Attachment E MD ERA Protocol.xlsx
XLSX spreadsheet 69 KB Posted
- Attached to
- 6515--PSG & EEG Replacement VISN Federal contract opportunity
- Solicitation number
- 36C25522Q0345
About this file
This document contains a risk assessment template for evaluating medical devices. The template includes columns for control ID, control title, risk assessment questions, data validation options, security objectives, likelihood and impact ratings, vulnerabilities from non-compliance, and mitigating factors. Additional tabs provide lists for accepted mitigation factors, common ports, protocols and services, and acronyms. The risk assessment is intended to evaluate devices for a federal contract opportunity issued by the Department of Veterans Affairs for replacement polysomnography and electroencephalogram equipment under solicitation number 36C25522Q0345 for VISN 15. The template provides a framework for assessing risks across technical, operational and administrative controls to identify security gaps and residual risks in medical devices being considered for the replacement PSG and EEG equipment.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C25522Q0345.pdf | ||
| Attachment C MD ERA Network.pdf | ||
| Attachment D MD ERA Inventory.xlsx | XLSX spreadsheet | |
| Attachment A 6550.pdf | ||
| Attachment B MDS2.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Risk Data-Key
| Question | Control ID | Control Title | Description | Risk Assessment Questionnaire | Data Validation Options | Action | Security Objectives | ||||||||||||
| (C-I-A) | Likelihood | Impact | Risk | Vulnerability (If Non-Compliant) | Impact of Non-Compliant Control | MDIA | Secured Location | Internal Connections Only | Minimal Record Storage | Maintenance Installation Contracts | Medical Device USB Drive 10N Memo | MDPP Scanning Stations | Physical Device Monitoring | Clinical Functionality (Alternate Method) | SOP | Networked Medical Device Databases (NMDD) | Mitigating Factors | Final Residual Risk | |
| PPA.1 | CM-2 | Operating System | The device runs on a supported operating system platform. | Does the device run on a supported Operating System? | Yes, No | Yes = Compliant | |||||||||||||
| No = Non-Compliant | I | Low | High | High | Unsupported operating Systems may be subject to vulnerabilities that will not be patched due to the unsupported nature of the operating system. | Unpatched Vulnerabilities | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High | ||||
| PPA.2 | CM-6 | Database Application | The device runs on a supported database application. | If the devices uses a database application, is it currently supported (e.g. not end-of-life)? | Yes, No | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | I | High | High | High | Unsupported database systems may be subject to vulnerabilities that will not be patched due to the unsupported nature of the operating system. | Unpatched Vulnerabilities | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High | |
| PPA.3 | AU-4 | Audit Logs | The device will maintain at least a 90 day history of transactions that will permit the audit of individual’s activities throughout the system. | Does the device maintain at least 90 days of audit logs associated with user activity? | Yes, No | Yes = Compliant | ||||||||||
| No = Non-Compliant | A | Moderate | High | Lack of or insufficient auditing can lead to potential cyber attacks or insider threat actions to go unnoticed or unattributed to a specific user. | Undetected or unattributed cyber breach | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | ||||||
| PPA.4 | SC-23 | Web Browser - Secure Communications Protocol | The device is configured to only use a secure communications protocol for web browser-based access. (i.e. SSL, TLS) | If the device utilizes a web browser for access, is it configured for secure communications (SSL, HTTPS, etc.)? | Yes, No, N/A - The device does not use a web browser for access | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | I | Moderate | Moderate | Using a non-secure communication protocol could expose patient data or potential expose the device to man-in-the-middle attacks. | Unauthorized Disclosure | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |
| PPA.5 | CM-11 | Patching - Windows Server Update Services | If the device runs a Microsoft Windows operating system, the device can use Microsoft Windows Server Update Services (WSUS) to obtain operating system patches. | If the device runs a Microsoft Operating System, does the device utilize a Microsoft Windows Server Update Services (WSUS) server? | Yes, No, N/A - The device is not a Windows Device | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | I | High | High | High | Critical patches, updates are more likely to be missed when requiring manual patching processes. | Unpatched Vulnerabilities | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High | |
| PPA.6 | SI-2 | Patching - Process | The device manufacturer will provide a complete, documented process to perform routine OS patch updates including all approval and notification procedures that must be completed prior to applying patches. | Has the device manufacturer provided a complete and documented process detailing how and when routine OS patch updates are to be applied, and by whom? | Yes, No | Yes = Compliant | ||||||
| No = Non-Compliant | I | High | High | High | If process is not known on how to apply OS patches and who is authorizes the update. Then OS patch update can not occur, due to lack of documentation. | Unpatched Vulnerabilities | ERROR:#REF! | x | 1 | Moderate | ||
| PPA.7 | SI-2 | Patching - Critical | The device manufacturer will provide complete documented process to perform critical operating system and application security patching within 30 days of the release of the patch from the software vendor. | Has the device manufacturer provided a documented process for addressing critical operating system and application patches for patching within 30 days from the release of the patch? | Yes, No | Yes = Compliant |
No = Non-Compliant
| I | High | High | High | Unable to apply critical patches in a timely fashion. | Elevated risk exposure due to unpatched critical vulnerabilities. | x | x | 2 | Moderate | |||||||
| PPA.8 | SI-3 | Antivirus Software | The device manufacturer supports the installation and operation of antivirus and will provide a complete, documented process to perform routine antivirus updates to include all approval notification procedures that must be completed prior to updating the antivirus software. | Does the device support the installation of anti-virus software, to include routine antivirus updates? | Yes, No | Yes = Compliant | ||||||||||
| No = Non-Compliant | I | High | High | High | Malware and virus aim at device can go undetected. | Loss of CIA | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High | |
| PPA.9 | MP-7 | Universal Serial Bus (USB) Ports | Unused USB ports are disabled upon initial deployment. | Are all unused USB ports disabled? | Yes, No, N/A - The device does not have USB ports | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | C-I | Moderate | High | High | Unauthorized services to include malware. | Loss of CIA | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High | |
| PPA.10 | CM-7 | Autorun | Autorun (Windows OS) behavior is disabled upon initial deployment. | Is autorun disabled on Windows OS devices? | Yes, No, N/A - The device is not a Windows Device | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | C-I | Moderate | High | High | Physical access could bypass access control and it can execute unauthorized applications. | Unauthorized disclosure or execution of malware. | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High | ||
| PPA.11 | RA-5 | Vulnerability Assessments | a) The manufacturer will support security testing to assess vulnerabilities on the device. | |||||||||||
| b) The device will be designed such that the testing will not affect the operational services of the device. | Does the device support automated vulnerability assessment scans without operational impact to the device? | Yes, No | Yes = Compliant | |||||||||||
| No = Non-Compliant | C-I-A | High | High | High | If we do not scan we do not find vulnerabilities. Scanning may cause system to crash. | Mitigation cannot be applied if vulneraries are not identified through scanning. | ERROR:#REF! | ERROR:#REF! | 0 | High | ||||
| PPA.12 | MP-6 | Media Sanitization | Proper disposal of medical devices that reach end of life. All medical device hard drives or other media containing VA sensitive data must follow VA’s current media sanitization policy. | If the device is being returned to the manufacturer at EOL or for other scenarios, is the VA Media Sanitization policy followed? | Yes, No, N/A - The device does not store sensitive data | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | C | Low | High | It will lead to unauthorized access. | Unauthorized disclosure of sensitive information e.g., ePHI/PII. | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | ||||
| PPA.13 | AC-2 | Role Based Access | The device will support role based access for all users. | Does the device support role-based access for all users? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I | Moderate | Moderate | Elevated privilege. Users have more access than required. | Users could perform unauthorized functions | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | ||||
| PPA.14 | AC-6 | Administrator Accounts | Administrator accounts: |
a) will be required for service, software installation, and system configuration and;
| Does the device require administrative access for service, software installation, and system configuration activities? | Yes, No | Yes = Compliant | |||||||||||
| No = Non-Compliant | C-I | Moderate | High | High | Unauthorized personnel being able to perform administrator functions. | Unauthorized changes can be made to the system. | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High |
| PPA.15 | IA-2 (1) | Administrator Accounts | b) will support the use of two factor authentication of the administrator account. | Does the device support two-factor authentication for administrative accounts? | Yes, No | Yes = Compliant | |||||||
| No = Non-Compliant | C-I | High | Moderate | (username and password more likely to be compromised) | Unauthorized access | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | ||
| PPA.16 |
Department of Veterans Affairs: Department of Veterans Affairs:
relates to role based access, could it be removed
| AC-6 | Operator Accounts | The device will operate with full clinical functionality under a general user or operator account. User privileges on the device should limit the user/operator to general use and operation of the device. | Does the device operate with full clinical functionality with user level privileges? | Yes, No | Yes = Compliant | |||||||||
| No = Non-Compliant | C-I | Moderate | Moderate | Elevated privilege. Users have more access than required. | Users could perform unauthorized functions | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | ||||
| PPA.17 | IA-5 | Default Usernames and Passwords | The device will not use default usernames and passwords. All default usernames will be renamed or disabled and all default passwords must be changed after installation of the device. | Have device's default usernames and/or passwords been changed? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I | High | Moderate | Default usernames and passwords are known by unauthorized users | Unauthorized access | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |||
| PPA.18 | AC-2 | Shared Accounts | The device will not require the use of shared accounts. | Does the device require or use shared accounts? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I | High | Moderate | Lack of non-repudiation | Lack of accountability | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |||
| PPA.19 | AC-2 | Shared Accounts | Shared accounts will be removed / disabled upon delivery. (i.e. generic accounts, work accounts) | Are all shared accounts removed or disabled on the device? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I | High | Moderate | Lack of non-repudiation | Lack of accountability | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |||
| PPA.20 | IA-2 | Individual User Authentication | The device will be configured for individual user authentication. | Is the device configured to used individual user authentication? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I | Moderate | Moderate | Lack of non-repudiation | Lack of accountability | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | ||||
| PPA.21 | IA-5(1) | Password Aging | The device will be configured to prompt a user to create a new password at least every 90 days. | Is the device configured to support a 90 day password age? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I | Moderate | High | High | Passwords are more likely to be compromised | Unauthorized access | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High | ||
| PPA.22 | IA-5(1) | Strong Passwords | The device will enforce the use of strong passwords with a minimum complexity setting of: |
• Minimum length of 8 characters
• Complexity rules:
o Minimum of one (1) uppercase letter o Minimum of one (1) lowercase letter o Minimum of one (1) number o Minimum of one (1) special character o Password must not match the last five (5) previously used passwords Is the device configured to support strong passwords with a minimum complexity setting of:
• Minimum length of 8 characters o Minimum of one (1) uppercase letter o Minimum of one (1) lowercase letter o Minimum of one (1) number o Minimum of one (1) special character
| o Password must not match the last five (5) previously used passwords | Yes, No | Yes = Compliant | ||||||||||||
| No = Non-Compliant | C-I | Moderate | Moderate | Passwords are more likely to be compromised | Unauthorized access | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |||
| PPA.23 | AC-11 | Auto Logoff/Session Lock | The device is capable of session lock after at least 15 minutes of inactivity and is configurable based on based on clinical use. | Is the device configured to lock session activity after 15 minutes of inactivity or configured in accordance with documented clinical requirements? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I | Moderate | Moderate | Privacy exposure | Unauthorized disclosure | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | ||||
| PPA.24 | IA-5(2) | User Authentication - Personal Identity Verification (PIV) Card/ Smart Card | The device supports Personal Identity Verification (PIV) card/smart card user authentication and card readers. | Does the device support PIV/Smart Card user authentication? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I | High | Moderate | (username and password more likely to be compromised) | Unauthorized access | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |||
| PPA.25 | SC-28 | Data Encryption – Mechanism | The device will support whole disk encryption as a means to protect patient data. | Does the device protect data-at-rest with whole disk encryption? | Yes, No, N/A - The device does not store sensitive data | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | C-I | Moderate | High | High | Data breach | Lost of confidentiality | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High |
| PPA.26 | SC-13 | Data Encryption - Federal Information Processing Standard Publication 140-2, (FIPS PUB 140-2) Validation | The device, its communication protocols, and any associated storage media are configured to use an encryption mechanism that is compliant with FIPS PUB 140-2. The device meets FIPS PUB 140-2 requirements and is accompanied by a manufacturer provided validation certificate or signed letter/statement confirming inclusion of the unmodified validated cryptographic module. | Does the device meet FIPS PUB 140-2 requirements? | Yes, No, N/A - The device does not contain cryptographic modules | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | C-I | Very Low | Moderate | Un-verified cryptographic modules could lead to weak encryption | Data breach | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |
| PPA.27 | SC-13 | Data Encryption – Health Insurance Portability and Accountability Act (HIPAA) | The device, its communication protocols, and any associated storage media are configured to meet HIPAA standards for encryption and decryption including 164.312(a)(2)(iv) and 164.312(e)(2)(ii) and implements a method to encrypt and decrypt ePHI. | Is the device configured to support data at rest and transmission security for sensitive data at rest and in-transit? | Yes, No, N/A - The device does not transmit, process, store ePHI | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | C-I | High | High | High | Data breach | Loss of confidentiality | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High |
| PPA.28 | AC-4(22) | Data Storage | If the device has the capability to store ePHI or PII, sensitive data will be stored on a separate hard drive. | Is ePHI or PII stored on a separate hard drive? | Yes, No, N/A - The device does not transmit, process, store ePHI | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | C-I | Low | Moderate | Data cannot be purged before equipment is serviced | Sensitive information could be compromised | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 |
| PPA.29 |
Department of Veterans Affairs: Department of Veterans Affairs:
SOP should be added as mitigating factor CP-9 Data backups – Process The device manufacturer will provide a complete, documented process for performing routine and emergency data backups and recovery. Are device back-up processes complete and documented, to include routine and emergency data back-ups and recovery? Yes, No, N/A - The device does not store data Yes = Compliant No = Non-Compliant
| N/A = N/A | C-I-A | Low | High | Loss of Data and incomplete recovery | Loss of Availability | |||||||||||
| ERROR:#REF! | x | ERROR:#REF! | x | 2 | 0 | |||||||||||
| PPA.30 | IA-4 | Unique Identification Numbers | The device generates a unique patient identified in lieu of using individual identifies (i.e.. name and social security number) to avoid linking personal information to a specific patient. | Is the device configured to create unique identification numbers for each patient vs. using individual identity information (Name and SSN)? | Yes, No, N/A - The device does not generate patient identifiers | Yes = Compliant | ||||||||||
| No = Non-Compliant | C-I | Low | High | Without unique identification number, ePHI/PII could be compromised | Loss of confidentiality and identity theft | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |||||
| PPA.31 | SA-5 | Bandwidth – Local Area Network (LAN) | The device manufacturer will provide a complete, documented technical specification defining LAN bandwidth requirements to enable full connectivity and optimal system performance. | Are comprehensive LAN requirements defined and documented for the device? | Yes, No | Yes = Compliant | ||||||||||
| No = Non-Compliant | C-I-A | Low | Moderate | If device LAN requirements are not defined or documented device may not connect to Network properly. | Loss of Availability possible due to incorrect network settings. | ERROR:#REF! | x | ERROR:#REF! | 1 | 0 | ||||||
| PPA.32 | SA5 | Bandwidth – Wide Area Network (WAN) | The device manufacturer will provide a complete, documented technical specification defining WAN bandwidth requirements to enable full connectivity and optimal system performance | Are comprehensive WAN requirements defined and documented for the device? | Yes, No | Yes = Compliant | ||||||||||
| No = Non-Compliant | C-I-A | Low | Moderate | If device WAN requirements are not defined or documented device may not connect to Network properly. | Loss of Availability possible due to incorrect network settings. | ERROR:#REF! | x | ERROR:#REF! | 1 | 0 | ||||||
| PPA.33 | SC-8 | Communication Protocols – Use of Clear Text | The device will not use clear text protocols for communication to and from the device. (i.e.. FTP; telnet) | Does the device use only secure protocols for communication to and from the device (SSH, SSL, etc. not FTP, telnet.) | Yes, No | Yes = Compliant | ||||||||||
| No = Non-Compliant | C-I-A | Moderate | High | Sensitive information can be intercepted during transmission. | Unauthorized disclosure e.g. man-in-the-middle, data theft. | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |||||||
| PPA.34 |
Department of Veterans Affairs: Department of Veterans Affairs:
| PPS are identified during PRE-procurement, in VA 6550A | SA-4(9) | Communication Protocols - Identification of Ports | a) The device manufacturer will provide a complete, documented technical specification defining all TCP and UDP ports that are required for operation. | |||||||
| Has the device manufacturer provided a detailed technical specification defining all TCP and UDP ports required for device operation? | Yes, No | Yes = Compliant | ||||||||
| No = Non-Compliant | C-I-A | Low | Moderate | Insufficient defined detailed documentation could expose the device to malware and virus | Unauthorized access e.g. session hijacking, installation of malware/ransomware | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 |
| PPA.35 |
Department of Veterans Affairs: Department of Veterans Affairs:
There needs to be a local SOP created for this as well.
PPS are identified during PRE-procurement, in VA 6550A
| SA-5 | Communication Protocols - Identification of Ports | b) The device manufacturer will provide a reference network diagram illustrating all communication requirements. | Has the device manufacturer provided a detailed network diagram illustrating on device communication requirements? | Yes, No | Yes = Compliant | |||||
| No = Non-Compliant | C-I-A | High | Moderate | Violation of configuration management policies and procedures could go undetected | Unauthorized network access | x | ERROR:#REF! | 1 | 0 | |
| PPA.36 |
Department of Veterans Affairs: Department of Veterans Affairs:
| PPS are defined in the Pre-procurement docs. | SA-5 | Static Internet Protocol (IP) Addresses | The device manufacturer will provide a complete, documented technical specification defining the number of static IP addresses required for device/system operation. | Has the device manufacturer defined the number of static IP addresses required for device / system operation? | Yes, No | Yes = Compliant | ||||
| No = Non-Compliant | C-I-A | Low | Low | If multiples static IP are required and not known it could affect the operation of device and make it less accessible. | Device operation may be affected if number of defined static address are not known thus compromising availability | ERROR:#REF! | x | 1 | 0 | |
| PPA.37 |
Department of Veterans Affairs: Department of Veterans Affairs:
| This could be mitigated slightly with IPv4 backwards compatibility. | CM-6 | Internet Protocol version 6 (IvP6) Compatibility | The device is IPv6 enabled. | Does the device support IPv6? | Yes, No | Yes = Compliant | ||||||
| No = Non-Compliant | I | Low | High | May not be able to talk to a IPv6 network | Loss of availability | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |
| PPA.38 |
Department of Veterans Affairs: Department of Veterans Affairs:
PPS are identified during PRE-procurement, in VA 6550A
| CM-6 | Active Ports and Protocols | The device configuration restricts active network communication ports and protocols to only those required to support intended operations. All unused ports and protocols are closed or disabled. | Are all unused communication ports, closed or disabled? | Yes, No | Yes = Compliant | |||||||
| No = Non-Compliant | I | High | High | If unused ports are not closed or disabled. Device would be susceptible to attack. | Unauthorized access to device could be gained. | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |
| PPA.39 |
Department of Veterans Affairs: Department of Veterans Affairs:
| S are identified during PRE-procurement, in VA 6550A | CM-6 | Active Services | The device configuration restricts running services on the device to only those required to support intended operations. All unused services (i.e.. Web services; remote connection services) are closed or disabled. | Are all unused services closed or disabled? | Yes, No | Yes = Compliant | ||||||
| No = Non-Compliant | I | High | High | Unauthorized access | Undisclosed information | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |
| PPA.40 |
Department of Veterans Affairs: Department of Veterans Affairs:
| Procedures are identified during PRE-procurement, in VA 6550A. | AC-17 | Remote Access - Servicing | a) The device manufacturer will provide a complete, documented technical specification defining the procedures to ensure secure remote monitoring, access, repair, maintenance, and troubleshooting. |
| b) The device manufacturer will provide a reference network diagram illustrating all remote servicing communication requirements. | Has the device manufacturer provided a complete, documented technical specification defining the procedures to ensure remote monitoring, access ,repair, maintenance and troubleshooting? | Yes, No, N/A - The device does not support remote access | Yes = Compliant |
No = Non-Compliant
| N/A = N/A | C-I | High | High | Unable to apply critical patches in a timely fashion. | Critical vulnerabilities detected. | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 |
| PPA.41 |
Department of Veterans Affairs: Department of Veterans Affairs:
Procedures are identified during PRE-procurement, in VA 6550 Appendix A AC-17 Remote Access - Software The device manufacturer will provide a complete, documented technical specification defining all remote access software required for manufacturer support of the system. Has the device manufacturer provide a complete, documented, specification defining all remote access software required for manufacturer support of the system? Yes, No, N/A - The device does not support remote access Yes - Compliant No - Non-Compliant
| N/A - The device does not support Remote Access | C-I | Moderate | High | Unable to apply critical patches in a timely fashion. | Critical vulnerabilities detected. | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 |
| PPA.42 |
Department of Veterans Affairs: Department of Veterans Affairs:
| Tools are identified during PRE-procurement, in VA 6550A | CM-7 | Internet Connection - IP/Port/Traffic | The device will not require a direct, unsecured connection to the Internet to enable operation or support. | Does the device require a direct, unsecured connection to the Internet to support device operation? | Yes, No | Yes - Non-Compliant | ||
| No - Compliant | C-I | Moderate | High | High | Unauthorized services to include malware. | Loss of CIA. | ||
| ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High | |||
| PPA.43 | SA-4(9) | Wireless Protocols | a) The device manufacturer will provide a complete, documented technical specification defining all wireless protocols (e.g., Wireless Medical Telemetry Service (WMTS), Bluetooth, and IEEE 802.11) used by the device. | |||||
| b) The device manufacturer will provide a reference network diagram illustrating all wireless communication requirements. | Has the device manufacturer provided a complete, documented, specification defining all wireless protocols used by the device? | Yes, No, N/A - The device does not support wireless protocols | Yes - Compliant |
No - Non-Compliant
| N/A - The device does not support wireless protocols. | C-I-A | Very Low | Moderate | Data Breach | Unauthorized use of wireless communications | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |
| PPA.44 | AC-18(1) | Wireless Protocols - Encryption | The device will support the use of a FIPS 140-2 encryption standard for wireless connectivity and communications without compromising device performance. | Does the device use FIPS 140-2 encryption standards for wireless communications? | Yes, No, N/A - The device does not support wireless protocols | Yes - Compliant |
No - Non-Compliant
| N/A - The device does not support wireless protocols. | C-I | Very Low | Moderate | Not meeting the Fops 140-2 requirement and unmodified cryptographic can lead to week encryption | Data breach | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |
| PPA.45 | AC-18(1) | Wireless Encryption: FIPS PUB 140-2 Validation | The device meets FIPS PUB 140-2 requirements and is accompanied by a manufacturer provided validation certificate or signed letter/statement confirming inclusion of the unmodified validated cryptographic module. | Has the manufacturer provided the FIPS 140-2 certificate for wireless communications? | Yes, No, N/A - The device does not support wireless protocols | Yes - Compliant |
No - Non-Compliant
| N/A - The device does not support wireless protocols. | C-I | Very Low | Moderate | Revocation of access codes in the system. | Providing confidentiality, authenticity and integrity of the data | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | 0 | |
| SA-4(9) | Wireless Data Transmission | The device manufacturer will provide a complete, documented technical specification defining all ePHI data elements transmitted via the device’s wireless communications. | Has the manufacturer provided a complete, documented technical specification defining all ePHI data elements that are transmitted via the device's wireless communications? | Yes, No, N/A - The device does not support wireless protocols | Yes - Compliant |
No - Non-Compliant N/A - The device does not support wireless protocols. C-I-A Moderate Moderate If not documented then potential vulnerabilities will go undetected Data leakage ERROR:#REF! ERROR:#REF! ERROR:#REF! ERROR:#REF! 0 0
2.AC-6(1)
Department of Veterans Affairs: Department of Veterans Affairs:
Needs to be a local SOP.
| AC-6(1) | Least Privilege | Authorize Access To Security Functions | The organization explicitly authorizes access to [Assignment: organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information]. | Technically speaking, does this device have the capability to establish multiple user roles and assign users to specific user roles, based on their assigned duties? | Yes, No | Yes = Compliant | |||||||||
| No = Non-compliant | C-I | Moderate | Moderate | Moderate | Elevated privilege. Users have more access than required. | Users could perform unauthorized functions | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | Moderate |
| 3.AC-6(1) |
Department of Veterans Affairs: Department of Veterans Affairs:
| Documented in Pre-Procurement. | AC-6(1) | Least Privilege | Authorize Access To Security Functions | The organization explicitly authorizes access to [Assignment: organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information]. | Does the device inherit User Access policies from the organization, e.g. GPO's or local access SOP? | Yes, No | Yes = Compliant | ||||||||||||
| No = Non-compliant | C-I | Moderate | Moderate | Moderate | Elevated privilege. Users have more access than required. | Users could perform unauthorized functions | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | Moderate | ||||
| 4.AC-6(1) | AC-6(1) | Least Privilege | Authorize Access To Security Functions | The organization explicitly authorizes access to organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information. | Is there device specific documentation describing which user roles are allowed which privileges on the device? | Yes, No | Yes = Compliant | ||||||||||||
| No = Non-compliant | C-I | Moderate | Moderate | Moderate | Execution of Security functions by unauthorized personnel. | Users could perform unauthorized functions | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | Moderate | |||||
| 5.AC-6(1) | AC-6(1) | Least Privilege | Authorize Access To Security Functions | The organization explicitly authorizes access to organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information. | Have user roles and privileges been implemented in accordance with documented policy? | Yes, No | Yes = Compliant | ||||||||||||
| No = Non-compliant | C-I | Low | High | Moderate | unauthorized personnel could have access to System security files, system management/configuration files … | Users could perform unauthorized functions | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | Moderate |
| 6.AC-6 (2) | AC-6(2) | Least Privilege | Non-Privileged Access For Non-security Functions | The organization requires that users of information system accounts, or roles, with access to organization-defined security functions or security-relevant information, use non- privileged accounts or roles, when accessing non-security functions. | Are users with elevated privileges forced to use a non-privileged user account when performing non-privileged, i.e. non-security, functions? | Yes, No | Yes = Compliant | ||||||||||||
| No = Non-compliant | C-I | Moderate | Moderate | Moderate | Elevated privilege. Users have more access than required. | Users could perform unauthorized functions | x | ERROR:#REF! | x | 2 | Low |
8.AC-6 (9) AC-6 (9)
Department of Veterans Affairs: Department of Veterans Affairs:
| Covered by local SOP | Least Privilege | Auditing Use Of Privileged Functions | The information system audits the execution of privileged functions. | Are privileged functions audited? (e.g. user management, configuration changes, etc.?)? | Yes, No | Yes = Compliant | ||||||
| No = Non-compliant | C-I | Moderate | High | High | Insider threat and advanced persistent threat will go undetected | Creates undetected and unauthorized process | x | x | x | 3 | Moderate |
12.AC-18 (1) AC-18 (1) Wireless Access | Authentication and Encryption The information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption. Is wireless access to the medical device permitted only through the use of authentication with encryption? Yes, No, N/A - The device does not support wireless protocols Yes = Compliant No = non-compliant
| N/A = compliant | C-I | Low | High | Moderate | Medical device and/or information system likely to be compromised | ||||
| Authentication credentials are sent as clear text | Data can be compromised | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | Moderate |
14.AU-3 (1) AU-3 (1) Content of Audit Records | Additional Audit Information The information system generates audit records containing the following additional information: [Assignment: organization-defined additional, more detailed information]. Does the medical device generate audit records? Yes, No Yes = Compliant No = Non-compliant
| C-I | Moderate | High | Moderate | Lack of or insufficient audit records can lead to insider threat actions to go unnoticed or unattributed | Undetected or unattributed cyber breach | x | x | x | 3 | Low | |
| 15.AU-4 | AU-4 | Audit Storage Capacity | Control: The organization allocates audit record storage capacity in accordance with [Assignment: organization-defined audit record storage requirements]. | Does the medical device allocate audit record storage capacity? | Yes, No | Yes = Compliant | |||||
| No = Non-compliant | A | Moderate | High | Moderate | Lack of or insufficient audit records can lead to insider threat actions to go unnoticed or unattributed | Data breach | x | x | x | 3 | Low |
| 16.AU-5 | AU-5 | Response to Audit Processing Failures | a. Alerts [Assignment: organization-defined personnel or roles] in the event of an audit processing failure; and | Is the medical device designed to alert personnel in the event of an audit processing failure? | Yes, No | Yes = Compliant | |||||
| No = Non-compliant | A | Moderate | High | Moderate | Insider threat and advanced persistent threat will go undetected | Data breach and/or data misplace | ERROR:#REF! | x | 1 | Low | |
| 17.AU-5 | AU-5 | Response to Audit Processing Failures | b. Takes the following additional actions: [Assignment: organization-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)]. | Does the medical device take action if an audit processing failure happen? | Yes, No | Yes = Compliant | |||||
| No = Non-compliant | A | Moderate | High | Moderate | Cannot prevent Malware attack | An attack could send large volumes of messages to overwhelm server or network. | x | x | 2 | Low | |
| 18.AU-7 | AU-7 | Audit Reduction and Report Generation | Control: The information system provides an audit reduction and report generation capability that: |
a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and B. Does not alter the original content or time ordering of audit records.
Does the medical device support on-demand and after-the-fact audit record reviews? Yes, No Yes = Compliant No = Non-compliant;
C-I Moderate Moderate Moderate It will be difficult to establish, correlate and investigate events leading to an outage or attack, or identify the responses.
| No automated Incidence Report | ERROR:#REF! | x | 1 | Low | |||||
| 19.AU-7 | AU-7 | Audit Reduction and Report Generation | b. Does not alter the original content or time ordering of audit records. | Does the device prevent the audit records from able to be altered? | Yes, No | Yes = Compliant |
No = Non-Compliant
| C-I | Low | Moderate | Low | Integrity of Audit record is compromised | |||||||||
| Records are not usable for forensic analysis | ERROR:#REF! | x | 1 | Low | |||||||||
| 20.AU-7 (1) | AU-7 (1) | Audit Reduction and Report Generation | Automatic Processing | The information system provides the capability to process audit records for events of interest based on [Assignment: organization-defined audit fields within audit records]. | Is the medical device configured to process audit records based according to defined lists? | Yes, No | Yes = Compliant | |||||||
| No = Non-compliant | C-I | Moderate | Moderate | Moderate | Conformity/compliance will not be determined | Failed audit | ERROR:#REF! | x | 1 | Low | |||
| 21.AU-8 | AU-8 | Time Stamps | Control: The information system: |
a. Uses internal system clocks to generate time stamps for audit records; and
b. Records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets [Assignment: organization-defined granularity of time measurement].
| Is the medical device configured to report time stamps to <SELECT: Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT)> with the following level of detail: < MM/DD/YY HH/MM/SS> | Yes, No. | Yes = Compliant | ||||||||
| No = Non-compliant | I | Low | Low | Low | No common time reference | Difficult to perform forensic analysis | ERROR:#REF! | x | 1 | Low |
| 22.AU-8 (1) | AU-8(1) | Time Stamps | Synchronization With Authoritative Time Source | The information system: |
(a) Compares the internal information system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and
| Is the medical device configured to synchronize its internal information system clock with an authorized NTP? | Yes, No. | Yes = Compliant | |||||||||
| No = Non-compliant | I | Low | Low | Low | No common time reference | Difficult to perform forensic analysis | ERROR:#REF! | x | 1 | Low | |
| 23.AU-8 (1) | AU-8(1) | Time Stamps | Synchronization With Authoritative Time Source | (b) Synchronizes the internal system clocks to the authoritative time source when the time difference is greater than [Assignment: organization-defined time period]. | Is the medical device configured to synchronize its internal information system clock with an authorized NTP when the time is out of synch by XXXX? | Yes, No. | Yes = Compliant | |||||
| No = Non-compliant | I | Low | Low | Low | No common time reference | Difficult to perform forensic analysis | ERROR:#REF! | x | 1 | Low |
27.CP-9
Department of Veterans Affairs: Department of Veterans Affairs:
Covered under local SOP CP-9 Information System Backup Control: The organization:
a. Conducts backups of user-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];
b. Conducts backups of system-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];
c. Conducts backups of information system documentation including security-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and
d. Protects the confidentiality, integrity, and availability of backup information at storage locations.
| Is there a device backup infrastructure in place for the medical device? | Yes, No. | Yes = Compliant | ||||||||
| No = Non-compliant | C-I-A | Low | High | Moderate | Data Loss | Loss of Availability | ||||
| Disruption of service | ERROR:#REF! | ERROR:#REF! | x | 1 | Low | |||||
| 28.CP-9 | CP-9 | Information System Backup | a. Conducts backups of user-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; | Does the medical device conduct backups of user-level information? | Yes, No, N/A - The device does not store user-level information | Yes = Compliant |
No = Non-compliant
| N/A = N/A | C-I-A | Low | High | Moderate | Loss of data generated by information system and/or application users. | Loss of Availability | ||||||||
| Disruption of service | ERROR:#REF! | x | 1 | Low | ||||||||||
| 29.CP-9 | CP-9 | Information System Backup | b. Conducts backups of system-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; | Does the medical device conduct backups of system-level information? | Yes, No | Yes = Compliant | ||||||||
| No = Non-compliant | C-I-A | Low | High | Moderate | Unable to recover system information after system failure | Loss of system information (CIA) | ERROR:#REF! | x | 1 | Low | ||||
| 30.CP-9 | CP-9 | Information System Backup | c. Conducts backups of information system documentation including security-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and | Does the medical device back-up security related information? | Yes, No | Yes = Compliant | ||||||||
| No = Non-compliant | C-I-A | Low | Moderate | Moderate | Failure to meet system recovery time and recovery point objectives | Information System temporary unavailable | ERROR:#REF! | x | 1 | Low | ||||
| 31.CP-9 | CP-9 | Information System Backup | d. Protects the confidentiality, integrity, and availability of backup information at storage locations. | Is there a process in place to protect the confidentiality, integrity, and availability (CIA) of backed-up data? | Yes, No, N/A - Sensitive data is not backed-up | Yes = Compliant |
No = Non-compliant
| N/A = N/A | C-I-A | Low | Moderate | Moderate | Unauthorized access of backed-up information | Loss of backed-up data (CIA) | ERROR:#REF! | ERROR:#REF! | x | 1 | Low |
| 32.CP-10 (1) | CP-10 | Information System Recovery and |
Reconstitution
| Control: The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure. | Does the medical device have an individual contingency plan? | Yes, No | Yes = Compliant | |||||||
| No = Non-compliant | A | Low | Moderate | Low | Unable to plan for system recovery | Loss of CIA | x | x | 2 | Low |
| 32.CP-10 (2) | CP-10 | Information System Recovery and |
Reconstitution
| Control: The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure. | Does the medical device have documented recovery and reconstitution procedures? | Yes, No | Yes = Compliant | |||||||
| No = Non-compliant | A | Low | Moderate | Moderate | Unsuccessful system restoration | Loss of data (CIA) | x | x | 2 | Low |
| 35.MP-2 | MP-2 | Media Access | Control: The organization restricts access to [Assignment: organization-defined types of digital and/or non-digital media] to [Assignment: organization-defined personnel or roles]. | Is access to the medical device restricted to a group of personnel or roles? | Yes, No | Yes = Compliant | ||||||
| No = Non-compliant | C-I | Low | Moderate | Low | Unauthorized personnel having access to digital and non digital media | Loss of confidentiality | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | Low |
| 36.MP-3 | MP-3 | Media Marking | Control: The organization: |
a. Marks information system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information; and
| Is medical device media marked indicating the distribution limitations, handling caveats, and any applicable security markings? | Yes, No, N/A = Explain | Yes = Compliant | ||||||||
| No = Non-compliant | C | Low | Low | Low | Mishandling of media devices not marked for security purpose | Loss of confidentiality and integrity | ERROR:#REF! | 0 | Low | |
| 37.MP-3 | MP-3 | Media Marking | b. Exempts [Assignment: organization-defined types of information system media] from marking as long as the media remain within [Assignment: organization-defined controlled areas]. | Are there exemptions for media marking for medical devices that remain within specified areas? | Yes, No, N/A = Explain | Yes = Compliant | ||||
| No = Non-compliant | C | Low | Low | Low | Unauthorized access and mishandling of unmarked media devices | Data breach | ERROR:#REF! | 0 | Low |
| 40.RA-5 (5) | RA-5 (5) | Vulnerability Scanning | Privileged Access | The information system implements privileged access authorization to [Assignment: organization- identified information system components] for selected [Assignment: organization-defined vulnerability scanning activities]. | Is the medical device configured to support privileged-access vulnerability scans? | Yes, No | Yes = Compliant | |||||
| No = Non-compliant | C-I-A | High | High | High | Failure to perform scanning could result in system vulnerabilities going undetected. Over time, undiscovered emerging vulnerabilities will increase the amount of risk. | Vulnerabilities could lead to compromises of Confidentiality, Integrity, and Availability (CIA). | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High |
51.SC-15
Department of Veterans Affairs: Department of Veterans Affairs:
addressed in 6550 Appendix A
Department of Veterans Affairs: Department of Veterans Affairs:
PPS are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:
There needs to be a local SOP created for this as well.
PPS are identified during PRE-procurement, in VA 6550A
Department of Veterans Affairs: Department of Veterans Affairs:
PPS are defined in the Pre-procurement docs.
Department of Veterans Affairs: Department of Veterans Affairs:
This could be mitigated slightly with IPv4 backwards compatibility.
Department of Veterans Affairs: Department of Veterans Affairs:
PPS are identified during PRE-procurement, in VA 6550A
Department of Veterans Affairs: Department of Veterans Affairs:
S are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:
Procedures are identified during PRE-procurement, in VA 6550A.
Department of Veterans Affairs: Department of Veterans Affairs:
Procedures are identified during PRE-procurement, in VA 6550 Appendix A
Department of Veterans Affairs: Department of Veterans Affairs:
Covered under local SOP
Department of Veterans Affairs: Department of Veterans Affairs:
Tools are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:
Described in Pre-Procurement VA 6550 Appendix A Department of Veterans Affairs: Department of Veterans Affairs:
Needs to be a local SOP.
Department of Veterans Affairs: Department of Veterans Affairs:
relates to role based access, could it be removed
Department of Veterans Affairs: Department of Veterans Affairs:
Needs to be a local SOP.
Department of Veterans Affairs: Department of Veterans Affairs:
Documented in Pre-Procurement.
Department of Veterans Affairs: Department of Veterans Affairs:
SOP required for device that does not follow VA's Elevated Privileges.
Department of Veterans Affairs: Department of Veterans Affairs:
Wanda to research if the USB 10 memo would apply
Department of Veterans Affairs: Department of Veterans Affairs:
Covered by local SOP Department of Veterans Affairs: Department of Veterans Affairs:
Addressed in 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:
addressed in 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:
information may be derived from MDS2 and 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:
can be derived from MDS2 and 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:
SOP should be added as mitigating factor SC-15 Collaborative Computing Devices Control: The information system:
a. Prohibits remote activation of collaborative computing devices with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and
If the device utilizes collaborative computing devices (e.g. cameras, microphones, etc.), does the Medical Device prohibit remote activation of the collaborative features? Yes, No, N/A = The device does not contain collaborative computing devices Yes = Compliant No = Non-compliant
| N/A = N/A | C | Moderate | High | High | Remote activation of unauthorized and unmonitored use of collaborative computing devices may provide unauthorized access to remote users. | System hijacking, installation of malware, unauthorized disclosure of sensitive information, compromise of data integrity, loss of system availability | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | 0 | High |
| 52.SC-15 | SC-15 | Collaborative Computing Devices | Control: The information system: |
b. Provides an explicit indication of use to users physically present at the devices. If collaborative features are enabled, are users physically present aware (e.g. flashing light indicating camera is on, etc.) Yes, No, N/A = The device does not contain collaborative computing devices Yes = Compliant No = Non-compliant
| N/A = N/A | C | Moderate | Moderate | Moderate | Remote attacks using collaborative technologies could go unnoticed by the local user. | Unauthorized disclosure of sensitive data, potential exploitation in compromise of the local device or other networked devices. | ERROR:#REF! | ERROR:#REF! | 0 | Moderate | |
| Accepted Mitigation Factors | |||||||||||
| AMF.1 | -- | MDIA | All devices are required to be behind a compliant MDIA ACL. | Is or will the device behind a compliant VLAN ACL? | No | Yes - Accepted Mitigation Factor |
No - No Risk Downgrades AMF.2 -- Secured Location Controlled and secured locations may reduce the risk of certain vulnerabilities. Is the device secured from physical access when not actively in use? No Yes - Accepted Mitigation Factor No - No Risk Downgrades AMF.3 -- Internet Requirement Devices that do not require the internet to operate may have a lower risk exposure. Is the device able to be operated without an active external connection? (e.g. connection outside of the VA network) No Yes - Accepted Mitigation Factor No - No Risk Downgrades AMF.4 -- Record Storage For the purposes of breach notification, breaches that occur on devices that contain less than 500 records are required to be reported annually, whereas breaches of 500 records or more must be reported immediately to HHS and in most cases the media. Is the device able to be restricted to store less than 500 patient records? No Yes- Accepted Mitigation Factor No - No Risk Downgrade N/A - Device does not store ePHI AMF.5 -- Maintenance Installation Contracts The VA Maintenance / Installation (Warranty) Contracts (VAIQ 7058822) intends to protect access to SPI during installation, maintenance, and repair of devices that may contain SPI. Is the device covered by a compliant VA Maintenance / Installation (Warranty) Contract? No Yes - Accepted Mitigation Factor No - No Risk Downgrade AMF.6 -- Medical Device USB Drive USB Drives or flash media allow exploits to be easily introduced into the VA environment. The HTM Memo "Guidance for Determining the Need for a Waiver for Medical Device USB Drives" defines requirements and best practices for utilizing USB Drives and Media. Prior to using a USB drive with the device, are the conditions in the 10N memo (e.g. …. ….. ……. )followed?
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .