Attachment 1 - DHA-MDE-Cybersecurity-RMF-Contracting-Requirements.pdf

PDF 709 KB Posted

Attached to
Patient Security System Federal contract opportunity
Solicitation number
HT940625Q0011
Issued by
Defense Health Agency

About this file

This document is the Defense Health Agency (DHA) Cybersecurity/Risk Management Framework (RMF) Contracting Requirements for Medical Device and Equipment (MDE), version dated January 17, 2024. The document establishes comprehensive cybersecurity requirements for vendors supplying medical devices and equipment to the DHA, focusing on ensuring the security posture of medical technologies throughout their lifecycle. Key requirements include establishing a test/laboratory environment, conducting technical vulnerability scans, maintaining continuous cybersecurity monitoring, providing monthly vulnerability reports, and complying with multiple federal cybersecurity regulations and guidelines including HIPAA, FISMA, NIST standards, and various DoD cybersecurity instructions.

Vendors must meet stringent technical and procedural requirements, such as passing pre-validation technical screenings without unmitigated vulnerabilities, obtaining a recommendation of Approval within twelve months of contract award, and maintaining an authorized security configuration. The document mandates that vendors provide ongoing cybersecurity maintenance, including timely software patches, updates, and compliance with Security Technical Implementation Guides (STIGs). Additionally, vendors must complete various cybersecurity trainings, undergo background investigations, use two-factor authentication, and adhere to acceptable use policies when accessing DHA networks. The requirements apply to standalone contracts, delivery orders, and call orders under blanket purchase agreements, with all requirements to be included in a single Not Separately Priced (NSP) Contract Line Item (CLIN).

View the file

Other files for this federal contract opportunity

Other files attached to Patient Security System, newest first.
File Type Posted
Attachment 3 - Floor Plan.pdf PDF
Amendment 0001 - Questions and Answers.pdf PDF
Attachment 2 - CyberLOG - ICS Combined MDERA - v6.4.1B.pdf PDF
RFQ - HT940625Q0011.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Defense Health Agency (DHA) Contracting Requirements for Medical Device and Equipment (MDE) Cybersecurity/Risk Management Framework (RMF)

Updated: January 17, 2024

DHA MDE Cybersecurity/RMF Contract/ordering Requirements Version 01-17-2024 ii | P a g e

Version Matrix

Version Date Author Description

1.0 16 November2018 Completed initial draft of Cybersecurity Language.

1.1 31 January2019 Updated document to reflect vendor comments/suggestions.

1.2 06 February2019 CyberLOG Final Document.

1.3 25 March 2019 CyberLOG Addition of Section B 1.11.

1.4 11 January 2022 CyberLOG Review of and clarification of requirements.

1.5 03 October 2023 CyberLOG/ICS Review of and clarification of requirements.

2.0 17 January 2024 CyberLOG/ICS/J6 Changes to support requirements, SMA, and NSP statement.

DHA MDE Cybersecurity/RMF Contracting Requirements Version 1-17-2024 iii | P a g e

Table of Contents A. General Defense Health Agency (DHA) Medical Device and Equipment (MDE) Cybersecurity/Risk

Management Framework (RMF) Contracting Requirements

1. New MDE and Software Purchases RMF Requirements:

B. DHA Cybersecurity/RMF Acceptance/MDE Delivery Requirements

1. System Security Requirements

2. RMF Assessment Timeframes

3. Business to Business (B2B) Connectivity Requirements

4. Warranty and Post-Warranty Service Maintenance Agreement RMF/Cybersecurity

Requirements/Continuous Monitoring/Risk Management

5. Cybersecurity Regulations and Guidance

1) Cybersecurity Regulations and Guidance

1 | P a g e

All requirements in this document will be referenced by a single Not Separately Priced (NSP) Contract Line Item (CLIN) in the contract/order and shall be included in vendor’s pricing with no additional or separate charges.

The government will not enter into a Non-Disclosure Agreement (NDA) with the vendor.

Federal law provides criminal prosecution of any Government employee disclosing confidential information, with or without an NDA (see 18 USC §1905).

All requirements in this document apply to stand-alone contracts as well as delivery or task orders under an ordering contract and call orders under a blanket purchase agreement. If the vendor receives a delivery or task order under an ordering contract or a call order under a blanket purchase agreement, the vendor shall ensure that all devices provided under the scope of said contract maintain the required/authorized security posture; the vendor shall not change versions without proper notification to both the program office responsible for device management, the contract agency, and the cyber security analysts. The vendor shall not make any delivery, nor receive payment prior to RMF approval on the updated version.

A. General Defense Health Agency (DHA) Medical Device and Equipment (MDE)

Cybersecurity/Risk Management Framework (RMF) Contracting Requirements

1. New MDE and Software Purchases RMF Requirements:

For the purposes of this contract/order, MDE is defined as any system, device, or software intended for use in, or in direct support of, the diagnosis of disease or other conditions, or in the cure, mitigation, treatment, or prevention of disease, or equipment used in the direct support of the medical mission.

The vendor agrees to comply with References listed in Section: 5 Cybersecurity Regulations and Guidance.

1.1. The vendor shall establish and maintain a test/laboratory environment that includes all contract/ordered equipment, to include 3rd party components that fall under the authorization boundary, and/or included in this contract/order, to support the RMF/Cybersecurity requirements. The vendor test lab shall be used for all self-assessment activities, Independent Verification and Validation (IV&V) compliance testing, and post Authority to Operate (ATO), or RMF Approval (herein referred to as Approval) actions.

1.2. Any commercial cloud offerings hosted outside the DHA Med-COI network must be Federal Risk and Authorization Management Program (FedRAMP) approved prior to implementing DHA RMF/Cybersecurity activities for the MDE. FedRAMP certification falls outside the DHA Cyber Logistics’ (CyberLOG) or Program Management Office’s (PMO) purview and is the responsibility of the vendor.

Information on FedRAMP certification can be found at www.fedramp.gov.

1.3. Software patches and updates: Many enterprises within the DoD automate patch installations and software updates for operating systems and DoD

2 | P a g e standard software applications. For applications such as databases and developed applications, updates must be scheduled in coordination with DHA.

Vendors shall notify the assigned DHA Cybersecurity Analyst and make available for DHA Contracting Officer’s Representative (COR) review if required, any updates/changes to the system prior to installation, to include but not limited to software updates, operating system, application upgrades, patches, and/or addition/removal of components. For purchases made through the DHA Integrated Clinical Systems Program Management Office (ICS PMO), the vendor shall submit all requests to dha.detrick.PEO-Med-Sys-J-6.mbx.dha-ics-cyber-rmf@health.mil. For all other purchases, or if the analyst is unknown, the vendor shall submit all requests to dha.detrick.med-log.mbx.cyberlog@health.mil.

Software updates will be analyzed by the Government to determine if reauthorization is required by Department of Defense Instruction (DoDI) 8510.01, RMF for DoD Information Technology (IT). Patches normally address bug fixes and cybersecurity issues. Per the DoDI 8500.01, Cybersecurity, Enclosure 3, paragraph 9.b(11), “All CYBERSECURITY products and [Information Assurance] IA-enabled products that require use of the product’s CYBERSECURITY capabilities will comply with the evaluation and validation requirements of Committee on National Security Systems Policy 11, National Policy Governing the Acquisition of IA and IA-Enabled Information Technology Products, June 2013, as amended.”

1.4. Reauthorization in accordance with DoD RMF requirements: Per DoDI 8510.01, Enclosure 6, para 2.f.(6)(a), “In accordance with Appendix III of Office of Management and Budget (OMB) Circular A-130, systems must be reassessed and reauthorized every 3 years or as a result of a system update that negatively affects the security posture (whichever is less).” The vendor must disclose to the Government any changes to configuration, to include but not limited to, software version changes, operating system changes/upgrades, major application or architectural changes (database version, web hosting software, etc.) a minimum of three (3) months prior to delivery/implementation within the DHA. Minor system updates and cybersecurity maintenance patching are generally not considered major application changes but will be evaluated by the PMO prior to implementation. The Government will determine if a reauthorization is required based on vendor-initiated system updates or changes. Program Offices or appropriate logistics organizations plan for this activity. The results of an annual cybersecurity review or a negative change to the system or environment at any time (i.e., a change increasing the residual risk) may result in a need for reauthorization prior to the regular three-year reauthorization.

1.5. The vendor shall ensure that all MDE provided under the scope of this contract/order maintain the required/authorized security posture; the vendor shall not change versions without proper notification to the program office responsible for device management, the contract agency, and the DHA cyber security analysts. The vendor shall not make any delivery, nor receive payment prior to RMF Approval on the updated version.

mailto:dha.detrick.PEO-Med-Sys-J-6.mbx.dha-ics-cyber-rmf@health.mil mailto:dha.detrick.PEO-Med-Sys-J-6.mbx.dha-ics-cyber-rmf@health.mil mailto:%20dha.detrick.med-log.mbx.cyberlog@health.mil.

mailto:%20dha.detrick.med-log.mbx.cyberlog@health.mil.

3 | P a g e

B. DHA Cybersecurity/RMF Acceptance/MDE Delivery Requirements

1. System Security Requirements

1.1. The vendor shall provide a Point of Contact (POC) responsible for the completion of the RMF/Cybersecurity process for the vendor device or system throughout the lifecycle of the system. The vendor shall provide Subject Matter Experts (SMEs) to support all assessments of contract/ordered products and materials outlined in the chart in paragraph 2.

1.1. RMF documentation shall cover all possible configurations, including all

3rdcomponents supported by this contract/order.

1.2. The vendor shall provide updated Nessus technical scans using the DHA full safe scan policy (provided by the Government), on the 10th day of each month until an approval is granted.

1.2. The vendor device or system shall pass pre-validation technical screening

(vulnerability scans utilizing Nessus, Security Content Automation Protocol (SCAP) scans, and Security Technical Implementation Guides (STIGs) checklists) within six (6) months of contract/order award. All technical scans shall be provided by the vendor to the Government Program Manager (PM) for review and made available for COR review if required. Vendor MDE shall pass fully credentialed screening using DHA approved template. Successful pre-validation technical screening shall meet the Cybersecurity criteria listed below:

1.2.1. No unmitigated Very High or High Severity/ Category I (CAT I) vulnerabilities as described in the appropriate DISA STIGs located on https://public.cyber.mil/stigs/downloads/

1.2.2. No unmitigated Moderate Severity/Category II (CAT II) vulnerabilities described in the appropriate DISA STIGs located on https://public.cyber.mil/stigs/downloads/

1.2.3. No unmitigated Very High or High Severity/ Category I (CAT I) vulnerabilities from Nessus vulnerability scans.

1.2.4. No unmitigated Moderate Severity/ Category II (CAT II) vulnerabilities from Nessus vulnerability scans.

1.3. The vendor shall submit mitigation statements to the Government for approval for all Very High, High, and Moderate Severity/CAT I, and CAT II vulnerabilities discovered during the RMF Assessment.

1.4. For all MDE identified by the Government as requiring a full Assess and Authorize (A&A), including IV&V test, the vendor shall not make any delivery and shall not receive payment until the PMO has completed a review of submitted RMF documentation and technical results, and the IV&V has been scheduled. IV&Vs cannot be scheduled until all documentation requirements https://public.cyber.mil/stigs/downloads/ https://public.cyber.mil/stigs/downloads/

4 | P a g e and technical requirements have been completed to the PMO’s satisfaction.

Additionally, all identified Plan of Actions and Milestones (POA&Ms) must have been appropriately mitigated to reduce the risk to the Government network and Protected Health Information (PHI)/Personally Identifiable Information (PII)/Controlled Unclassified Information (CUI) data housed within the system.

Delivery may take place prior to this milestone (IV&V scheduling) only if written permission is provided by the Contracting Officer.

1.5. For all MDE identified by the Government as requiring an Assess and

Incorporate (A&I) or Assess and Use (A&U) certification, the vendor shall not make any delivery and shall not receive payment until the PMO has completed a review of submitted RMF documentation and technical results, and the system has been submitted for an approval. RMF Approval cannot be requested until all documentation requirements and technical requirements have been completed to the PMO’s satisfaction. Additionally, all identified POA&Ms must have been appropriately mitigated to reduce the risk to the Government network and PHI/PII/CUI data housed within the MDE. The vendor must receive written confirmation from the PMO or Contracting Officer that the system has been submitted for an assess only Approval and that the vendor may proceed with delivery. Delivery may take place prior to this milestone only if written permission is provided by the Contracting Officer.

1.6. The vendor shall obtain a recommendation of Approval from a Government-appointed 3rd validator within twelve (12) months of contract/order award.

1.7. Prior to final acceptance and installation, as a part of acceptance testing, the vendor shall provide procedures for the accepting sites to ensure the delivered device matches the DHA authorized configuration. The vendor shall coordinate running Nessus and SCAP scans, or the vendor prescribed alternative procedures required to validate the configuration, with the site and the assigned DHA Cybersecurity Analyst to verify compliance. Any deviations from the approved configuration will require the vendor to bring the system into compliance before final acceptance and payment.

1.8. Pursuant to warranty period and subsequent Service Maintenance Agreements

(SMAs), the vendor shall, after the issuance of an Approval, ensure that the vendor’s device or system maintains its Approval for as long as the system is installed in the DHA network. The vendor shall ensure that RMF/Cybersecurity maintenance is included in all SMA offerings.

The vendor shall maintain an Approval on all equipment/product versions, owned or operated by the DHA, and covered under this contract/order. If the vendor cannot support the Approval for all DHA contract/ordered versions of the equipment/product, the vendor can meet this requirement by offering to provide all upgrades to the equipment/product that are required to maintain the Approval, either at no cost to the Government or at a fixed price that is included in a subsequent SMA offering under the vendor’s contract/order. During the period of time the vendor’s product is installed on the DHA network, the vendor shall provide all required cybersecurity patches/updates/upgrades, including

5 | P a g e

Operating System and application upgrades where necessary. Maintaining the Approval shall be included as part of the vendor’s warranty. For updates/patches, executable files shall be distributed by the vendor accordingly, or implemented by the manufacturer’s technical staff, dependent on the contract/order processes.

1.9. The vendor shall notify the assigned DHA Cybersecurity Analyst, PMO POC, and Contracting Officer in writing of any inabilities to comply with DoD RMF/Cybersecurity requirements.

2. RMF Assessment Timeframes

2.1. Required Timeframes: The vendor and Government will complete their respective required actions within the referenced timeframes in Table 1 below, but no later than one (1) year after order/contract/order award. If the vendor has completed all required actions in a timely and acceptable manner while the Government experiences delays, the vendor would be given additional time for future actions corresponding to the amount of Government delay. Vendor failure to meet specified timelines in the table below would be considered a vendor-caused delay.

Vendor Requirements Initial Draft Date Due Final Date Due Vendor to contact Gov POC, or identified Cybersecurity Analyst (must include Contract/PO information)

5 business days post award N/A

Medical Device and Equipment Readiness Assessment (MDERA, Hardware/Software/ Architecture Documents

15 business days post award

20 business days post award

RMF Documentation Production 30 Business Days post award

88 Business Days post award

Technical Nessus Scans 20 Business Days post award

130 Business Days post award

Technical STIG Checklists 20 Business Days post award

130 Business Days post award

Technical SCAP 20 Business Days post award

130 Business Days post award

Table 1 - Required Timeframes

2.2 Informational Overview of the RMF Process: The following diagrams, Figure 1 and Figure 2, provide a summary overview of the entire process to obtain approval under DHA RMF/Cybersecurity requirements. These diagrams are for informational purposes only and are subject to change without notice.

6 | P a g e

Figure 1 Assess and Authorize Process

7 | P a g e

2.3 A&I process specifically tailors the RMF process to MDE based on the unique system characters associated with these medical devices and systems. The process defines the method to identify in-scope MDE, and the necessary steps to assess and incorporate the MDE into an authorized DHA managed enclave (authorization boundary).

Figure 2 Assess and Incorporate/Assess and Use Process

Note: Not all above actions occur in a sequential manner, as some actions may be worked concurrently.

3. Business to Business (B2B) Connectivity Requirements

If a vendor requires a B2B connection, or remote access to government networks in order to maintain, analyze, or otherwise support its equipment/product, the vendor shall adhere to the following requirements:

8 | P a g e

3.1. Information Assurance contract/order Training and Certification. Contractors requiring a privileged-level account for administrative/maintenance support of systems/applications on the DHA network will meet DHA requirements for a privileged-level account before being granted a network account. Requirements include:

3.1.1. Cyber (IA/IT) certification. Per DoD Manual 8140.03 and DFARS

252.239.7001, the contractor personnel supporting Cyber (IA/IT) functions shall be appropriately certified upon contract award.

Contractors will be defined at Information Assurance Technical Level I (IAT Level I) and be required to meet minimum Professional Baseline certifications at the time of contract/order award. Contractors will be given six (6) months to meet Computer Environment (CE) and Cyber Security Fundamental training requirements. Not meeting the requirements in accordance with DoDM 8140.03 will result in the contractor account and access being ‘Disabled’ or ‘Deleted’ until such time as those conditions are met.

3.1.2. Background Investigation. Tiered investigation based on role requirements (for more information see https://www.dcsa.mil/Portals/91/Documents/pv/fso/Tier_Investigations.p df).

3.1.3. Professional Baseline Certification. The minimum Professional Baseline certification for IAT-II are: CCNA Security, CompTIA Cyber Security+.

Higher certifications (GSCL, CISM, CISSP, CASP+, etc.) will satisfy this requirement.

3.1.4. CE Certification. The CE certifications are determined by the role of the contractor and shall be met within six (6) months of contract or order issuance in accordance with DoD 8140.03.

3.1.5. Two-Factor Authentication. Contractors will authenticate to the B2B gateway using two-factor authentication. The only methods for authenticating are the Common Access Card (CAC) and NIPRNet Enterprise Alternate Token System (NEATS) tokens.

3.1.6. Network Account Request Package (Authorized & Privileged). The contractor will submit a request package through either the facility Provost Marshall Office in conjunction with the facility Information Management Department (for contractors requiring on-site access), or through the Information Assurance/Cyber Security Branch (for contractors requiring remote access to a DHA network). Remote access shall be through a DHA B2B solution.

3.1.7. Cybersecurity Training. DoD Cyber Awareness Challenge Training shall be completed by all contractor personnel and associated subcontractor personnel prior to issuance of network access and annually thereafter.

9 | P a g e

DoD Cyber Awareness Challenge Training is available at the following website: https://public.cyber.mil/cyber-training/training-catalog/?_training_topics=cybersecurity-awareness-courses

3.1.8. PII Training. DoD PII Training shall be completed by all contractor personnel and associated sub-contractor personnel prior to issuance of network access and annually thereafter. DoD PII Training is available at the following website: https://public.cyber.mil/cyber-training/training-catalog/?_training_topics=cybersecurity-awareness-courses

3.1.9. Health Insurance Portability and Accountability Act (HIPAA) Training.

DoD HIPAA Training shall be completed by all contractor personnel and associated subcontractor personnel prior to issuance of network access and annually thereafter. DoD HIPAA Training is available at the following website:

https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf?ORG=MHS

3.1.10. Acceptable Use Policy (AUP). All vendors/contractors shall sign/acknowledge the DHA Standard Acceptable Use Policy (AUP) prior to being granted a DHA network account. The DHA Standard AUP is available at the following website: https://health.mil/Reference- Center/Policies?query=Acceptable%20Use

4. Warranty and Post-Warranty Service Maintenance Agreement RMF/Cybersecurity

Requirements/Continuous Monitoring/Risk Management.

During the initial warranty period of the device, the vendor is responsible for ensuring a continued positive security posture through DHA mandated Continuous Monitoring activities. Continuous Monitoring requires software updates/upgrades, patch management, application of DoD required security configurations via Security Technical Implementation Guides (STIGs), vulnerability scanning, and remediation of discovered vulnerabilities.

Post warranty cybersecurity maintenance will be covered in subsequent Service Maintenance Agreements.

4.1. In accordance with SEC. 524B. of the ‘Consolidated Appropriations Act, 2023’ titled ENSURING CYBERSECURITY OF DEVICES, the vendor shall design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available post-market updates and patches to the device and related systems on a reasonably justified regular cycle, or as soon as possible for critical vulnerabilities that could cause uncontrolled risks. The vendor shall disclose if patching can be accomplished by the government, or if a specialized support is required to maintain a compliant cybersecurity posture.

4.2. The vendor shall establish and maintain a test/laboratory environment that includes all contract/ordered equipment, to include 3rd party components that fall under the authorization boundary, and/or included in this contract/order, to https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf?ORG=MHS https://health.mil/Reference-Center/Policies?query=Acceptable%20Use https://health.mil/Reference-Center/Policies?query=Acceptable%20Use https://health.mil/Reference-Center/Policies?query=Acceptable%20Use

10 | P a g e support the RMF/Cybersecurity requirements. The vendor test lab shall be used for all self-assessment activities, Independent Verification and Validation (IV&V) compliance testing, and post Authority to Operate (ATO), or RMF Approval (herein referred to as Approval) actions for as long as the system is supportable by the vendor. Supportable is defined as serviceable by a qualified Service Engineer or Original Equipment Manufacturer (OEM).

4.3. The vendor shall update all ATO or approved products required supporting documentation in the event of a system policy, procedural, logical, or technical change to the system or device.

4.4. The vendor shall maintain the authorized security configuration and notify the government for approval prior to instituting changes to devices installed within the DHA network. A major upgrade such as major software or hardware revision must be reassessed for RMF Compliance, or addition to the approved products list. Minor upgrades must be assessed by the Government to determine if a reauthorization is required. The vendor shall support reauthorizations due to both major and minor upgrades.

4.5. The vendor shall ensure its device or system is in compliance with the DoD IAVM program upon each deployment.

4.6. The vendor shall ensure any deployment post acceptance (including rebuilds) deploys with a fully-patched, approved version. Prior to final acceptance and installation, the vendor shall coordinate running Nessus and SCAP scans, or the vendor prescribed alternative procedures required to validate the configuration, with the site and the assigned DHA Cybersecurity Analyst to verify compliance. Any deviations from the approved configuration shall require the vendor to bring the system into compliance prior to final acceptance and putting the system in operation.

4.7. The vendor shall maintain the system or device and update to comply with updated STIGs made available by the Government within three (3) months of notification by the Government.

4.8. The vendor shall provide vulnerability and configuration scan results using Nessus and the DHA policy to the Government monthly, providing raw scan results and administrative reports no later than the tenth (10th) calendar day of each month.

4.9. The vendor shall close all discovered vulnerabilities or shall submit to the Government for approval POA&Ms outlining mitigation and timelines for closing any open vulnerabilities within one (1) month of discovery.

4.10. The vendor shall review all required policies, plans, and procedures documentation on an annual basis and submit changes to the Government for approval.

4.11. The vendor shall use the Government-approved method for remote access administration (DHA B2B) of the system or device.

11 | P a g e

5. Cybersecurity Regulations and Guidance

1) Cybersecurity Regulations and Guidance

The vendor shall use and comply with the most recent published versions of the following references, as well as all regulations or guidance referenced within those publications:

(a) United States Law

(i) The Health Insurance Portability and Accountability Act of 1996

(HIPAA)

(ii) The Federal Information Security Management Act (FISMA)

(iii) The E-Government Act of 2002

(iv) H.R.2617—Consolidated Appropriations Act, 2023

(b) OMB

(i) Circular A-130

(ii) Guidance M-05-24, Implementation of Homeland Security Presidential

Directive (HSPD) 12—Policy for a Common Identification Standard for Federal Employees and Vendors

(c) National Institute of Standards and Technology (NIST)

(i) NIST Special Publication (SP) 800-37 Rev. 2—Guide for Applying the RMF to Federal Information Systems

(ii) NIST SP 800-39—Managing Information Security Risk: Organization, Mission and Information System View

(iii) NIST SP 800-53 Rev. 5—Security and Privacy Controls for Federal Information Systems and Organizations

(iv) NIST SP 800-60—Volume 1 Revision 1: Guide for Mapping Types of Information and Information Systems to Security Categories

(d) Federal Information Processing Standards (FIPS)

The following publications are located at

(i) FIPS Publication (FIPS PUB) 140-2, Security Requirements for

Cryptographic Modules

(ii) FIPS PUB 199, Standards for Security Categorization of Federal

Information and Information Systems

(iii) FIPS PUB 200, Minimum Security Requirements for Federal

Information and Information Systems

(iv) FIPS PUB 201-3, Personal Identity Verification of Federal Employees and Vendors

(e) DoD

(i) DoD Instruction 5200.02, DoD Personnel Security Program (PSP)

(ii) DoD Instruction 8500.01, Cybersecurity

(iii) DoD Instruction 8520.02, Public Key Infrastructure (PKI) and Public

Key (PK) Enabling

12 | P a g e

(iv) DoD Instruction 8510.01, RMF

(v) DoD Instruction 8551.01, Ports, Protocols, and Services Management

(PPSM)

(vi) DoD Instruction 8580.02, Security of Individually Identifiable Health

Information in DoD Health Care Programs

(vii) DoD Instruction 6025.18, Privacy of Individually Identifiable Health

Information in DoD Health Care Programs

(viii) DoD Directive 5400.11, DoD Privacy Program

13 | P a g e

A. General Defense Health Agency (DHA) Medical Device and Equipment (MDE) Cybersecurity/Risk Management Framework (RMF) Contracting Requirements
1. New MDE and Software Purchases RMF Requirements:
B. DHA Cybersecurity/RMF Acceptance/MDE Delivery Requirements
1. System Security Requirements
2. RMF Assessment Timeframes
3. Business to Business (B2B) Connectivity Requirements
4. Warranty and Post-Warranty Service Maintenance Agreement RMF/Cybersecurity Requirements/Continuous Monitoring/Risk Management.
5. Cybersecurity Regulations and Guidance
1) Cybersecurity Regulations and Guidance

File details come from the government source that posted it. Updated .