MD ERA Inventory Template.xlsx

XLSX spreadsheet 59 KB Posted

Attached to
Patient Queuing System Federal contract opportunity
Solicitation number
36C25523Q0183_1
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 15

About this file

This document outlines the technical specifications for a patient queuing system solicitation by the VA Saint Louis Health Care System. The solicitation requests vendors to provide touchscreen kiosks with integrated printers, indoor speakers, media PCs for signage, and hosting options for a web-based queuing system. The software must be fully supported by the original manufacturer and utilize the newest version available. Perpetual licensing is required for the software and access to reinstall software if needed. All equipment, installation services, and project management support are to be provided by the vendor in response to this solicitation.

View the file

Other files for this federal contract opportunity

Other files attached to Patient Queuing System, newest first.
File Type Posted
MDS2.pdf PDF
36C25523Q0183_1.pdf PDF
MD ERA PortsProtocolsServices.xlsx XLSX spreadsheet
HIMSS NEMA Standard HN 1-2013 Manufacturer Disclosure Statement For Medical Device Security.pdf PDF
6550 Appendix A.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Risk Data-Key

QuestionControl IDControl TitleDescriptionRisk Assessment QuestionnaireData Validation OptionsActionSecurity Objectives
(C-I-A)LikelihoodImpactRiskVulnerability (If Non-Compliant)Impact of Non-Compliant ControlMDIASecured LocationInternal Connections OnlyMinimal Record StorageMaintenance Installation ContractsMedical Device USB Drive 10N MemoMDPP Scanning StationsPhysical Device MonitoringClinical Functionality (Alternate Method)Local SOPsNetworked Medical Device Databases (NMDD)Mitigating FactorsFinal Residual Risk
PPA.1CM-2Operating SystemThe device runs on a supported operating system platform.Does the device run on a supported Operating System?Yes, NoYes = Compliant
No = Non-CompliantILowHighHighUnsupported operating Systems may be subject to vulnerabilities that will not be patched due to the unupported nature of the operating system.Unpatched VulnerablitiesERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.2CM-6Database ApplicationThe device runs on a supported database application.If the devices uses a database application, is it currently supported (e.g. not end-of-life)?Yes, NoYes = Compliant

No = Non-Compliant

N/A = N/AIHighHighHighUnsupported database systems may be subject to vulnerabilities that will not be patched due to the unupported nature of the operating sytsem.Unpatched VulnerablitiesERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.3AU-4Audit LogsThe device will maintain at least a 90 day history of transactions that will permit the audit of individual’s activities throughout the system.Does the device maintain at least 90 days of audit logs associated with user activity?Yes, NoYes = Compliant
No = Non-CompliantAModerateHighLack of or insufficient auditing can lead to potential cyber attacks or insider threat actions to go unnoticed or unattributed to a specific user.Undetected or unatrributed cyber breachERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.4SC-23Web Browser - Secure Communications ProtocolThe device is configured to only use a secure communications protocol for web browser-based access. (i.e. SSL, TLS)If the device utilizes a web browser for access, is it configured for secure communications (SSL, HTTPS, etc.)?Yes, No, N/A - The device does not use a web browser for accessYes = Compliant

No = Non-Compliant

N/A = N/AIModerateModerateUsing a non-secure communication protocol could expose patient data or potential expose the device to man-in-the-middle attacks.Unauthorized DisclosureERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.5CM-11Patching - Windows Server Update ServicesIf the device runs a Microsoft Windows operating system, the device can use Microsoft Windows Server Update Services (WSUS) to obtain operating system patches.If the device runs a Microsoft Operating System, does the device utilize a Microsoft Windows Server Update Services (WSUS) server?Yes, No, N/A - The device is not a Windows DeviceYes = Compliant

No = Non-Compliant

N/A = N/AIHighHighHighCritical patches, updates are more likely to be missed when requiring manual patching processes.Unpatched VulnerablitiesERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.6SI-2Patching - ProcessThe device manufacturer will provide a complete, documented process to perform routine OS patch updates including all approval and notification procedures that must be completed prior to applying patches.Has the device manufacturer provided a complete and documented process detailing how and when routine OS patch updates are to be applied, and by whom?Yes, NoYes = Compliant
No = Non-CompliantIHighHighHighIf process is not known on how to apply OS patches and who is authorizes the update. Then OS patch update can not occur, due to lack of documentation.Unpatched VulnerablitiesERROR:#REF!0High
PPA.7SI-2Patching - CriticalThe device manufacturer will provide complete documented process to perform critical operating system and application security patching within 30 days of the release of the patch from the software vendor.Has the device manufacturer provided a documented process for addressing critical operating system and application patches for patching within 30 days from the release of the patch?Yes, NoYes = Compliant

No = Non-Compliant

IHighHighHighUnable to apply critical patches in a timely fashion.Elavated risk exposure due to unpatched critical vulnerabilities.ERROR:#REF!0High
PPA.8SI-3Antivirus SoftwareThe device manufacturer supports the installation and operation of antivirus and will provide a complete, documented process to perform routine antivirus updates to include all approval notification procedures that must be completed prior to updating the antivirus software.Does the device support the installation of anti-virus software, to include routine antivirus updates?Yes, NoYes = Compliant
No = Non-CompliantIHighHighHighMalware and virus aim at device can go undetected.Loss of CIAERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.9MP-7Universal Serial Bus (USB) PortsUnused USB ports are disabled upon initial deployment.Are all unused USB ports disabled?Yes, No, N/A - The device does not have USB portsYes = Compliant

No = Non-Compliant

N/A = N/AC-IModerateHighHighUnauthorized services to include malware.Loss of CIAERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.10CM-7AutoRunAutoRun (Windows OS) behavior is disabled upon initial deployment.Is autorun disabled on Windows OS devices?Yes, No, N/A - The device is not a Windows DeviceYes = Compliant

No = Non-Compliant

N/A = N/AC-IModerateHighHighPhysical access could bypass access control and it can execute unauthorized applications.Unauthorized disclosure or execution of malware.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.11RA-5Vulnerability Assessmentsa) The manufacturer will support security testing to assess vulnerabilities on the device.
b) The device will be designed such that the testing will not affect the operational services of the device.Does the device support automated vulnerability assment scans without operational impact to the device?Yes, NoYes = Compliant
No = Non-CompliantC-I-AHighHighHighIf we do not scan we do not find vulnerabilities. Scanning may cause system to crash.Mitigation cannot be applied if vulnerabities are not identified through scanning.ERROR:#REF!ERROR:#REF!0High
PPA.12MP-6Media SanitizationProper disposal of medical devices that reach end of life. All medical device hard drives or other media containing VA sensitive data must follow VA’s current media sanitization policy.If the device is being returned to the manufacturerer at EOL or for other scenarios, is the VA Media Sanitization policy followed?Yes, No, N/A - The device does not store sensitive dataYes = Compliant

No = Non-Compliant

N/A = N/ACLowHighIt will lead to unauthorized access.Unauthorized disclosure of sensitive information e.g., ePHI/PII.ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.13AC-2Role Based AccessThe device will support role based access for all users.Does the device support role-based access for all users?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateModerateElevated priviledge. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.14AC-6Administrator AccountsAdministrator accounts:

a) will be required for service, software installation, and system configuration and;

Does the device require administrative access for service, software installation, and system configuration activities?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateHighHighUnauthorized personnel being able to perform adminstrator functions.Unauthorized changes can be made to the system.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.15IA-2 (1)Adminstrator Accountsb) will support the use of two factor authentication of the administrator account.Does the device support two-factor authentication for administrative accounts?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerate(username and password more likely to be compromised)Unauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.16

Department of Veterans Affairs: Department of Veterans Affairs:

relates to role based access, could it be removed

AC-6Operator AccountsThe device will operate with full clinical functionality under a general user or operator account. User privileges on the device should limit the user/operator to general use and operation of the device.Does the device operate with full clinical functionality with user level privileges?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateModerateElevated priviledge. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.17IA-5Default Usernames and PasswordsThe device will not use default usernames and passwords. All default usernames will be renamed or disabled and all default passwords must be changed after installation of the device.Have device's default usernames and/or passwords been changed?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerateDefault usernames and passwords are known by unauthorized usersUnauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.18AC-2Shared AccountsThe device will not require the use of shared accounts.Does the device require or use shared accounts?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerateLack of non-repudiationLack of accountabilityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.19AC-2Shared AccountsShared accounts will be removed / disabled upon delivery. (i.e. generic accounts, work accounts)Are all shared accounts removed or disabled on the device?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerateLack of non-repudiationLack of accountabilityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.20IA-2Individual User AuthenticationThe device will be configured for individual user authentication.Is the device configured to used individual user authentication?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateModerateLack of non-repudiationLack of accountabilityERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.21IA-5(1)Password AgingThe device will be configured to prompt a user to create a new password at least every 90 days.Is the device configured to support a 90 day password age?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateHighHighPasswords are more likely to be compromisedUnauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.22IA-5(1)Strong PasswordsThe device will enforce the use of strong passwords with a minimum complexity setting of:

• Minimum length of 8 characters

• Complexity rules:

o Minimum of one (1) uppercase letter o Minimum of one (1) lowercase letter o Minimum of one (1) number o Minimum of one (1) special character o Password must not match the last five (5) previously used passwords Is the device configured to support strong passwords with a minimum complexity setting of:

• Minimum length of 8 characters o Minimum of one (1) uppercase letter o Minimum of one (1) lowercase letter o Minimum of one (1) number o Minimum of one (1) special character

o Password must not match the last five (5) previously used passwordsYes, NoYes = Compliant
No = Non-CompliantC-IModerateModeratePasswords are more likely to be compromisedUnauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.23AC-11Auto Logoff/Session LockThe device is capable of session lock after at least 15 minutes of inactivity and is configurable based on based on clinical use.Is the device configured to lock session activity after 15 minutes of inactivity or configured in accordance with documented clinical requirements?Yes, NoYes = Compliant
No = Non-CompliantC-IModerateModeratePrivacy exposureUnauthorized disclosureERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.24IA-5(2)User Authentication - Personal Identity Verification (PIV) Card/ Smart CardThe device supports Personal Identity Verification (PIV) card/smart card user authentication and card readers.Does the device support PIV/Smart Card user authentication?Yes, NoYes = Compliant
No = Non-CompliantC-IHighModerate(username and password more likely to be compromised)Unauthorized accessERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.25SC-28Data Encryption – MechanismThe device will support whole disk encryption as a means to protect patient data.Does the device protect data-at-rest with whole disk encryption?Yes, No, N/A - The device does not store sensitive dataYes = Compliant

No = Non-Compliant

N/A = N/AC-IModerateHighHighData breachLost of confidentialityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.26SC-13Data Encryption - Federal Information Processing Standard Publication 140-2, (FIPS PUB 140-2) ValidationThe device, its communication protocols, and any associated storage media are configured to use an encryption mechanism that is compliant with FIPS PUB 140-2. The device meets FIPS PUB 140-2 requirements and is accompanied by a manufacturer provided validation certificate or signed letter/statement confirming inclusion of the unmodified validated cryptographic module.Does the device meet FIPS PUB 140-2 requirements?Yes, No, N/A - The device does not contain cryptographic modulesYes = Compliant

No = Non-Compliant

N/A = N/AC-IVery LowModerateUn-verifed crypticgrahic modules could lead to weak encryptionData breachERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.27SC-13Data Encryption – Health Insurance Portability and Accountability Act (HIPAA)The device, its communication protocols, and any associated storage media are configured to meet HIPAA standards for encryption and decryption including 164.312(a)(2)(iv) and 164.312(e)(2)(ii) and implements a method to encrypt and decrypt ePHI.Is the device configured to support data at rest and transimission security for sensitive data at rest and in-transit?Yes, No, N/A - The device does not transmit, process, store ePHIYes = Compliant

No = Non-Compliant

N/A = N/AC-IHighHighHighData breachLoss of confidentialityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.28AC-4(22)Data StorageIf the device has the capability to store ePHI or PII, sensitive data will be stored on a separate hard drive.Is ePHI or PII stored on a separate hard drive?Yes, No, N/A - The device does not transmit, process, store ePHIYes = Compliant

No = Non-Compliant

N/A = N/AC-ILowModerateData cannot be purged before equipment is servicedSensitive information could be compromisedERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.29

Department of Veterans Affairs: Department of Veterans Affairs:

SOP should be added as mitigating factor CP-9 Data backups – Process The device manufacturer will provide a complete, documented process for performing routine and emergency data backups and recovery. Are device back-up processes complete and documented, to include routine and emergency data back-ups and recovery? Yes, No, N/A - The device does not store data Yes = Compliant No = Non-Compliant

N/A = N/AC-I-ALowHighLoss of Data and incomplete recoveryLoss of Availability
ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.30IA-4Unique Identification NumbersThe device generates a unique patient identified in lieu of using individual identifies (ie. name and social security number) to avoid linking personal information to a specific patient.Is the device configured to create unique identification numbers for each patient vs. using individual idenity information (Name and SSN)?Yes, No, N/A - The device does not generate patient identifiersYes = Compliant
No = Non-CompliantC-ILowHighWithout unique identification number, ePHI/PII could be compromisedLoss of confidentiality and identity theftERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.31SA-5Bandwidth – Local Area Network (LAN)The device manufacturer will provide a complete, documented technical specification defining LAN bandwidth requirements to enable full connectivity and optimal system performance.Are comprehensive LAN requirements defined and documented for the device?Yes, NoYes = Compliant
No = Non-CompliantC-I-ALowModerateIf device LAN requirements are not defined or documented device may not connect to Network properly.Loss of Availability possible due to incorrect network settings.ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.32SA5Bandwidth – Wide Area Network (WAN)The device manufacturer will provide a complete, documented technical specification defining WAN bandwidth requirements to enable full connectivity and optimal system performanceAre comprehensive WAN requirements defined and documented for the device?Yes, NoYes = Compliant
No = Non-CompliantC-I-ALowModerateIf device WAN requirements are not defined or documented device may not connect to Network properly.Loss of Availability possible due to incorrect network settings.ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.33SC-8Communication Protocols – Use of Clear TextThe device will not use clear text protocols for communication to and from the device. (ie. FTP; telnet)Does the device use only secure protocols for communication to and from the device (SSH, SSL, etc. not FTP, telnet.)Yes, NoYes = Compliant
No = Non-CompliantC-I-AModerateHighSensitive information can be intercepted during transmission.Unauthorized disclosure e.g. man-in-the-middle, data theft.ERROR:#REF!ERROR:#REF!00
PPA.34

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are identified during PRE-procurement, in VA 6550ASA-4(9)Communication Protocols - Identification of Portsa) The device manufacturer will provide a complete, documented technical specification defining all TCP and UDP ports that are required for operation.
Has the device manufacturer provided a detailed technical specification defining all TCP and UDP ports required for device operation?Yes, NoYes = Compliant
No = Non-CompliantC-I-ALowModerateInsufficient defined detailed documentation could expose the device to malware and virusUnauthorized access e.g. session hijacking, installation of malware/ransomwareERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.35

Department of Veterans Affairs: Department of Veterans Affairs:

There needs to be a local SOP created for this as well.

PPS are identified during PRE-procurement, in VA 6550A

SA-5Communication Protocols - Identification of Portsb) The device manufacturer will provide a reference network diagram illustrating all communication requirements.Has the device manufacturer provided a detailed network diagram illustrating on device communication requirements?Yes, NoYes = Compliant
No = Non-CompliantC-I-AHighModerateViolation of configuration management policies and procedures could go undetectedUnauthorized network accessERROR:#REF!ERROR:#REF!00
PPA.36

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are defined in the Pre-procurment docs.SA-5Static Internet Protocol (IP) AddressesThe device manufacturer will provide a complete, documented technical specification defining the number of static IP addresses required for device/system operation.Has the device manufacturer definied the number of static IP addresses required for device / system operation?Yes, NoYes = Compliant
No = Non-CompliantC-I-ALowLowIf multiples static IP are required and not known it could affect the operation of device and make it less accessible.Device operation may be affected if number of defined static address are not known thus compromising availabilityERROR:#REF!00
PPA.37

Department of Veterans Affairs: Department of Veterans Affairs:

This could be mitigated slightly with IPv4 backwards compatability.CM-6Internet Protocol version 6 (IvP6) CompatibilityThe device is IPv6 enabled.Does the device support IPv6?Yes, NoYes = Compliant
No = Non-CompliantILowHighMay not be able to talk to a IPv6 networkLoss of availablityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.38

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are identified during PRE-procurement, in VA 6550A

CM-6Active Ports and ProtocolsThe device configuration restricts active network communication ports and protocols to only those required to support intended operations. All unused ports and protocols are closed or disabled.Are all unused communication ports, closed or disabled?Yes, NoYes = Compliant
No = Non-CompliantIHighHighIf unused ports are not closed or disabled. Device would be susceptible to attack.Unauthorized access to device could be gained.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.39

Department of Veterans Affairs: Department of Veterans Affairs:

S are identified during PRE-procurement, in VA 6550ACM-6Active ServicesThe device configuration restricts running services on the device to only those required to support intended operations. All unused services (ie. Web services; remote connection services) are closed or disabled.Are all unused services closed or disabled?Yes, NoYes = Compliant
No = Non-CompliantIHighHighUnauthorized accessUndisclosed informationERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.40

Department of Veterans Affairs: Department of Veterans Affairs:

Procedures are identified during PRE-procurement, in VA 6550A.AC-17Remote Access - Servicinga) The device manufacturer will provide a complete, documented technical specification defining the procedures to ensure secure remote monitoring, access, repair, maintenance, and troubleshooting.
b) The device manufacturer will provide a reference network diagram illustrating all remote servicing communication requirements.Has the device manufacturer provided a complete, documented technical specification defining the procedureds to ensure remote monitoring, access ,repair, maintenance and troubleshooting?Yes, No, N/A - The device does not support remote accessYes = Compliant

No = Non-Comliant

N/A = N/AC-IHighHighUnable to apply critical patches in a timely fashion.Critical vulnerabilities detected.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.41

Department of Veterans Affairs: Department of Veterans Affairs:

Procedures are identified during PRE-procurement, in VA 6550 Appendix A AC-17 Remote Access - Software The device manufacturer will provide a complete, documented technical specification defining all remote access software required for manufacturer support of the system. Has the device manufacturer provide a complete, documented, specification defining all remote acces software required for manufacturer support of the system? Yes, No, N/A - The device does not support remote access Yes - Compliant No - Non-Comliant

N/A - The device does not support Remote AccessC-IModerateHighUnable to apply critical patches in a timely fashion.Critical vulnerabilities detected.ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.42

Department of Veterans Affairs: Department of Veterans Affairs:

Tools are identified during PRE-procurement, in VA 6550ACM-7Internet Connection - IP/Port/TrafficThe device will not require a direct, unsecured connection to the Internet to enable operation or support.Does the device require a direct, unsecured connection to the Internet to support device operation?Yes, NoYes - Non-Compliant
No - CompliantC-IModerateHighHighUnauthorized services to include malware.Loss of CIA.
ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
PPA.43SA-4(9)Wireless Protocolsa) The device manufacturer will provide a complete, documented technical specification defining all wireless protocols (e.g., Wireless Medical Telemetry Service (WMTS), Bluetooth, and IEEE 802.11) used by the device.
b) The device manufacturer will provide a reference network diagram illustrating all wireless communication requirements.Has the device manufacturere provided a complete, documented, specification defining all wireless protocols used by the device?Yess, No, N/A - The device does not support wireless protocolsYes - Compliant

No - Non-Compliant

N/A - The device does not support wireless protocols.C-I-AVery LowModerateData BreachUnauthorized use of wireless communicationsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.44AC-18(1)Wireless Protocols - EncryptionThe device will support the use of a FIPS 140-2 encryption standard for wireless connectivity and communications without compromising device performance.Does the device use FIPS 140-2 encryption standards for wireless communications?Yes, No, N/A - The device does not support wireless protocolsYes - Compliant

No - Non-Compliant

N/A - The device does not support wireless protocols.C-IVery LowModerateNot meeting the Fips 140-2 requirement and unmodified cryptographic can lead to week encryptionData breachERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
PPA.45AC-18(1)Wireless Encryption: FIPS PUB 140-2 ValidationThe device meets FIPS PUB 140-2 requirements and is accompanied by a manufacturer provided validation certificate or signed letter/statement confirming inclusion of the unmodified validated cryptographic module.Has the manufacturer provided the FIPS 140-2 certificate for wireless communications?Yes, No, N/A - The device does not support wireless protocolsYes - Compliant

No - Non-Compliant

N/A - The device does not support wireless protocols.C-IVery LowModerateRevocation of access codes in the system.Providing confidentiality, authenticity and integrity of the dataERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!00
SA-4(9)Wireless Data TransmissionThe device manufacturer will provide a complete, documented technical specification defining all ePHI data elements transmitted via the device’s wireless communications.Has the manufacturer provided a complete, documented technical specification defining all ePHI data elements that are transmitted via the device's wireless communications?Yes, No, N/A - The device does not support wireless protocolsYes - Compliant

No - Non-Compliant N/A - The device does not support wireless protocols. C-I-A Moderate Moderate If not documented then potential vunlerabilities will go undetected Data leakage ERROR:#REF! ERROR:#REF! ERROR:#REF! ERROR:#REF! 0 0

2.AC-6(1)

Department of Veterans Affairs: Department of Veterans Affairs:

Needs to be a local SOP.

AC-6(1)Least Privilege | Authorize Access To Security FunctionsThe organization explicitly authorizes access to [Assignment: organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information].Technically speaking, does this device have the capability to establish multiple user roles and assign users to specific user roles, based on their assigned duties?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateElevated priviledge. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
3.AC-6(1)

Department of Veterans Affairs: Department of Veterans Affairs:

Documented in Pre-Procurement.AC-6(1)Least Privilege | Authorize Access To Security FunctionsThe organization explicitly authorizes access to [Assignment: organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information].Does the device inherit User Access policies from the organization, e.g GPO's or local access SOP?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateElevated priviledge. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
4.AC-6(1)AC-6(1)Least Privilege | Authorize Access To Security FunctionsThe organization explicitly authorizes access to organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information.Is there device specific documentation describing which user roles are allowed which priveleges on the device?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateExecution of Security functions by unauthorized personnel.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
5.AC-6(1)AC-6(1)Least Privilege | Authorize Access To Security FunctionsThe organization explicitly authorizes access to organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information.Have user roles and privileges been implemented in accordance with documented policy?Yes, NoYes = Compliant
No = Non-compliantC-ILowHighModerateunauthorized personnel could have access to System security files, system management/configuration files …Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
6.AC-6 (2)AC-6(2)Least Privilege | Non-Privileged Access For Non-security FunctionsThe organization requires that users of information system accounts, or roles, with access to organization-defined security functions or security-relevant information, use non- privileged accounts or roles, when accessing non-security functions.Are users with elevated privileges forced to use a non-privileged user account when performing non-privileged, i.e. non-security, functions?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateElevated priviledge. Users have more access than required.Users could perform unauthorized functionsERROR:#REF!ERROR:#REF!0Moderate

8.AC-6 (9) AC-6 (9)

Department of Veterans Affairs: Department of Veterans Affairs:

Covered by local SOPLeast Privilege | Auditing Use Of Privileged FunctionsThe information system audits the execution of privileged functions.Are privileged functions audited? (e.g. user management, configuration changes, etc.?)?Yes, NoYes = Compliant
No = Non-compliantC-IModerateHighHighInsider threat and advanced persistent threat will go undetectedCreates undetected and unauthorized processERROR:#REF!ERROR:#REF!0High

12.AC-18 (1) AC-18 (1) Wireless Access | Authentication and Encryption The information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption. Is wireless access to the medical device permitted only through the use of authentication with encryption? Yes, No, N/A - The device does not support wireless protocols Yes = Compliant No = non-compliant

N/A = compliantC-ILowHighModerateMedical device and/or information system likely to be compromised
Authentication credentials are sent as clear textData can be compromisedERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate

14.AU-3 (1) AU-3 (1) Content of Audit Records | Additional Audit Information The information system generates audit records containing the following additional information: [Assignment: organization-defined additional, more detailed information]. Does the medical device generate audit records? Yes, No Yes = Compliant No = Non-compliant

C-IModerateHighModerateLack of or insufficient audit records can lead to insider threat actions to go unnoticed or unattributedUndetected or unatrributed cyber breachERROR:#REF!0Moderate
15.AU-4AU-4Audit Storage CapacityControl: The organization allocates audit record storage capacity in accordance with [Assignment: organization-defined audit record storage requirements].Does the medical device allocate audit record storage capacity?Yes, NoYes = Compliant
No = Non-compliantAModerateHighModerateLack of or insufficient audit records can lead to insider threat actions to go unnoticed or unattributedData breachERROR:#REF!ERROR:#REF!0Moderate
16.AU-5AU-5Response to Audit Processing Failuresa. Alerts [Assignment: organization-defined personnel or roles] in the event of an audit processing failure; andIs the medical device designed to alert personnel in the event of an audit processing failure?Yes, NoYes = Compliant
No = Non-compliantAModerateHighModerateInsider threat and advanced persistent threat will go undetectedData breach and/or data missplaceERROR:#REF!ERROR:#REF!0Moderate
17.AU-5AU-5Response to Audit Processing Failuresb. Takes the following additional actions: [Assignment: organization-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)].Does the medical device take action if an audit processing failutre happen?Yes, NoYes = Compliant
No = Non-compliantAModerateHighModerateCannot prevent Malware attackAn attack could send large volumes of messages to overwhelm server or network.ERROR:#REF!ERROR:#REF!0Moderate
18.AU-7AU-7Audit Reduction and Report GenerationControl: The information system provides an audit reduction and report generation capability that:

a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and

b. Does not alter the original content or time ordering of audit records.

Does the medical devicesuppot on-demand and after-the-fact audit record reviews? Yes, No Yes = Compliant No = Non-compliant;

C-I Moderate Moderate Moderate It will be difficult to establish, correlate and investigate events leading to an outage or attack, or identify the responses.

No automated Incidence ReportERROR:#REF!ERROR:#REF!0Moderate
19.AU-7AU-7Audit Reduction and Report Generationb. Does not alter the original content or time ordering of audit records.Does the device prevent the audit records from able to be altered?Yes, NoYes = Compliant

No = Non-Compliant

C-ILowModerateLowIntegrity of Audit record is compromised
Records are not usable for forensic analysisERROR:#REF!ERROR:#REF!0Low
20.AU-7 (1)AU-7 (1)Audit Reduction and Report Generation | Automatic ProcessingThe information system provides the capability to process audit records for events of interest based on [Assignment: organization-defined audit fields within audit records].Is the medical device configured to process audit records based according to defined lists?Yes, NoYes = Compliant
No = Non-compliantC-IModerateModerateModerateComformity/compliance will not be determinedFailed auditERROR:#REF!ERROR:#REF!0Moderate
21.AU-8AU-8Time StampsControl: The information system:

a. Uses internal system clocks to generate time stamps for audit records; and

b. Records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets [Assignment: organization-defined granularity of time measurement].

Is the medical device configured to report time stamps to <SELECT: Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT)> with the following level of detail: < MM/DD/YY HH/MM/SS>Yes, No.Yes = Compliant
No = Non-compliantILowLowLowNo common time referenceDifficult to perform forensic analysisERROR:#REF!ERROR:#REF!0Low
22.AU-8 (1)AU-8(1)Time Stamps | Synchronization With Authoritative Time SourceThe information system:

(a) Compares the internal information system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and

Is the medical device configured to synchronize its internal information system clock with an authorized NTP?Yes, No.Yes = Compliant
No = Non-compliantILowLowLowNo common time referenceDifficult to perform forensic analysisERROR:#REF!ERROR:#REF!0Low
23.AU-8 (1)AU-8(1)Time Stamps | Synchronization With Authoritative Time Source(b) Synchronizes the internal system clocks to the authoritative time source when the time difference is greater than [Assignment: organization-defined time period].Is the medical device configured to synchronize its internal information system clock with an authorized NTP when the time is out of synch by XXXX?Yes, No.Yes = Compliant
No = Non-compliantILowLowLowNo common time referenceDifficult to perform forensic analysisERROR:#REF!ERROR:#REF!0Low

27.CP-9

Department of Veterans Affairs: Department of Veterans Affairs:

Covered under local SOP

Department of Veterans Affairs: Department of Veterans Affairs:

relates to role based access, could it be removed CP-9 Information System Backup Control: The organization:

a. Conducts backups of user-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];

b. Conducts backups of system-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];

c. Conducts backups of information system documentation including security-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and

d. Protects the confidentiality, integrity, and availability of backup information at storage locations.

Is there a device backup infrastructure in place for the medical device?Yes, No.Yes = Compliant
No = Non-compliantC-I-ALowHighModerateData LossLoss of Availability
Disruption of serviceERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
28.CP-9CP-9Information System Backupa. Conducts backups of user-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];Does the medical device conduct backups of user-level information?Yes, No, N/A - The device does not store user-level informationYes = Compliant

No = Non-compliant

N/A = N/AC-I-ALowHighModerateLoss of data generated by information system and/or application users.Loss of Availability
Disruption of serviceERROR:#REF!ERROR:#REF!0Moderate
29.CP-9CP-9Information System Backupb. Conducts backups of system-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];Does the medical device conduct backups of system-level information?Yes, NoYes = Compliant
No = Non-compliantC-I-ALowHighModerateUnable to recover system information after system failureLoss of system information (CIA)ERROR:#REF!ERROR:#REF!0Moderate
30.CP-9CP-9Information System Backupc. Conducts backups of information system documentation including security-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; andDoes the medical device back-up security related information?Yes, NoYes = Compliant
No = Non-compliantC-I-ALowModerateModerateFailure to meet system recovery time and recovery ponit objectivesInformation System temporary unavailableERROR:#REF!ERROR:#REF!0Moderate
31.CP-9CP-9Information System Backupd. Protects the confidentiality, integrity, and availability of backup information at storage locations.Is there a process in place to protect the confidentiality, integrity, and availability (CIA) of backed-up data?Yes, No, N/A - Sensitive data is not backed-upYes = Compliant

No = Non-compliant

N/A = N/AC-I-ALowModerateModerateUnauthorized access of backed-up informationLoss of backed-up data (CIA)ERROR:#REF!ERROR:#REF!ERROR:#REF!0Moderate
32.CP-10CP-10Information System Recovery and

Reconstitution

Control: The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.Does the medical device have an individual contingency plan?Yes, NoYes = Compliant
No = Non-compliantALowModerateLowUnable to plan for system recoveryLoss of CIAERROR:#REF!ERROR:#REF!0Low
32.CP-10CP-10Information System Recovery and

Reconstitution

Control: The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.Does the medical device have documented recovery and reconstitution procedures?Yes, NoYes = Compliant
No = Non-compliantALowModerateModerateUnsuccessful system restorationLoss of data (CIA)ERROR:#REF!ERROR:#REF!0Moderate
35.MP-2MP-2Media AccessControl: The organization restricts access to [Assignment: organization-defined types of digital and/or non-digital media] to [Assignment: organization-defined personnel or roles].Is access to the medical device restricted to a group of personnel or roles?Yes, NoYes = Compliant
No = Non-compliantC-ILowModerateLowUnauthorized personnel having access to digital and non digital mediaLoss of confidentialityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0Low
36.MP-3MP-3Media MarkingControl: The organization:

a. Marks information system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information; and

Is medical device media marked indicating the distribution limitations, handling caveats, and any applicable security markings?Yes, No, N/A = ExplainYes = Compliant
No = Non-compliantCLowLowLowMishandling of media devices not marked for security purposeLoss of confidentiality and integrityERROR:#REF!0Low
37.MP-3MP-3Media Markingb. Exempts [Assignment: organization-defined types of information system media] from marking as long as the media remain within [Assignment: organization-defined controlled areas].Are there exemptions for media marking for medical devices that remain within specified areas?Yes, No, N/A = ExplainYes = Compliant
No = Non-compliantCLowLowLowUnauthorized access and mishandling of unmarked media devicesData breachERROR:#REF!0Low

Wanda to research if the USB 10 memo would apply

40.RA-5 (5)RA-5 (5)Vulnerability Scanning | Privileged AccessThe information system implements privileged access authorization to [Assignment: organization- identified information system components] for selected [Assignment: organization-defined vulnerability scanning activities].Is the medical device configured to support privileged-access vulnerablity scans?Yes, NoYes = Compliant
No = Non-compliantC-I-AHighHighHighFailure to perform scanning could result in system vulnerabilities going undetected. Over time, undiscovered emerging vulnerabilities will incrise the amount of risk.Vulnerabilities could lead to compromises of Confidentiality, Integrity, and Availability (CIA).ERROR:#REF!ERROR:#REF!ERROR:#REF!0High

Addressed in 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:

addressed in 6550 appedenix A Department of Veterans Affairs: Department of Veterans Affairs:

information may be derived from MDS2 and 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:

can be derived from MDS2 and 6550 appendix A Department of Veterans Affairs: Department of Veterans Affairs:

SOP should be added as mitigating factor

51.SC-15

Department of Veterans Affairs: Department of Veterans Affairs:

addressed in 6550 Appendix A

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:

There needs to be a local SOP created for this as well.

PPS are identified during PRE-procurement, in VA 6550A

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are defined in the Pre-procurment docs.

Department of Veterans Affairs: Department of Veterans Affairs:

This could be mitigated slightly with IPv4 backwards compatability.

Department of Veterans Affairs: Department of Veterans Affairs:

PPS are identified during PRE-procurement, in VA 6550A

Department of Veterans Affairs: Department of Veterans Affairs:

S are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:

Procedures are identified during PRE-procurement, in VA 6550A.

Department of Veterans Affairs: Department of Veterans Affairs:

Procedures are identified during PRE-procurement, in VA 6550 Appendix A

Department of Veterans Affairs: Department of Veterans Affairs:

Tools are identified during PRE-procurement, in VA 6550A Department of Veterans Affairs: Department of Veterans Affairs:

Described in Pre-Procurement VA 6550 Appendix A Department of Veterans Affairs: Department of Veterans Affairs:

Needs to be a local SOP.

Department of Veterans Affairs: Department of Veterans Affairs:

Needs to be a local SOP.

Department of Veterans Affairs: Department of Veterans Affairs:

Documented in Pre-Procurement. SC-15 Collaborative Computing Devices Control: The information system:

a. Prohibits remote activation of collaborative computing devices with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and

If the device utilizes collaborative computing devices (e.g. cameras, microphones, etc.), does the Medical Device prohibit remote activation of the collaborative features? Yes, No, N/A = The device does not contain collaborative computing devices Yes = Compliant No = Non-compliant

N/A = N/ACModerateHighHighRemote activation of unauthorized and unmonitored use of collaborative computing devices may provide unathorized access to remote users.System hijacking, installation of malware, unauthorized disclosure of sensitive information, compromise of data integrity, loss of system avialabilityERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!0High
52.SC-15SC-15Collaborative Computing DevicesControl: The information system:

b. Provides an explicit indication of use to users physically present at the devices. If collaborative features are enabled, are users physically present aware (e.g. flashing light indicating camera is on, etc.) Yes, No, N/A = The device does not contain collaborative computing devices Yes = Compliant No = Non-compliant

N/A = N/ACModerateModerateModerateRemote attacks using collaborative technologies could go unnoticed by the local user.Unauthorized disclosure of sensitive data, potential exploitation in compromise of the local device or other networked devices.ERROR:#REF!ERROR:#REF!0Moderate
Accepted Mitigation Factors
AMF.1--MDIAAll devices are requried to be behind a compliant MDIA ACL.Is or will the device behind a compliant VLAN ACL?NoYes - Accepted Mitigation Factor

No - No Risk Downgrades AMF.2 -- Secured Location Controlled and secured locations may reduce the risk of certain vulnerabilities. Is the device secured from physical access when not actively in use? No Yes - Accepted Mitigation Factor No - No Risk Downgrades AMF.3 -- Internet Requirement Devices that do not require the internet to operate may have a lower risk exposure. Is the device able to be operated without an active external connection? (e.g. connection outside of the VA network) No Yes - Accepted Mitigation Factor No - No Risk Downgrades AMF.4 -- Record Storage For the purposes of breach notification, breaches that occur on devices that contain less than 500 records are required to be reported annually, whereas breaches of 500 records or more must be reported immediatedly to HHS and in most cases the media. Is the devcie able to be restriced to store less than 500 patient records? No Yes- Accepted Mitigation Factor No - No Risk Downgrade N/A - Device does not store ePHI AMF.5 -- Maintenance Installation Contracts The VA Maintenance / Installation (Warranty) Contracts (VAIQ 7058822) intends to protect access to SPI during installation, maintenance, and repair of devices that may contrain SPI. Is the device covered by a compliant VA Maintenance / Installation (Warranty) Contract? No Yes - Accepted Mitgation Factor No - No Risk Downgrade AMF.6 -- Medical Device USB Drive USB Drives or flash media allow exploits to be easily introduced into the VA environment. The HTM Memo "Guidance for Determining the Need for a Waiver for Medical Device USB Drives" defines requirements and best practices for utilzing USB Drives and Media. Prior to using a USB drive with the device, are the conditions in the 10N memo (e.g. …. ….. ……. )followed? No Yes - Accepted Mitigation Factor No - No Risk Downgrades AMF.7 -- MDPP Scanning Stations MDPP Mobile Media Scanning Stations are intended to proactively scan mobile media prior to connecting to a Medical Device?

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .