OIS MOU ISA SOP Final_20191007.pdf
PDF 282 KB Posted
- Attached to
- 7A21--VISN 22 POC Middleware Federal contract opportunity
- Solicitation number
- 36C26221Q0044
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OFFICE OF
INFORMATION
SECURITY
ISRM/BRD MOU/ISA
Standard Operating Procedure
Standard Operating Procedures Version 1.0 September 27, 2019
Document Change Control
Version Release
Date Summary of Changes
Reviewer Name/Title
Signature
1.0 9/15/2019 Initial Publication
Leigh Zirbel/Joseph Decoteau/Deedra Jones
//S//
This section is used by the author of the ISRM/BRD MOU ISA Standard Operating Procedure to track and record changes to this document.
Table of Contents
PURPOSE
BACKGROUND
SCOPE
ROLES AND RESPONSIBILITIES
Project Manager (PM)
Contracting Officer (CO)
Contracting Officer Representative (COR)
Information System Owner (ISO)
Privacy Officer (PO)
Business Requirements Division (BRD)
BRD MOU ISA Team Analysts
Research Support Division (RSD)
Specialized Device Security Division (SDSD)
ESO Information System Security Officers (ISSOs)
PROCEDURES
System Interconnection Requirements
MOU/ISA Types
MOU/ISA Intake Process
Signatory Process/Authority
Annual Review and Continuous Monitoring
Decommissioned External Connections
Veteran Guest Internet Access (VGIA)
RESCISSIONS
DEFINITIONS
ACRONYMS
REFERENCES
PURPOSE
The purpose of this Standard Operating Procedure (SOP) is to establish cybersecurity procedures for processing and reviewing MOU/ISAs.
BACKGROUND
Federal security regulations require documentation of security controls for interconnecting systems to ensure the confidentiality, integrity, and availability of networks and data. A Memorandum of Understanding (MOU) and Interconnection Security Agreement (ISA) are required for the authorization of connections to information systems that do not share the same Authorizing Official (AO). Department of Veterans Affairs (VA) Handbook 6500, Risk Management Framework for VA Information Systems-Tier 3: VA Information Security Program, states the MOU/ISA is required to document security controls for external information systems that process, store, or transmit VA information.
SCOPE
This SOP outlines procedures for all stakeholders to review and complete MOU/ISAs.
This applies to all connections between a VA information system and another information system outside VA’s approved accreditation boundaries and/or systems that do not share the same authorizing officials.
ROLES AND RESPONSIBILITIES
Project Manager (PM)
• Manages completion, timelines, and quality standards of the MOU/ISA documentation.
• Collaborates with an integrated project team to make sure that all stakeholders have contributed to a complete MOU/ISA.
Contracting Officer (CO)
• Ensures that services being provided are within the contract specifications.
• Furnishes contract technical direction.
Contracting Officer Representative (COR)
• Serves as liaison between Department of Veterans Affairs and the contractor.
• Monitors contractor performance throughout the lifecycle of the contract.
Information System Owner (ISO)
• Initiates and completes the MOU/ISA Intake form.
• Works with Information System Security Officers (ISSOs) to evaluate security requirements.
• Works with third-party companies to set up network interconnections.
Privacy Officer (PO)
• Manages the risks and business impacts of privacy laws and policies.
• Assists the cybersecurity team with ensuring privacy requirements are included for all interconnections.
Business Requirements Division (BRD)
• Serves as Subject Matter Experts (SMEs) for MOU/ISAs.
• Manages and monitors the entire MOU/ISA process.
• Provides MOU/ISA training and coordinates annual reviews.
• Reviews National MOU/ISAs annually to ensure security controls are still in place.
• Reviews and updates MOU/ISA templates annually or as needed.
• Signs the review sheets for all National Business MOU/ISAs.
BRD MOU ISA Team Analysts
• Performs quality and security reviews of MOU/ISA documentation.
• Works with Points of Contact (POCs) to address non-compliance issues discovered during quality reviews.
Research Support Division (RSD)
• Serves as SMEs for quality and security reviews of all Research MOU/ISAs.
• Signs the review sheets for all National Research MOU/ISAs.
• Reviews Research National MOU/ISAs annually to ensure security controls are still in place.
Specialized Device Security Division (SDSD)
• Serves as SMEs for quality and security reviews of all Specialized Device MOU/ISAs.
• Signs the review sheets for all National Special Purpose System and Medical Device MOU/ISAs.
• Reviews Special Purpose System and Medical Device National MOU/ISAs annually to ensure security controls are still in place.
ESO Information System Security Officers (ISSOs)
• Verifies the security content in the MOU/ISA is accurate and reports deficiencies to the document stakeholders.
• Uploads draft and final MOU/ISA documents to the MOU/ISA Document Site portal.
• Confirms completed MOU/ISAs are uploaded to applicable security controls in the Governance Risk Compliance (GRC) tool.
• Provides assistance and guidance to stakeholders with the system interconnection approval process.
• Provides cybersecurity subject matter expertise for MOU/ISA content.
• Reviews Local MOU/ISAs annually to ensure security controls are still in place.
PROCEDURES
System Interconnection Requirements
A system interconnection is defined as the direct connection of two or more IT systems for the purpose of sharing data and other information resources.
All dedicated connections between information systems that do not have the same authorizing official require an MOU/ISA. VA MOU/ISAs are one combined document for all agreements.
A Memorandum of Understanding defines: the responsibilities of the participating organizations; the terms and conditions for sharing data and information resources in a secure manner; the purpose of the interconnection; and the terms of the agreement. The MOU also identifies the stakeholders of the agreement.
An Interconnection Security Agreement specifies the technical and security requirements for establishing, operating, and maintaining the interconnection. The ISA documents the requirements for connecting the IT systems, describes the security controls that will be used to protect the systems and data, provides a system diagram of the interconnection, and provides signature lines for all stakeholders.
The Department of Veterans Affairs documents all external connections using the VA approved MOU/ISA templates. The VA MOU/ISA templates outline all minimum security and system requirements as required by NIST 800-47 and VA Handbook 6500, as well as the type of connection as defined in VA Handbook 6513, Secure External Connections.
MOU/ISA Types
VA LAN Extension MOU
A Local Area Network (LAN) Extension MOU is required for VA networks and/or equipment connected to a VA facility, but physically located and extended to an external organization’s premises. The VA network and/or equipment are not connected to the external organization’s network systems.
VA Standard MOU/ISA
A VA MOU/ISA document is required for all external connections (local and national) as outlined in VA Handbook 6513, Secure External Connections.
Connections that do not share the same VA Authorizing Official for the systems will require an MOU/ISA.
State Prescription Monitoring Program (SPMP) MOU/ISAs
An SPMP MOU/ISA is required for all SPMP vendors that receive prescription monitoring data from VA. SPMP vendor MOU/ISAs are written in a specific format for this program area and encompass the entire VA. The purpose of the SPMP MOU/ISA is to ensure prescription reporting requirements are met as mandated by Federal Law. All relevant agreements will be documented in AC-20.1, CA-3.1, SA-9.1 and SA-9.E02 in GRC.
Inter-Agency MOU/ISAs
An Inter-Agency MOU/ISA is an agreement supplied by another Federal agency for systems that require an interconnection to the Department of Veterans Affairs. VA accepts these documents for interconnections because other federal agencies are required to meet the same level of security as outlined in NIST 800-47. These documents are submitted to the MOU/ISA Intake portal and reviewed by the BRD MOU/ISA team to ensure compliance.
MOU/ISA Intake Process
• Requests for an MOU/ISA document for an external connection are entered on the MOU/ISA Document Site located here. Specific instructions for the portal are located here.
• All requests submitted on the portal are received and reviewed by BRD for required security language and interconnection details.
• After BRD initial review, if changes are needed, feedback is provided to the requestor and the vendor/other organization for review and input on the proposed changes. The timeframe for completion of this process is dependent on stakeholder engagement and responsiveness. Delays caused by unresponsive stakeholders will be escalated to senior leadership and may result in a notice of disconnect for an existing external connection.
• After final review and approval by BRD, the document is sent to the requestor for signatures. After all signatures have been obtained, the document is uploaded to the MOU/ISA Document Site located here. The document is also uploaded as an artifact to the applicable GRC controls. The signatory process is defined below.
Signatory Process/Authority https://vaww.portal2.va.gov/sites/infosecurity/FY15CRISPAudit/CRISPRemediationContract/WorkSite/SitePages/MOU-ISA_Version2.aspx https://vaww.portal2.va.gov/sites/infosecurity/fieldsecurity/ESO%20Library/MOU%20ISA%20Templates/MOU%20ISA%20Intake%20Form%20Instructions.pdf https://vaww.portal2.va.gov/sites/infosecurity/FY15CRISPAudit/CRISPRemediationContract/WorkSite/Lists/Enterprise_MOUISA_Tracker/Landing%20Page%20Filter%20by%20GRC.aspx
VA Handbook 6500.3, “Assessment, Authorization and Continuous Monitoring of VA Information Systems,” dictates that the AO is responsible for reviewing and approving National MOU/ISAs.
• Enterprise ISSOs and POs review the National MOU/ISA and sign on the review sheet.
• National MOU/ISAs are signed by the Authorizing Officials for each system.
• Local MOU/ISAs are signed by the System Owners for each system.
• Signature blocks are defined by BRD and applied to the final document before routing occurs.
• MOU/ISAs must be signed using a digital certificate or wet signature. Images of signatures, generic digital signatures, or default Adobe signatures are not accepted.
Annual Review and Continuous Monitoring
ISOs and ISSOs are required to ensure MOU/ISAs are reviewed annually from the last signature date. The following lists the requirements for completing the MOU/ISA annual review process:
• The review includes whether the connection is still required, connection details and content are accurate, and POCs are current.
• Check the External Connections Compliance Tracking (ECCT) tool to ensure accurate reporting and documentation for external connections.
• Document the review using the MOU/ISA Review document. All required changes must be listed on the review document and the document must be digitally signed by the reviewers.
• If major changes are needed, a new MOU/ISA document must be submitted to BRD within 30 days of the annual review to ensure the MOU/ISA is updated and reauthorized.
• Ensure all MOU/ISA artifacts are uploaded to the appropriate security control families in GRC.
• If an MOU/ISA document is missing or required changes cannot be rectified within 15 business days, enter a Plan of Action and Milestones (POA&M) for a 90-day extension in GRC for the following controls: CA-3, AC-20, and SA- 9.
Decommissioned External Connections
An interconnection will be decommissioned if the interconnection is no longer necessary or if there is no longer a business or contractual justification for it.
In order to decommission an interconnection, a Change Gear ticket must be submitted for ESECC review. If the interconnection is a site-to-site connection, it must be deleted from the RAP ISSO Portal.
A request is submitted through the MOU/ISA Document Site portal to archive the MOU/ISA document for all decommissioned interconnections.
Veteran Guest Internet Access (VGIA)
An MOU/ISA is not required. The following security controls for all VGIA networks must be addressed:
AC-8 Advisory Banners (Regional control)
AC-11 Session Lock (Local control)
SC-7 Content Filtering and Logfile Monitoring (Regional control, local facility monitors) https://vaww.ramp.vansoc.va.gov/ISOPortal/Pages/Dashboard.aspx
RESCISSIONS
There are no rescissions to this document as of this writing.
DEFINITIONS
BRD (Business Requirements Division) – A division of VA Office of Information Security/Information Security Risk Management that provides cybersecurity expertise at an enterprise level for programs, projects and business lines across the VA.
ECC (External Connections Compliance) – A set of standards that reduce the likelihood of compromised connections from external entities.
ISA (Interconnection Security Agreement) - An agreement established between organizations that own and operate connected IT systems to document the technical requirements of the interconnection.
MOU (Memorandum of Understanding) - A formal agreement between two or more parties to establish official partnerships.
ACRONYMS
• AO – Authorizing Official
• CO – Contracting Officer
• COR – Contracting Officer Representative
• ESECC – Enterprise Security External Change Council
• EUO – End User Operations
• GRC – Governance Risk Compliance
• ISRM – Information Security Risk Management
• ISO – Information System Owner
• ISSO – Information System Security Officer
• LAN – Local Area Network
• OIT – Office of Information Technology
• PM – Project Manager
• PO – Privacy Officer
• POA&M – Plan of Action and Milestones
• POC – Point of Contact
• RSD – Research Support Division
• SDSD – Specialized Device Security Division
• SME – Subject Matter Expert
• SPMP – State Prescription Monitoring Program
• VGIA – Veteran Guest Internet Access
REFERENCES
• NIST 800-18, Guide for Developing Security Plans for Federal Information Systems
• NIST 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems
• NIST 800-47, Security Guide for Interconnecting Information Technology Systems
• NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
• NIST SP 800-53A Rev 4, Assessing the Security and Privacy Controls in Federal Information Systems and Organizations
• 45 C.F.R § 160.103, HIPAA Regulations; Definitions
• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems
• OIS POAM Management SOP
• OMB M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information
• VA Directive 6066, Protected Health Information (PHI) and Business Associate Agreements Management
• VA Directive 6500, Managing Information Security Risk: VA Information Security Program
• VA Handbook and Directive 6513, Secure External Connections
• VA Handbook 6500, Risk Management Framework for VA Information Systems - Tier 3: VA Information Security Program
• VHA Handbook 1605.05, Business Associate Agreements https://www1.va.gov/vapubs/viewPublication.asp?Pub_ID=637&FType=2 https://www1.va.gov/vapubs/viewPublication.asp?Pub_ID=793&FType=2
| PURPOSE |
| BACKGROUND |
| SCOPE |
| ROLES AND RESPONSIBILITIES |
| Project Manager (PM) |
| Contracting Officer (CO) |
| Contracting Officer Representative (COR) |
| Information System Owner (ISO) |
| Privacy Officer (PO) |
| Business Requirements Division (BRD) |
| BRD MOU ISA Team Analysts |
| Research Support Division (RSD) |
| Specialized Device Security Division (SDSD) |
| ESO Information System Security Officers (ISSOs) |
| PROCEDURES |
| System Interconnection Requirements |
| MOU/ISA Types |
| VA LAN Extension MOU |
| VA Standard MOU/ISA |
| State Prescription Monitoring Program (SPMP) MOU/ISAs |
| Inter-Agency MOU/ISAs |
| MOU/ISA Intake Process |
| Signatory Process/Authority |
| Annual Review and Continuous Monitoring |
| Decommissioned External Connections |
| Veteran Guest Internet Access (VGIA) |
| RESCISSIONS |
| DEFINITIONS |
| ACRONYMS |
| REFERENCES |
File details come from the government source that posted it. Updated .