Attachment C - App A-VISN4-Western PA Home Oxygen_FINAL.pdf

PDF 645 KB Posted

Attached to
Home Oxygen West, VISN 4 Federal contract opportunity
Solicitation number
36C24421R0068
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 4

About this file

This document contains a checklist for assessing information security requirements for federal acquisitions involving contractor access to or storage of sensitive government information. The checklist must be completed by an acquisition team including contracting officers, information security officers, and program managers. It addresses whether acquisitions require contractor personnel access to government systems or sensitive data, use of contractor-owned IT systems to process or store government information, or connection of contractor devices to government networks. If any of these apply, various security requirements must be incorporated including risk designations, security clauses, privacy training, and certification and accreditation of contractor systems. Comments from information security and privacy officers note that for the related federal contract opportunity for home oxygen services, sensitive medical information disclosed to contractors is no longer government owned once provided, so full security controls and assessments are not required, but privacy training and secure transmission of data should be addressed in the contract.

View the file

Other files for this federal contract opportunity

Other files attached to Home Oxygen West, VISN 4, newest first.
File Type Posted
PWS May 4 2021.pdf PDF
Attachment A-Schedule CLIN.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Reference: ____________________ HANDBOOK 6500.6

APPENDIX A

CHECKLIST FOR INFORMATION SECURITY IN THE INITIATION PHASE OF

ACQUISITIONS

1. BACKGROUND

In accordance with VA policy, contractors’ storage, generation, transmission or exchanging of VA sensitive information requires appropriate security controls to be in place. The VA Information Security Program policy – VA Directive and Handbook 6500 and additional 6500 series directives and handbooks - provide the framework for security within VA.

2. INSTRUCTIONS

This checklist must be completed at the initiation of all IT service acquisitions, statements of work, third-party service agreements and any other legally binding agreement in order to determine what, if any, security and privacy controls are necessary specifically as it relates to the VAAR security clause. OGC guidance should be sought on data ownership issues, as necessary. The checklist can also be used for other types of contracts, if appropriate or needed. In order to successfully complete this checklist, each question below must be addressed in coordination with all members of the local Acquisition Team including: the Procurement Requestor or Program Manager from the program office or facility, the Contracting Officer Representative (COR), the Information Security Officer (ISO), the Contracting Officer (CO) from the program office or facility’s servicing Acquisition office, and the Privacy Officer (PO). The ISO is the arbitrator if there are questions or disagreements on the appropriate answers.

1. Is this an acquisition or purchase of only commodities or goods (e.g. equipment or software)?

If yes, then the security clause is not required as long as VA sensitive information is not involved.

If no, then proceed to the next question.

Yes No

2. Does the contract involve “VA sensitive information?”

(See 3. PROCEDURES a.)

If yes, proceed to next question.

If no, then the security clause is not required.

3. Will this acquisition require services of contractor personnel?

If no, proceed to question 5.

If yes, proceed to next question.

4. Will the personnel perform a function that requires access to a VA system or VA sensitive information (e.g., system administrator privileged access to a VA system, or contractor systems or processes that utilize VA sensitive information)?

NOTE: See 3.a. under PROCEDURES regarding contracts and agreements concerning medical treatment for Veterans.

If the answer above is no, then proceed to the next question.

If yes, then VA security policies apply. Contracting Officials need to work with the Program Manager or (procurement requestor), COTR, PO, and ISO to:

i. Include the appropriate risk designation of the contractors based on the PDAT determination.

ii. Incorporate the security clause (Appendix B) into the contract involved and the appropriate security/privacy language outlined in Appendix C into the solicitation.

iii. Determine if protected health information is disclosed or accessed and if a BAA is required.

5. Will this acquisition require use of a contractor-owned

Information Technology (IT) system or computer assets, and

a. The IT system hardware components are located at an offsite contractor facility; and

b. The IT system is not connected to a VA network;

and

c. The contractor has exclusive administrative control to the components; and

d. The purpose of the requirement for the system is to process or store VA information on behalf of the VA.

If any of the answers to 5a-5d are no, proceed to the next question.

If yes, then VA security policies apply. Incorporate the clause from Appendix B and the appropriate security/privacy language from Appendix C respectively into the solicitation and contract and initiate planning for the certification and accreditation of the contractor system(s). Contracting Officials need to work with the COTR and ISO to:

• Determine the security impact of the IT system as

High, Moderate, or Low per 6500 Handbook, Information Security Program.

• Ensure Contractor understanding of the IT security requirements for certification and accreditation (authorization) (C&A) of the contractor system. See VA Handbook 6500.3, Certification and Accreditation.

• Ensure that the proper VA Management Official is appointed by the Certification Program Office to formally authorize operation of the system in accordance with VA Handbook 6500 and 6500.3.

• Enforce contractor performance (timely submission of deliverables, compliance with personnel screening requirements, maintenance of secure system configurations and participation in annual IT Federal Information Security Management Act (FISMA) assessments to ensure compliance with FISMA requirements).

• Ensure yearly FISMA assessments are completed and uploaded into SMART.

6. Will this acquisition require services that involve connection of one or more contractor-owned IT devices (such as a laptop computer or remote connection from a contractor system) to a VA internal trusted (i.e., non-public) network?

If no, then include a statement in the SOW that “The C&A requirements do not apply, and that a Security Accreditation Package is not required: and proceed to the next question.

If yes, then incorporate the security clause from Appendix B and the appropriate security/privacy language from Appendix C respectively into the solicitation and contract. Contracting Officials need to work with the COR and the ISO to:

• Ensure contractor understands and implements the

IT security requirements for system interconnection documents required per the Memorandum of Understanding or Interconnection Agreement (MOU- ISA). The standard operating procedure (SOP) and a template for a MOU-ISA are located on the Information Protection Risk Management (IPRM) Portal and can be provided to the contractor.

• Ensure contractor understands their participation in IT security requirements for C&A of the VA system to which they connect.

• Enforce contractor performance (timely submission of deliverables, compliance with personnel screening requirements, and appropriate termination activity as appropriate).

7. Is the acquisition a service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or a MOU-ISA for system interconnection?

If no, then specify the mechanism/documentation used to ensure the VA sensitive information is protected.

If yes, then incorporate the security clause and the appropriate security language from Appendices B and C into the solicitation and contract. The COTR needs to:

• Ensure that a Contractor Security Control Assessment (CSCA) is completed within 30 days of contract approval and yearly on the renewal date of the contract.

• Ensure that the CSCA is sent to the ISO and the OCS Certification Program Office for review to ensure that appropriate security controls are being implemented in service contracts.

• Ensure a copy of the CSCA is maintained in the Security Management and Reporting Tool (SMART) database. COTR will provide a copy of the completed CSCA to ISO for uploading into SMART database.

3. SIGNATURES

Please provide the name and telephone number of each Acquisition Team member who participated in completing this checklist. By signing this checklist, the Contracting Officer is representing that Security was considered for this requirement through coordination with members of the Acquisition Team including the program or requesting office's IT Security point of contact.

(1) Contracting Officer Representative:

Name: Phone:

Signature: Date:

(2) Information Security Officer:

Name: Phone:

Signature: Date:

(3) Contracting Officer:

Name: Phone:

Signature: Date:

(4) Procurement Requestor/Program Manager:

Name: Phone:

Title:

Signature: Date:

(5) Privacy Officer:

Name: Phone:

Signature: Date:

(6) Other Team Members participating in the acquisition (e.g., Records Management Officer/Compliance Officer):

Name: Phone:

Title:

Signature: Date:

Reference:

VISN-04 Western PA Home Oxygen

Name Phone: 717-272-6621 Ext. 3513
Signature Date: March 30, 2021
Name Phone_2: 412-822-3211
Signature Date_2: 03/30/2021
Name Phone_3:
Signature Date_3:
Name Phone_4:
Title:
Signature Date_4:
Name Phone_5: 412-822-1123
Signature Date_5: 3/30/21
Name Phone_6: 412-216-2321
Title_2: Facility Records Officer
Signature Date_6: 31 Mar 2021
Text1: Daniel Pellman
Text2: Terry Dziadik
Text3:
Text4:
Text5: Lisa Hoss
Text6: Christopher L. Kot
2021-03-30T09:56:23-0400
DANIEL PELLMAN 1131976
2021-03-30T10:29:38-0400
Terry M. Dziadik 1800485
2021-03-30T11:55:58-0400
LISA D HOSS 235167
2021-03-31T07:03:10-0400
Christopher L. Kot 320858
Check Box13: Off
Check Box14: Yes
Check Box15: Off
Check Box16: Yes
Check Box17: Off
Check Box18: Off
Check Box19: Off
Check Box20: Off
Check Box21: Off
Check Box22: Off
Check Box23: Off
Check Box24: Off
Check Box25: Off
Check Box26: Yes
Check Box27: Off
Check Box28: Yes
Check Box29: Yes
Check Box30: Off
Check Box31: Yes
Check Box32: Off
Check Box33: Yes
Check Box34: Off
Text7: ISSO/PO Comments:

According to VA Handbook 6500.6 Section #3.a. “VA sensitive information that has been properly disclosed by VA to the contractor is not subject to the VAAR security clause.” VA sensitive information is being properly disclosed to the contractor as part of this contract. The contractor is not storing VA data on behalf of the VA. The information required to be provided to the contractor must be transmitted in a secure manner. All email communications must use VA-approved encryption. A Contractor Security Control Assessment (CSCA) is also not required because the data is no longer owned by the VA once it is provided to the contractor to perform a healthcare operation. However, the following paragraph from 6500.6 Appendix C should be incorporated into the contract:

Appendix C: #3a

The COR is responsible for ensuring that all Contractors comply with physical security policies.

All Contractors must receive Privacy training annually using one of the following methods:

• Complete “VA Privacy Training for Personnel without Access to VA Computer Systems or Direct Access to or Use to VA Sensitive Information” training by using VA’s TMS system (https://www.tms.va.gov/). Contractors may use the TMS Managed Self Enrollment method to complete the training in TMS. The COR must ensure that all contractors are validated in the PIH domain.

• Complete the hard copy version of “VA Privacy Training for Personnel without Access to VA Computer Systems or Direct Access to or Use to VA Sensitive Information”. Signed training documents must be submitted to the COR.

Training must be completed prior to the performance of the contract and annually thereafter. Proof of training completion must be verified and tracked by the COR.

Text8: Comments:
Text9:
Text11:
CIO/ITOPS: CIO / ITOPS:

File details come from the government source that posted it. Updated .