D.3 VA Privacy Act, Information Security Awareness and Rules of Behavior.pdf

PDF 249 KB Posted

Attached to
Q201--Tazewell CBOC Federal contract opportunity
Solicitation number
36C24621R0068_2
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 6

View the file

Other files for this federal contract opportunity

Other files attached to Q201--Tazewell CBOC, newest first.
File Type Posted
36C24621R0068 Amendment 00001.pdf PDF
D.7 MCP 658-11-34 Reporting Critical Results.docx DOCX document
D.29 Wage Determination Tazewell County.pdf PDF
D.9 MCM 658-116A-10 Telephone Calls - Suicide or Homicide.pdf PDF
D.34 Immigration Certification.docx DOCX document
D.1 QASP.docx DOCX document
D.22 Electronic Clinical Performance Metrics.pdf PDF
D.12 MCP 658-119-28 Anticoagulation Management.pdf PDF
D.27 FORMS IN CONTINGENCY SITUATION (COMPUTER DOWNTIME).doc DOC document
D.10 MCM 658-116A-21 Suicide Assessment, Intervention, and Documentation.pdf PDF
D.6 Laboratory Computer Procedure Manual.pdf PDF
D.2 Past Performance Questionnaire.docx DOCX document
D.14 Tele-Dermatology-Specialty Supplement (tderm-spp).pdf PDF
D.28 Service Contract Act of 1965.pdf PDF
D.17 2020 Rad Protocols.pdf PDF
D.23 Code 10 COMPUTER DOWNTIME.pdf PDF
D.8 MCM 658-11-75 Med Recon (2019).pdf PDF
D.30 Demographic Information.docx DOCX document
D.20 SOP for Maternity Care at Salem VAMC.pdf PDF
D.19 SOP for Mammography at Salem VAMC.pdf PDF
D.18 SOP for Cervical Cancer Screening at Salem VAMC.pdf PDF
D.13 Home Telehealth Operations Manual.pdf PDF
D.15 Tele-Eye Care Supplement.pdf PDF
D.5 LAB Ward Instruction Manual 21st Edition 2019.pdf PDF
D.4 Conflicts of Interest Certification Statement Tazewell CBOC.docx DOCX document
D.7 MCP 658-11-34 Reporting Critical Results.pdf PDF
D.33 COVID 19 Janssen Vaccine Redistribution to CBOC SOP.pdf PDF
D.31 Salem Save Lives Act SOP v.2 4.8.2021.pdf PDF
D.25 CBOC Report Performance Measures.pdf PDF
D.32 COVID 19 Moderna Vaccine Redistribution to CBOC SOP.pdf PDF
D.26 658-136-30 - Management of Electronic Health Records Document Scanning.pdf PDF
D.24 Downtime procedures.pdf PDF
D.16 Asynchronus Telehealth Manual.pdf PDF
D.11 MCM 658-136-33 Patient Rights and Responsibilities.pdf PDF
D.21 Ancillary Diagnostic Laboratory Testing Program (MCM658-113-02).pdf PDF
36C24621R0068_2.pdf PDF
Show all 36

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FY21 Text-Only Course Transcript Page 51

Appendix B: Non-Organizational Rules of Behavior

DEPARTMENT OF VETERANS AFFAIRS INFORMATION SECURITY RULES OF BEHAVIOR FOR

NON-ORGANIZATIONAL USERS

1. COVERAGE

a. This Department of Veterans Affairs (VA) Information Security Rules of Behavior (ROB) for

Non-Organizational Users identifies the specific responsibilities and expected behavior for non-organizational users of VA information and information systems as required by 38 U.S.C. § 5723(f)(5), Office of Management and Budget Circular A-130, Appendix I, paragraph 4(h) (6-7) and VA Handbook 6500, Risk Management Framework for VA Information Systems – Tier3: VA Information Security Program.

b. Organizational users are VA employees, contractors, researchers, students, volunteers, and representatives of Federal, state, local or tribal agencies who are authorized to access VA information and information systems but do not represent a Veteran or claimant. The rules of behavior for organizational users are identified in the Department of Veterans Affairs Information Security Rules of Behavior for Organizational Users.

c. Non-Organizational users are users other than users explicitly categorized as organizational users. These include individuals with a Veteran/claimant power of attorney. Change Management Agents at the local facility are responsible for onboarding power of attorney/private attorneys.

d. VA information is the information under the control of VA or stored on a VA information system. This includes both VA sensitive and non-sensitive information. Information properly disclosed by VA to a non-organizational user (e.g., contents of a Veteran’s claims file for purposes of representing a Veteran or claimant) is no longer VA information and its security and confidentiality is the responsibility of the recipient.

e. This ROB for Non-Organizational Users does not supersede any policies of VA facilities or other agency components that provide higher levels of protection to VA’s information or information systems. The ROB provides the minimum requirements, with which individual users of VA information and information systems agree to comply, and VA facilities and other agency components may issue requirements for protection that exceed the ROB.

2. COMPLIANCE

a. Non-Organizational Users are required to comply with this ROB. Non-compliance with this

ROB may result in suspension or removal of access to VA information or information systems. Such a suspension would not prevent the authorized disclosure of records to an individual; however, it may prevent disclosure through a particular method, e.g., by suspension of access

Initials

D.3 VA Privacy Act, Information Security Awareness and Rules of Behavior 36C24621R0068

FY21 Text-Only Course Transcript Page 52 through a VA information system. Depending on the severity of the violation and management discretion, consequences may include access restriction or suspension of access privileges. Theft, conversion, or unauthorized disclosure or disposal of Federal property or disclosure of information may result in criminal sanctions.

b. Unauthorized access, upload, download, change, circumvention, or deletion of information on VA systems without authorization; unauthorized modification of VA systems; denying or granting access to VA systems without authorization; unauthorized purpose on VA systems;

or otherwise misusing VA systems or resources is strictly prohibited and may result in criminal sanctions.

c. The ROB does not create any other right or benefit (substantive or procedural) enforceable by law, by a party in litigation with the U.S. Government.

3. ACKNOWLEDGEMENT

a. Non-Organizational Users must sign this ROB before access is provided to VA information and information systems. Thereafter, this ROB must be signed annually by all non-organizational users of the VA information or information systems. This signature indicates agreement to comply with this ROB, and refusal to sign this ROB will result in denied of access to VA information or information systems.

b. This ROB may be signed in hard copy or electronically. If signed using the hard copy method, the user must initial and date each page and provide the information requested under Acknowledgement and Acceptance.

4. INFORMATION SECURITY RULES of BEHAVIOR Access and Use of VA Information and Information Systems I Will:

• Comply with all Federal and VA information security, privacy, and records management policies.

• Follow established procedures for requesting access to any VA information system and for notifying VA when the access is no longer needed.

• Only use my access to VA information and information systems for officially authorized purposes. The use of VA computer systems and/or records must not violate any VA policy regarding jurisdiction, restrictions, limitations or areas of responsibility.

• Only use VA-approved solutions, software, or services for connecting non-VA-owned systems to VA’s network either remotely or directly.

• Log off or lock any computer or console with access to or displaying VA information before I leave my workstation.

I Will Not:

FY21 Text-Only Course Transcript Page 53

• Have any expectation of privacy in my activities while accessing or using VA information systems, as I understand that all activity is logged for security purposes.

• Attempt to probe computer systems to exploit system controls or to obtain unauthorized access to VA sensitive information.

• Use personally owned equipment on-site at a VA facility to directly connect to the VA network, or connect remotely to the VA network unless approved prior to use.

Protection of VA-Issued Devices I Will:

• Protect Government Furnished Equipment (GFE) from theft, loss, destruction, misuse, and threats.

• Follow VA policies and procedures for handling Federal Government IT equipment and sign for items provided to me for my exclusive use and return them when no longer required for VA activities.

I Will Not:

• Swap or surrender VA hard drives or other storage devices to anyone other than an authorized Office of Information and Technology (OI&T) employee.

• Attempt to override, circumvent, alter, or disable operational, technical, or management security configuration controls unless expressly directed to do so by authorized VA staff.

Data Protection I Will:

• If authorized to directly connect to a VA system, only use virus protection software, anti-spyware, and firewall/intrusion detection software authorized by VA.

I Will Not:

• Download or install prohibited software from the Internet, or other publicly available sources, offered as free trials, shareware, or other unlicensed software to a VA-owned system.

• Disable or degrade software programs used by VA that install security software updates on computer equipment and all electronic devices used to connect to VA information systems, or used to create, store, or use VA information.

Teleworking and Remote Access I Will:

• Keep Government Furnished Equipment (GFE) and VA information safe, secure, and separated from my personal property and information, regardless of work location.

• Protect GFE from theft, loss, destruction, misuse, and emerging threats. _____

FY21 Text-Only Course Transcript Page 54

• Obtain approval prior to using remote access capabilities to connect non-GFE devices to VA’s network.

• Notify my supervisor, Contracting Officer’s Representative (COR), and authorized staff, or designee prior to any international travel with a VA mobile device so that appropriate actions can be taken prior to my departure and upon my return, including potentially issuing a specifically configured device for international travel and/or inspecting the device or reimaging the hard drive upon return.

• Comply with any security measures, including using a specifically configured device issued for international travel and surrendering the device for inspection or reimaging.

• Safeguard electronic and physical VA sensitive information while working at home or during travel.

• Provide authorized OI&T personnel access to inspect the remote location pursuant to an approved telework agreement that includes access to VA sensitive information.

• Protect information about remote access mechanisms from unauthorized use and disclosure.

• Exercise a higher level of awareness in protecting VA mobile devices or other GFE when traveling internationally as laws and individual rights vary by country and threats against devices with agency information may be heightened.

I Will Not:

• Access non-public VA information systems from publicly available IT computers, such as remotely connecting to the internal VA network from computers in a public library.

• Access any VA information system from any foreign country unless approved by a VA authorized staff.

• Access VA’s internal network from any foreign country designated as a security risk unless approved by a VA authorized staff. This prohibition does not affect access to VA external web applications.

User Accountability I Will:

• Complete mandatory security and privacy awareness training within designated time frames.

• Complete any additional role-based security training required based on my role and responsibilities.

• Understand that authorized VA personnel may review my conduct or actions concerning VA information and information systems and take appropriate action.

• If applicable, have my GFE scanned and serviced by VA authorized personnel; this may require me to return it promptly to a VA facility upon request. _____

FY21 Text-Only Course Transcript Page 55

• Permit only those authorized by OIT to perform maintenance on GFE or VA IT components, including installation or removal of hardware or software.

• Sign specific VA Information Security ROBs as required for access or use of specific VA systems or non-VA systems.

Sensitive Information I Will Not:

• Disclose information protected by VA’s privacy statutes or regulations without appropriate legal authority. Unauthorized disclosure of this information may have an adverse effect on agency operations, agency assets, and individuals including myself.

Identification and Authentication I Will:

• Use passwords that meet the VA minimum requirements.

• Protect my passwords; verify codes, tokens, and credentials to prevent unauthorized use and disclosure.

I Will Not:

• Store my VA passwords or verify codes in any format on any IT system, unless that file has been encrypted using Federal Information Processing Standards (FIPS) 140-2 (or its successor) validated encryption, and I am the only person who can decrypt the file.

• Hardcode credentials into scripts or programs.

• Divulge a personal username, password, access code, verify code, or other access credential to anyone.

Incident Reporting I Will:

• Report suspected or identified information security incidents, including loss or theft of GFE, unauthorized disclosures of VA information or unauthorized access to a VA information system, as well as anti-virus, antispyware, firewall or intrusion detection software errors, or significant alert messages (security and privacy) on VA information systems to a VA ISSO, and Information System Owner immediately upon suspicion.

Social Media & Networking to Conduct Official VA Business I Will:

• Use the VA intranet to conduct VA business on social media/networking sites wherever possible. _____

FY21 Text-Only Course Transcript Page 56

• Use web-based collaboration and social media tools in accordance with VA Directive 6515, Use of Web-Based Collaboration Technologies.

• Limit the personal use of social media/networking sites in accordance with VA Directive 6001, Limited Personal use of Government Office Equipment Including Information Technology.

• Obtain approval from the Office of Public and Intergovernmental Affairs (OPIA) before establishing a VA social media account.

• Ensure that my use of social media to conduct VA business complies with law, guidance, and VA policy.

• Be professional at all times when posting to VA-related social media.

• Use my best judgment when interacting on social media about matters related to VA’s mission.

• Post only factual information about which I have actual/firsthand knowledge, in my capacity as a VA representative.

• Identify myself and my roles as a VA representative when commenting or providing information on matters related to VA’s mission, and ensure that my profile and any related content is consistent with how I wish to present myself to colleagues, Veterans, and the general public.

• Only post and use content in accordance with applicable ethics, intellectual property, records, and privacy laws, regulations, and policies.

• Use only instant messaging services approved by VA.

• Publish a disclaimer that the views are my own and do not represent VA, if content I publish on blogs, wikis or any other form of user-generated media might reasonably be perceived as the position of VA.

I Will Not:

• Comment on VA mission-related legal matters unless I am the VA official spokesperson for the matter and have management approval to do so.

• Comment or provide information on any matter about which I do not have actual, up-to-date knowledge, in my capacity as a VA representative.

• Post information protected by the Privacy Act of 1974, 38 USC 5701, 5705, or 7332, the Health Insurance Portability and Accountability Act (HIPAA Rules,) or VA policy on any non-VA websites, without legal authority and prior approval by authorized official.

• Use my VA title or indicate that I represent VA when acting outside of my official capacities.

• Use profanity; make libelous statements; or use privately created works without the express, written permission of the author.

• Quote more than short excerpts of another person’s work unless the source is properly credited. _____

FY21 Text-Only Course Transcript Page 57

5. ACKNOWLEDGEMENT AND ACCEPTANCE

a. I acknowledge that I have received a copy of the VA Information Security Rules of Behavior for Non-Organizational Users.

b. I understand, accept, and agree to comply with all terms and conditions of the VA Information Security Rules of Behavior for Non-Organizational Users.

c. These provisions are consistent with and do not supersede, conflict with, or otherwise alter the employee obligations, rights, or liabilities created by existing statute or Executive order relating to (1) classified information, (2) communications to Congress, (3) the reporting to an Inspector General of a violation of any law, rule, or regulation, or mismanagement, a gross waste of funds, an abuse of authority, or a substantial and specific danger to public health or safety, or (4) any other whistleblower protection. The definitions, requirements, obligations, rights, sanctions, and liabilities created by controlling Executive orders and statutory provisions are incorporated into this agreement and are controlling.

Print or type your full name Signature Date

Office Phone ___________ Position Title ________________________________

Purpose of this Document
Using Hyperlinks Within This Document
Topic 1: Introduction
1.1 Welcome
1.2 Purpose of Taking This Course
1.3 Types of VA Sensitive Information
1.4 Organizational and Non-Organizational Users
1.5 General Rules of Behavior
1.6 What to Expect and Course Completion
Topic 2: Handling VA Information
2.1 Introduction and Objectives
2.2 Protecting PII and PHI
2.3 Proper Handling of Information
2.4 Picking the Palette: Common Mishandling of Information
2.5 Picking the Palette: Preventing Mismailing
2.6 Records Management Awareness
2.7 Summary
Topic 3: Protecting VA Electronic Resources
3.1 Introduction and Objectives
3.2 VA-Issued Electronic Resources
3.3 Picking the Palette: GFE and Personal Devices
3.4 Software Downloads
3.5 VA-Issued Mobile Devices
3.6 Handling VA-Issued Mobile Devices
3.7 Picking the Palette: Loss or Misuse of VA Equipment
3.8 Summary
Topic 4: Accessing VA Information
4.1 Introduction and Objectives
4.2 Need to Know and Minimum Access
4.3 Picking the Palette: Need to Know
4.4 Identification and Authentication
4.5 Picking the Palette: Lost PIV Card
4.6 Picking the Palette: Securing Workstations
4.7 Unsecured Wireless Connections
4.8 Summary
Topic 5: Safeguarding VA Electronic Information
5.1 Introduction and Objectives
5.2 Transmitting Data Securely
5.3 Guidelines for Emailing Sensitive Information
5.4 Use VA Email for VA Business
5.5 Storing and Sharing VA Sensitive Information
5.6 Identity Theft
5.7 Picking the Palette: Mishandling VA Sensitive Information on Network Drives
5.8 Safeguarding External and Removable Media
5.9 Internet Awareness and Safety
5.10 Picking the Palette: Recognizing Social Media Safety
5.11 Limited Personal Use (VA Directive 6001)
5.12 Summary
Topic 6: Working Remotely
6.1 Introduction and Objectives
6.2 Non-GFE Network Connections
6.3 Protecting VA Sensitive Information When Working Remotely
6.4 Picking the Palette: Protecting VA Sensitive Information When Working Remotely
6.5 Summary
Topic 7: Reporting Incidents
7.1 Introduction and Objectives
7.2 Recognizing a Potential Incident
7.3 Reporting Incidents
7.4 Consequences for Causing an Incident
7.5 Insider Threat Awareness
7.6 Picking the Palette: Recognizing Insider Threats
7.7 Picking the Palette: Recognizing Phishing Attempts
7.8 Picking the Palette: Recognizing Social Engineering
7.9 Summary
Topic 8: Course Summary and Rules of Behavior
8.1 Course Summary
8.2 Acknowledge and Accept ROBs
8.3 Completion
Appendix A: Organizational Rules of Behavior
1. COVERAGE
2. COMPLIANCE
3. ACKNOWLEDGEMENT
4. INFORMATION SECURITY RULES of BEHAVIOR
Access and Use of VA Information and Information Systems
Protection of VA-Issued Devices
Data Protection
Teleworking and Remote Access
User Accountability
Sensitive Information
Identification and Authentication
Social Media & Networking to Conduct Official VA Business

5. ACKNOWLEDGEMENT AND ACCEPTANCE

Appendix B: Non-Organizational Rules of Behavior
1. COVERAGE
2. COMPLIANCE
3. ACKNOWLEDGEMENT
4. INFORMATION SECURITY RULES of BEHAVIOR
Access and Use of VA Information and Information Systems
Protection of VA-Issued Devices
Data Protection
Teleworking and Remote Access
User Accountability
Sensitive Information
Identification and Authentication
Incident Reporting
Social Media & Networking to Conduct Official VA Business

5. ACKNOWLEDGEMENT AND ACCEPTANCE

Appendix C: Glossary
A
B – N/A
C
D
E
F
G
H
I
J – N/A
K
L
M
N
O
P
Q – N/A
R
S
T
U – N/A
V
W
X – N/A
Y
Z – N/A
Appendix D: Privacy and Information Security Resources
VA Knowledge Service Site
VA Forms and Memorandums
VHA Publications
VA Web Links
TMS Courses
Federal Web Links:
VA Contact Information

File details come from the government source that posted it. Updated .