Attachment 17 - Handbook - 6500.6.pdf

PDF 737 KB Posted

Attached to
Y1DA--EHRM Infrastructure Upgrade Construction Fort Meade VAMC Federal contract opportunity
Solicitation number
36C77622B0055
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This document package includes an attachment describing a federal contract opportunity and the related solicitation. The solicitation calls for upgrades to the EHRM infrastructure at the Fort Meade VAMC, including construction services. The solicitation was issued by the Department of Veterans Affairs Technology Acquisition Center in Austin. The period of performance and response deadline are not specified. The contracting agency and location of work indicate the incumbent is the Department of Veterans Affairs.

View the file

Other files for this federal contract opportunity

Show all 23

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Department of Veterans Affairs VA HANDBOOK 6500 Washington, DC 20420 Transmittal Sheet

February 24, 2021

RISK MANAGEMENT FRAMEWORK FOR VA INFORMATION SYSTEMS

VA INFORMATION SECURITY PROGRAM

1. REASON FOR ISSUE: Reissue handbook to provide policy and procedural guidance on the VA Risk Management Framework (RMF) process. Reissues VA Handbook 6500 to align with VA policy in VA Directive 6500, VA Cybersecurity Program.

2. SUMMARY OF CONTENTS/MAJOR CHANGES:

a. VA Handbook 6500 addresses all steps of the RMF as defined in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37 Revision 2;

b. Incorporates content from VA Handbook 6500.3, Assessment, Authorization and Continuous Monitoring of VA Information Systems; and

c. Removes security and privacy control descriptions, baselines, and organization-defined parameters, which is in the Information Security Knowledge Service.

3. RESPONSIBLE OFFICE: The Office of the Assistant Secretary for Information and Technology (005), Office of Information Security (005R), is responsible for this Handbook.

4. RELATED DIRECTIVE: VA Directive 6500, VA Cybersecurity Program.

5. RESCISSIONS: VA Handbook 6500, Risk Management Framework for VA Information

Systems – Tier 3: VA Information Security Program, dated March 10, 2015, and its appendices, and VA Handbook 6500.3, Assessment, Authorization and Continuous Monitoring of VA Information Systems, dated February 3, 2014.

CERTIFIED BY:

/s/ John P. Medve Acting Assistant Secretary for Enterprise Integration

BY DIRECTION OF THE SECRETARY OF

VETERANS AFFAIRS:

/s/

Dominic A. Cussatt Acting Assistant Secretary for Information and Technology/ Chief Information Officer

DISTRIBUTION: Electronic Only

VA Handbook 6500 February 24, 2021

CONTENTS

PARAGRAPH PAGE

1. PURPOSE

2. SCOPE

3. BACKGROUND/OVERVIEW

4. RESPONSIBILITIES

(1) Assistant Secretary for Information and Technology/

(2) Office of Information Technology (OIT) Deputy Assistant Secretary for Information Security

(3) Executive Director for Office of Acquisitions, Logistics, and Construction

(4) OIT Deputy Assistant Secretary for Development,Security and Operations (DAS DevSecOps),

(5) OIT Associate Deputy Assistant Secretary for Enterprise Program Management Office

(6) OIT Associate Deputy Assistant Secretary for Information Technology Operations and Services (ADAS ITOPS)

(7) Under Secretaries, Assistant Secretaries and Other Key Officials

(8) Senior Agency Official for Privacy (SAOP)

(9) VA Enterprise Architect shall:

(10) Risk Management Framework Technical Advisory Group (RMF TAG) shall

(11) Information System Security Officer (ISSO)

(12) Information System Security Manager

(13) Authorizing Officials (AOs)

(14) Authorizing Official Designated Representative

(15) Information System Owner

(16) Chief Privacy Officer

(17) Privacy Officer

(18) Information System Security Engineer

(19) Security Control Assessors

(20) Information Security Architect

(21) Risk Executive Function………………………………………………………………20

CONTENTS, cont.

PARAGRAPH PAGE

5. RISK MANAGEMENT OF INFORMATION TECHNOLOGY PRODUCTS, SERVICES,

AND PLATFORM INFORMATION TECHNOLOGY

6. PROCEDURES

(1) PREPARE

(2) CATEGORIZE SYSTEM

(3) SELECT SECURITY CONTROLS

(4) IMPLEMENT SECURITY CONTROLS

(5) ASSESS SECURITY CONTROLS

(6) AUTHORIZE SYSTEM

(7) CONTINUOUS MONITORING

CONTENTS, cont.

APPENDICES PAGE

APPENDIX A. Terms and Definitions ..................................................................................... A-1 APPENDIX B. Acronyms and Abbreviations ........................................................................ B-1 APPENDIX C. References ........................................................................................................ C-1

APPENDIX D. High-Level Summary of RMF Tasks.............................................................. D-1 Table 1: Prepare Tasks—Organization Level ..................................................................... D-1

Table 2: Prepare Tasks—System Level.............................................................................. D-4

Table 3: Categorize Tasks ................................................................................................. D-10

Table 4: Select Tasks and Outcomes ............................................................................... D-12

Table 5: Implement Tasks and Outcomes ........................................................................ D-16

Table 6: Assess Tasks and Outcomes.............................................................................. D-17

Table 7: Authorize Tasks and Outcomes .......................................................................... D-20

Table 8: Monitor Tasks and Outcomes ............................................................................. D-23

FIGURES PAGE

Figure 1: VA IT Resources

Figure 2: VA Risk Management Framework Steps

TABLES PAGE

Table 1: Appointment of RMF Roles

VA INFORMATION SECURITY PROGRAM

1. PURPOSE.

a. Updates VA Handbook 6500 to align with VA policy in VA Directive 6500, VA

Cybersecurity Program;

b. Establishes associated cybersecurity policy and assigns responsibilities for executing and maintaining the Risk Management Framework (RMF);

c. Directs visibility of authorization documentation and reuse of artifacts between and among VA Information Technology (IT) stakeholders; and

d. Provides procedural guidance for the reciprocal acceptance of authorization decisions and artifacts within VA and between VA and other Federal agencies, for the authorization and connection of information systems.

2. SCOPE.

a. The VA Handbook 6500 satisfies the Federal and statutorily requirements of:

(1) Federal Information Security Modernization Act (FISMA);

(2) U.S. Code (U.S.C) title 38, Veterans’ Benefits Act, Subchapter III - Information

Security;

(3) National Institute of Standards and Technology (NIST) Special Publication (SP) 800- 37, Risk Management Framework for Information Systems and Organizations, A System Life Cycle Approach for Security and Privacy;

(4) Office of Management and Budget (OMB) Circular A-130;

(5) The Privacy Act of 1974;

(6) Health Insurance Portability and Accountability Act of 1996 (HIPAA); and

(7) The Health Information Technology for Economic and Clinical Health (HITECH) Act.

b. This handbook serves all Administrations, Staff Offices, Staff Organizations, Boards, and Special Programs of the Department of Veterans Affairs associated with the design, development, implementation, assessment, operation, maintenance, and disposition of information systems including:

(1) Individuals with mission or Business Ownership responsibilities or fiduciary responsibilities (e.g., heads of Federal agencies);

(2) Individuals with information system, information security, or privacy management, oversight, or governance responsibilities (e.g., senior leaders, Risk Executives, Authorizing Officials (AOs), Chief Information Officers (CIO), Chief Information Security Officers (CISOs), and Senior Agency Officials for Privacy (SAOP));

(3) Individuals responsible for conducting security or privacy assessments and for monitoring information systems, for example, Control Assessors, auditors, and

System Owners;

(4) Individuals with security or privacy implementation and operational responsibilities, for example, System Owners, Common Control Providers, Information Owners/Stewards, mission or Business Owners, Security or Privacy Architects, and

Information System Security or Privacy engineers;

(5) Individuals with information system development and acquisition responsibilities (e.g., Program Managers, Procurement Officials, component product and system developers, Systems Integrators, and Enterprise Architects); and

(6) Individuals with logistical or disposition-related responsibilities (e.g., Program Managers, Procurement Officials, System Integrators, and Property Managers).

c. All VA IT that receive, process, store, display, or transmit VA information. These technologies are broadly grouped as VA Information Systems, Platform IT, cyber-physical systems, IT services, and IT products. This includes IT supporting research, development, test and evaluation, and IT operated by a contractor or other entity on behalf of VA.

d. Nothing in this handbook alters or supersedes the existing authorities and policies of VA and other Federal laws and regulations.

3. BACKGROUND/OVERVIEW.

a. VA will establish and use a multi-level risk management approach that addresses security and privacy risk at the organization level, the mission/business process level, and the information system level. VA’s approach in this handbook is consistent with the principles described in NIST SP 800-39, Managing Information Security Risk:

Organization, Mission, and Information System View.

b. The forms of VA IT, as shown in Figure 1, range in size and complexity. The forms encompass individual hardware and software products, stand-alone systems, massive computing environments, enclaves, and networks.

Figure 1: VA IT Resources

c. The risk management for VA IT will be conducted as described in this handbook and consistent with the principals established in NIST SP 800-37. The RMF consists of the steps and depicted in Figure 2.

Figure 2: VA Risk Management Framework Steps

d. The RMF will inform the system development life cycle (SDLC) by addressing security and privacy requirements for all VA IT. The relationship between the RMF and SDLC is summarized in Appendix D, High-level Summary of RMF Tasks.

4. RESPONSIBILITIES.

a. VA Directive 6500 describes the responsibilities for VA senior officials, information owners, information system users, and the Office of Inspector General for information security. Each subordinate VA directive and handbook issued by the Office of Information Security will support the overall VA information security program and will include definitive roles and responsibilities for specific security control families that will require additional responsibilities to protect VA information and information systems.

b. Table 1 identifies the RMF roles assigned at VA and the appropriate authority for the appointment of each RMF role.

Table 1: Appointment of RMF Roles

Role Appointed By

Chief Information Officer Secretary

Senior Agency Official for Privacy Secretary

Chief Information Security Officer Chief Information Officer

Authorizing Official Chief Information Officer

Risk Executive Function Chief Information Officer

Chief Privacy Officer Senior Agency Official for Privacy

Information System Security Officer Under Secretary

Information Security Architect Under Secretary

Information System Security Engineer Under Secretary

Security Control Assessor Chief Information Security Officer

Authorizing Official Designated Representative Authorizing Official

Information System Owner Associate Deputy Assistant Secretary for Enterprise Program Management Office

Deputy Assistant Secretary for Information Technology Operations and Services

Privacy Officer Chief Privacy Officer

Risk Management Framework Technical Advisory Group Representative

Under Secretaries, Assistant Secretaries and Other Key Officials

c. Additional roles and responsibilities with significant information and information security responsibilities necessary for implementing VA’s RMF include the following:

(1) Assistant Secretary for Information and Technology/Chief Information Officer (CIO) shall:

(a) Oversee implementation of this handbook, direct and oversee the cybersecurity risk management of VA IT, and distribute RMF information standards and sharing requirements;

(b) In coordination with the Deputy Assistant Secretary for Development, Security and Operations (DAS DevSecOps), the Associate Deputy Assistant Secretary for

Enterprise Program Management Office (ADAS EPMO) and the Associate Deputy Assistant Secretary for Information Technology Operations and Services (ADAS ITOPS), ensure development testing, evaluation and operational testing, and evaluation activities and findings are integrated into the RMF;

(c) Ensure trained and qualified AOs are appointed in writing for all VA information systems and platform IT systems operating within or on behalf of VA in accordance with VA Directive 6500 and that the systems are authorized in accordance with this handbook:

i. The AO role must be assigned to government personnel only; and

ii. Relevant IT expertise must be a factor in the selection and appointment of AOs responsible for authorizing IT systems.

(2) Office of Information Technology (OIT) Deputy Assistant Secretary for

Information Security. The Deputy Assistant Secretary (DAS) for Information Security, as the Chief Information Security Officer (CISO) under the authority, direction, and control of the VA CIO, shall:

(a) Direct and coordinate the VA Cybersecurity Program, which includes the establishment and maintenance of the RMF. In addition, the VA CISO oversees the Risk Management Framework Technical Advisory Group (RMF TAG) and the Information Security Knowledge Service;

(b) Provide guidance at a design and architectural level for Information System

Security Engineering services;

(c) Inform VA Office of Acquisition, Logistics, and Construction (OALC) of acquisition program risks related to failure in addressing cybersecurity requirements in accordance with the VA Cybersecurity Program;

(d) Assist in development of VA Architecture and Engineering to support the RMF (and indirectly authorization decisions);

(e) Ensure that security controls and assessment procedures used by VA are consistent with control correlation identifiers (CCIs), security requirements guides, security technical implementation guides (STIGs), and NIST;

(f) Support development and providing RMF training and awareness products and a distributive training capability to support VA IT, and post the training materials on the Information Security Knowledge Service; and

(g) Identify, develop and provide VA Enterprise RMF management tools.

(3) Executive Director for Office of Acquisitions, Logistics, and Construction (OALC) shall coordinate with the VA CIO to ensure RMF processes are appropriately integrated with VA acquisition system processes for acquisitions of VA

IT.

(4) OIT Deputy Assistant Secretary for Development, Security and Operations (DAS DevSecOps), in coordination with the VA CIO, ADAS EMPO and ADAS ITOPS ensures development testing and evaluation, and operational testing and evaluation activities and findings are integrated into the RMF.

(5) OIT Associate Deputy Assistant Secretary for Enterprise Program Management Office (ADAS EPMO) ensures integration of development testing and evaluation activities into the RMF and provides the RMF TAG with input as appropriate or required, and shall:

(a) Ensure integration of development testing and evaluation activities into the RMF and provide the RMF TAG with input as appropriate or required;

(b) Develop risk model and risk assessment tools to help ensure that VA programs and projects are reviewed by the approving authority for alignment with the VA

Technical Reference Model;

(c) Ensure that information security requirements necessary to protect the organization’s core mission and business processes are adequately addressed in all aspects of enterprise architecture, including reference models, segment and solution architectures, and the resulting information systems supporting those mission and business processes;

(d) Assist in development of VA architecture and engineering to support the RMF (and indirectly, authorization decisions); and

(e) IT Workforce Development supporting development and providing RMF training and awareness products in a distributive training capability to support VA IT and post the training materials on Information Security Knowledge Service.

(6) OIT Associate Deputy Assistant Secretary for Information Technology

Operations and Services (ADAS ITOPS), under the authority, direction, and control of the VA CIO, shall:

(a) Review plans and results of operational testing to ensure adequate evaluation of cybersecurity for all VA IT acquisitions subject to oversight;

(b) In coordination with VA CIO, ensure integration of IT operations and services activities into the RMF and provide the RMF TAG with input as appropriate or required; and

(c) Verify that an Information System Owner is appointed for all information systems and platform IT systems.

(7) Under Secretaries, Assistant Secretaries and Other Key Officials shall:

(a) Ensure that all VA information system and platform IT systems are categorized according to the guidelines provided in this handbook;

(b) Develop and issue guidance for platform IT systems that reflects operational and environmental demands as needed;

(c) Ensure VA IT under their authority comply with the RMF;

(d) Ensure participation in the RMF TAG; and

(e) Ensure that contracts and other agreements include specific IT security requirements in accordance with this handbook.

(8) Senior Agency Official for Privacy (SAOP) shall:

(a) Review and approve, in accordance with Federal Information Processing Standard (FIPS) Publication 199 and NIST SP 800-60, the categorization of information systems that create, collect, use, process, store, maintain, disseminate, disclose, or dispose of Personally Identifiable Information (PII);

(b) Review the authorization package for information systems that create, collect, use, process, store, maintain, disseminate, disclose, or dispose of PII, to ensure that privacy risks are managed prior to system authorization; and

(c) Determine whether additional measures are required to manage privacy risks prior to leveraging the authorization.

(9) VA Enterprise Architect shall:

(a) Be responsible for strategies, standards, and plans that have been developed for achieving an assured, integrated, and survivable information enterprise;

(b) Provide guidance at a design and architectural level for information system security engineering service;

(c) Assist in the development of VA architecture and engineering to support the RMF and indirectly, authorization decisions); and

(d) Advise AOs, Information System Security Officers, and the Risk Executive Function on a range of security-related issues including, for example, information system boundaries, assessing severity of information system weaknesses and deficiencies, Plan of Action and Milestones (POA&M), risk mitigation approaches, security alerts, and potentially adverse effects of identified vulnerabilities

(10) Risk Management Framework Technical Advisory Group (RMF TAG) will provide implementation guidance for the RMF by interfacing with VA IT, cybersecurity community of interest, and other entities. The RMF TAG shall:

(a) Provide detailed analysis and authoring support for the Information Security Knowledge Service;

(b) Recommend changes to security controls, security control baselines, VA assignment values, associated implementation guidance, and assessment procedures to the VA CIO;

(c) Recommend changes to cybersecurity risk management processes to the VA

CIO;

(d) Advise VA forums established to resolve RMF priorities and cross-cutting issues;

(e) Develop and manage automation requirements for VA services that support the RMF; and

(f) Develop guidance for facilitating RMF reciprocity throughout VA.

(11) Information System Security Officer (ISSO) has authority and responsibility to establish and manage a coordinated security assessment process for information technologies governed by the VA cybersecurity program and shall:

(a) Review and recommend guidance of the RMF within the VA cybersecurity program;

(b) Track the assessment and authorization status of information systems and platform IT systems governed by the VA cybersecurity program;

(c) Identify and recommend changes and improvements to the security assessment process, security test and evaluation, and risk assessment methodology, including procedures, risk factors, assessment approach, and analysis approach to the RMF TAG for inclusion in the Information Security Knowledge Service;

(d) Serve as the single cybersecurity coordination point for joint or VA-wide programs that are deploying information technologies to VA enclaves;

(e) Maintain and report information system and platform IT systems assessment and authorization status and issues in accordance with VA guidance;

(f) Coordinate with the information system security manager to ensure security issues are addressed appropriately;

(g) Collect and maintain data as needed to meet system cybersecurity reporting;

(h) Communicate the value of IT security throughout all levels of the organization stakeholder;

(i) Maintain cooperative relationships with business partners or System Owners of other interconnected systems;

(j) Verify and validate, in conjunction with the Information System Owners and managers, that appropriate security measures are implemented and functioning as intended;

(k) Ensure that protection and detection capabilities are acquired or developed within Area of Responsibility (AOR) using the information system security engineering approach and that these capabilities are consistent with organization-level cybersecurity architecture;

(l) Manage local information security programs and serve as the principal security advisor to Information System Owners regarding security considerations in applications, systems, procurement or development, implementation, operation, maintenance, and disposal activities (i.e., SDLC management);

(m) Identify alternative information compensating controls to address organizational security objective;

(n) Identify IT security program implications of new technologies or technology upgrades;

(o) Interpret and recommend security requirements relative to the capabilities of new information technologies;

(p) At a local level, interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise cybersecurity program;

(q) Monitor information security data sources to maintain organizational situational awareness;

(r) Monitor the system and its environment of operation in close coordination with the Information System Owner;

(s) Monitor compliance with the security awareness training requirements for each employee and contractor;

(t) Serve as the liaison to the VA Training Manager to ensure security awareness training is provided within their AOR;

(u) Coordinate, monitor, and conduct periodic reviews to ensure compliance with the VA National or Contractor Rules of Behavior (RoB) requirement for users of VA information systems and VA information;

(v) Collaborate with the VA Identity Safety Service to provide training on identity theft; fraud prevention and mitigation; and to assist in the prevention and mitigation of potential identity theft and fraud;

(w) Participate in security self-assessments, external and internal audits of system safeguards and program elements, and in Assessment & Authorization (A&A) of the systems supporting the offices and facilities within their AOR;

(x) Assess the security impact of system changes and providing recommendations of those changes;

(y) Collaborate in the development and maintenance of information System Security Plan (ISSP) and system risk analysis in coordination, advisement, and participation with the System Owner;

(z) Provide cybersecurity and supply chain risk management guidance within AOR for the development of Continuity of Operations Plans (CONOPs);

(aa) Ensure that cybersecurity awareness and training are provided to IT personnel commensurate with their responsibilities, and Rules of Behavior (RoB) are signed in accordance to cybersecurity guidelines, processes and requirements;

(bb) Provide system-related input on cybersecurity requirements to be included in statements of work and other appropriate procurement documents, as appropriate;

(cc) Define and provide security and privacy requirements for the system, and the environment of operation to the System Owner;

(dd) Recognize and notify the VA-CSOC of any confirmed or suspected incident within one hour of discovery of the potential incident and assisting in the investigation, if necessary, in accordance with VA policy;

(ee) Recommend resource allocations required to securely operate and maintain an organization's cybersecurity requirements;

(ff) Recommend and assist in the development of local security policies and procedures, coordinate review and approval of those policies and procedures, and review compliance;

(gg) Responsible for assisting in physical and environment protection and personnel security and managing corrective measures as the result of a cybersecurity incident or discovery of a vulnerability;

(hh) Ensure compliance with Federal security requirements and VA security policies;

(ii) Collaborate with facility Privacy Officers and others as appropriate for the implementation and assurance of reasonable safeguards as required by the

Privacy Act, the HIPAA Privacy and Security Rules, and other Federal privacy statutes;

(jj) Assist in the determination of the appropriate security categorization of the IT system commensurate with the FIPS 200 impact level;

(kk) Promote awareness of local security issues among management and ensure sound security principles are reflected in the organization's vision and goals;

(ll) Oversee local policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies;

(mm) Participate in the Risk Governance process to provide security risks, mitigations, and input on other technical risk;

(nn) At a local level, evaluate the effectiveness of the procurement function in addressing information security requirements, and supply chain risks through procurement activities and recommend improvements;

(oo) Work with System Owner to forecast ongoing service needs to ensure security assumptions are integrated appropriately; and

(pp) Ensure that security policies and procedures are integrated into the System

Security Plan and Risk Analysis processes and documents for the protection of critical dependencies (heating, ventilation & air conditioning (HVAC), electricity, water, sewage, badging etc.).

(12) Information System Security Manager (ISSM) advises appropriate AO of changes affecting the VA's cybersecurity posture and shall:

(a) In coordination with key stakeholders, assist with the creation of the organization's information security plans and policies;

(b) In coordination with Information System Owners, evaluate cost/benefit, economic, and risk analysis in decision-making process;

(c) Report the security and privacy posture of the system to the AO and other organizational officials on an ongoing basis in accordance with VA RMF strategy;

(d) Provide guidance when it comes to analyzing and evaluating networks and security vulnerabilities, and managing security systems such as anti-virus, firewalls, patch management, intrusion detection, and encryption daily;

(e) Coordinate with organizational managers to ensure a coherent, coordinated, and holistic approach to security across the operational units;

(f) Ensure that cybersecurity inspections, tests, and reviews are coordinated for the network environment;

(g) At all levels of the organization, interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program;

(h) Ensure that security improvement actions are evaluated, validated, and implemented as required;

(i) Participate in an information security risk assessment during the Security

Assessment and Authorization process; and

(j) Define the operating unit's information security compliance/assessment program to include the development, management, and reporting of POA&Ms.

(13) Authorizing Officials (AOs) are selected from senior leadership positions within business owner and mission owner organizations to promote accountability in authorization decisions that balance mission and business needs and security concerns. AOs shall:

(a) Review security and business risk and provide risk-based decisions (acceptance or rejection) on behalf of the Department;

(b) Ensure all appropriate RMF tasks are initiated and completed, with appropriate documentation, for assigned information systems and platform IT systems;

(c) Monitor and tracking overall execution of CCI-level POA&M;

(d) Promote reciprocity to the maximum extent possible; but

(e) Not delegate authorization decisions to the AO designated representative.

(14) Authorizing Official Designated Representative (AODR), acting on behalf of the

AO shall:

(a) Review security and business risks and make risk-based decision recommendations for AO consideration;

(b) Coordinate and conduct the day-to-day activities associated with managing risk to information systems and organizations;

(c) Carry out many of the activities of the AO related to the execution of the RMF;

however

(d) The only activity that cannot be delegated by the AO to the designated representative is the authorization decision and signing of the associated authorization decision document (i.e., the acceptance of risk).

(15) Information System Owner, in alignment with the AO chain of command for the Department, must have a full understanding of the SDLC process and shall:

(a) Receive security assessment results from the assessor to ensure accuracy, take appropriate steps to reduce or eliminate vulnerabilities, and submit completed authorization packages to AO for adjudication;

(b) Obtain an ISSO for each assigned information system or platform IT system with the support, authority, and resources to satisfy the responsibilities established in this handbook;

(c) Categorize systems in accordance with FIPS 199 and document the categorization in the appropriate document;

(d) Assist in the overall development, maintenance, and tracking of the security plan for assigned information system and platform IT systems, to include identification of applicable CCIs (Common security controls owner performs this function for inherited controls.);

(e) Monitor the implementation and compliance of the VA approved Continuous Monitoring strategy for the system;

(f) Ensure that accurate documentation of asset identification and authorization boundaries are properly identified, monitored, and maintained;

(g) Based on guidance from the AO, the Information System Owner informs appropriate organizational officials of the need to conduct the security authorization, ensures that the necessary resources are available for the effort, and provides the required information system access, information, and documentation to the security control assessor;

(h) Report the security and privacy posture of the system to the AO and other organizational officials in accordance with the organizational continuous monitoring strategy;

(i) Address the operational interests of the user community (i.e., users who require access to the system to satisfy mission, business, or operational requirements);

(j) Conduct initial remediation actions on the controls and reassess remediated controls;

(k) Based on guidance from AO, the Information System Owner informs appropriate organizational officials of the need to conduct security authorization;

(l) Lead in the development and maintenance of contingency/continuity plans and system risk analysis for all systems within their area of responsibility in coordination, advisement, and participation with the ISSO;

(m) Lead and/or assist in the procurement, development, integration, modification, operation, maintenance, and disposal of an information system;

(n) Evaluate cost/benefit, economic, and risk analysis in decision-making process;

(o) Periodically repeat selected test procedures from the system’s security authorization to ensure the security controls continue to operate effectively at the proper levels of assurance per NIST guidance and over the life cycle of the system;

(p) Ensure that all VA employees in their respective organizations complete required security and privacy awareness training initially and annually thereafter and ensure employees complete role-based training as required by their specific duties/responsibilities;

(q) Participate in self-assessments, external and internal audits of system safeguards and program elements, including A&A of the system;

(r) Participate in risk assessments by coordination, advisement, and reviews as outlined in the System Security Plan;

(s) Ensure cybersecurity requirements from the ISSO are incorporated within environment of operation for the system;

(t) Recognize and notify the responsible ISSO and Privacy Officer of any suspected incidents within one hour upon discovery and assist in the investigation of incidents if necessary;

(u) Identify requirements for resources needed to effectively implement technical security controls;

(v) In coordination with the ISSO, forecast ongoing service needs to ensure security assumptions are integrated appropriately; and

(w) Integrate security policies and procedures into continuity/contingency planning documents for the protection of critical dependencies (HVAC, electricity, water, sewage, badging etc.).

(16) Chief Privacy Officer shall assist in the development of the system-level privacy policies and procedures, and ensure compliance with VA privacy policies and procedures.

(17) Privacy Officer shall:

(a) Assist in the development of the system-level privacy policies and procedures, and ensure compliance with VA privacy policies and procedures;

(b) Monitor a system and its environment of operation to include developing and updating privacy plans, working in conjunction with the ISSO; and

(c) In coordination with the Information System Owner, ISSO and other Privacy Services Office stakeholders, assess and submit a Privacy Impact Assessment

(PIA) and Privacy Threshold Analysis (PTA) when required.

(18) Information System Security Engineer shall:

(a) Capture and refine security requirements for systems and ensure that the requirements are effectively integrated into systems and system elements through security or privacy architecting, design, development, and configuration;

and

(b) Implement any activity associated with protecting information and information systems from unauthorized system activity or behavior to provide confidentiality, integrity, and availability.

(19) Security Control Assessors are appointed under the CISO and shall:

(a) Conduct an onsite assessment of the security controls employed within or inherited by an information system to determine the overall effectiveness of the controls (i.e., to determine if the documented controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements identified for protecting the system at its specified level of sensitivity);

(b) Provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation through the onsite assessment and recommend corrective actions to address identified vulnerabilities;

(c) Prepare a security assessment report containing the results, findings, and recommendations from the assessment and provide the results to the System Owner and to the Office of Information Security (OIS) ; and

(d) Conduct and/or monitor risk assessments of continuous monitoring tools.

(20) Information Security Architect shall:

(a) Serve as the primary liaison between the Enterprise Architect and the Information Systems Security Engineer and coordinate with System Owners, Common

Control Providers, and Information System Security or Privacy Officers on the allocation of controls;

(b) In coordination with ISSOs or Privacy Officers, advise AOs, CIOs, Senior Accountable Officials for Risk Management or Risk Executive Function, Senior

Agency Information Security Officers, and SAOPs on a range of security and privacy issues; and

(c) Be generally responsible for aspects of the enterprise architecture that protect information and information systems from unauthorized system activity or behavior to provide confidentiality, integrity, and availability.

(21) Risk Executive Function is an individual or group within an organization that provides a comprehensive, organization-wide approach to risk management. The VA Secretary may choose to retain the Risk Executive Function, or to delegate the function. Membership within this function requires a mix of skills, expertise, and perspectives to understand the strategic goals and objectives of the VA organization, organizational missions/business functions, technical possibilities and constraints, and key mandates and guidance that shape VA operations. This role is an inherent

U.S. Government function and is assigned to government personnel only. The group is led by the Senior Accountable Official for Risk Management and serves as the common risk management resource for stakeholders having a vested interest in the mission/business success of VA. The Risk Executive Function shall:

(a) Ensure that risk considerations for systems (including authorization decisions for those systems and the common controls inherited by those systems), are viewed from an organization-wide perspective regarding the organization’s strategic goals and objectives in carrying out its core missions and business functions;

(b) Ensure that managing risk is consistent throughout the organization, reflects organizational risk tolerance, and is considered along with other types of risk to ensure mission/business success;

(c) Coordinate with senior leaders and executives to establish risk management roles and responsibilities, manage threat, vulnerability, and security and privacy risk (including supply chain risk) information for organizational systems and the environments in which the systems operate;

(d) Identify the organizational risk posture based on the aggregated risk from the operation and use of systems and the respective environments of operation for which the organization is responsible;

(e) Provide oversight for the risk management activities carried out by organizations to help ensure consistent and effective risk-based decisions; and

(f) Presume neither a specific organizational structure nor formal responsibility assigned to any one individual or group within the organization.

5. RISK MANAGEMENT OF INFORMATION TECHNOLOGY PRODUCTS, SERVICES,

AND Platform information technology.

a. The Information System Security Officer (ISSO), with the review and approval of the responsible AO, is responsible for ensuring all products, services and platform IT have completed the appropriate evaluation and configuration processes prior to incorporation into or connection to an information system or platform IT system.

(1) Information Technology Products. IT products will be configured in accordance with applicable STIGs. STIGs are product-specific and document applicable federal policies and security requirements, as well as best practices and configuration guidelines. STIGs are associated with security controls through CCIs, which are decompositions of NIST SP 800-53 security controls into single, actionable, measurable items. Security Requirements Guides are developed by Defense Information Systems Agency (DISA) to provide general security compliance guidelines and serve as source guidance documents for STIGs. When a STIG is not available for a product, the DISA Requirements Guide and other NIST approved checklists published on the NIST checklist repository may be used. STIG and Security Requirements Guide compliance results for products will be documented as security control assessment results within a product-level security assessment report and reviewed by the responsible ISSO, Security Control Assessor (under the direction of the AO) prior to acceptance or connection into an authorized computing environment (e.g., an information system or platform IT system with an authorization). This review ensures products will not introduce vulnerabilities into the hosting information system or platform IT system, and maximizes testing and review results to minimize duplication of effort across VA. See the Information Security Knowledge Service for additional guidance on the review of products.

(2) Information Technology Services. In general, IT services are outside the service user organization’s authorization boundary, and the service user’s organization has no direct control over the application or assessment of required security controls.

There are internal IT services and external IT services. VA organizations that use external IT services are typically not responsible for authorizing them (i.e., issuing an authorization decision). However, for use of external IT services, the VA must review the external assessment package, present the risk to the Department and AO for approval based on the signed Authority to Use (ATU).

(a) Internal IT services are delivered by VA Information Systems. VA organizations that use internal IT services must ensure the categorization of the VA Information System delivering the service is appropriate to the system and data utilized.

Written agreements describing the roles and responsibilities of both the providing and the receiving organization are in place.

(b) VA organizations that use external IT services provided by a non-VA Federal government agency must ensure the categorization of the Information System delivering the service is appropriate to the confidentiality, integrity, and availability needs of the information and mission, and that the Information System delivering the service is operating under a current authorization from that agency.

Interagency agreements or government statements of work for these external services must contain requirements for Service Level Agreements that include the application of appropriate security controls. The AO should review other

Federal agency security packages and approve such packages for use by VA.

(c) VA organizations that use external IT services provided by a commercial or other non-Federal government entity must ensure the security protections of the Information System delivering the service is appropriate to the confidentiality, integrity, and availability needs of the VA organization's information and mission via the Enterprise Mission Assurance Support Services (eMASS) tool. VA organizations must perform categorization in accordance with FIPS 199 and tailor appropriately to determine the set of security and privacy controls to be included in requests for proposals. VA organizations will assess the adequacy of security proposed by potential service providers and accept the proposed approach, negotiate changes to the approach to meet VA needs, or reject the offer. The accepted security approach must be documented in the resulting contract or order.

(d) VA organizations contracting for external IT services in the form of commercial cloud computing services must comply with VA cloud computing policy, VA Handbook 6517, Risk Management Framework for Cloud Computing Services.

(3) Platform Information Technology. Platform IT that does not rise to the level of a platform IT system may be categorized using FIPS 199 with the resultant security and privacy control baselines tailored as needed. Otherwise, the specific cybersecurity needs of platform IT must be assessed on a case-by-case basis and security and privacy controls applied as appropriate. These include computer resources, both hardware and software, that are physically a part of, and are essential to the mission performance of cyber-physical systems (e.g. medical devices).

6. PROCEDURES.

a. The RMF process is applicable to all information system and platform IT systems, as well as VA-partnered systems where it has been agreed that VA standards will be followed. IT below the system level (e.g., products, IT services) will not be subjected to the full process. However, IT below the system level must be securely configured in accordance with applicable VA policies and security controls, documented in the authorization package for acceptance or connection into an authorized computing environment (i.e., an authorized information system or platform IT system).

b. There are seven steps in the RMF; a preparatory step to ensure that organizations are ready to execute the process and six main steps. All seven steps are essential for the successful execution of the RMF. The steps are:

(1) PREPARE.

(a) The Prepare step is intended to leverage activities already being conducted within security, privacy, and supply chain programs to emphasize the importance of having VA-wide governance and the appropriate resources in place to enable the execution of cost-effective and consistent risk management processes across VA. The Prepare step assists in the execution of the RMF from an organizational and a system-level perspective by establishing a plan and priorities for managing security and privacy risk.

(b) The organizational-level prepare steps include:

i. Risk Management Roles. Identifying individuals within VA and assign key roles for executing the RMF. The roles and responsibilities may include personnel that are internal or external to VA;

ii. Risk Management Strategy. Developing a risk management strategy for the VA that includes a determination and expression of VA risk tolerance. The risk management strategy guides and informs risk-based decisions including how security and privacy risk is framed, assessed, responded to, and monitored;

iii. Organizational Risk Assessment. Developing a VA-wide risk assessment or update to current risk assessment. Risk assessment at the organization level leverages aggregated information from system-level risk assessment results, continuous monitoring, and any strategic risk considerations relevant to the

VA;

iv. Organizationally-Tailored Control Baselines and Cybersecurity Framework Profiles. Tailoring control baselines for VA-wide use. A VA-wide tailored baseline provides a fully specified set of controls, control enhancements, and supplemental guidance derived from established controls baselined in

Committee on National Security Systems Instruction (CNSSI) 1253, encompassed in the Cybersecurity Framework Profile;

v. Common Control Identification. Identifying, documenting and publishing common controls that are available for inheritance by information system and platform IT systems. A particular requirement may not be fully met by a common control. In such cases, the control is considered a hybrid control and is noted as such by VA, including specifying which parts of the control requirements are provided for inheritance by the common control and which parts are to be provided at the system level;

vi. Impact-Level Prioritization. Prioritizing organizational systems with the same impact level. This task is carried out only after VA systems have been categorized; and

vii. Organizational Continuous Monitoring Strategy. Developing and implementing a VA-wide strategy for monitoring control effectiveness which identifies the minimum monitoring frequency for implemented controls across VA.

(c) The system-level prepare steps include:

i. Mission or Business Focus. Identifying the missions, business functions, and mission/business processes that the system is intended to support;

ii. System Stakeholders. Identifying stakeholders who have an interest in the design, development, implementation, assessment, operation, maintenance, or disposal of the system;

iii. Asset Identification. Identifying assets that require protection;

iv. Privacy Assessment. Determine the privacy risks for systems that access or use Personal Identifiable Information (PII)/Personal Health Information (PHI).

Complete PTA of any system that will use or access PII/PHI. If PII/PHI are identified, then a PIA must be completed. Contact the ISO for assistance with identification of risks and compliance documentation.

v. Authorization Boundary. Determining the authorization boundary of the system; whether logical or geographical, for the purposes of obtaining an Authorization to Operate (ATO).

vi. Information Types. Identifying the types of information to be processed, stored, and transmitted by the system;

vii. Information Life Cycle. Identifying and understanding all stages of the information life cycle for each information type of information processed, stored, or transmitted by the system;

viii. Risk Assessment. Conducting a system-level risk assessment and update the risk assessment results in accordance with the organizational continuous monitoring strategy;

ix. Requirements Definition. Defining the security and privacy requirements for the system and the environment of operation;

x. Enterprise Architecture. Determining the placement of the system within the enterprise architecture;

xi. Requirements Allocation. Allocating security and privacy requirements to the system and to the environment of operation; and

xii. System Registration. Registering the system with organizational program or management offices.

(4) CATEGORIZE SYSTEM.

(a) System Description. Document the characteristics of the system.

i. These include system design and requirements documentation; authorization boundary information; list of security and privacy requirements allocated to the system, system elements, and the environment of operation; physical or other processes controlled by system elements; system element information;

system component inventory; system element supply chain information, including inventory and supplier information; security categorization; data map of the information life cycle for information types processed, stored, and transmitted by the system; information on system use, users, and roles.

(b) Security Categorization. Categorize the system and document the security categorization results.

i. In the categorization process, the System Owner identifies the potential impact (low, moderate, or high) resulting from loss of confidentiality, integrity, and availability if a security breach occurs. The generalized format for expressing the security category of an information system is: Security Category information system = {(confidentiality, impact), (integrity, impact), (availability, impact)}, where the acceptable values for potential impact are low,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .