D.02 210910-005- VA Rules of Behavior Org Users FY22.pdf
PDF 272 KB Posted
- Attached to
- Q201--MSO-2021-COM-0056 Amend to Respond to Questions CBOC Truth or Consequences, NM Federal contract opportunity
- Solicitation number
- 36C26222R0050
View the file
Other files for this federal contract opportunity
Show all 39
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Department of Veterans Affairs
Memorandum
Date:
From: Acting Assistant Secretary for Information and Technology, Chief Information Officer (005)
Subj: Updated Department of Veterans Affairs Information Security Rules of Behavior for Organizational Users for FY22 (VIEWS # 05325150)
To: Under Secretaries, Assistant Secretaries and Other Key Officials
1. Publication of this memorandum will rescind and supersede the Updated VA Information Security Rules of Behavior for Organizational Users Memorandum (VIEWS #02995033) signed September 21, 2020.
2. The Office of Information and Technology (OI&T) has updated the attached Department of Veterans Affairs’ Information Security Rules of Behavior (ROB) for Organizational Users which pursuant to VA Directive 6500, VA Cybersecurity Program, is required to be signed annually by all Organizational Users. Organizational Users shall sign the ROB via the Annual Privacy and Information Security Awareness and Rules of Behavior training (TMS ID 10176) or by wet or electronic signature. The updated ROB is effective immediately. The updates do not reflect any major policy changes but rather provide for additional clarification through minor grammar, stylistic and content modifications.
3. The Department of Veterans Affairs Information Security Rules of Behavior for Organizational Users shall be incorporated into the Annual Privacy and Information Security Awareness and Rules of Behavior training published by IT Workforce Development.
4. If you have any questions please contact Gary Stevens, Executive Director, Information Security Policy and Strategy, at gary.stevens2@va.gov or 202-632-7538.
Neil C. Evans, M.D.
Chief Officer, Connected Care, Performing the Delegable Duties of the Assistant Secretary for Information and Technology and Chief Information Officer mailto:gary.stevens2@va.gov
Updated Department of Veterans Affairs Information Security Rules of Behavior for Organizational Users for FY22 (VIEWS # 05325150)
Attachments:
Department of Veterans Affairs Information Security Rules of Behavior for Organizational Users
CC:
Acting Principal Deputy Assistant Secretary and Deputy Chief Information Officer (005A) Executive Director, IT Program Integration and Chief of Staff (005) Deputy Assistant Secretary, Development and Operations (005D) Deputy Assistant Secretary, Information Security and Chief Information Security Officer (005R) Deputy Chief Information Officer, Strategic Sourcing (005G) Deputy Chief Information Officer, Account Management (005C) Deputy Chief Information Officer, IT Resource Management (005F) Deputy Chief Information Officer, Quality, Performance, and Risk and Chief Risk Officer (005X)
Department of Veterans Affairs VA InfoSec ROB Org Users for FY22 Washington, DC 20420
DEPARTMENT OF VETERANS AFFAIRS
INFORMATION SECURITY RULES OF BEHAVIOR
FOR ORGANIZATIONAL USERS
1. COVERAGE
a. This Department of Veterans Affairs (VA) Information Security Rules of Behavior
(ROB) for Organizational Users identifies the specific responsibilities and expected behavior for organizational users of VA information and information systems as required by Office of Management and Budget Circular A-130, Appendix I, paragraph 4h (6-7), VA Directive 6500, VA Cybersecurity Program and VA Handbook 6500, Risk Management Framework for VA Information Systems – VA Information Security Program.
b. Organizational users are VA employees, contractors, researchers, students, volunteers and representatives of Federal, state, local or tribal agencies who are authorized to access VA information and information systems for performance of official duties but do not represent a Veteran or claimant.
c. Non-organizational users are users other than users explicitly categorized as organizational users. These include affiliates and individuals with a Veteran/claimant power of attorney. Change Management Agents at the local facility are responsible for on-boarding power of attorney/private attorneys. The rules of behavior for Non-Organizational Users are identified in the Department of Veterans Affairs Information Security Rules of Behavior for Non-Organizational Users.
d. The ROB provides the minimum requirements with which organizational users of VA information and information systems must comply and does not supersede any policies of VA facilities or other agency components that provide higher levels of protection to certain information or information systems. When appropriate, organizational users may exceed these minimum requirements to protect VA information and information systems by exercising due diligence and ethical standards.
2. COMPLIANCE
a. Organizational Users are required to comply with the ROB. Non-compliance with the ROB may be cause for disciplinary or adverse actions. Depending on the severity of the violation and management discretion, consequences may include restricting access, suspension of access privileges, admonishment, reprimand, demotion, suspension and removal. Theft, conversion, or unauthorized disclosure or disposal of Federal property or information may result in criminal sanctions.
VA InfoSec ROB Org Users for FY22
b. Unauthorized access, upload, download, change, circumvention, or deletion of information on VA systems; unauthorized modification of VA systems; denying or granting access to VA systems without authorization; unauthorized use of VA systems; or otherwise misusing VA systems or resources is strictly prohibited.
c. The ROB does not create any other right or benefit (substantive or procedural) enforceable by law, by a party in litigation with the U.S. Government.
3. ACKNOWLEDGEMENT
a. Organizational Users must sign the ROB for Organizational Users before access is provided to VA information and information systems. Thereafter, this ROB for Organizational Users must be signed annually by all users of VA information and information systems. This signature acknowledges agreement to comply with the ROB and refusal to sign this ROB will result in denied access to VA information and information systems. Any refusal to sign the ROB for Organizational Users may result in disciplinary or adverse action.
b. The ROB for Organizational Users may be signed in hard copy or electronically.
If signed using the hard copy method, the user should initial and date each page and provide the information requested under Acknowledgement and Acceptance.
For other Federal, state, local and tribal agency users, documentation of a signed VA Information Security ROB will be provided to the VA requesting official.
c. If an individual is both an Organizational and a Non-Organizational User they shall sign both ROBs.
4. INFORMATION SECURITY RULES of BEHAVIOR
Access and Use of VA Information and Information Systems
I Will:
• Comply with all federal statutes, regulations and policies applicable to VA information security, privacy and records management.
• Use only VA-approved devices, systems, software, services and data that I am authorized to use, including complying with any software licensing or copyright restrictions.
• Follow established procedures for requesting access to any VA computer system and for notifying my VA supervisor or designee when the access is no longer needed.
• Only use my access to VA information and information systems for officially authorized and assigned duties. The use of VA information and information systems must not violate any VA policy regarding jurisdiction, restrictions, limitations or areas of responsibility.
• Log out of all information systems at the end of each workday.
• Log off or lock any VA computer or console before leaving my workstation.
• Only use other Federal government information systems as expressly authorized by the terms of those systems; personal use is prohibited.
• Only use VA-approved solutions for connecting non-VA-owned systems to VA’s network.
I Will Not:
• Have any expectation of privacy in any information that I access, create, receive or maintain, or in my activities while accessing or using VA information systems as I understand that all activity is logged for security purposes.
• Attempt to probe computer systems to exploit system controls or to obtain unauthorized access to VA sensitive information.
• Engage in any activity that is prohibited by VA Directive 6001, Limited Personal Use of Government Office Equipment Including Information Technology.
• Have a VA network connection and a non-VA network connection, such as a modem or phone line or wireless network card, physically connected to any device at the same time unless the dual connection is explicitly authorized by my Information System Owner and local Area Manager (AM) or designee.
• Host, set up, administer, or operate any type of Internet server or wireless access point on any VA network unless explicitly authorized by my Information System Owner and local Area Manager (AM) or designee.
Protection of VA-Issued Devices
• Secure mobile devices (e.g., laptops, tablets, smartphones) and portable storage devices (e.g., Compact Discs (CD), Digital Video Discs (DVD), Universal Serial Bus (USB) flash drives.
• Swap or surrender VA hard drives or other storage devices to anyone other than an authorized Office of Information & Technology (OI&T) employee.
• Attempt to override, circumvent, alter or disable operational, technical, or management security configuration controls unless expressly directed to do so by authorized VA staff.
Data Protection
• Only use virus protection software, anti-spyware and firewall/intrusion detection software authorized by VA.
• Safeguard VA mobile devices and portable storage devices containing VA information, at work and remotely, using Federal Information Processing Standards (FIPS) 140-2 validated encryption (or its successor) unless it is not technically possible.
• Only use VA-owned or approved storage devices encrypted with FIPS 140-2 (or its successor) validated encryption, consistent with VA’s approved configuration and security control requirements to perform VA work.
• Use VA email in the performance of my duties when issued a VA email account.
• Only use non-VA email when use of a non-VA email account is unavoidable.
• Only disseminate VA information to the public when authorized to do so and in the performance of my duties.
• Transmit VA sensitive information via wireless technologies unless the connection uses FIPS 140-2 (or its successor) validated encryption.
• I will not auto-forward email messages or forward phone calls outside the VA network.
• Download software from the Internet, or other public available sources, offered as free trials, shareware, or other unlicensed software to a VA-owned system.
• Disable or degrade software programs used by VA that install security software updates on computer equipment used to connect to VA information systems, or used to create, store or use VA information.
Teleworking and Remote Access
• Keep Government Furnished Equipment (GFE) and VA information safe, secure, and separated from my personal property and information, regardless of work location.
• Protect GFE from theft, loss, destruction, misuse and emerging threats.
• Obtain approval prior to using remote access capabilities to connect non-GFE devices to VA’s network.
• Secure all appropriate approvals prior to and upon return from any international telework arrangement with a GFE mobile device (e.g. laptop, smartphone).
• Comply with any security measures, including using a specifically configured device issued for international travel and surrendering the device for inspection or reimaging.
• Safeguard electronic and physical VA sensitive information while working at home or during travel.
• Provide VA authorized personnel access to inspect the remote location pursuant to an approved telework agreement that includes access to VA sensitive information.
• Protect information about remote access mechanisms from unauthorized use and disclosure.
• Exercise a higher level of awareness in protecting GFE mobile devices when traveling internationally as laws and individual rights vary by country and threats against Federal employee devices may be heightened.
• Access non-public VA information technology (IT) resources from publicly available IT computers, such as remotely connecting to the internal VA network from computers in a public library.
• Access VA’s internal network from any foreign country designated as posing a significant threat unless all appropriate approvals have been obtained. This prohibition does not affect access to VA external web applications.
User Accountability
• Complete mandatory security and privacy awareness training within designated time frames and complete any additional role-based security training required for my roles and responsibilities.
• Understand that authorized VA personnel may review my conduct or actions concerning VA information and information systems and take appropriate action.
• Have my GFE scanned and serviced by VA authorized personnel. This may require me to return it promptly to a VA facility upon demand.
• Permit only those authorized by OI&T to perform maintenance on IT components, including installation or removal of hardware or software.
• Sign VA Information Security ROBs as required for access or use of specific VA systems.
• Comply with any requirement to sign a non-VA entity’s ROB to conduct VA business.
Sensitive Information
• Ensure responsible practices whenever Veteran data is accessed or used in accordance with VA policy and guidance.
• Ensure that all printed material containing VA sensitive information is physically secured when not in use (e.g., locked cabinet, locked door).
• Only provide access to VA sensitive information to those who have a need-to-know for their professional duties.
• Only post sensitive information to web-based collaboration tools restricted to those who have a need-to-know and when proper safeguards are in place.
• Recognize that access to certain databases has the potential to cause great risk to VA, its customers and employees due to the number and/or sensitivity of the records being accessed.
• Act accordingly to ensure the confidentiality and security of sensitive records in a database is commensurate with the increased potential risk.
• Obtain approval from my supervisor to use, process, transport, transmit, download, print or store VA sensitive information remotely (outside of VA owned or managed facilities (e.g., medical centers, Community-Based Outpatient Clinics (CBOC), or regional offices)).
• Protect VA sensitive information from unauthorized disclosure, use, modification, or destruction and use encryption products approved and provided by VA to protect sensitive data.
• Transmit VA sensitive information via fax only when no other reasonable means exist and when either someone is at the receiving machine to receive the transmission or the receiving machine is in a secure location.
• Encrypt email, including attachments, that contain VA sensitive information. I will not encrypt email that does not include VA sensitive information, or any email excluded from the encryption requirement.
• Protect VA sensitive information aggregated in lists, databases, or logbooks and include only the minimum necessary VA sensitive information to perform a legitimate business function.
• Ensure fax transmissions are sent to the appropriate destination. This includes double checking the fax number, confirming delivery and using a fax cover sheet with the required notification message included.
• Disclose any information protected by VA’s privacy statutes or regulations without appropriate legal authority. I understand unauthorized disclosure of this information may have a serious adverse effect on agency operations, agency assets and individuals.
• Allow VA sensitive information to reside on non-VA systems or devices unless specifically designated and authorized in advance from all appropriate individuals which may include my VA supervisor and Information System Owner.
• Make unauthorized disclosure of VA sensitive information through any means of communication including, but not limited to verbal communications, email, text messaging, instant messaging, online chat, social media and web sites.
Identification and Authentication
• Use passwords that meet the VA minimum requirements.
• Protect my passwords; verify codes, tokens and credentials from unauthorized use and disclosure.
• Store my passwords or verify codes in any format on an IT system, unless it has been encrypted using FIPS 140-2 (or its successor) validated encryption and I am the only person who can decrypt the file.
• Hardcode credentials into scripts or programs on an IT system.
Incident Reporting
• Report suspected or identified information security incidents including unauthorized disclosures of VA information, or access to a VA information system, as well as anti-virus, antispyware, firewall or intrusion detection software errors, or significant alert messages (security and privacy) to my VA supervisor, Information Security Security Officer (ISSO) or designee immediately upon suspicion.
Social Media & Networking to Conduct Official VA Business
• Use the VA Intranet to conduct VA business on social media/networking sites wherever possible.
• Use web-based collaboration and social media tools in accordance with VA Directive 6515, use of Web-Based Collaboration Technologies.
• Limit the personal use of social media/networking sites, in accordance with VA Directive 6001, Limited Personal use of Government Office Equipment Including Information Technology.
• Obtain approval from the Office of Public and Intergovernmental Affairs (OPIA) before establishing a VA social media account.
• Ensure that my use of social media, to conduct VA business, complies with law, guidance and VA policy.
• Be professional at all times when posting to VA-related social media.
• Use my best judgment when interacting on social media about matters related to VA’s mission.
• In my capacity as a VA representative, post only information about which I have actual knowledge.
• Identify myself and my roles as a VA representative when commenting or providing information on matters related to the VA’s mission and ensure that my profile and any related content is consistent with how I wish to present myself to colleagues, Veterans and the general public.
• Only post and use content in accordance with applicable ethics, intellectual property, records and privacy laws, regulations and policies.
• Use only instant messaging services approved by VA.
• Publish a disclaimer that the views are my own and do not represent VA, if content I publish on blogs, wikis or any other form of user-generated media might reasonably be perceived as the position of VA.
• Comment on VA mission-related legal matters unless I am the VA official spokesperson for the matter and have management approval to do so.
• Comment or provide information on any matter about which I do not have actual, up-to-date knowledge, in my capacity as a VA representative.
• Post information protected by the Privacy Act of 1974, 38 U.S.C. §§ 5701, 5705, or 7332, the Health Insurance Portability and Accountability Act (HIPAA) Rules, or against VA policy on any non-VA websites, without legal authority and prior approval by an authorized official.
• Use profanity, make libelous statements, or use privately created works without the express, written permission of the author.
• Quote more than short excerpts of another person’s work unless the source is properly credited.
5. ACKNOWLEDGEMENT AND ACCEPTANCE
a. I acknowledge that I have received a copy of VA information Security Rules of Behavior for Organizational Users.
b. I understand, accept and agree to comply with all terms and conditions of VA Information Security Rules of Behavior for Organizational Users.
c. These provisions are consistent with and do not supersede, conflict with, or otherwise alter the employee obligations, rights, or liabilities created by existing statute or Executive order relating to (1) classified information, (2) communications to Congress, (3) the reporting to an Inspector General of a violation of any law, rule, or regulation, or mismanagement, a gross waste of funds, an abuse of authority, or a substantial and specific danger to public health or safety, or (4) any other whistleblower protection. The definitions, requirements, obligations, rights, sanctions and liabilities created by controlling Executive orders and statutory provisions are incorporated into this agreement and are controlling.
Print or type your full name Signature Date
Office Phone Position Title
| V05325150_MEMO_Rules_of_Behavior_Memo_for_OrgUsers_FY22_09.02.2021 |
| Updated Department of Veterans Affairs Information Security Rules of Behavior for Organizational Users for FY22 (VIEWS # 05325150) |
| Under Secretaries, Assistant Secretaries and Other Key Officials |
V05325150 _Attachment_VA_Rules_of_Behavior_Org-Users_FY22_09.02.2021
| Print or type your full name: | |
| Office Phone: | |
| Date: | |
| Position Title: | |
| 2021-09-09T16:09:09-0400 | |
| Neil C. Evans 107139 |
Date1_af_date: 9/9/21
File details come from the government source that posted it. Updated .