D.9 Information Security 02.pdf

PDF 334 KB Posted

Attached to
Q201--McCurtain CBOC Federal contract opportunity
Solicitation number
36C25923R0040
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 19

About this file

This memorandum establishes an information security program policy for the Eastern Oklahoma VA Healthcare System, VISN 19, and associated community-based outpatient clinics. It assigns responsibilities to various roles for implementing and complying with the security program. The medical center director must provide necessary support to the information security program and ensure compliance with federal requirements. The information system security officer is responsible for managing the local security program, assisting with risk assessments and security plans, incident response, and training and awareness programs. Local program managers must determine user access needs and ensure compliance. System administrators are tasked with day-to-day security operations. Contracting officers must incorporate security requirements into contracts, and human resources and law enforcement staff have background check responsibilities. All users must comply with rules of behavior.

The related federal contract opportunity is a solicitation for McCurtain CBOC within the Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 19. No further details are provided on products, services, pricing or other terms.

View the file

Other files for this federal contract opportunity

Other files attached to Q201--McCurtain CBOC, newest first.
File Type Posted
D.22 Quality Assurance Surveillance Plan - McCurtain CBOC.pdf PDF
36C25923R0040 0007.docx DOCX document
McCurtain CBOC Follow - up QA.pdf PDF
36C25923R0040 0006.docx DOCX document
McCurtain CBOC QA 05162024.pdf PDF
D.26 Medications Vaccines Listing.pdf PDF
D.27 McCurtain CBOC Schedule.xlsx XLSX spreadsheet
36C25923R0040 v2 05162024.pdf PDF
36C25923R0040 0005.docx DOCX document
36C25923R0040 0004.docx DOCX document
36C25923R0040 0003.docx DOCX document
36C25923R0040 0002.docx DOCX document
36C25923R0040 0001.docx DOCX document
D.24 No Show-Minimum Scheduling Effort SOP 02.pdf PDF
D.20 Past Performance References 02.pdf PDF
D.11 Suicide Prevention.pdf PDF
D.7 Pretreatment and Transportation of Soiled Critical 1 02.pdf PDF
D.3 Patient Rights and Responsibilities 02.pdf PDF
D.2 11-108 Medication Reconciliation Process.pdf PDF
D.25 Documentation Checklist.pdf PDF
D.23 eQM measurements for 2023.pdf PDF
D.19 Document Scanning Policy 02.pdf PDF
D.18 Outpatient Scheduling Processes and Procedures 02.pdf PDF
D.16 Immigration Certification 02.pdf PDF
D.12 SCA 15 -5333 Wage Determination 01252024.pdf PDF
D.22 Quality Assurance Surveillance Plan - McCurtain.pdf PDF
D.17 42 CFR Part 493-Laboratory Requirements 02.pdf PDF
D.14 Org Conflict of Interest 02.pdf PDF
D.10 Communication Test Results to Providers 02.pdf PDF
D.5 Specimen Handling and Transporting From CBOCs 02.pdf PDF
D.1 Anticoagulation Program .pdf PDF
D.21 Past Performance Questionnaire 02.pdf PDF
D.15 Contractor Rules of Behavior 02.pdf PDF
D.13 DBA OK20240071 Wage Determination.pdf PDF
D.8 Pretreatment and Transportation Soiled Critical 2 02.pdf PDF
D.6 EOC 2022 02.pdf PDF
D.4 Women's Health Mammography and Cervical Screening Care Coordination 02.pdf PDF
36C25923R0040.pdf PDF
Show all 38

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF VETERANS AFFAIRS

VETERANS HEALTH ADMINISTRATION

VISN 19

EASTERN OKLAHOMA VA HEALTHCARE SYSTEM MUSKOGEE, OKLAHOMA

MEDICAL CENTER MEMORANDUM 00-15 AUGUST 30, 2019

INFORMATION SECURITY PROGRAM POLICY

I. PURPOSE:

a. This document establishes policy responsibilities and procedures for the security of Veterans Affairs’ (VA’s) information and information systems contained in this organization. The security program of the Eastern Oklahoma VA Healthcare System (EOVAHCS), VISN 19 and CBOCs is designed to protect all Information Technology (IT) Systems, Information and Telecommunication resources from unauthorized access, disclosure, modification, destruction or misuse. The EOVAHCS complies with VA Directive and Handbook 6500, Managing Information Security Risk: VA Handbook 6500, Risk Management Framework for VA Information Systems- Tier 3: Federal IT security laws and regulations, including the Computer Security Act of 1987 (PL 100- 235), Office of Management and Budget (OMB) Circular A-130 and its appendices, Federal Information Security Management Act of 2002 (FISMA), Health Insurance Portability and Accountability Act (HIPPA) and National Institute of Standards and Technology (NIST) guidance.

b. For the purpose of this document, the term “sensitive data” refers to information whose loss, misuse or unauthorized access to (or modification of) could adversely affect the national or departmental interest or the conduct of Federal or departmental programs or the privacy to which individuals are entitled including medical, benefits, personal and individually identified health information in electronic or any other form and copyright-protected software. This information includes, but is not limited to, all information that is collected, transmitted, used, stored, or disposed of, by or under the direction of this staff and its contractors.

c. All users responsible for implementing the policy and procedures outlined in VA Directive and Handbook 6500, as well as the VA National or Contractor ROB will be provided copies of the documentation.

d. Violations of security policy or procedures will be brought to the attention of management for appropriate disciplinary action and reported in accordance with local and national Office of Information and Technology (OI&T) Incident Reporting policies and standard operating procedures.

e. Security requirements also apply to VA or contractor-operated services and information resources located and operated at contract facilities, at other government agencies that support VA mission requirements, or any other third-party utilizing VA information in order to perform a VA authorized activity.

D.9 INFORMATION SECURITY PROGRAM POLICY

36C25923R0040

EOVAHCS Information Security Program Policy 08-30-19 Medical Center Memorandum 00-15

f. The security controls apply to all information resources used to carry out the VA mission. For example, the controls apply to desktop PC workstations, laptop computers, other portable devices, servers, network devices, office automation equipment (such as copiers and fax machines with communication capabilities), and operated by or on behalf of VA.

g. Security applies to all information collected, transmitted, used, stored, or disposed of, by or on behalf of VA.

II. POLICY:

a. The EOVAHCS consisting of Vinita, Ernest Childers, and McAlester community-based outpatient clinics (CBOC) and associated annex facilities will follow the security policy and procedures contained in VA Directive and Handbook 6500.

b. For any deviations from the control requirements outlines in 6500, the EOVAHCS has implemented compensating controls and/or waivers that have been approved through appropriate channels. These compensating controls and waivers are maintained by the Information System Security Officer (ISSO) and attached to the appropriate security plans of the systems involved located in the Risk Vision Tool.

c. The EOVAHCS has developed standard operating procedures (SOPs) for the policies/controls that need to be defined at the local level.

These SOP’s have been distributed to the individuals required to perform the procedures and copies can also be obtained from the Area Manager and ISSO

d. All policies, procedures and any actions/activities taken as a result of these policies must be documented and retained for six (6) years from the date of its creation or the date when it last was in effect, whichever is later.

e. All documentation related to the information security program will be reviewed annually and updated as needed in response to environmental or operational changes affecting the security of the sensitive data.

Note: Detailed policies and procedures required by applicable laws are found in the handbook.

III. RESPONSIBILITIES:

a. Medical Center Directors are responsible for:

(1) Providing the necessary support to the Information Security Program in their organizations and ensuring that the EOVAHCS meet all the information security requirements mandated by Executive and VA policy and other Federal legislation (e.g., FISMA, HIPAA).

(2) Ensuring a VA ISSO and a VHA Health Care Security Requirements Compliance, Advisory, and Security Engineering Security Engineer (for VHA projects) are fully involved in all new projects concerning the development or acquisition of systems, equipment, or services including risk analysis, security plans, request for proposals, and other procurement documents that require the ISSO’s participation.

(3) Ensuring that respective staff, with defined FISMA security roles, provides the ISSO, in a timely manner, the information required to complete the quarterly FISMA reporting to OI&T and OMB.

(4) Ensuring all Plan of Action and Milestones (POA&M) corrective actions are taken by their respective staff.

b. Information System Security Officer is the agency officials’ assigned responsibility by OI&T Field Operations and Security to ensure that the appropriate operational security posture is maintained for an information system or program. The VA ISSOs are responsible for:

(1) Ensuring compliance with Federal Security Regulations and VA Security Policies;

(2) Reviewing proposed statements of work for VA contracts to ensure that the resulting contracts sufficiently define information security requirements, as appropriate;

(3) Managing their local information security programs and serving as the principal security advisor to system owners regarding security considerations in applications, systems, procurement or development, implementation, operation and maintenance, disposal activities (i.e., life cycle management);

(4) Assisting in the determination of an appropriate level of security commensurate with the impact level;

(5) Coordinating, advising and participating in the development and maintenance of information system security plans and contingency plans for all systems under their responsibility;

(6) Ensuring risk assessments are accomplished every three years, reviewed/updated annually and when there is a major change to the system, re-evaluating sensitivity of the system, risks and mitigation strategies with the assistance of other VA officials with significant information and information system responsibilities;

(7) Verifying and validating, in conjunction with the system owners and managers, hat appropriate security measures are implemented and functioning as intended;

(8) Working with the system owner and manager, repeating a selected sub-set of security control certification and accreditation security control assessment test procedures, as it pertains to the information systems at the site, to ensure that controls remain in place, operating correctly and producing the desired results. Controls most apt to change over time must be included and these tests and results must be documented to support the continuous monitoring program;

(9) Participating in security self-assessments, external and internal audits of system safeguards and program elements and in certification and accreditation of the systems supporting the offices and facility under their area of responsibility;

(10) Assisting other VA officials with significant IT responsibilities (i.e., system managers, contracting staff, human resources staff, police) in remediating and updating the POA&M identified during the certification and accreditation process, periodic compliance validation reviews and the FISMA annual assessment reporting;

(11) Notifying the VA Network & Security Operations Center (VA NSOC) and/or the Office of Inspector General (OIG) of any suspected incidents within one hour of identifying that an incident has occurred and assisting in the investigation of incidents, if necessary;

(12) Maintaining cooperative relationships with business partners or other interconnected systems;

(13) Monitoring compliance with the security awareness and training requirements for each employee/contractor;

(14) Coordinating, monitoring and conducting periodic reviews to ensure compliance with the National Rules of Behavior requirement for each system information user;

(15) Serving as the primary point of contact for security awareness and training within their area of responsibility;

(16) Coordinating with the facility Privacy Officer for the assurance of reasonable safeguards as required by the HIPAA Privacy Rule, HIPAA Security Rule or other federal privacy statutes;

(17) Working with the facility Privacy Officer to assure information security and privacy policies complement and support each other; and

(18) Notifying OI&T staff to add, change, suspend or revoke access privileges in a timely manner when a user under his/her supervision or oversight no longer requires access privileges or he/she fails to comply with this policy.

c. Local Program Management: Must determine whether Federal employees and contractors require information system access in the accomplishment of the VA mission. Specifically, the managers and/or supervisors are responsible for:

(1) Ensuring that all users are adequately instructed, trained and supervised on IT security and information protection issues;

(2) Ensuring their offices and staff are in compliance with Federal Security Regulations and VA security policies;

(3) Determining the Federal employee’s or contractor’s “need to know” before access is granted. Access to any VA information or information system must not be authorized for a person who does not have a need for access to the system in the normal performance of his/her official duties;

(4) Ensuring users under his/her supervision or oversight comply with this policy and pursue appropriate disciplinary action for noncompliance;

(5) Ensuring users under his/her supervision or oversight complete all security and privacy training requirements;

(6) Ensuring users under his/her supervision or oversight review and sign the VA National Rules of Behavior on an annual basis;

(7) Notifying system administrators and ISSO of new users per locally approved procedures;

(8) Notifying system managers and ISSO to revoke access privileges in a timely manner when a user under his/her supervision or oversight no longer requires access privileges or he/she fails to comply with this policy;

(9) Authorizing remote access privileges for personnel and reviewing remote access user security agreements on an annual basis, determined by the date of authorized agreement for remote access, at a minimum to verify the continuing need for access and the appropriate level of privileges;

(10) Ensuring appropriate background investigations (BIs) are initiated and verified on all Federal employees and contractors under their supervision through the VA Security and Investigations Center;

(11) Ensuring employees report any suspected incidents immediately upon discovery to management officials and ISSOs;

(12) Assisting other VA officials with significant information system responsibilities in the remediation and updating of the POA&M identified during the certification and accreditation process, periodic compliance validation reviews and the FISMA annual assessment report to reduce or eliminate system vulnerabilities;

(13) Notifying the responsible ISSO of any suspected incidents immediately upon discovery and assisting in the investigation of incidents if necessary.

d. Area Managers/System Administrators/Network Administrators are responsible for day to day operations of the systems. The role of a system administrator must include security of Local Area Network (LAN) or application administration and account administration. The system/network administrator is responsible for:

(1) Ensuring compliance with Federal Security Regulations and VA security policies;

(2) Assisting in the development and maintenance of information system security plans and contingency plans for all systems under their responsibility;

(3) Participating in risk assessments every three years, review/update annually or when there is a major change to the system to re-evaluate sensitivity of the system, risks and mitigation strategies;

(4) Participating in self-assessments, external and internal audits of system safeguards and program elements and in certification and accreditation of the system;

(5) Evaluating proposed technical security controls to assure proper integration with other system operations;

(6) Identifying requirements for resources needed to effectively implement technical security controls;

(7) Ensuring the integrity in implementation and operational effectiveness of technical security controls by conducting technical control testing and security control assessments (SCA);

(8) Developing system administration and operational procedures and manuals as directed by the system owner;

(9) Evaluating and developing procedures that assure proper integration of service continuity with other system operations;

(10) Notifying the responsible ISSO of any suspected incidents within one hour upon discovery and assisting in the investigation of incidents if necessary;

(11) Reading and understanding all applicable training and awareness materials;

(12) Providing information on users and/or the system in support of any reports or documents necessary for oversight and C&A;

(13) Reading and understanding all applicable use policies or other rules of behavior regarding use or abuse of the Operating Unit’s information system resources;

(14) Understanding which systems, or parts of systems, for which they are directly responsible (e.g., network equipment, servers, LAN, etc.), the sensitivity of the information contained in these systems and the appropriate measures to take to protect the information;

(15) Periodically repeating selected security control assessment test procedures from the systems security certification and accreditation to ensure the systems controls continue to operate effectively at the proper levels of assurance per NIST guidance and over the life cycle of the system; and

(16) Assisting other VA officials with significant IT responsibilities in the remediation and updating the POA&M identified during the certification and accreditation process, periodic compliance validation reviews and the FISMA annual assessment reporting to reduce or eliminate system vulnerabilities.

e. Contracting Officers (CO) / Contracting Officer’s Technical Representatives (COTRs) are responsible for:

(1) Ensuring that security requirements and security specifications are explicitly included in information systems and information system support service acquisition contracts;

(2) Ensuring that contracts contain the security language necessary for compliance with FISMA and 38 U.S.C. 5721-28 and provide adequate security for information and information systems used by the contractor, including the requirement for signing the National Rules of Behavior, when applicable;

(3) Ensuring contracts for services include appropriate background investigation requirements; and ensuring that contractors have the appropriate background investigation on record in accordance with VA Directive and Handbook 0710;

(4) Assisting other VA officials with significant IT responsibilities in the remediation and updating the POA&M identified during the certification and accreditation process, periodic compliance validation reviews and the FISMA annual assessment reporting to reduce or eliminate system vulnerabilities.

f. Local Human Resource (HR) staff/Security and Law Enforcement staff are responsible for implementing specific security role-based functions and are responsible for the following:

(1) Complying with all department information security program policies, procedures and practices that pertain to their specific positions;

(2) Assisting other VA officials with significant IT responsibilities in the remediation and updating the POA&M identified during the certification and accreditation process, periodic compliance validation reviews and the FISMA annual assessment reporting to reduce or eliminate system vulnerabilities.

g. Users of VA Information and Information Systems are responsible for complying with the VA National Rules of Behavior.

VII. REFERENCES:

a. Computer Security Act of 1987-PL 100-235

b. Health Insurance Portability and Accountability Act (HIPAA) PL 104-191

c. VA Directive and Handbook 6500, Information Security Program

d. Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources

e. FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems

f. National Institute of Standards and Technology (NIST) Guidelines

VIII. FOLLOW-UP RESPONSIBILITY: The facility Information System Security Officer (ISSO) is responsible for the content of this Medical Center Memorandum.

IX. RECISSION: Medical Center Memorandum 00-15, Information Security Program Policy and Handbook dated February 26, 2016.

/s/

MARK E. MORGAN, MHA, FACHE

Medical Center Director

DIST: C

File details come from the government source that posted it. Updated .