule.xlsx XLSX spreadsheet
36C26221Q0044.docx DOCX document
Show all 24

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

OFFICE OF

INFORMATION

SECURITY

ISRM/BRD MOU/ISA

Standard Operating Procedure

Standard Operating Procedures Version 1.0 September 27, 2019

Document Change Control

Version Release

Date Summary of Changes

Reviewer Name/Title

Signature

1.0 9/15/2019 Initial Publication

Leigh Zirbel/Joseph Decoteau/Deedra Jones

//S//

This section is used by the author of the ISRM/BRD MOU ISA Standard Operating Procedure to track and record changes to this document.

Table of Contents

PURPOSE

BACKGROUND

SCOPE

ROLES AND RESPONSIBILITIES

Project Manager (PM)

Contracting Officer (CO)

Contracting Officer Representative (COR)

Information System Owner (ISO)

Privacy Officer (PO)

Business Requirements Division (BRD)

BRD MOU ISA Team Analysts

Research Support Division (RSD)

Specialized Device Security Division (SDSD)

ESO Information System Security Officers (ISSOs)

PROCEDURES

System Interconnection Requirements

MOU/ISA Types

MOU/ISA Intake Process

Signatory Process/Authority

Annual Review and Continuous Monitoring

Decommissioned External Connections

Veteran Guest Internet Access (VGIA)

RESCISSIONS

DEFINITIONS

ACRONYMS

REFERENCES

PURPOSE

The purpose of this Standard Operating Procedure (SOP) is to establish cybersecurity procedures for processing and reviewing MOU/ISAs.

BACKGROUND

Federal security regulations require documentation of security controls for interconnecting systems to ensure the confidentiality, integrity, and availability of networks and data. A Memorandum of Understanding (MOU) and Interconnection Security Agreement (ISA) are required for the authorization of connections to information systems that do not share the same Authorizing Official (AO). Department of Veterans Affairs (VA) Handbook 6500, Risk Management Framework for VA Information Systems-Tier 3: VA Information Security Program, states the MOU/ISA is required to document security controls for external information systems that process, store, or transmit VA information.

SCOPE

This SOP outlines procedures for all stakeholders to review and complete MOU/ISAs.

This applies to all connections between a VA information system and another information system outside VA’s approved accreditation boundaries and/or systems that do not share the same authorizing officials.

ROLES AND RESPONSIBILITIES

Project Manager (PM)

• Manages completion, timelines, and quality standards of the MOU/ISA documentation.

• Collaborates with an integrated project team to make sure that all stakeholders have contributed to a complete MOU/ISA.

Contracting Officer (CO)

• Ensures that services being provided are within the contract specifications.

• Furnishes contract technical direction.

Contracting Officer Representative (COR)

• Serves as liaison between Department of Veterans Affairs and the contractor.

• Monitors contractor performance throughout the lifecycle of the contract.

Information System Owner (ISO)

• Initiates and completes the MOU/ISA Intake form.

• Works with Information System Security Officers (ISSOs) to evaluate security requirements.

• Works with third-party companies to set up network interconnections.

Privacy Officer (PO)

• Manages the risks and business impacts of privacy laws and policies.

• Assists the cybersecurity team with ensuring privacy requirements are included for all interconnections.

Business Requirements Division (BRD)

• Serves as Subject Matter Experts (SMEs) for MOU/ISAs.

• Manages and monitors the entire MOU/ISA process.

• Provides MOU/ISA training and coordinates annual reviews.

• Reviews National MOU/ISAs annually to ensure security controls are still in place.

• Reviews and updates MOU/ISA templates annually or as needed.

• Signs the review sheets for all National Business MOU/ISAs.

BRD MOU ISA Team Analysts

• Performs quality and security reviews of MOU/ISA documentation.

• Works with Points of Contact (POCs) to address non-compliance issues discovered during quality reviews.

Research Support Division (RSD)

• Serves as SMEs for quality and security reviews of all Research MOU/ISAs.

• Signs the review sheets for all National Research MOU/ISAs.

• Reviews Research National MOU/ISAs annually to ensure security controls are still in place.

Specialized Device Security Division (SDSD)

• Serves as SMEs for quality and security reviews of all Specialized Device MOU/ISAs.

• Signs the review sheets for all National Special Purpose System and Medical Device MOU/ISAs.

• Reviews Special Purpose System and Medical Device National MOU/ISAs annually to ensure security controls are still in place.

ESO Information System Security Officers (ISSOs)

• Verifies the security content in the MOU/ISA is accurate and reports deficiencies to the document stakeholders.

• Uploads draft and final MOU/ISA documents to the MOU/ISA Document Site portal.

• Confirms completed MOU/ISAs are uploaded to applicable security controls in the Governance Risk Compliance (GRC) tool.

• Provides assistance and guidance to stakeholders with the system interconnection approval process.

• Provides cybersecurity subject matter expertise for MOU/ISA content.

• Reviews Local MOU/ISAs annually to ensure security controls are still in place.

PROCEDURES

System Interconnection Requirements

A system interconnection is defined as the direct connection of two or more IT systems for the purpose of sharing data and other information resources.

All dedicated connections between information systems that do not have the same authorizing official require an MOU/ISA. VA MOU/ISAs are one combined document for all agreements.

A Memorandum of Understanding defines: the responsibilities of the participating organizations; the terms and conditions for sharing data and information resources in a secure manner; the purpose of the interconnection; and the terms of the agreement. The MOU also identifies the stakeholders of the agreement.

An Interconnection Security Agreement specifies the technical and security requirements for establishing, operating, and maintaining the interconnection. The ISA documents the requirements for connecting the IT systems, describes the security controls that will be used to protect the systems and data, provides a system diagram of the interconnection, and provides signature lines for all stakeholders.

The Department of Veterans Affairs documents all external connections using the VA approved MOU/ISA templates. The VA MOU/ISA templates outline all minimum security and system requirements as required by NIST 800-47 and VA Handbook 6500, as well as the type of connection as defined in VA Handbook 6513, Secure External Connections.

MOU/ISA Types

VA LAN Extension MOU

A Local Area Network (LAN) Extension MOU is required for VA networks and/or equipment connected to a VA facility, but physically located and extended to an external organization’s premises. The VA network and/or equipment are not connected to the external organization’s network systems.

VA Standard MOU/ISA

A VA MOU/ISA document is required for all external connections (local and national) as outlined in VA Handbook 6513, Secure External Connections.

Connections that do not share the same VA Authorizing Official for the systems will require an MOU/ISA.

State Prescription Monitoring Program (SPMP) MOU/ISAs

An SPMP MOU/ISA is required for all SPMP vendors that receive prescription monitoring data from VA. SPMP vendor MOU/ISAs are written in a specific format for this program area and encompass the entire VA. The purpose of the SPMP MOU/ISA is to ensure prescription reporting requirements are met as mandated by Federal Law. All relevant agreements will be documented in AC-20.1, CA-3.1, SA-9.1 and SA-9.E02 in GRC.

Inter-Agency MOU/ISAs

An Inter-Agency MOU/ISA is an agreement supplied by another Federal agency for systems that require an interconnection to the Department of Veterans Affairs. VA accepts these documents for interconnections because other federal agencies are required to meet the same level of security as outlined in NIST 800-47. These documents are submitted to the MOU/ISA Intake portal and reviewed by the BRD MOU/ISA team to ensure compliance.

MOU/ISA Intake Process

• Requests for an MOU/ISA document for an external connection are entered on the MOU/ISA Document Site located here. Specific instructions for the portal are located here.

• All requests submitted on the portal are received and reviewed by BRD for required security language and interconnection details.

• After BRD initial review, if changes are needed, feedback is provided to the requestor and the vendor/other organization for review and input on the proposed changes. The timeframe for completion of this process is dependent on stakeholder engagement and responsiveness. Delays caused by unresponsive stakeholders will be escalated to senior leadership and may result in a notice of disconnect for an existing external connection.

• After final review and approval by BRD, the document is sent to the requestor for signatures. After all signatures have been obtained, the document is uploaded to the MOU/ISA Document Site located here. The document is also uploaded as an artifact to the applicable GRC controls. The signatory process is defined below.

Signatory Process/Authority https://vaww.portal2.va.gov/sites/infosecurity/FY15CRISPAudit/CRISPRemediationContract/WorkSite/SitePages/MOU-ISA_Version2.aspx https://vaww.portal2.va.gov/sites/infosecurity/fieldsecurity/ESO%20Library/MOU%20ISA%20Templates/MOU%20ISA%20Intake%20Form%20Instructions.pdf https://vaww.portal2.va.gov/sites/infosecurity/FY15CRISPAudit/CRISPRemediationContract/WorkSite/Lists/Enterprise_MOUISA_Tracker/Landing%20Page%20Filter%20by%20GRC.aspx

VA Handbook 6500.3, “Assessment, Authorization and Continuous Monitoring of VA Information Systems,” dictates that the AO is responsible for reviewing and approving National MOU/ISAs.

• Enterprise ISSOs and POs review the National MOU/ISA and sign on the review sheet.

• National MOU/ISAs are signed by the Authorizing Officials for each system.

• Local MOU/ISAs are signed by the System Owners for each system.

• Signature blocks are defined by BRD and applied to the final document before routing occurs.

• MOU/ISAs must be signed using a digital certificate or wet signature. Images of signatures, generic digital signatures, or default Adobe signatures are not accepted.

Annual Review and Continuous Monitoring

ISOs and ISSOs are required to ensure MOU/ISAs are reviewed annually from the last signature date. The following lists the requirements for completing the MOU/ISA annual review process:

• The review includes whether the connection is still required, connection details and content are accurate, and POCs are current.

• Check the External Connections Compliance Tracking (ECCT) tool to ensure accurate reporting and documentation for external connections.

• Document the review using the MOU/ISA Review document. All required changes must be listed on the review document and the document must be digitally signed by the reviewers.

• If major changes are needed, a new MOU/ISA document must be submitted to BRD within 30 days of the annual review to ensure the MOU/ISA is updated and reauthorized.

• Ensure all MOU/ISA artifacts are uploaded to the appropriate security control families in GRC.

• If an MOU/ISA document is missing or required changes cannot be rectified within 15 business days, enter a Plan of Action and Milestones (POA&M) for a 90-day extension in GRC for the following controls: CA-3, AC-20, and SA- 9.

Decommissioned External Connections

An interconnection will be decommissioned if the interconnection is no longer necessary or if there is no longer a business or contractual justification for it.

In order to decommission an interconnection, a Change Gear ticket must be submitted for ESECC review. If the interconnection is a site-to-site connection, it must be deleted from the RAP ISSO Portal.

A request is submitted through the MOU/ISA Document Site portal to archive the MOU/ISA document for all decommissioned interconnections.

Veteran Guest Internet Access (VGIA)

An MOU/ISA is not required. The following security controls for all VGIA networks must be addressed:

AC-8 Advisory Banners (Regional control)

AC-11 Session Lock (Local control)

SC-7 Content Filtering and Logfile Monitoring (Regional control, local facility monitors) https://vaww.ramp.vansoc.va.gov/ISOPortal/Pages/Dashboard.aspx

RESCISSIONS

There are no rescissions to this document as of this writing.

DEFINITIONS

BRD (Business Requirements Division) – A division of VA Office of Information Security/Information Security Risk Management that provides cybersecurity expertise at an enterprise level for programs, projects and business lines across the VA.

ECC (External Connections Compliance) – A set of standards that reduce the likelihood of compromised connections from external entities.

ISA (Interconnection Security Agreement) - An agreement established between organizations that own and operate connected IT systems to document the technical requirements of the interconnection.

MOU (Memorandum of Understanding) - A formal agreement between two or more parties to establish official partnerships.

ACRONYMS

• AO – Authorizing Official

• CO – Contracting Officer

• COR – Contracting Officer Representative

• ESECC – Enterprise Security External Change Council

• EUO – End User Operations

• GRC – Governance Risk Compliance

• ISRM – Information Security Risk Management

• ISO – Information System Owner

• ISSO – Information System Security Officer

• LAN – Local Area Network

• OIT – Office of Information Technology

• PM – Project Manager

• PO – Privacy Officer

• POA&M – Plan of Action and Milestones

• POC – Point of Contact

• RSD – Research Support Division

• SDSD – Specialized Device Security Division

• SME – Subject Matter Expert

• SPMP – State Prescription Monitoring Program

• VGIA – Veteran Guest Internet Access

REFERENCES

• NIST 800-18, Guide for Developing Security Plans for Federal Information Systems

• NIST 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems

• NIST 800-47, Security Guide for Interconnecting Information Technology Systems

• NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations

• NIST SP 800-53A Rev 4, Assessing the Security and Privacy Controls in Federal Information Systems and Organizations

• 45 C.F.R § 160.103, HIPAA Regulations; Definitions

• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems

• OIS POAM Management SOP

• OMB M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information

• VA Directive 6066, Protected Health Information (PHI) and Business Associate Agreements Management

• VA Directive 6500, Managing Information Security Risk: VA Information Security Program

• VA Handbook and Directive 6513, Secure External Connections

• VA Handbook 6500, Risk Management Framework for VA Information Systems - Tier 3: VA Information Security Program

• VHA Handbook 1605.05, Business Associate Agreements https://www1.va.gov/vapubs/viewPublication.asp?Pub_ID=637&FType=2 https://www1.va.gov/vapubs/viewPublication.asp?Pub_ID=793&FType=2

PURPOSE
BACKGROUND
SCOPE
ROLES AND RESPONSIBILITIES
Project Manager (PM)
Contracting Officer (CO)
Contracting Officer Representative (COR)
Information System Owner (ISO)
Privacy Officer (PO)
Business Requirements Division (BRD)
BRD MOU ISA Team Analysts
Research Support Division (RSD)
Specialized Device Security Division (SDSD)
ESO Information System Security Officers (ISSOs)
PROCEDURES
System Interconnection Requirements
MOU/ISA Types
VA LAN Extension MOU
VA Standard MOU/ISA
State Prescription Monitoring Program (SPMP) MOU/ISAs
Inter-Agency MOU/ISAs
MOU/ISA Intake Process
Signatory Process/Authority
Annual Review and Continuous Monitoring
Decommissioned External Connections
Veteran Guest Internet Access (VGIA)
RESCISSIONS
DEFINITIONS
ACRONYMS
REFERENCES

File details come from the government source that posted it. Updated .