D.2 IT SECURITY OR NURSES.pdf
PDF 76 KB Posted
- Attached to
- Q401--Operating Room RN Service MPLS Federal contract opportunity
- Solicitation number
- 36C26323Q0681
About this file
This document outlines security requirements for contractors supporting the Minneapolis VA Health Care System. Contractors and their personnel must comply with all applicable federal laws, regulations, standards, and VA directives regarding information and information system security. Access to VA information and systems is restricted to authorized personnel for approved purposes. Background investigations are required, and national security clearances must be verified for applicable personnel. Custom software and outsourced IT operations must generally be performed within the U.S., and security plans are required for any foreign services. Mandatory training includes annual security and privacy awareness, and all personnel must acknowledge rules of behavior before system access. Failure to complete training or sign rules of behavior annually may result in suspension of access privileges or removal from work on the contract.
The related federal contract opportunity seeks up to five full-time equivalent operating room registered nurses for one year to support the Minneapolis VA Health Care System. Questions must be received by the specified date and emailed to the listed points of contact.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C26323Q0681 SF30 Amendment 002 Document.pdf | ||
| ATTACHMENT 2 OR NURSES PWS Revised.pdf | ||
| ATTACHMENT 3 B.3 SCHEDULE.pdf | ||
| ATTACHMENT 1 RFQ Q and A.pdf | ||
| 36C26323Q0681 SF 30 Amendment 001 Document.pdf | ||
| 36C26323Q0681 0002.docx | DOCX document | |
| 36C26323Q0681 0001.docx | DOCX document | |
| D.4 CONTRACTOR CERTIFICATION IMMIGRATION AND NATIONALITY ACT OF 1952.pdf | ||
| D.3 RULES OF BEHAVIOR.pdf | ||
| D.7 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING-CERTIFICATE OF COMPLIANCE.pdf | ||
| D.5 SERVICE CONTRACT ACT WD 15-4945.pdf | ||
| D.1 QUALITY SURVEILANCE PLAN (QASP).pdf | ||
| D.6 ORGANIZATIONAL CONFLICTS OF INTEREST.pdf | ||
| 36C26323Q0681_1.docx | DOCX document | |
| D.8 KEY PERSONNEL TRACKER.xlsx | XLSX spreadsheet | |
| 36C26323Q0681 RFQ Document.pdf |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY
1. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and
VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
b. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel
Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense
Security Service (DSS). Verification of a Security Clearance must be processed through the Special
Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S.
services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor's employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
3. NOT REQUIRED - THIS SECTION REMOVED BY THE MINNEAPOLIS VA HOSPITAL PRIVACY OFFICER
4. NOT REQUIRED - THIS SECTION REMOVED BY THE MINNEAPOLIS VA HOSPITAL PRIVACY OFFICER
5. NOT REQUIRED - THIS SECTION REMOVED BY THE MINNEAPOLIS VA HOSPITAL PRIVACY OFFICER
6. NOT REQUIRED - THIS SECTION REMOVED BY THE MINNEAPOLIS VA HOSPITAL PRIVACY OFFICER
7. NOT REQUIRED - THIS SECTION REMOVED BY THE MINNEAPOLIS VA HOSPITAL PRIVACY OFFICER
8. NOT REQUIRED - THIS SECTION REMOVED BY THE MINNEAPOLIS VA HOSPITAL PRIVACY OFFICER
9. TRAINING
a. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:
(1) Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;
(2) Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;
(3) Successfully complete the appropriate VA privacy training and annually complete required privacy training; and
(4) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document - e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information
Technology Security Training Requirements.]
b. The contractor shall provide to the contracting officer and/or the COR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.
c. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.
(End of Clause)
File details come from the government source that posted it. Updated .