Attachment E MD ERA Protocol.xlsx

XLSX spreadsheet 69 KB Posted

Attached to
6515--PSG & EEG Replacement VISN Federal contract opportunity
Solicitation number
36C25522Q0345
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 15

About this file

This document contains a risk assessment template for evaluating medical devices. The template includes columns for control ID, control title, risk assessment questions, data validation options, security objectives, likelihood and impact ratings, vulnerabilities from non-compliance, and mitigating factors. Additional tabs provide lists for accepted mitigation factors, common ports, protocols and services, and acronyms. The risk assessment is intended to evaluate devices for a federal contract opportunity issued by the Department of Veterans Affairs for replacement polysomnography and electroencephalogram equipment under solicitation number 36C25522Q0345 for VISN 15. The template provides a framework for assessing risks across technical, operational and administrative controls to identify security gaps and residual risks in medical devices being considered for the replacement PSG and EEG equipment.

View the file

Other files for this federal contract opportunity

Other files attached to 6515--PSG & EEG Replacement VISN, newest first.
File Type Posted
36C25522Q0345.pdf PDF
Attachment C MD ERA Network.pdf PDF
Attachment D MD ERA Inventory.xlsx XLSX spreadsheet
Attachment A 6550.pdf PDF
Attachment B MDS2.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Risk Data-Key

QuestionControl IDControl TitleDescriptionRisk Assessment QuestionnaireData Validation OptionsActionSecurity Objectives
(C-I-A)LikelihoodImpactRiskVulnerability (If Non-Compliant)Impact of Non-Compliant ControlMDIASecured LocationInternal Connections OnlyMinimal Record StorageMaintenance Installation ContractsMedical Device USB Drive 10N MemoMDPP Scanning StationsPhysical Device MonitoringClinical Functionality (Alternate Method)SOPNetworked Medical Device Databases (NMDD)Mitigating FactorsFinal Residual Risk
PPA.1CM-2Operating SystemThe device runs on a supported operating system platform.Does the device run on a supported Operating System?Yes, NoYes = Compliant
No = Non-CompliantILowHighHighUnsupported operating Systems may be subject to vulnerabilities that will not be patched due to the unsupported nature of the operating system.Unpatched VulnerabilitiesERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.2CM-6Database ApplicationThe device runs on a supported database application.If the devices uses a database application, is it currently supported (e.g. not end-of-life)?Yes, NoYes = Compliant

No = Non-Compliant

N/A = N/AIHighHighHighUnsupported database systems may be subject to vulnerabilities that will not be patched due to the unsupported nature of the operating system.Unpatched VulnerabilitiesERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.3AU-4Audit LogsThe device will maintain at least a 90 day history of transactions that will permit the audit of individual’s activities throughout the system.Does the device maintain at least 90 days of audit logs associated with user activity?Yes, NoYes = Compliant
No = Non-CompliantAModerateHighLack of or insufficient auditing can lead to potential cyber attacks or insider threat actions to go unnoticed or unattributed to a specific user.Undetected or unattributed cyber breachERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.4SC-23Web Browser - Secure Communications ProtocolThe device is configured to only use a secure communications protocol for web browser-based access. (i.e. SSL, TLS)If the device utilizes a web browser for access, is it configured for secure communications (SSL, HTTPS, etc.)?Yes, No, N/A - The device does not use a web browser for accessYes = Compliant

No = Non-Compliant

N/A = N/AIModerateModerateUsing a non-secure communication protocol could expose patient data or potential expose the device to man-in-the-middle attacks.Unauthorized DisclosureERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.5CM-11Patching - Windows Server Update ServicesIf the device runs a Microsoft Windows operating system, the device can use Microsoft Windows Server Update Services (WSUS) to obtain operating system patches.If the device runs a Microsoft Operating System, does the device utilize a Microsoft Windows Server Update Services (WSUS) server?Yes, No, N/A - The device is not a Windows DeviceYes = Compliant

No = Non-Compliant

N/A = N/AIHighHighHighCritical patches, updates are more likely to be missed when requiring manual patching processes.Unpatched VulnerabilitiesERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.6SI-2Patching - ProcessThe device manufacturer will provide a complete, documented process to perform routine OS patch updates including all approval and notification procedures that must be completed prior to applying patches.Has the device manufacturer provided a complete and documented process detailing how and when routine OS patch updates are to be applied, and by whom?Yes, NoYes = Compliant
No = Non-CompliantIHighHighHighIf process is not known on how to apply OS patches and who is authorizes the update. Then OS patch update can not occur, due to lack of documentation.Unpatched VulnerabilitiesERROR:#REF!x1Moderate
PPA.7SI-2Patching - CriticalThe device manufacturer will provide complete documented process to perform critical operating system and application security patching within 30 days of the release of the patch from the software vendor.Has the device manufacturer provided a documented process for addressing critical operating system and application patches for patching within 30 days from the release of the patch?Yes, NoYes = Compliant

No = Non-Compliant

IHighHighHighUnable to apply critical patches in a timely fashion.Elevated risk exposure due to unpatched critical vulnerabilities.xx2Moderate
PPA.8SI-3Antivirus SoftwareThe device manufacturer supports the installation and operation of antivirus and will provide a complete, documented process to perform routine antivirus updates to include all approval notification procedures that must be completed prior to updating the antivirus software.Does the device support the installation of anti-virus software, to include routine antivirus updates?Yes, NoYes = Compliant
No = Non-CompliantIHighHighHighMalware and virus aim at device can go undetected.Loss of CIAERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.9MP-7Universal Serial Bus (USB) PortsUnused USB ports are disabled upon initial deployment.Are all unused USB ports disabled?Yes, No, N/A - The device does not have USB portsYes = Compliant

No = Non-Compliant

N/A = N/AC-IModerateHighHighUnauthorized services to include malware.Loss of CIAERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.10CM-7AutorunAutorun (Windows OS) behavior is disabled upon initial deployment.Is autorun disabled on Windows OS devices?Yes, No, N/A - The device is not a Windows DeviceYes = Compliant

No = Non-Compliant

N/A = N/AC-IModerateHighHighPhysical access could bypass access control and it can execute unauthorized applications.Unauthorized disclosure or execution of malware.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.11RA-5Vulnerability Assessmentsa) The manufacturer will support security testing to assess vulnerabilities on the device.
b) The device will be designed such that the testing will not affect the operational services of the device.Does the device support automated vulnerability assessment scans without operational impact to the device?Yes, NoYes = Compliant
No = Non-CompliantC-I-AHighHighHighIf we do not scan we do not find vulnerabilities. Scanning may cause system to crash.Mitigation cannot be applied if vulneraries are not identified through scanning.ERROR:#REF!ERROR:#REF!0High
PPA.12MP-6Media SanitizationProper disposal of medical devices that reach end of life. All medical device hard drives or other media containing VA sensitive data must follow VA’s current media sanitization policy.If the device is being returned to the manufacturer at EOL or for other scenarios, is the VA Media Sanitization policy followed?Yes, No, N/A - The device does not store sensitive dataYes = Compliant

No = Non-Compliant

N/A = N/ACLowHighIt will lead to unauthorized access.Unauthorized disclosure of sensitive information e.g., ePHI/PII.ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.13AC-2Role Based AccessThe device will support role based access for all users.Does the device support role-based access for all users?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateModerateElevated privilege. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.14AC-6Administrator AccountsAdministrator accounts:

a) will be required for service, software installation, and system configuration and;

Does the device require administrative access for service, software installation, and system configuration activities?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateHighHighUnauthorized personnel being able to perform administrator functions.Unauthorized changes can be made to the system.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.15IA-2 (1)Administrator Accountsb) will support the use of two factor authentication of the administrator account.Does the device support two-factor authentication for administrative accounts?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerate(username and password more likely to be compromised)Unauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.16

Department of Veterans Affairs: Department of Veterans Affairs:

relates to role based access, could it be removed

AC-6Operator AccountsThe device will operate with full clinical functionality under a general user or operator account. User privileges on the device should limit the user/operator to general use and operation of the device.Does the device operate with full clinical functionality with user level privileges?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateModerateElevated privilege. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.17IA-5Default Usernames and PasswordsThe device will not use default usernames and passwords. All default usernames will be renamed or disabled and all default passwords must be changed after installation of the device.Have device's default usernames and/or passwords been changed?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerateDefault usernames and passwords are known by unauthorized usersUnauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.18AC-2Shared AccountsThe device will not require the use of shared accounts.Does the device require or use shared accounts?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerateLack of non-repudiationLack of accountabilityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.19AC-2Shared AccountsShared accounts will be removed / disabled upon delivery. (i.e. generic accounts, work accounts)Are all shared accounts removed or disabled on the device?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerateLack of non-repudiationLack of accountabilityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.20IA-2Individual User AuthenticationThe device will be configured for individual user authentication.Is the device configured to used individual user authentication?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateModerateLack of non-repudiationLack of accountabilityERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.21IA-5(1)Password AgingThe device will be configured to prompt a user to create a new password at least every 90 days.Is the device configured to support a 90 day password age?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateHighHighPasswords are more likely to be compromisedUnauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.22IA-5(1)Strong PasswordsThe device will enforce the use of strong passwords with a minimum complexity setting of:

• Minimum length of 8 characters

• Complexity rules:

o Minimum of one (1) uppercase letter o Minimum of one (1) lowercase letter o Minimum of one (1) number o Minimum of one (1) special character o Password must not match the last five (5) previously used passwords Is the device configured to support strong passwords with a minimum complexity setting of:

• Minimum length of 8 characters o Minimum of one (1) uppercase letter o Minimum of one (1) lowercase letter o Minimum of one (1) number o Minimum of one (1) special character

o Password must not match the last five (5) previously used passwordsYes, NoYes = Compliant
No = Non-CompliantC-IModerateModeratePasswords are more likely to be compromisedUnauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.23AC-11Auto Logoff/Session LockThe device is capable of session lock after at least 15 minutes of inactivity and is configurable based on based on clinical use.Is the device configured to lock session activity after 15 minutes of inactivity or configured in accordance with documented clinical requirements?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateModeratePrivacy exposureUnauthorized disclosureERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.24IA-5(2)User Authentication - Personal Identity Verification (PIV) Card/ Smart CardThe device supports Personal Identity Verification (PIV) card/smart card user authentication and card readers.Does the device support PIV/Smart Card user authentication?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerate(username and password more likely to be compromised)Unauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.25SC-28Data Encryption – MechanismThe device will support whole disk encryption as a means to protect patient data.Does the device protect data-at-rest with whole disk encryption?Yes, No, N/A - The device does not store sensitive dataYes = Compliant

No = Non-Compliant

N/A = N/AC-IModerateHighHighData breachLost of confidentialityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.26SC-13Data Encryption - Federal Information Processing Standard Publication 140-2, (FIPS PUB 140-2) ValidationThe device, its communication protocols, and any associated storage media are configured to use an encryption mechanism that is compliant with FIPS PUB 140-2. The device meets FIPS PUB 140-2 requirements and is accompanied by a manufacturer provided validation certificate or signed letter/statement confirming inclusion of the unmodified validated cryptographic module.Does the device meet FIPS PUB 140-2 requirements?Yes, No, N/A - The device does not contain cryptographic modulesYes = Compliant

No = Non-Compliant

N/A = N/AC-IVery LowModerateUn-verified cryptographic modules could lead to weak encryptionData breachERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.27SC-13Data Encryption – Health Insurance Portability and Accountability Act (HIPAA)The device, its communication protocols, and any associated storage media are configured to meet HIPAA standards for encryption and decryption including 164.312(a)(2)(iv) and 164.312(e)(2)(ii) and implements a method to encrypt and decrypt ePHI.Is the device configured to support data at rest and transmission security for sensitive data at rest and in-transit?Yes, No, N/A - The device does not transmit, process, store ePHIYes = Compliant

No = Non-Compliant

N/A = N/AC-IHighHighHighData breachLoss of confidentialityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.28AC-4(22)Data StorageIf the device has the capability to store ePHI or PII, sensitive data will be stored on a separate hard drive.Is ePHI or PII stored on a separate hard drive?Yes, No, N/A - The device does not transmit, process, store ePHIYes = Compliant

No = Non-Compliant

N/A = N/AC-ILowModerateData cannot be purged before equipment is servicedSensitive information could be compromisedERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.29

Department of Veterans Affairs: Department of Veterans Affairs:

SOP should be added as mitigating factor CP-9 Data backups – Process The device manufacturer will provide a complete, documented process for performing routine and emergency data backups and recovery. Are device back-up processes complete and documented, to include routine and emergency data back-ups and recovery? Yes, No, N/A - The device does not store data Yes = Compliant No = Non-Compliant

N/A = N/AC-I-ALowHighLoss of Data and incomplete recoveryLoss of Availability
ERROR:#REF!xERROR:#REF!x20
PPA.30IA-4Unique Identification NumbersThe device generates a unique patient identified in lieu of using individual identifies (i.e.. name and social security number) to avoid linking personal information to a specific patient.Is the device configured to create unique identification numbers for each patient vs. using individual identity information (Name and SSN)?Yes, No, N/A - The device does not generate patient identifiersYes = Compliant
No = Non-CompliantC-ILowHighWithout unique identification number, ePHI/PII could be compromisedLoss of confidentiality and identity theftERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.31SA-5Bandwidth – Local Area Network (LAN)The device manufacturer will provide a complete, documented technical specification defining LAN bandwidth requirements to enable full connectivity and optimal system performance.Are comprehensive LAN requirements defined and documented for the device?Yes, NoYes = Compliant
No = Non-CompliantC-I-ALowModerateIf device LAN requirements are not defined or documented device may not connect to Network properly.Loss of Availability possible due to incorrect network settings.ERROR:#REF!xERROR:#REF!10
PPA.32SA5Bandwidth – Wide Area Network (WAN)The device manufacturer will provide a complete, documented technical specification defining WAN bandwidth requirements to enable full connectivity and optimal system performanceAre comprehensive WAN requirements defined and documented for the device?Yes, NoYes = Compliant
No = Non-CompliantC-I-ALowModerateIf device WAN requirements are not defined or documented device may not connect to Network properly.Loss of Availability possible due to incorrect network settings.ERROR:#REF!xERROR:#REF!10
PPA.33SC-8Communication Protocols – Use of Clear TextThe device will not use clear text protocols for communication to and from the device. (i.e.. FTP; telnet)Does the device use only secure protocols for communication to and from the device (SSH, SSL, etc. not FTP, telnet.)Yes, NoYes = Compliant
No = Non-CompliantC-I-AModerateHighSensitive information can be intercepted during transmission.Unauthorized disclosure e.g. man-in-the-middle, data theft.ERROR:#REF!ERROR:#REF!00
PPA.34

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are identified during PRE-procurement, in VA 6550ASA-4(9)Communication Protocols - Identification of Portsa) The device manufacturer will provide a complete, documented technical specification defining all TCP and UDP ports that are required for operation.
Has the device manufacturer provided a detailed technical specification defining all TCP and UDP ports required for device operation?Yes, NoYes = Compliant
No = Non-CompliantC-I-ALowModerateInsufficient defined detailed documentation could expose the device to malware and virusUnauthorized access e.g. session hijacking, installation of malware/ransomwareERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.35

Department of Veterans Affairs: Department of Veterans Affairs:

There needs to be a local SOP created for this as well.

PPS are identified during PRE-procurement, in VA 6550A

SA-5Communication Protocols - Identification of Portsb) The device manufacturer will provide a reference network diagram illustrating all communication requirements.Has the device manufacturer provided a detailed network diagram illustrating on device communication requirements?Yes, NoYes = Compliant
No = Non-CompliantC-I-AHighModerateViolation of configuration management policies and procedures could go undetectedUnauthorized network accessxERROR:#REF!10
PPA.36

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are defined in the Pre-procurement docs.SA-5Static Internet Protocol (IP) AddressesThe device manufacturer will provide a complete, documented technical specification defining the number of static IP addresses required for device/system operation.Has the device manufacturer defined the number of static IP addresses required for device / system operation?Yes, NoYes = Compliant
No = Non-CompliantC-I-ALowLowIf multiples static IP are required and not known it could affect the operation of device and make it less accessible.Device operation may be affected if number of defined static address are not known thus compromising availabilityERROR:#REF!x10
PPA.37

Department of Veterans Affairs: Department of Veterans Affairs:

This could be mitigated slightly with IPv4 backwards compatibility.CM-6Internet Protocol version 6 (IvP6) CompatibilityThe device is IPv6 enabled.Does the device support IPv6?Yes, NoYes = Compliant
No = Non-CompliantILowHighMay not be able to talk to a IPv6 networkLoss of availabilityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.38

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are identified during PRE-procurement, in VA 6550A

CM-6Active Ports and ProtocolsThe device configuration restricts active network communication ports and protocols to only those required to support intended operations. All unused ports and protocols are closed or disabled.Are all unused communication ports, closed or disabled?Yes, NoYes = Compliant
No = Non-CompliantIHighHighIf unused ports are not closed or disabled. Device would be susceptible to attack.Unauthorized access to device could be gained.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.39

Department of Veterans Affairs: Department of Veterans Affairs:

S are identified during PRE-procurement, in VA 6550ACM-6Active ServicesThe device configuration restricts running services on the device to only those required to support intended operations. All unused services (i.e.. Web services; remote connection services) are closed or disabled.Are all unused services closed or disabled?Yes, NoYes = Compliant
No = Non-CompliantIHighHighUnauthorized accessUndisclosed informationERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.40

Department of Veterans Affairs: Department of Veterans Affairs:

Procedures are identified during PRE-procurement, in VA 6550A.AC-17Remote Access - Servicinga) The device manufacturer will provide a complete, documented technical specification defining the procedures to ensure secure remote monitoring, access, repair, maintenance, and troubleshooting.
b) The device manufacturer will provide a reference network diagram illustrating all remote servicing communication requirements.Has the device manufacturer provided a complete, documented technical specification defining the procedures to ensure remote monitoring, access ,repair, maintenance and troubleshooting?Yes, No, N/A - The device does not support remote accessYes = Compliant

No = Non-Compliant

N/A = N/AC-IHighHighUnable to apply critical patches in a timely fashion.Critical vulnerabilities detected.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.41

Department of Veterans Affairs: Department of Veterans Affairs:

Procedures are identified during PRE-procurement, in VA 6550 Appendix A AC-17 Remote Access - Software The device manufacturer will provide a complete, documented technical specification defining all remote access software required for manufacturer support of the system. Has the device manufacturer provide a complete, documented, specification defining all remote access software required for manufacturer support of the system? Yes, No, N/A - The device does not support remote access Yes - Compliant No - Non-Compliant

N/A - The device does not support Remote AccessC-IModerateHighUnable to apply critical patches in a timely fashion.Critical vulnerabilities detected.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.42

Department of Veterans Affairs: Department of Veterans Affairs:

Tools are identified during PRE-procurement, in VA 6550ACM-7Internet Connection - IP/Port/TrafficThe device will not require a direct, unsecured connection to the Internet to enable operation or support.Does the device require a direct, unsecured connection to the Internet to support device operation?Yes, NoYes - Non-Compliant
No - CompliantC-IModerateHighHighUnauthorized services to include malware.Loss of CIA.
ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.43SA-4(9)Wireless Protocolsa) The device manufacturer will provide a complete, documented technical specification defining all wireless protocols (e.g., Wireless Medical Telemetry Service (WMTS), Bluetooth, and IEEE 802.11) used by the device.
b) The device manufacturer will provide a reference network diagram illustrating all wireless communication requirements.Has the device manufacturer provided a complete, documented, specification defining all wireless protocols used by the device?Yes, No, N/A - The device does not support wireless protocolsYes - Compliant

No - Non-Compliant

N/A - The device does not support wireless protocols.C-I-AVery LowModerateData BreachUnauthorized use of wireless communicationsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.44AC-18(1)Wireless Protocols - EncryptionThe device will support the use of a FIPS 140-2 encryption standard for wireless connectivity and communications without compromising device performance.Does the device use FIPS 140-2 encryption standards for wireless communications?Yes, No, N/A - The device does not support wireless protocolsYes - Compliant

No - Non-Compliant

N/A - The device does not support wireless protocols.C-IVery LowModerateNot meeting the Fops 140-2 requirement and unmodified cryptographic can lead to week encryptionData breachERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.45AC-18(1)Wireless Encryption: FIPS PUB 140-2 ValidationThe device meets FIPS PUB 140-2 requirements and is accompanied by a manufacturer provided validation certificate or signed letter/statement confirming inclusion of the unmodified validated cryptographic module.Has the manufacturer provided the FIPS 140-2 certificate for wireless communications?Yes, No, N/A - The device does not support wireless protocolsYes - Compliant

No - Non-Compliant

N/A - The device does not support wireless protocols.C-IVery LowModerateRevocation of access codes in the system.Providing confidentiality, authenticity and integrity of the dataERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
SA-4(9)Wireless Data TransmissionThe device manufacturer will provide a complete, documented technical specification defining all ePHI data elements transmitted via the device’s wireless communications.Has the manufacturer provided a complete, documented technical specification defining all ePHI data elements that are transmitted via the device's wireless communications?Yes, No, N/A - The device does not support wireless protocolsYes - Compliant

No - Non-Compliant N/A - The device does not support wireless protocols. C-I-A Moderate Moderate If not documented then potential vulnerabilities will go undetected Data leakage ERROR:#REF! ERROR:#REF! ERROR:#REF! ERROR:#REF! 0 0

2.AC-6(1)

Department of Veterans Affairs: Department of Veterans Affairs:

Needs to be a local SOP.

AC-6(1)Least Privilege | Authorize Access To Security FunctionsThe organization explicitly authorizes access to [Assignment: organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information].Technically speaking, does this device have the capability to establish multiple user roles and assign users to specific user roles, based on their assigned duties?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateElevated privilege. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
3.AC-6(1)

Department of Veterans Affairs: Department of Veterans Affairs:

Documented in Pre-Procurement.AC-6(1)Least Privilege | Authorize Access To Security FunctionsThe organization explicitly authorizes access to [Assignment: organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information].Does the device inherit User Access policies from the organization, e.g. GPO's or local access SOP?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateElevated privilege. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
4.AC-6(1)AC-6(1)Least Privilege | Authorize Access To Security FunctionsThe organization explicitly authorizes access to organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information.Is there device specific documentation describing which user roles are allowed which privileges on the device?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateExecution of Security functions by unauthorized personnel.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
5.AC-6(1)AC-6(1)Least Privilege | Authorize Access To Security FunctionsThe organization explicitly authorizes access to organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information.Have user roles and privileges been implemented in accordance with documented policy?Yes, NoYes = Compliant
No = Non-compliantC-ILowHighModerateunauthorized personnel could have access to System security files, system management/configuration files …Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
6.AC-6 (2)AC-6(2)Least Privilege | Non-Privileged Access For Non-security FunctionsThe organization requires that users of information system accounts, or roles, with access to organization-defined security functions or security-relevant information, use non- privileged accounts or roles, when accessing non-security functions.Are users with elevated privileges forced to use a non-privileged user account when performing non-privileged, i.e. non-security, functions?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateElevated privilege. Users have more access than required.Users could perform unauthorized functionsxERROR:#REF!x2Low

8.AC-6 (9) AC-6 (9)

Department of Veterans Affairs: Department of Veterans Affairs:

Covered by local SOPLeast Privilege | Auditing Use Of Privileged FunctionsThe information system audits the execution of privileged functions.Are privileged functions audited? (e.g. user management, configuration changes, etc.?)?Yes, NoYes = Compliant
No = Non-compliantC-IModerateHighHighInsider threat and advanced persistent threat will go undetectedCreates undetected and unauthorized processxxx3Moderate

12.AC-18 (1) AC-18 (1) Wireless Access | Authentication and Encryption The information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption. Is wireless access to the medical device permitted only through the use of authentication with encryption? Yes, No, N/A - The device does not support wireless protocols Yes = Compliant No = non-compliant

N/A = compliantC-ILowHighModerateMedical device and/or information system likely to be compromised
Authentication credentials are sent as clear textData can be compromisedERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate

14.AU-3 (1) AU-3 (1) Content of Audit Records | Additional Audit Information The information system generates audit records containing the following additional information: [Assignment: organization-defined additional, more detailed information]. Does the medical device generate audit records? Yes, No Yes = Compliant No = Non-compliant

C-IModerateHighModerateLack of or insufficient audit records can lead to insider threat actions to go unnoticed or unattributedUndetected or unattributed cyber breachxxx3Low
15.AU-4AU-4Audit Storage CapacityControl: The organization allocates audit record storage capacity in accordance with [Assignment: organization-defined audit record storage requirements].Does the medical device allocate audit record storage capacity?Yes, NoYes = Compliant
No = Non-compliantAModerateHighModerateLack of or insufficient audit records can lead to insider threat actions to go unnoticed or unattributedData breachxxx3Low
16.AU-5AU-5Response to Audit Processing Failuresa. Alerts [Assignment: organization-defined personnel or roles] in the event of an audit processing failure; andIs the medical device designed to alert personnel in the event of an audit processing failure?Yes, NoYes = Compliant
No = Non-compliantAModerateHighModerateInsider threat and advanced persistent threat will go undetectedData breach and/or data misplaceERROR:#REF!x1Low
17.AU-5AU-5Response to Audit Processing Failuresb. Takes the following additional actions: [Assignment: organization-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)].Does the medical device take action if an audit processing failure happen?Yes, NoYes = Compliant
No = Non-compliantAModerateHighModerateCannot prevent Malware attackAn attack could send large volumes of messages to overwhelm server or network.xx2Low
18.AU-7AU-7Audit Reduction and Report GenerationControl: The information system provides an audit reduction and report generation capability that:

a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and B. Does not alter the original content or time ordering of audit records.

Does the medical device support on-demand and after-the-fact audit record reviews? Yes, No Yes = Compliant No = Non-compliant;

C-I Moderate Moderate Moderate It will be difficult to establish, correlate and investigate events leading to an outage or attack, or identify the responses.

No automated Incidence ReportERROR:#REF!x1Low
19.AU-7AU-7Audit Reduction and Report Generationb. Does not alter the original content or time ordering of audit records.Does the device prevent the audit records from able to be altered?Yes, NoYes = Compliant

No = Non-Compliant

C-ILowModerateLowIntegrity of Audit record is compromised
Records are not usable for forensic analysisERROR:#REF!x1Low
20.AU-7 (1)AU-7 (1)Audit Reduction and Report Generation | Automatic ProcessingThe information system provides the capability to process audit records for events of interest based on [Assignment: organization-defined audit fields within audit records].Is the medical device configured to process audit records based according to defined lists?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateConformity/compliance will not be determinedFailed auditERROR:#REF!x1Low
21.AU-8AU-8Time StampsControl: The information system:

a. Uses internal system clocks to generate time stamps for audit records; and

b. Records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets [Assignment: organization-defined granularity of time measurement].

Is the medical device configured to report time stamps to <SELECT: Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT)> with the following level of detail: < MM/DD/YY HH/MM/SS>Yes, No.Yes = Compliant
No = Non-compliantILowLowLowNo common time referenceDifficult to perform forensic analysisERROR:#REF!x1Low
22.AU-8 (1)AU-8(1)Time Stamps | Synchronization With Authoritative Time SourceThe information system:

(a) Compares the internal information system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and

Is the medical device configured to synchronize its internal information system clock with an authorized NTP?Yes, No.Yes = Compliant
No = Non-compliantILowLowLowNo common time referenceDifficult to perform forensic analysisERROR:#REF!x1Low
23.AU-8 (1)AU-8(1)Time Stamps | Synchronization With Authoritative Time Source(b) Synchronizes the internal system clocks to the authoritative time source when the time difference is greater than [Assignment: organization-defined time period].Is the medical device configured to synchronize its internal information system clock with an authorized NTP when the time is out of synch by XXXX?Yes, No.Yes = Compliant
No = Non-compliantILowLowLowNo common time referenceDifficult to perform forensic analysisERROR:#REF!x1Low

27.CP-9

Department of Veterans Affairs: Department of Veterans Affairs:

Covered under local SOP CP-9 Information System Backup Control: The organization:

a. Conducts backups of user-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];

b. Conducts backups of system-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];

c. Conducts backups of information system documentation including security-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and

d. Protects the confidentiality, integrity, and availability of backup information at storage locations.

Is there a device backup infrastructure in place for the medical device?Yes, No.Yes = Compliant
No = Non-compliantC-I-ALowHighModerateData LossLoss of Availability
Disruption of serviceERROR:#REF!ERROR:#REF!x1Low
28.CP-9CP-9Information System Backupa. Conducts backups of user-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];Does the medical device conduct backups of user-level information?Yes, No, N/A - The device does not store user-level informationYes = Compliant

No = Non-compliant

N/A = N/AC-I-ALowHighModerateLoss of data generated by information system and/or application users.Loss of Availability
Disruption of serviceERROR:#REF!x1Low
29.CP-9CP-9Information System Backupb. Conducts backups of system-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];Does the medical device conduct backups of system-level information?Yes, NoYes = Compliant
No = Non-compliantC-I-ALowHighModerateUnable to recover system information after system failureLoss of system information (CIA)ERROR:#REF!x1Low
30.CP-9CP-9Information System Backupc. Conducts backups of information system documentation including security-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; andDoes the medical device back-up security related information?Yes, NoYes = Compliant
No = Non-compliantC-I-ALowModerateModerateFailure to meet system recovery time and recovery point objectivesInformation System temporary unavailableERROR:#REF!x1Low
31.CP-9CP-9Information System Backupd. Protects the confidentiality, integrity, and availability of backup information at storage locations.Is there a process in place to protect the confidentiality, integrity, and availability (CIA) of backed-up data?Yes, No, N/A - Sensitive data is not backed-upYes = Compliant

No = Non-compliant

N/A = N/AC-I-ALowModerateModerateUnauthorized access of backed-up informationLoss of backed-up data (CIA)ERROR:#REF!ERROR:#REF!x1Low
32.CP-10 (1)CP-10Information System Recovery and

Reconstitution

Control: The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.Does the medical device have an individual contingency plan?Yes, NoYes = Compliant
No = Non-compliantALowModerateLowUnable to plan for system recoveryLoss of CIAxx2Low
32.CP-10 (2)CP-10Information System Recovery and

Reconstitution

Control: The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.Does the medical device have documented recovery and reconstitution procedures?Yes, NoYes = Compliant
No = Non-compliantALowModerateModerateUnsuccessful system restorationLoss of data (CIA)xx2Low
35.MP-2MP-2Media AccessControl: The organization restricts access to [Assignment: organization-defined types of digital and/or non-digital media] to [Assignment: organization-defined personnel or roles].Is access to the medical device restricted to a group of personnel or roles?Yes, NoYes = Compliant
No = Non-compliantC-ILowModerateLowUnauthorized personnel having access to digital and non digital mediaLoss of confidentialityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Low
36.MP-3MP-3Media MarkingControl: The organization:

a. Marks information system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information; and

Is medical device media marked indicating the distribution limitations, handling caveats, and any applicable security markings?Yes, No, N/A = ExplainYes = Compliant
No = Non-compliantCLowLowLowMishandling of media devices not marked for security purposeLoss of confidentiality and integrityERROR:#REF!0Low
37.MP-3MP-3Media Markingb. Exempts [Assignment: organization-defined types of information system media] from marking as long as the media remain within [Assignment: organization-defined controlled areas].Are there exemptions for media marking for medical devices that remain within specified areas?Yes, No, N/A = ExplainYes = Compliant
No = Non-compliantCLowLowLowUnauthorized access and mishandling of unmarked media devicesData breachERROR:#REF!0Low
40.RA-5 (5)RA-5 (5)Vulnerability Scanning | Privileged AccessThe information system implements privileged access authorization to [Assignment: organization- identified information system components] for selected [Assignment: organization-defined vulnerability scanning activities].Is the medical device configured to support privileged-access vulnerability scans?Yes, NoYes = Compliant
No = Non-compliantC-I-AHighHighHighFailure to perform scanning could result in system vulnerabilities going undetected. Over time, undiscovered emerging vulnerabilities will increase the amount of risk.Vulnerabilities could lead to compromises of Confidentiality, Integrity, and Availability (CIA).ERROR:#REF!ERROR:#REF!ERROR:#REF!0High

51.SC-15

Department of Veterans Affairs: Department of Veterans Affairs:

addressed in 6550 Appendix A

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:

There needs to be a local SOP created for this as well.

PPS are identified during PRE-procurement, in VA 6550A

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are defined in the Pre-procurement docs.

Department of Veterans Affairs: Department of Veterans Affairs:

This could be mitigated slightly with IPv4 backwards compatibility.

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are identified during PRE-procurement, in VA 6550A

Department of Veterans Affairs: Department of Veterans Affairs:

S are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:

Procedures are identified during PRE-procurement, in VA 6550A.

Department of Veterans Affairs: Department of Veterans Affairs:

Procedures are identified during PRE-procurement, in VA 6550 Appendix A

Department of Veterans Affairs: Department of Veterans Affairs:

Covered under local SOP

Department of Veterans Affairs: Department of Veterans Affairs:

Tools are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:

Described in Pre-Procurement VA 6550 Appendix A Department of Veterans Affairs: Department of Veterans Affairs:

Needs to be a local SOP.

Department of Veterans Affairs: Department of Veterans Affairs:

relates to role based access, could it be removed

Department of Veterans Affairs: Department of Veterans Affairs:

Needs to be a local SOP.

Department of Veterans Affairs: Department of Veterans Affairs:

Documented in Pre-Procurement.

Department of Veterans Affairs: Department of Veterans Affairs:

SOP required for device that does not follow VA's Elevated Privileges.

Department of Veterans Affairs: Department of Veterans Affairs:

Wanda to research if the USB 10 memo would apply

Department of Veterans Affairs: Department of Veterans Affairs:

Covered by local SOP Department of Veterans Affairs: Department of Veterans Affairs:

Addressed in 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:

addressed in 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:

information may be derived from MDS2 and 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:

can be derived from MDS2 and 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:

SOP should be added as mitigating factor SC-15 Collaborative Computing Devices Control: The information system:

a. Prohibits remote activation of collaborative computing devices with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and

If the device utilizes collaborative computing devices (e.g. cameras, microphones, etc.), does the Medical Device prohibit remote activation of the collaborative features? Yes, No, N/A = The device does not contain collaborative computing devices Yes = Compliant No = Non-compliant

N/A = N/ACModerateHighHighRemote activation of unauthorized and unmonitored use of collaborative computing devices may provide unauthorized access to remote users.System hijacking, installation of malware, unauthorized disclosure of sensitive information, compromise of data integrity, loss of system availabilityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
52.SC-15SC-15Collaborative Computing DevicesControl: The information system:

b. Provides an explicit indication of use to users physically present at the devices. If collaborative features are enabled, are users physically present aware (e.g. flashing light indicating camera is on, etc.) Yes, No, N/A = The device does not contain collaborative computing devices Yes = Compliant No = Non-compliant

N/A = N/ACModerateModerateModerateRemote attacks using collaborative technologies could go unnoticed by the local user.Unauthorized disclosure of sensitive data, potential exploitation in compromise of the local device or other networked devices.ERROR:#REF!ERROR:#REF!0Moderate
Accepted Mitigation Factors
AMF.1--MDIAAll devices are required to be behind a compliant MDIA ACL.Is or will the device behind a compliant VLAN ACL?NoYes - Accepted Mitigation Factor

No - No Risk Downgrades AMF.2 -- Secured Location Controlled and secured locations may reduce the risk of certain vulnerabilities. Is the device secured from physical access when not actively in use? No Yes - Accepted Mitigation Factor No - No Risk Downgrades AMF.3 -- Internet Requirement Devices that do not require the internet to operate may have a lower risk exposure. Is the device able to be operated without an active external connection? (e.g. connection outside of the VA network) No Yes - Accepted Mitigation Factor No - No Risk Downgrades AMF.4 -- Record Storage For the purposes of breach notification, breaches that occur on devices that contain less than 500 records are required to be reported annually, whereas breaches of 500 records or more must be reported immediately to HHS and in most cases the media. Is the device able to be restricted to store less than 500 patient records? No Yes- Accepted Mitigation Factor No - No Risk Downgrade N/A - Device does not store ePHI AMF.5 -- Maintenance Installation Contracts The VA Maintenance / Installation (Warranty) Contracts (VAIQ 7058822) intends to protect access to SPI during installation, maintenance, and repair of devices that may contain SPI. Is the device covered by a compliant VA Maintenance / Installation (Warranty) Contract? No Yes - Accepted Mitigation Factor No - No Risk Downgrade AMF.6 -- Medical Device USB Drive USB Drives or flash media allow exploits to be easily introduced into the VA environment. The HTM Memo "Guidance for Determining the Need for a Waiver for Medical Device USB Drives" defines requirements and best practices for utilizing USB Drives and Media. Prior to using a USB drive with the device, are the conditions in the 10N memo (e.g. …. ….. ……. )followed?

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .