D7 VA RULES OF BEHAVIOR VA HANDBOOK 6500.6.docx

DOCX document 36 KB Posted

Attached to
Q201--Columbus, MS CBOC Services Federal contract opportunity
Solicitation number
36C25621R0090
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 16

View the file

Other files for this federal contract opportunity

Other files attached to Q201--Columbus, MS CBOC Services, newest first.
File Type Posted
36C25621R0090 0008.docx DOCX document
36C25621R0090 0007.docx DOCX document
36C25621R0090 0006.docx DOCX document
36C25621R0090 0005.docx DOCX document
36C25621R0090 0004.docx DOCX document
36C25621R0090 0002.docx DOCX document
Evaluation Criteria - Updated.docx DOCX document
D5 PAST PERFORMANCE QUESTIONNAIRE.docx DOCX document
36C25621R0090 0003.docx DOCX document
36C25621R0090 0001.docx DOCX document
D18 VA MEDICAL CENTER MEMORANDUM B-136-21.docx DOCX document
D16 HEALTH INFORMATION MANAGEMENT AND HEALTH RECORDS.pdf PDF
D13 VHA Dir 2011 012 Medication Reconciliation.pdf PDF
D9 WD Davis Bacon Lowdnes County.pdf PDF
D4 Sub Contracting Plan Template.docx DOCX document
D2 ORGANIZATIONAL CONFLICTS OF INTEREST VA DIRECTIVE 1660.03.docx DOCX document
D1 QASP Columbus CBOC.docx DOCX document
D24 HL7 DICOM APPROVED DEVICES.xlsx XLSX spreadsheet
D23 LOCAL POLICY MEDICATION RECONCILIATION.docx DOCX document
D14 VHA Directive 1033 Anticoagulation Therapy Management.pdf PDF
D10 DIRECTIVE 1088 COMMUNICATING TEST RESULTS TO PROVIDERS AND PATIENTS GUIDANCE.pdf PDF
S02 D8 WD Lowndes.pdf PDF
D6 PAST PERFORMANCE REFERENCES.rtf RTF text file
D5 PAST PERFORMANCE QUESTIONNAIRE.rtf RTF text file
36C25621R0090.docx DOCX document
D28 ENVIRONMENT OF CARE GUIDE.pdf PDF
D21 ORDERING AND REPORTING TEST RESULTS.docx DOCX document
D20 LOCAL ANTICOAGULATION THERAPY POLICY.docx DOCX document
D19 FY14 VHA T21 IMPLEMENTATION.rtf RTF text file
S02 D15 VHA Hbk 1106.01 Pathology and Laboratory Medicine Service Procedures.pdf PDF
D12 TELEHEALTH OPERATIONS MANUAL.pdf PDF
D11 HEALTH CARE SERVICES FOR WOMEN VETERANS VHA DIR 1330.01.pdf PDF
D25 DICOM APPROVED DEVICES.xlsx XLSX spreadsheet
D27 Record Management Policy.docx DOCX document
D26 CONTRACTOR CERTIFICATION-ImmigNationalityAct.docx DOCX document
D22 LOCAL POLICY ANCILLARY TESTING.docx DOCX document
D17 LOCAL PATHOLOGY AND LABORATORY MEDICINE SERVICE.rtf RTF text file
D3 D18 SMALL BUSINESS SUBCONTRACTING PLAN CERTIFICATION.pdf PDF
Show all 38

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT D15

VA HANDBOOK 6500.6 APPENDIX D CONTRACTOR RULES OF BEHAVIOR

VA HANDBOOK 6500.6 APPENDIX D

CONTRACTOR RULES OF BEHAVIOR

This User Agreement contains rights and authorizations regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the Department of Veterans Affairs (VA). This User Agreement covers my access to all VA data whether electronic or hard copy ("Data"), VA information systems and resources ("Systems"), and VA sites ("Sites"). This User Agreement incorporates Rules of Behavior for using VA, and other information systems and resources under the contract.

1. GENERAL TERMS AND CONDITIONS FOR ALL ACTIONS AND ACTIVITIES UNDER THE CONTRACT:

a. I understand and agree that I have no reasonable expectation of privacy in accessing or using any VA, or other Federal Government information systems.

b. I consent to reviews and actions by the Office of Information & Technology (OI&T) staff designated and authorized by the VA Chief Information Officer (CIO) and to the VA OIG regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA. These actions may include monitoring, recording, copying, inspecting, restricting access, blocking, tracking, and disclosing to all authorized OI&T, VA, and law enforcement personnel as directed by the VA CIO without my prior consent or notification.

c. I consent to reviews and actions by authorized VA systems administrators and Information Security Officers solely for protection of the VA infrastructure, including, but not limited to monitoring, recording, auditing, inspecting, investigating, restricting access, blocking, tracking, disclosing to authorized personnel, or any other authorized actions by all authorized OI&T, VA, and law enforcement personnel.

d. I understand and accept that unauthorized attempts or acts to access, upload, change, or delete information on Federal Government systems; modify Federal government systems; deny access to Federal government systems; accrue resources for unauthorized use on Federal government systems; or otherwise misuse Federal government systems or resources are prohibited.

e. I understand that such unauthorized attempts or acts are subject to action that may result in criminal, civil, or administrative penalties. This includes penalties for violations of Federal laws including, but not limited to, 18 U.S.C. §1030 (fraud and related activity in connection with computers) and 18 U.S.C. §2701 (unlawful access to stored communications).

f. I agree that OI&T staff, in the course of obtaining access to information or systems on my behalf for performance under the contract, may provide information about me including, but not limited to, appropriate unique personal identifiers such as date of birth and social security number to other system administrators, Information Security Officers (ISOs), or other authorized staff without further notifying me or obtaining additional written or verbal permission from me.

g. I understand I must comply with VA’s security and data privacy directives and handbooks. I understand that copies of those directives and handbooks can be obtained from the Contracting Officer's Technical Representative (COTR). If the contractor believes the policies and guidance provided by the COTR is a material unilateral change to the contract, the contractor must elevate such concerns to the Contracting Officer for resolution.

h. I will report suspected or identified information security/privacy incidents to the COTR and to the local ISO or Privacy Officer as appropriate.

2. GENERAL RULES OF BEHAVIOR

a. Rules of Behavior are part of a comprehensive program to provide complete information security. These rules establish standards of behavior in recognition of the fact that knowledgeable users are the foundation of a successful security program. Users must understand that taking personal responsibility for the security of their computer and the information it contains is an essential part of their job.

b. The following rules apply to all VA contractors. I agree to:

(1) Follow established procedures for requesting, accessing, and closing user accounts and access. I will not request or obtain access beyond what is normally granted to users or by what is outlined in the contract.

(2) Use only systems, software, databases, and data which I am authorized to use, including any copyright restrictions.

(3)

(4) I will not use other equipment (OE) (non-contractor owned) for the storage, transfer, or processing of VA sensitive information without a VA CIO approved waiver, unless it has been reviewed and approved by local management and is included in the language of the contract. If authorized to use OE IT equipment, I must ensure that the system meets all applicable 6500 Handbook requirements for OE.

(5) Not use my position of trust and access rights to exploit system controls or access information for any reason other than in the performance of the contract.

(6) Not attempt to override or disable security, technical, or management controls unless expressly permitted to do so as an explicit requirement under the contract or at the direction of the COTR or ISO. If I am allowed or required to have a local administrator account on a government-owned computer, that local administrative account does not confer me unrestricted access or use, nor the authority to bypass security or other controls except as expressly permitted by the VA CIO or CIO's designee.

(7) Contractors’ use of systems, information, or sites is strictly limited to fulfill the terms of the contract. I understand no personal use is authorized. I will only use other Federal government information systems as expressly authorized by the terms of those systems. I accept that the restrictions under ethics regulations and criminal law still apply.

(8) Grant access to systems and information only to those who have an official need to know.

(9) Protect passwords from access by other individuals.

(10) Create and change passwords in accordance with VA Handbook 6500 on systems and any devices protecting VA information as well as the rules of behavior and security settings for the particular system in question.

(11) Protect information and systems from unauthorized disclosure, use, modification, or destruction. I will only use encryption that is FIPS 140-2 validated to safeguard VA sensitive information, both safeguarding VA sensitive information in storage and in transit regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA.

(12) Follow VA Handbook 6500.1, Electronic Media Sanitization to protect VA information. I will contact the COTR for policies and guidance on complying with this requirement and will follow the COTR's orders.

(13) Ensure that the COTR has previously approved VA information for public dissemination, including e-mail communications outside of the VA as appropriate. I will not make any unauthorized disclosure of any VA sensitive information through the use of any means of communication including but not limited to e-mail, instant messaging, online chat, and web bulletin boards or logs.

(14) Not host, set up, administer, or run an Internet server related to my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA unless explicitly authorized under the contract or in writing by the COTR. (14)Protect government property from theft, destruction, or misuse. I will follow VA directives and handbooks on handling Federal government IT equipment, information, and systems. I will not take VA sensitive information from the workplace without authorization from the COTR. (15)Only use anti-virus software, antispyware, and firewall/intrusion detection software authorized by VA. I will contact the COTR for policies and guidance on complying with this requirement and will follow the COTR's orders regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with VA. (16)Not disable or degrade the standard anti-virus software, antispyware, and/or firewall/intrusion detection software on the computer I use to access and use information assets or resources associated with my performance of services under the contract terms with VA. I will report anti- virus, antispyware, firewall or intrusion detection software errors, or significant alert messages to the COTR.

(17) Understand that restoration of service of any VA system is a concern of all users of the system.

(18) Complete required information security and privacy training, and complete required training for the particular systems to which I require access.

3. ADDITIONAL CONDITIONS FOR USE OF NON- VA INFORMATION TECHNOLOGY RESOURCES

4.

a. When required to complete work under the contract, I will directly connect to the VA network whenever possible. If a direct connection to the VA network is not possible, then I will use VA approved remote access software and services.

b. Remote access to non-public VA information technology resources is prohibited from publicly-available IT computers, such as remotely connecting to the internal VA network from computers in a public library.

c. I will not have both a VA network line and any kind of non-VA network line including a wireless network card, modem with phone line, or other network device physically connected to my computer at the same time, unless the dual connection is explicitly authorized by the COTR.

d. I understand that I may not obviate or evade my responsibility to adhere to VA security requirements by subcontracting any work under any given contract or agreement with VA, and that any subcontractor(s) I engage shall likewise be bound by the same security requirements and penalties for violating the same.

5. STATEMENT ON LITIGATION

This User Agreement does not and should not be relied upon to create any other right or benefit, substantive or procedural, enforceable by law, by a party to litigation with the United States Government.

6. ACKNOWLEDGEMENT AND ACCEPTANCE

I acknowledge receipt of this User Agreement. I understand and accept all terms and conditions of this User Agreement, and I will comply with the terms and conditions of this agreement and any additional VA warning banners, directives, handbooks, notices, or directions regarding access to or use of information systems or information. The terms and conditions of this document do not supersede the terms and conditions of the signatory’s employer and VA.

Print or type your full name Signature Last 4 digits of SSN Date Office Phone Position Title Contractor’s Company Name

Please complete and return the original signed document to the COR within the timeframe stated in the terms of the contract.

GEN030.09.03.15

File details come from the government source that posted it. Updated .