VA Directive 6500.pdf

PDF 253 KB Posted

Attached to
7A21--VISN 22 POC Middleware Federal contract opportunity
Solicitation number
36C26221Q0044
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 22

View the file

Other files for this federal contract opportunity

Other files attached to 7A21--VISN 22 POC Middleware, newest first.
File Type Posted
(Insert Company Name) VA MOU Appendix A POC List 2017.12.18 - TEMPLATE.docx DOCX document
MOU ISA Intake Form Instructions.pdf PDF
MOU ISA Annual Review SharePoint User Guide.pdf PDF
(Insert Company Name) VA MOU ISA Checklist 2017.12.18.xlsx XLSX spreadsheet
36C26221Q0044 0002_1.docx DOCX document
2020 MOU ISA New Template Brown Bag.pptx PPTX presentation
lab_52_poc_hl7_spec.docx DOCX document
Appendix C Template 2018.08.08.pdf PDF
VA Handbook 6500.6 Appendix A.pdf PDF
36C26221Q0044 0002 - RFQ Amendment.docx DOCX document
OIS MOU ISA SOP Final_20191007.pdf PDF
VA MOU ISA Approved Final Template-09092020.docx DOCX document
MOU ISA Review Form-.pdf PDF
(Insert Company Name) VA LAN Extension MOU 2017.12.11 - TEMPLATE.docx DOCX document
Attachment B - Middleware SOW v2.docx DOCX document
RFQ - 36C26221Q0044 v2.docx DOCX document
36C26221Q0044 0001 Amendment.docx DOCX document
36C26221Q0044 0001_1.docx DOCX document
Attachment E - Past Performance References.docx DOCX document
Attachment D - VA Handbook 6500.6 Appendix C.pdf PDF
Attachment B - Middleware SOW.docx DOCX document
Attachment C - VA Directive 6550.pdf PDF
Attachment A - Schedule.xlsx XLSX spreadsheet
36C26221Q0044.docx DOCX document
Show all 24

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF VETERANS AFFAIRS VA DIRECTIVE 6500

Washington, DC 20420 Transmittal Sheet January 23, 2019

VA CYBERSECURITY PROGRAM

1. REASON FOR ISSUE: Reissues VA Directive 6500 pursuant to the authority to maintain a VA cybersecurity program to protect and defend VA information and information technology (IT) that is consistent with VA’s information security statutes, 38 United States Code (U.S.C.) §§ 5721-5728, the Federal Information Security Modernization Act (FISMA), 44 U.S.C. §§ 3551-3558, and Office of Management and Budget (OMB) Circular A-130.

2. SUMMARY OF CONTENTS/MAJOR CHANGES:

a. Establishes the governance structure as the Risk Executive Function;

b. Establishes the Risk Management Framework (RMF) Technical Advisory Group (TAG), which serves as the governing body for security control management and implementation;

c. Establishes the Information Security Knowledge Service (KS) to provide cybersecurity policies, procedures, and guidance; and

d. Aligns the VA’s Information Security Program with the National Institute of Standards and Technology (NIST) Cybersecurity Framework.

3. RESPONSIBLE OFFICE: Office of the Assistant Secretary for Information and Technology (005) and Office of Information Security (005R).

4. RELATED HANDBOOK: VA Handbook 6500, VA Risk Management Framework.

5. RESCISSIONS: VA Directive 6500, Managing Information Security Risk: VA Information Security Program, dated September 20, 2012 and VA Handbook 6500.1, Electronic Media Sanitization, dated November 3, 2008.

CERTIFIED BY:

/s/ Melissa S. Glynn, Ph.D.

Assistant Secretary for Enterprise Integration

DISTRIBUTION: Electronic Only

BY DIRECTION OF THE SECRETARY

OF VETERANS AFFAIRS:

/s/ James R. Gfrerer Assistant Secretary for Information and Technology and Chief Information Officer

VA Directive 6500 January 23, 2019

This page is intentionally blank.

January 23, 2019 VA Directive 6500

VA CYBERSECURITY PROGRAM

1. PURPOSE.

The purpose of the VA cybersecurity program is to set the direction for the protection and informed risk management of VA information and information systems (ISs). This directive:

a. Reissues VA Directive 6500 to establish a VA cybersecurity program to protect and defend VA information and information technology (IT);

b. Establishes a governance structure as the security Risk Executive Function;

c. Establishes the Information Security Program Risk Management Framework (RMF) Technical Advisory Group (TAG) to strengthen VA’s ability to rapidly deploy secure systems;

d. Establishes the Information Security Knowledge Service (KS) to provide cybersecurity policies, procedures, and guidance; and

e. Aligns the VA’s Information Security Program with the National Institute of Standards and Technology (NIST) Cybersecurity Framework.

2. POLICY.

VA Cybersecurity Program. VA will use this directive as well as the RMF as defined in NIST Special Publication (SP) 800-37, and as implemented by VA Handbook 6500 and the security control baselines in NIST SP 800-53. This information will be located on the VA

KS.

The five core cybersecurity functions that define the VA cybersecurity program are based on the NIST Cybersecurity Framework and the Executive Order 13800, Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure, issued on May 11, 2017.

The core functions are: identify, protect, detect, respond, and recover. Collectively, these five core functions enable the VA to: Provide mission and operational resilience under any cyber situation or condition; Act collectively, consistently, and effectively in its own defense;

Allow VA IT to perform as designed and adequately meet operational requirements; and work securely and seamlessly among mission partners.

a. Identify Function. The Identify Function defines the foundational policies necessary to apply the Cybersecurity Framework to VA, and institutionalizes VA’s understanding and the processes necessary to manage cybersecurity risk to systems, assets, data, and capabilities, and identify any gaps in VA’s cybersecurity practices. Outcome categories within the Identify Function include: Asset Management; Business Environment;

Governance; Risk Assessment; and Risk Management Strategy; and associated activities, as described below:

(1) Asset Management

(a) VA will identify and manage all assets (e.g., data, personnel, devices, systems, and facilities) consistent with their relative importance to VA business objectives and risk strategy.

(b) All VA ISs will be registered in the VA Systems Inventory (VASI) in accordance with VA policy and will be registered as part of a security accreditation in VA’s Governance, Risk and Compliance tool committee.

(c) VA will register all systems (e.g., physical plant systems and medical device systems) at the Department level.

(d) VA will develop information flow control policies and enforce approved authorizations for controlling the flow of information within the system and between interconnected systems.

(e) VA will assign an appropriate level of confidentiality, integrity, and availability to all VA information in electronic format that reflects the importance of both information sharing and protection.

(2) Business Environment

(a) VA will use its understanding of its three major business environments (health, benefits, and memorial affairs) and support functions to inform cybersecurity roles and responsibilities, and make informed risk management decisions.

(b) VA will define its mission and business processes with consideration for information security and privacy and the resulting risk, and determine information protection, Personally Identifiable Information (PII), and Protected Health Information (PHI) processing needs arising from the defined mission and business processes.

(c) VA will develop and implement a plan for managing financial and supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services.

(d) VA will develop, document, and regularly update VA’s critical infrastructure and key resources protection plan, and address information security and privacy issues in the plan.

(e) VA will identify critical system assets supporting essential mission and business functions so additional safeguards and countermeasures can be employed as needed. The identification of critical information assets also facilitates the prioritization of organizational resources.

(f) VA will perform a criticality analysis when an architecture or design is being developed including the use of authoritative sources to identify critical system components and functions. Component and function criticality are assessed in terms of the impact of a component or function failure on the organizational missions supported by the system containing those components and functions.

(g) Performance will be measured, assessed for effectiveness, and managed relative to contributions to mission outcomes and strategic goals and objectives in accordance with 40 U.S.C. § 11313.

(h) VA will implement cybersecurity solutions consistent with enterprise architecture principles and guidelines within the VA Architecture Framework and VA cybersecurity architectures developed or approved by the VA Chief Information Officer (CIO).

(i) VA will implement operational resilience by requiring three conditions to be met:

(i) information resources are trustworthy; (ii) missions are ready for information resources degradation or loss; and (iii) network operations have the means to prevail in the face of adverse events.

(j) VA will define resiliency requirements to support the delivery of critical services during all operating states (e.g., under duress, under attack, during recovery, and normal operations) based on the criticality of the system to enable VA to complete its mission.

(3) Governance

(a) VA will define governance practices that include the policies, procedures, processes, and guidance to manage and monitor VA’s regulatory, legal, risk, environmental, and operational requirements and to inform management of cybersecurity risks.

(b) VA will develop, document, and disseminate cybersecurity policies, procedures, processes, and guidance, and review and update them regularly. VA will define and implement remediation actions for violations of cybersecurity policies.

(c) VA will develop and disseminate an organization-wide information security program plan that provides an overview of the requirements for the security program and a description of the security program management controls and common controls in place or planned for meeting those requirements, the identification and assignment of roles and responsibilities, and reflecting the coordination among organizational entities responsible for information security.

(d) VA will implement a comprehensive security governance structure that provides assurance that information security strategies are aligned with and support mission and business objectives, and are consistent with applicable laws and regulations through adherence to policies and internal controls.

(e) VA will appoint a Senior Agency Official for Privacy (SAOP) with the authority, mission, accountability, and resources to coordinate, develop, and implement applicable privacy requirements and manage privacy risks through an organization-wide privacy program.

(f) VA will establish a principal governing body for its information security programs via a charter signed by the CIO. The principal governing body governs the management processes for information security and validates the effectiveness of those programs with a goal of continuously improving VA’s security posture.

This governing body serves as the VA Risk Executive Function as described in NIST SP 800-37 and NIST SP 800-39.

(g) VA will establish the RMF TAG to support the VA Chief Information Security Officer (CISO). The RMF TAG serves as the governing body for security control management and implementation.

(h) VA will establish the Information Security KS as the authoritative source for VA cybersecurity policies, procedures, processes, and guidance. The KS supports RMF practitioners by providing access to VA security control baselines, security control descriptions, security control overlays, implementation guidance, and assessment procedures.

(i) VA will align cybersecurity policies and capabilities with, and be mutually supportive of, personnel, physical, and industrial information and operations security policies and capabilities.

(4) Risk Assessment

(a) VA will demonstrate understanding of the cybersecurity risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals.

(b) VA will perform risk assessments in accordance with NIST SP 800-30 and as described in the VA KS. The risk factors described in NIST SP 800-30 will be used across VA Administrations and Staff Offices to ensure ease of sharing risk information.

(c) VA will tailor the rigor of the risk assessments to accommodate resource constraints and the availability of detailed risk factor information (e.g., threat data). However, any tailoring must be clearly explained in risk assessment reports to ensure that Authorizing Officials (AO) understand to what degree they can rely on the results of the risk assessments.

(d) VA will monitor systems and hosted applications for new threats and scan the environment on an established schedule with agency-established criteria for performing special scans based on new threats.

(e) VA will establish and institutionalize contact with selected groups and associations within the security and privacy communities to share current security- and privacy-related information, including threats, vulnerabilities, and incidents; maintain currency with recommended security and privacy practices, techniques, and technologies; and facilitate ongoing security and privacy education and training for organizational personnel.

(f) VA will manage cybersecurity risks consistently across VA in a way that reflects organizational risk tolerance and is considered along with other organizational risks to ensure mission and business success.

(g) VA will implement a process to ensure that Plans of Action and Milestones (POAMs) for the security and privacy programs and associated organizational systems are developed and maintained. The POAMs document the remedial information security and privacy actions to adequately respond to risk.

(h) VA will respond to findings from security and privacy assessments, monitoring, and audits by managing the risk through strengthening existing controls or implementing new controls, accepting the risk with appropriate justification or rationale, sharing or transferring the risk, or rejecting the risk. If the risk response is to mitigate the risk and the mitigation cannot be completed immediately, a POAM entry will be generated.

(i) VA will manage all interconnections of VA IT to minimize shared risk by ensuring that the security posture of one system is not undermined by vulnerabilities of interconnected systems.

(5) Risk Management

(a) VA will establish priorities, constraints, risk tolerances, and assumptions, and use them to support operational risk decisions.

(b) VA will implement a multi-tiered cybersecurity risk management process to protect U.S. interests, VA operational capabilities, and VA individuals, organizations, and assets as described in NIST SP 800-39.

(c) VA will publish a comprehensive risk management strategy that defines how VA will manage security, privacy, and supply chain risk, including the determination of risk tolerance and the development and execution of organization-wide investment strategies for information resources and information security.

(d) VA will manage risk by identifying assumptions and constraints affecting risk assessments, risk response, and risk monitoring; the organizational risk tolerance; and priorities and trade-offs considered by the organization for managing risk.

(e) VA will satisfy information protection requirements by the selection and implementation of appropriate security and privacy controls in NIST SP 800-53.

Controls are implemented by common control providers, system owners (SOs), or program managers, and risk-based authorization decisions are granted by AOs. Detailed guidance on system categorization and security control selection is provided in VA Handbook 6500.

(f) VA will begin risk management tasks early in the system development life cycle.

(g) VA will manage the security and privacy state of VA systems and the environments in which those systems operate throughout the authorization process. The authorization process is integrated with continuous monitoring processes to facilitate ongoing understanding and acceptance of security and privacy risks.

(h) VA continues risk management during operations and sustainment, which may include the application of new or revised security or privacy controls prior to the integration of new IT services or products into an existing operational system, to maintain the security of the operational system.

b. Protect Function. The Protect Function supports the ability to limit or contain the impact of a potential cybersecurity event by developing and implementing the appropriate safeguards to ensure delivery of critical IT services. Outcome categories within the Protect Function include: Access Control; Awareness and Training; Data Security; Information Protection Processes and Procedures; Maintenance; and Protective Technology; and associated activities, as described below:

(1) Identity Management and Access Control

(a) VA will limit access to physical and logical assets and associated facilities to authorized users, processes, and devices, and manage the assets consistent with the assessed risk of unauthorized access.

(b) VA IT will use only VA-approved identity credentials to authenticate entities requesting access. This requirement extends to all mission partners using VA IT.

(c) VA will public key-enable VA ISs and implement a VA-wide Public Key Infrastructure (PKI) solution that will be managed by the VA PKI Program Management Office.

(d) VA will develop, approve, and maintain a list of individuals with authorized access to VA facilities and issue authorization credentials for facility access.

(e) VA will document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed, and authorize remote access to VA systems prior to allowing such connections.

(f) VA will define system access authorizations to support separation of duties.

(g) VA will employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational mission and business functions.

(h) VA will isolate or segregate system components performing different missions or business functions when necessary to limit unauthorized information flows among components and provide the opportunity to deploy greater levels of protection for selected system components.

(i) VA will proof identities and bind them to credentials, and will use this for assertion in interactions when appropriate.

(2) Awareness and Training

(a) All authorized users of VA IS will receive an initial cybersecurity awareness orientation as a condition of access and, thereafter, participate annually in both VA and the Administration’s enterprise cybersecurity awareness program.

(b) VA will provide VA personnel and partners with cybersecurity awareness education and training to perform their information security-related duties and responsibilities consistent with VA policies, procedures, and agreements.

(c) VA will implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with VA systems are developed, maintained, and executed in a timely manner.

(d) VA will provide specialized training and awareness for privileged users, third-party stakeholders, and senior executives.

(e) VA will identify appropriate content for security and privacy training based on the assigned roles and responsibilities of individuals, specific VA security and privacy requirements, and the systems to which personnel have authorized access.

(3) Data Security

(a) VA will manage information, records, and data throughout the information life cycle consistent with VA’s risk strategy to protect the confidentiality, integrity, and availability of information. Federal Register Volume 67, Number 36 (Friday, February 22, 2002)]

(b) VA will protect moderate and high impact information at rest and during transmission unless encrypting such information is technically infeasible or would demonstrably affect the ability of VA to carry out its missions, functions, or operations; and the risk of not encrypting is accepted by the AO and approved by the CIO, in consultation with the SAOP (as appropriate).

(c) VA will establish a Data Management Board and develop and implement guidelines supporting data modeling, quality, integrity, and de-identification needs of PII/PHI across the information life cycle.

(d) VA will establish a Data Integrity Board to oversee organizational Computer Matching Agreements.

(e) VA IT that processes or stores PII or PHI will comply with appropriate VA policy.

(f) Cryptography required to protect VA information will be implemented in accordance with Federal Information Processing Standards (FIPS) 140-2.

(g) VA will protect against data breaches.

(h) VA will employ integrity verification tools to detect unauthorized changes to selected software, firmware, hardware, and information.

(4) Information Protection Processes and Procedures

(a) VA will use and maintain security policies that address purpose, scope, roles, responsibilities, management commitment, and coordination among organizational entities to manage protection of information systems and assets.

(b) All VA IT will comply with applicable security configuration guides, with any exceptions documented and approved by the responsible AO.

(c) VA will use automation whenever possible in support of cybersecurity objectives, including, but not limited to, secure configuration management, continuous monitoring, active cyber defense, incident reporting, and situational awareness.

(d) VA will fully integrate cybersecurity into system life cycles so that it will be a visible element of VA architectures, capability identification and development processes, integrated testing, IT portfolios, acquisition, operational readiness assessments, supply chain risk management, system security engineering (SSE), and operations and maintenance activities.

(e) VA will plan and budget for security and privacy control implementation, assessment, and sustainment throughout the system life cycle, including timely and effective configuration and vulnerability management.

(f) VA will integrate SSE principals and concepts to design, develop, implement, modify, test, and evaluate information systems and system architectures as described in NIST SP 800-160.

(g) VA will review proposed configuration-controlled changes to systems, approve or disapprove such changes with explicit consideration for security impact analyses, and document the decision.

(h) VA will conduct backups of user-level information and system-level information contained in VA systems, and conduct backups of system documentation including security-related documentation.

(i) VA will protect the confidentiality, integrity, and availability of backup information at storage locations.

(j) VA will establish a physical security program to protect VA IT from damage, loss, theft, or unauthorized physical access in accordance with VA policy.

(k) VA will update policies and procedures to address system and organizational changes or problems encountered during implementation, execution, or testing of the VA information security program.

(l) VA will implement a threat awareness program that includes a cross-organizational information sharing capability. Threat information sharing may be bilateral (e.g., government/commercial cooperatives) or multilateral (e.g., organizations taking part in threat-sharing consortia). Threat information may be highly sensitive, requiring special agreements and protection, or less sensitive and freely shared.

(m) VA will develop, test, implement, manage, and maintain appropriate response and recovery plans. At a minimum, VA will manage and test all plans on a yearly basis, including Incident Response, Business Continuity, Incident Recovery, and Disaster Recovery plans.

(n) VA will develop cybersecurity workforce management policies and capabilities to support identification and qualifications for a professional cybersecurity workforce.

(o) VA personnel may be considered for administrative or judicial sanctions if they knowingly, willfully, or negligently compromise, damage, or place at risk VA information by not ensuring implementation of VA security requirements in accordance with VA policy.

(p) VA will identify, report, and correct system flaws and incorporate flaw remediation into VA’s configuration management process.

(5) Media Sanitization

(a) VA will comply with NIST 800-88 for the purposes of media sanitization on all IT equipment.

(b) VA will use approved techniques or methods to dispose of, destroy, or erase VA information, consistent with VA retention guidelines and National Archives and Records Administration (NARA) approved records control schedules. This applies to originals as well as copies and archived records, including system logs that may contain PII/PHI.

(c) The VA Office of Inspector General (OIG) may issue a separate, more stringent electronic media sanitization policy, which OIG must follow, due to special security needs or resulting from the need to follow special procedures to ensure the admissibility of electronic evidence in legal proceedings.

(d) VA offices and facilities notified by the Office of the General Counsel (OGC) that their IT equipment, electronic storage media, or information residing on either, is subject to retention for possible litigation purposes, must immediately cease the repair, reuse, disposal, destruction, or sanitization of the involved equipment, storage media, or data. These restrictions also apply to non-VA IT equipment (including research equipment and/or grant-owned equipment), electronic storage media, and VA information residing on either.

(e) Office of Information and Technology (OI&T) staff must train Information Security Officers (ISOs) (and other designated staff assigned to perform media sanitization and/or process electronic storage media for sanitization) on VA data sanitization policies and procedures. They must also provide current copies of any VA policies and documents describing or depicting sanitization methods and procedures to appropriate staff members.

(f) Contracts involving media sanitization, electronic storage media, and IT equipment (e.g., sharing agreements and Memoranda of Understanding [MOU]), maintenance contracts, service contracts, and vendor repair agreements (including third party vendor repair and lease agreements) must include the appropriate security language concerning the protection of VA assets, including appropriate media sanitization for electronic storage media and IT systems and equipment.

(g) Users of non-VA leased or owned IT equipment including, but not limited to, personally-owned equipment (which requires an approved waiver from the VA CIO), vendor-owned equipment, or research equipment obtained through a grant used to store, process, or access VA sensitive information are required to protect all VA sensitive information from subsequent disclosure to unauthorized persons during use and when the equipment is no longer used to access VA sensitive information.

(h) VA has a contracted, agency-wide program in place to sanitize and properly dispose of media containing VA sensitive information. ISOs are the points of contact for this program and facilitate all phases of the program for each Administration and Staff Office.

(i) IT electronic media may be sanitized under a locally developed contract or in-house, whichever is deemed to be more cost-effective. Procedures for contracting sanitization services or completing services in-house are outlined in this directive and must be followed.

(j) Returning leased equipment constitutes a risk. VA employees must sanitize VA sensitive information residing on leased equipment before releasing that equipment from direct VA control, or ensure the contract states the media will not be returned upon termination of the contract. Depending upon the contract, this may include VA licensed software installed on leased equipment. Copyright protected software must be removed from equipment prior to repair, disposal, or reuse unless it: (i) will be reused by an agency component included as a part of the same group license under which the program was initially installed, or (ii) is required to ensure the repair was successful. If installing Commercial Off-the- Shelf (COTS) software, pre-approval is required by OI&T and the Contracting Officer. If the COTS software requires a user license limited to that individual, the individual must remove that software from the machine before releasing the machine for another individual’s use.

(k) When non-VA owned IT equipment is no longer used to access or store VA sensitive information, all equipment hard disk drives and internal memory is to be sanitized in accordance with VA policy. All other electronic storage media used to store, process, or access VA sensitive information must be sanitized in accordance with VA policy when the media are no longer used to access VA sensitive information being disposed of or removed from VA control.

(l) OI&T and facility property managers are required to report within VA usable excess IT equipment and redistribute that equipment for use, if appropriate. If the excess IT equipment cannot be used within the agency, then donations of equipment to schools (grades K-12) are encouraged under the auspices of Executive Order 12999 (Computers for Learning Program), signed on April 16, 1996.

(m) OI&T and facility property managers are encouraged to use VA’s MOU established with UNICOR for processing scrap IT equipment and for the recycling of scrap electronic equipment in general.

(6) Maintenance

(a) VA will perform maintenance and repairs of VA IT ISs and system components consistent with VA policies and procedures.

(b) VA will schedule, document, manage, and review records of maintenance, repair, or replacements of system components in accordance with manufacturer or vendor specifications and/or organizational requirements. System maintenance also includes those components not directly associated with information processing and/or data or information retention, such as mobile devices, scanners, copiers, and printers.

(c) VA will approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or moved to another location, to ensure that VA sensitive information and PII is maintained under VA control.

(7) Protective Technology

(a) VA will manage technical security solutions to ensure the security and resilience of systems and assets are consistent with related policies, procedures, and agreements.

(b) VA will collect and keep audit data to support technical analysis relating to misuse, penetration, or other incidents involving IT under their purview, and provide this data to appropriate law enforcement or other investigating agencies as necessary.

(c) VA will employ technical and non-technical safeguards to limit the use of portable media, including digital (e.g., external or removable hard disk drives and flash drives) and non-digital media (e.g., paper and microfilm), and protect the portable media when not in use.

(d) VA will configure systems to provide only essential capabilities, and prohibit or restrict the use of selected functions, ports, protocols, and/or services.

(e) VA will monitor and control communications and networks at external boundaries and at key internal boundaries, and connect to external networks or systems only through managed interfaces.

(f) VA will pre-define functional states to achieve availability (e.g., under duress, under attack, during recovery, and normal operations) based on the criticality of the system to enable VA to complete its mission.

c. Detect Function. The Detect Function enables timely discovery of cybersecurity events by implementing the appropriate activities to identify the occurrence of a cybersecurity event. Outcome categories within the Detect Function include: Anomalies and Events; Security Continuous Monitoring; and Detection Processes; and associated activities, as described below:

(1) Anomalies and Events

(a) VA will detect anomalous activities in a timely manner and determine the potential impact of events on VA systems and networks.

(b) VA will sense, correlate, and make visible to mission owners and network operators the security posture, from individual device or software objects to aggregated systems of systems.

(c) VA will receive system security alerts, advisories, and directives from external organizations (e.g., US-CERT) on an ongoing basis and generate internal security alerts, advisories, and directives as deemed necessary.

(d) VA will establish baseline configurations for systems and system components, including communications and connectivity-related aspects of systems. Baseline configurations of systems reflect the current enterprise architecture.

(e) VA will monitor systems to detect attacks, indicators of potential attacks, and unauthorized local, network, and remote connections.

(f) VA will track and document cybersecurity and privacy incidents.

(g) VA will implement an incident handling capability for security and privacy incidents that includes preparation, detection and analysis, impact determination, containment, eradication, and recovery.

(h) VA will ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the VA Administrations and Staff Offices.

(i) VA will correlate incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.

(j) VA’s incident response capability will issue an alert when system-generated indications of compromise or potential compromise occurs. Alerts may be generated from a variety of sources, including, for example, audit records or inputs from malicious code protection mechanisms, intrusion detection or prevention mechanisms, or boundary protection devices such as firewalls, gateways, and routers.

(2) Continuous Security Monitoring

(a) VA will monitor information and assets at discrete intervals to identify cybersecurity events and verify the effectiveness of protective measures.

(b) VA will develop a security and privacy continuous monitoring strategy, and implement a security and privacy continuous monitoring program that assesses security and privacy controls and associated risks at a frequency sufficient to support risk-based decisions. Having access to security- and privacy-related information on a continuing basis through reports and dashboards gives VA the capability to make more effective and timely risk management decisions, including ongoing authorization decisions.

(c) VA will establish and maintain a continuous monitoring capability as specified in NIST SP 800-137 that provides cohesive collection, transmission, storage, aggregation, and presentation of data that conveys current operational status to affected VA stakeholders.

(d) VA will monitor physical access to the facility where the system resides to detect and respond to physical security incidents.

(e) VA will monitor personnel activity to detect potential cybersecurity events.

(f) VA will implement an insider threat program that includes a cross-discipline insider threat incident handling team. Insider threat programs include controls to detect and prevent malicious insider activity through the centralized integration and analysis of both technical and non-technical information to identify potential insider threat concerns.

(g) VA will implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code, and automatically update malicious code protection mechanisms whenever new releases are available in accordance with guidance in the VA KS.

(h) VA will define acceptable and unacceptable mobile code and mobile code technologies, and establish usage restrictions and implementation guidance for acceptable mobile code and mobile code technologies. VA will also authorize, monitor, and control the use of mobile code within its systems.

(i) VA will require that providers of external system services comply with organizational security and privacy requirements. VA will monitor security and privacy control compliance by external service providers on an ongoing basis.

(j) VA will establish policy and procedures to ensure that requirements for the protection of Controlled Unclassified Information (CUI) processed, stored, or transmitted on external systems are implemented in accordance with NIST SP 800-171.

(k) VA will identify software programs authorized to execute on the system and employ a deny-all or permit-by-exception policy (whitelisting) to allow the execution of authorized software programs on the system.

(l) VA will detect network services that have not been authorized or approved.

(m) VA will employ automated mechanisms to detect the presence of unauthorized hardware, software, and firmware components within the system and take actions when unauthorized components are detected.

(n) VA will enforce physical access authorizations and verify individual access authorizations before granting access to the facility to prevent unauthorized personnel from accessing VA facilities and systems.

(o) VA will scan for vulnerabilities in the system and hosted applications as specified in the KS, and when new vulnerabilities potentially affecting the system are identified and reported.

(3) Detection Processes

(a) VA will maintain and test detection processes and procedures to ensure timely and adequate awareness of anomalous events.

(b) VA will require personnel to report suspected security and privacy incidents to the organizational incident response capability.

(c) VA will provide an incident response support resource, integral to the organizational incident response capability, which offers advice and assistance to users for the handling and reporting of security and privacy incidents.

(d) VA will implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems are developed and maintained, and continue to be executed in a timely manner.

d. Respond Function. The Respond Function supports the ability to contain the impact of a potential cybersecurity event and identifies the appropriate actions to take regarding the detected cybersecurity event. Outcome categories within the Respond Function include: Response Planning; Communications; Analysis; Mitigation; and Improvements;

and associated activities, as described below:

(1) Response Planning

(a) VA will develop and implement an incident response plan that provides the organization with a roadmap for implementing its incident response capability.

For incidents involving PII/PHI, VA will include a process to determine whether notice to oversight organizations or affected individuals is appropriate and provide that notice accordingly.

(b) VA will execute and maintain response processes and procedures to ensure timely response to detected cybersecurity events.

(2) Communications

(a) VA will coordinate their response activities with internal and external stakeholders as appropriate, to include external support from law enforcement agencies.

(b) VA will explicitly designate responsibility for incident response in the Incident Response Plan.

(c) VA will require personnel to report suspected security, privacy, and supply chain incidents.

(d) VA will coordinate among many organizational entities including, for example, mission/business owners, SOs, AOs, human resources offices, physical and personnel security offices, legal departments, operations personnel, procurement offices, and the risk executive (function), to effectively handle incidents.

(e) VA will contact personnel on the alert notification list when an alert or notification is issued. Personnel on the alert notification list can include, for example, system administrators, mission or business owners, SOs, system security officers, or privacy officers.

(f) VA will correlate incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.

(g) VA will coordinate with external organizations as defined in the Incident Response Plan to correlate and share incident information to achieve a cross-organizational perspective on incident awareness and more effective incident responses.

(3) Response and Recovery Analysis

(a) VA will conduct analysis to ensure adequate response and support recovery activities.

(b) VA will employ automated tools and mechanisms to support near real-time analysis of alerts and notifications generated by VA systems.

(c) VA will test the incident response capability for the system to determine the incident response effectiveness and document the results.

(d) VA will determine the impact of an incident on VA’s mission and business practices.

(e) VA will establish an integrated team of forensic and malicious code analysts, tool developers, and real-time operations personnel to handle incidents and facilitate information sharing.

(f) VA will conduct forensic activities as defined in the VA Cybersecurity Incident Response Plan.

(g) VA will identify classes of incidents and the actions to take in response to those classes of incidents to ensure continuation of organizational mission and business functions.

(4) Mitigation

(a) VA will perform activities to prevent expansion of an event, mitigate its effects, and eradicate the incident.

(b) VA will mitigate risk of a security or privacy incident to the VA by strengthening existing controls or implementing new controls, accepting the risk with appropriate justification or rationale, sharing or transferring the risk, or rejecting the risk.

(c) VA will accept the risk of newly identified security or privacy incidents if the risk response is to mitigate the risk and the mitigation cannot be completed immediately; in these cases, a POAM will be generated.

(d) VA will incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly.

(5) Improvements

(a) VA will improve organizational response activities by incorporating lessons learned from current and previous detection/response activities.

(b) VA will use qualitative and quantitative data from incident response testing and actual events to determine the effectiveness of incident response processes, continuously improve incident response processes incorporating advanced information security practices, and provide incident response measures and metrics that are accurate, consistent, and in a reproducible format.

(c) VA will update the Incident Response Plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing, and communicate Incident Response Plan changes to incident response personnel and organizations.

e. Recover Function. The Recover Function supports timely recovery to normal operations to reduce the impact from a cybersecurity event. Outcome Categories within the Recover Function include: Recovery Planning; Improvements; and Communications; and associated activities, as described below:

(1) Recovery Planning

(a) VA will define necessary incident recovery plans and will test those plans in accordance with federal guidelines.

(b) VA will execute and maintain recovery processes and procedures to ensure timely restoration of systems or assets affected by cybersecurity events in accordance with disaster recovery plans.

(c) VA will develop and implement contingency plans using guidance found in NIST SP 800-34 that identifies essential mission and business functions and associated contingency requirements, and provides recovery objectives, restoration priorities, and metrics. The contingency plans also address maintaining essential mission and business functions despite a system disruption, compromise, or failure, and the eventual full system restoration without deterioration of the security and privacy controls originally planned and implemented.

(2) Improvements

(a) VA will improve recovery planning and processes by incorporating lessons learned into future activities.

(b) VA will update contingency plans to address changes to the organization, system, or environment of operation, and problems encountered during contingency plan implementation, execution, or testing, and communicate contingency plan changes to key contingency personnel and organizations.

(3) Communications

(a) VA will coordinate restoration activities with internal and external parties, such as coordinating centers, Internet Service Providers, owners of attacking systems, victims, other computer security incident response teams, and vendors.

(b) VA will manage communication with the public regarding cybersecurity and privacy incidents through the Office of Public and Intergovernmental Affairs

(OP&IA).

(c) VA will manage its reputation after an incident has been resolved through

OP&IA.

(d) VA will share information internally on recovery activities among organizational stakeholders, including, for example, executive and management teams, mission/business owners, SOs, AOs, human resources offices, physical and personnel security offices, legal departments, operations personnel, procurement offices, and the risk executive (function).

3. RESPONSIBILITIES.

a. Secretary of Veterans Affairs. The Secretary ensures agency compliance with requirements under 38 U.S.C. § 5723 and 44 U.S.C. § 3554.

b. Inspector General of Veterans Affairs. The Inspector General shall carry out the responsibilities under 38 U.S.C. § 5723 and 44 U.S.C. § 3554.

c. Assistant Secretary for Information and Technology, and Chief Information Officer (A/S OI&T / CIO) shall:

(1) Carry out the responsibilities under 38 U.S.C. § 5723 and 44 U.S.C. § 3554.

(2) Charter and co-chairs the cybersecurity governing body.

(3) Monitor, evaluate, and provide advice to the Secretary of VA regarding all VA cybersecurity activities, and oversees implementation of this directive.

(4) Appoint a VA CISO in accordance with 44 U.S.C. § 3554.

(5) Direct and coordinate with the Executive Director for Quality, Performance and Risk (QPR) to ensure that risk management strategies and policies are aligned with overarching VA cybersecurity strategy.

(6) Direct and coordinate with the Deputy Assistant Secretary (DAS) for IT Resource Management (ITRM) to develop cybersecurity workforce management policies and capabilities to support identification and qualifications for a professional cybersecurity workforce.

(7) Direct and coordinate with the Assistant Secretary for the Office of Operations, Security, and Preparedness (OSP) to ensure that cybersecurity policies and capabilities are aligned with and mutually supportive of personnel, physical, industrial, information, and operations security policies and capabilities.

(8) Coordinate with the Office of Acquisition, Logistics, and Construction’s (OALC) Executive Director for Office of Acquisition and Logistics to ensure that cybersecurity responsibilities are integrated into processes for VA acquisition programs, including research and development.

(9) Direct and coordinate with the DAS for IT Operations and Services (ITOPS) to ensure that cybersecurity responsibilities are integrated into the operational testing and evaluation for VA programs.

(10) Direct, coordinate, and advocate resources for VA-wide cybersecurity solutions, including overseeing appropriations allocated to the VA cybersecurity program.

(11) Direct and coordinate with VA Administrations and Staff Offices to ensure that cybersecurity responsibilities are addressed for all VA IT.

(12) Integrate cybersecurity threat information sharing activities internal and external to VA to enhance VA cyber situational awareness.

(13) Develop policy for negotiating, performing, and concluding agreements with partners to engage in cooperative cybersecurity activities.

(14) Develop and implement policy regarding continuous monitoring of VA IT.

(15) Appoint an AO for all VA IT systems and ensure all VA systems are authorized.

(16) Appoint a senior employee to chair a committee to provide oversight for VA’s selected Governance, Risk and Compliance tool committee.

(17) Ensure an annual assessment of the VA cybersecurity program is conducted.

d. Authorizing Official (AO). An AO shall:

(1) Make authorization decisions for VA ISs under their purview by formally assuming responsibility for operating VA ISs at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.

e. Deputy Chief Information Officer (DCIO) for Office of Information Security (OIS).

Under the authority and direction of the VA CIO, and in addition to the responsibilities as the VA Chief Information Security Officer (CISO), the DCIO, OIS shall:

(1) Carry out the responsibilities under 38 U.S.C. § 5723 and 44 U.S.C. § 3554.

(2) Chair the cybersecurity governing body.

(3) Develop a VA cybersecurity strategy that defines goals and objectives that, when implemented, guides and supports operational risk decisions.

(4) Develop and maintains cybersecurity policy in support of the cybersecurity program.

(5) Develop, implement, and manage cybersecurity for the VA enterprise network consistent with this directive and its supporting guidance.

(6) Develop or acquire solutions that support cybersecurity objectives for use throughout VA via the cybersecurity governing body process.

(7) Publish and maintain the VA Information Security Risk Management Strategy.

(8) Establish and maintain the VA Information Security KS.

(9) Oversee and maintain the connection approval process in coordination with the Governance, Risk and Compliance tool committee and VA cybersecurity governing body, when appropriate.

(10) Facilitate information sharing efforts between VA and its federal and industry partners in support of approved cybersecurity agreements.

(11) Support training exercises, workforce development, network evaluation, and other efforts to build cybersecurity capacity.

(12) Ensure the continued development and maintenance of guidance and standard procedures to catalog, regulate, and control the use and management of Internet Protocols, data services, and associated ports on VA networks.

(13) Support development of cybersecurity training and awareness products and a distributive training capability to support VA.

(14) Coordinate with OSP to ensure cyber readiness inspection guidance and metrics provide a unity of effort among the security disciplines (i.e., personnel, physical, industrial, information, operations, and cybersecurity).

(15) Implement a process to ensure that POAMs for the security and privacy programs and associated organizational systems are developed and maintained.

f. VA Chief Information Security Officer (CISO). On behalf of the VA CIO, the VA CISO shall:

(1) Direct and coordinate the VA cybersecurity program and, as delegated, carries out the VA CIO’s responsibilities pursuant to 44 U.S.C. § 3554 and 38 U.S.C. § 5723.

(2…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .