S02 Attachment 1 MOU ISA Template to be Used.pdf

PDF 789 KB Posted

Attached to
DH10--Fraud Prevention Solution and Technical Support Federal contract opportunity
Solicitation number
36C10A22R0002
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This memorandum of understanding and interconnection security agreement template establishes security requirements and protocols for connecting the Department of Veterans Affairs' [VA Organization 1 System] with [Organization 2 System]. The connection will exchange data to expedite processing between VA and [Organization 2].

The agreement defines notification procedures for security incidents, system changes, and personnel changes. It requires at least annual review and reauthorization for significant changes. The parties will share costs for the interconnection and are responsible for their respective systems' security controls. Sensitive data exchanged includes PII, PHI, and financial information, categorized as low to high impact per FIPS 199. Audit logs must be retained for one year or according to NARA. Training and background checks for staff will meet contractual requirements.

View the file

Other files for this federal contract opportunity

Other files attached to DH10--Fraud Prevention Solution and Technical Support, newest first.
File Type Posted
36C10A22R0002 0002_1.docx DOCX document
S06 36C10A22R0002 0002 Attachment Solicitation.pdf PDF
S06 36C10A22R0002 0002.pdf PDF
S06 36C10A22R0002 0001.docx DOCX document
36C10A22R0002 0001_1.docx DOCX document
S02 36C10A22R0002.pdf PDF
36C10A22R0002.docx DOCX document
S02 Attachment 2 Subcontracting Plan DRAFT.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FOR OFFICIAL USE ONLY

i O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Xpiren

MEMORANDUM OF UNDERSTANDING AND

INTERCONNECTION SECURITY AGREEMENT

Between [VA Organization 1] And [Organization 2]

[September 9, 2020] [Version 2.0] i i O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Template color key (This Text Box to be removed from final draft)

Black text: boilerplate text that has been approved by VA management and must remain in document (flag/ comment on any areas of concern to discuss with the VA) [VA Organization 1]: Replace with name of the VA organization (can be performed by a find and replace all (CTRL+H) [Organization 2]: Replace with name of non-VA organization / company name [VA Organization 1’s System]: Replace with correct name of system or informational asset [Organization 2’s System]: Replace with correct name of system or informational asset Blue text: replace with appropriate text and change to black once done Green text: this is informational/instructional text that should be removed from final draft Last – Update the Document Control Change Sheet to reflect the most recent status changes of the MOU/ISA.

i i i O F F I C E O F I N F O R M A T I O N S E C U R I T Y

DOCUMENT CONTROL CHANGE SHEET

Date Filename/Version # Authors Revision Description

09/09/2020 Template 2.0 Joseph Decoteau/Leigh Zirbel/Crystal White/James Mark McGee

Update VA Template and release new version to the field.

MM/DD/YYYY Example: [Organization 2] ABC-

VHA MOU ISA 1.0

VA POC Name / Org 2 POC Name [Include 2 Authors: VA and Organization 2 point of contact (POC) who drafted this document]

[Indicate New Agreement or Description of revision to existing agreement] i v O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Table of Contents

INTRODUCTION _________________________________________________________________ 1

1 SUPERSEDES: _______________________________________________________________ 2

1.1 Authority ________________________________________________________________________ 2

2 MEMORANDUM OF UNDERSTANDING ____________________________________________ 2

2.1 Background ______________________________________________________________________ 2

2.2 Communications __________________________________________________________________ 3

2.2.1 Security Incidents _________________________________________________________________ 3

2.2.2 Disasters and Other Contingencies _____________________________________________________ 4

2.2.3 Material Changes to System Configuration _______________________________________________ 4

2.2.4 New Interconnections ______________________________________________________________ 4

2.2.5 Personnel Changes ________________________________________________________________ 4

2.2.6 Security ________________________________________________________________________ 5

2.2.7 Cost Considerations________________________________________________________________ 5

3 INTERCONNECTION SECURITY REQUIREMENTS ______________________________________ 5

3.1 Background ______________________________________________________________________ 5

3.1.1 System Description ________________________________________________________________ 5

3.1.2 System Hardware and Software Requirements ____________________________________________ 5

3.2 System Security Considerations ______________________________________________________ 6

3.2.1 General Information/Data Description __________________________________________________ 6

3.2.2 Security Assessment _______________________________________________________________ 7

3.2.3 Services Offered __________________________________________________________________ 7

3.2.4 Information System Security Officer at Interconnection Site ___________________________________ 7

3.2.5 Sensitivity Categorization ____________________________________________________________ 7

3.2.6 User Community __________________________________________________________________ 7

3.2.7 Information Exchange Security _______________________________________________________ 8

3.2.8 Trusted Behavior Expectations ________________________________________________________ 8

3.2.9 Formal Security Policy ______________________________________________________________ 8

3.2.10 Audit Trail Responsibilities _________________________________________________________ 8

3.2.11 Security Parameters _____________________________________________________________ 8

3.2.12 Training and Awareness ___________________________________________________________ 9

3.3 TOPOLOGICAL DRAWING____________________________________________________________ 9

4 Duration __________________________________________________________________ 10

5 SIGNATORY AUTHORITY ______________________________________________________ 11

Appendix A: Points of Contact _____________________________________________________ 12

Appendix B: Definitions of Sensitive Information Types __________________________________ 13

Appendix C: Interconnection Ports and Protocols _______________________________________ 16

1 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

INTRODUCTION

The purpose of this document is to establish a management agreement between [VA Organization 1] and [Organization 2] regarding the development, management, operation, and security of a system interconnection between [VA Organization 1 System], owned or leased by [VA Organization 1], and [Organization 2 System], owned or leased by [Organization 2]. This agreement will govern the relationship between [VA Organization 1] and [Organization 2], including designated managerial and technical staff, in the absence of a common management authority.

[VA Organization 1] utilizes a Memorandum of Understanding (MOU) to document the terms and conditions for sharing data and information resources in a secure manner. The following supporting information within the MOU will define the purpose of the interconnection, identify relative authorities, specify the responsibilities of both organizations, and define the terms of the agreement. Additionally, the MOU provides details pertaining to apportionment of cost and timeline for terminating or reauthorizing the interconnection.

Technical details on how the interconnection is established or maintained are included within the Interconnection Security Agreement (ISA). A system interconnection is a direct connection between two or more information technology (IT) systems for sharing data and other information resources. [VA Organization 1] uses the ISA to formally document the reasons, methodology, and approvals for:

interconnecting IT systems; to identify the basic components of an interconnection; to identify methods and levels of interconnectivity; and to discuss potential security risks associated with the interconnections.

This document does not replace any existing contract(s) between [VA Organization 1] and [Organization 2]. This fully executed agreement will be documented in applicable security controls in the current Governance and Risk Compliance tool and will be maintained as evidence for the respective system(s).

2 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

1 SUPERSEDES:

[Indicate if this is a new agreement or if it supersedes another agreement]

1.1 Authority

The authority for this interconnection is based on:

• Federal Information Security Modernization Act (FISMA)

• NIST 800-47, Security Guide for Interconnecting Information Technology Systems

• VA Directive and Handbook 6513, Secure External Connections

• VA Directive 6500, VA Directive 6500: VA Cybersecurity Program, and Handbook 6500, Risk Management Framework for VA Information Systems: Tier 3 – VA Information Security Program

• Health Insurance Portability and Accountability Act (HIPAA) Security Rule, 45 C.F.R. Part 160

• 38 United States Code (U.S.C.) §§ 5721-5728, Veteran’s Benefits, Information Security

• OMB Circular A-130, Managing Information as a Strategic Resource

• 18 U.S.C. 641 Criminal Code: Public Money, Property or Records

• 18 U.S.C. 1905 Criminal Code: Disclosure of Confidential Information

[The Privacy Officer must ensure the correct authorities are identified below, based on the type of information being transmitted.]

The authority for [VA Organization 1] to share data for the purpose outlined under this Agreement with [Organization 2] is as follows:

• HIPAA Privacy Rule, 45 Code of Federal Regulations (C.F.R.) Part 164, Standards for Privacy of Individually Identifiable Health Information [Add specific HIPAA provisions where applicable]

• Privacy Act of 1974, 5 U.S.C. § 552a, as amended

• [Add System of Records Notice (SORN) Name, Routine Use, or other Privacy Act authority if applicable]

• VA Claims Confidentiality Statute, 38 U.S.C § 5701 [Add specific citation (e.g., (b)(3) or (e)) if applicable]

• Confidentiality of Certain Medical Records, 38 U.S.C. § 7332 [Add specific citation if applicable]

2 MEMORANDUM OF UNDERSTANDING

2.1 Background

It is the intent of both parties to this agreement to interconnect the following IT systems to exchange data between [VA Organization 1 System] and [Organization 2 System]. [VA Organization 1] requires the use of or access to [Organization 2 System], and [Organization 2] requires the use of or access to [VA Organization 1 System], via an interconnection as approved by the VA Office of Information

3 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Technology (OIT) System Owner. The expected benefit of the interconnection is to expedite the processing of data associated with [VA Organization 1] and [Organization 2].

Each IT system is described below:

[VA Organization 1]’s System

– Name [Enter full name of [VA Organization 1 System] here]

– Function [Enter details about the function of [VA Organization 1 System] here]

– Location [Enter physical location(s) of [VA Organization 1 System] here (Include street, city, and zip code)]

[Organization 2]’s System

– Name [Enter full name of [Organization 2 System] here]

– Function [Enter details about the function of [Organization 2 System] here]

– Location [Enter physical location of [Organization 2 System] here. Include street, city, and zip]

2.2 Communications

Frequent formal communications are essential to ensure the successful management and operation of the interconnection. The parties agree to maintain open lines of communication between designated staff at both the managerial and technical levels. Communications described herein must be conducted in writing (mail or email, excluding any sensitive VA information) unless otherwise noted.

The owners of [VA Organization 1 System] and [Organization 2 System] agree to designate and provide contact information for the technical lead(s) for their respective system and to facilitate direct contact between technical leads to support the management and operation of the interconnection (see Appendix A). To safeguard the confidentiality, integrity, and availability of the connected systems and the data stored, processed, and transmitted, the parties agree to provide notice of specific events within the timeframes indicated below.

2.2.1 Security Incidents

If [Organization 2] employee, contractor, or agent becomes aware of the theft, loss or compromise of any device used to transport, access, or store VA data, [Organization 2] shall notify [VA Organization 1] POCs listed in Appendix A by telephone or email within one hour upon discovery of a security incident.

[Organization 2] will provide details of the security incident, the potential risk to VA data, and all actions taken to remediate the issue. Reportable items include event type, date and time of event, user identification, workstation identification, success or failure of access attempts, and security actions

4 O F F I C E O F I N F O R M A T I O N S E C U R I T Y taken by system administrators or security officers. VA Information System Security Officers (ISSO) or Privacy Officers (PO) will contact VA-CSOC within one hour of notification.

[Organization 2] will also provide VA with a written closing action report once the security event or incident has been resolved. VA will follow this same notification process should a security event occur within the VA boundary involving [Organization 2]’s provided data. Designated POCs will follow established incident response and reporting procedures, determine whether the incident warrants escalation, and comply with established escalation requirements for responding to security incidents.

[VA Organization 1] will report security incidents to the [Organization 2] POCs listed in Appendix A.

[Enter a brief description of Organization 2’s security incident reporting requirements.]

2.2.2 Disasters and Other Contingencies

Technical staff will immediately notify their designated counterparts listed within Appendix A by telephone or email in the event of a disaster or other incident that disrupts the normal operation of one or both connected systems.

2.2.3 Material Changes to System Configuration

A significant change to an information system may include changes to the system itself or to the environment of operation. Significant changes to the information system may include but are not limited to: installation of new or major upgrades to the operating system, middleware component, or application; modifications to system ports, protocols, or services (see Appendix C); installation of a new or upgraded hardware platform; modifications to cryptographic modules or services; or modifications to security controls. Significant changes to the environment of operation which materially impact the interconnection to require reporting, may include, but are not limited to: moving to a new facility;

adding new core missions or business functions; acquiring specific and credible threat information that the organization is being targeted by a threat source; or establishing new or modified laws, policies or regulations. Major changes to the information collected or maintained are those changes that could result in greater disclosure of information or a change in the way personal information/data is used.

Planned technical changes to the system architecture will be coordinated with the appropriate security and technical staff. All changes must be submitted, approved, and implemented as a modification to the existing connection through the appropriate change management process. Prior to requesting or implementing a change to the interconnection, the System Owner will conduct a risk assessment based on the new system architecture and determine if the proposed change requires reauthorization of the interconnection. Formal reauthorization is required whenever a system undergoes a significant change.

The MOU/ISA must be updated and re-signed within 30 calendar days of implementation. The POCs listed in Appendix A are responsible for updating and reauthorizing this document.

2.2.4 New Interconnections

The initiating party will notify the other party at least 30 calendar days before it connects its IT system, described in Section 2.1, with any other IT system that materially impacts the security of the interconnection covered by this MOU/ISA. This includes connecting the IT system with systems that are owned and operated by third parties.

2.2.5 Personnel Changes

The responsible parties for each system are listed in Appendix A. The parties agree to provide notification of the separation, long-term absence or any other significant status changes in user profiles or personnel listed in Appendix A. The appendix will be updated as necessary to ensure accuracy.

5 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Updating Appendix A does not require the re-signing of this MOU/ISA by either party. It is the responsibility of each respective approving authority to ensure the timely updating of this appendix and for the notification of such changes to the alternate party within thirty (30) days of any personnel change.

2.2.6 Security

Both parties agree to work together to ensure the joint security of the connected systems and the information/data stored, processed, and transmitted, as specified in the ISA section of this document.

2.2.7 Cost Considerations

Both parties agree to share the costs of the interconnecting mechanisms and/or media. Percentage of cost assumed by each organization (e.g., 50/50, 40/60, etc.) must be agreed upon in advance, and no such expenditures or financial commitments shall be made without the written concurrence of both parties. Modifications to either system that are necessary to support the interconnection are the responsibility of the respective system owner’s organization.

3 INTERCONNECTION SECURITY REQUIREMENTS

3.1 Background

The technical details of the interconnection are detailed in this ISA section of the document. The parties agree to work together to develop the ISA section. The MOU/ISA must be signed by both parties before the interconnection is activated. Proposed changes to either system or the interconnecting medium will be reviewed and evaluated as outlined in Section 2.2.3 Material Changes to System Configuration and

2.2.4 New Interconnections. The MOU/ISA must be updated and re-signed within 30 calendar days before changes (as described in Section 2.2.3 and 2.2.4) are implemented. Signatories to the MOU/ISA shall be the [VA Organization 1] System Owner, ISSO and PO and at least one (1) [Organization 2] System Owner. The document will become an integral piece of the VA Assessment and Authorization (A&A) documentation and will be included in subsequent authorization requests.

3.1.1 System Description

[VA Organization 1 System] and [Organization 2 System] system descriptions are listed in Section 2.1 of this document.

3.1.2 System Hardware and Software Requirements

[Identify hardware that will be needed to support the interconnection, including communications lines, routers, firewalls, hubs, switches, servers, and computer workstations. If existing hardware is not sufficient or compatible, specify what new hardware is required.]

[Identify software (must be VA TRM (Technical Reference Model) approved) that will be needed to support the interconnection, including software for firewalls, servers, and computer workstations. If existing software is not sufficient, specify what new software is required.]

6 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

3.2 System Security Considerations

3.2.1 General Information/Data Description

[VA Organization 1 System]

The following is a description of information/data to be transmitted from [VA Organization 1] to [Organization 2] including Federal Information Processing Standard (FIPS) 199 sensitivity categorization level.

• Information Type Transmitted: [Describe what information/data types will be transmitted from [VA Organization 1] to [Organization 2]. Example answers include, PII (Personally Identifiable Information), PHI (Protected Health Information), VA owned sensitive information, and financial data. See Appendix B for definitions of sensitive information types.]

• Data Flow Description: [Describe how information/data will be transmitted from [VA Organization 1] to [Organization 2]. Describe if it is collected, transmitted and/or stored.]

• The FIPS 199 Sensitivity Categorization Level is [Low/Moderate/High]. [The FIPS Level is to be filled out by the sponsoring facility’s VA staff (ISSO/Contracting Officer’s Representative (COR)/etc.). Please review definitions of low, moderate, and high in the publicly available FIPS 199 document (search for “Potential Impact on Organizations and Individuals”). This cannot be listed as N/A.] o Confidentiality – [Low/Moderate/High] o Integrity - [Low/Moderate/High] o Availability - [Low/Moderate/High]

[Organization 2 System]

The following is a description of information/data to be transmitted from [Organization 2] to [VA Organization 1] including Federal Information Processing Standard (FIPS) 199 sensitivity categorization level.

• Information Type Transmitted: [Describe what information/data types will be transmitted from [Organization 2] to [VA Organization 1]. Example answers include, PII, PHI, VA owned sensitive information, and financial data. See Appendix B for definitions of sensitive information types.]

• Data Flow Description: [Describe how information/data will be transmitted from [Organization 2] to [VA Organization 1]. Describe if it is collected, transmitted and/or stored.]

• The FIPS 199 Sensitivity Categorization Level is [Low/Moderate/High]. [The FIPS Level is to be filled out by the sponsoring facility’s VA staff (ISSO/ Contracting Officer’s Representative (COR)/etc.). Please review definitions of low, moderate, and high in the publicly available FIPS 199 document (search for “Potential Impact on Organizations and Individuals”). This cannot be listed as N/A.] o Confidentiality – [Low/Moderate/High] o Integrity - [Low/Moderate/High] o Availability - [Low/Moderate/High]

7 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

The interconnection between [VA Organization 1 System] and [Organization 2 System] is a [one-way or two-way path].

Purpose for Data Transfer: [Describe the purpose of the data transfer: e.g., access to clinical images by off-site radiologists; financial information used to generate billing information; subject data to be analyzed under a VA or a non-VA research protocol]

VA-owned data transmitted to [Organization 2] via this interconnection is physically stored at [Enter location of physical storage, e.g. facility address, server names, Cloud entity, etc.].

Provisions for Destruction or Return of the Data (if applicable): [Describe the provisions for the return or destruction of the sensitive information to VA at the completion of the contract, project, clinical application/evaluation, etc., if applicable]

3.2.2 Security Assessment

[VA Organization 1]

[Describe any outside assessments, self-assessments or security control reviews (e.g., Risk Assessment or VA Security Control Assessment), who they were conducted by, the date(s), the expiration date(s) and frequency of which the assessments are performed. Describe any documentation, dates, and signatories.]

[Organization 2]

[Describe any outside assessments, self-assessments or security control reviews (e.g., Risk Assessment, Security Control Assessment, 3rd party reviews), who they were conducted by, the date(s), the expiration date(s) and frequency of which the assessments are performed. Describe any documentation, dates, and signatories.]

3.2.3 Services Offered

[Describe the nature of the information services offered via the interconnection by each organization.]

3.2.4 Information System Security Officer at Interconnection Site There must be an established ISSO (or business partner equivalent) at all interconnection sites described herein, to provide oversight through the duration of the system development lifecycle (SDLC) phases (development, deployment, operations, and disposal) of the interconnection and to ensure that the systems maintain appropriate security controls. ISSO (or business partner equivalent) contact information is listed in Appendix A.

3.2.5 Sensitivity Categorization

Refer to Section 2.1 of this document.

3.2.6 User Community

The minimum requirements for employees to work in support of this interconnection, to include background investigations and security clearances, will be determined by the contract(s) or requirements governing the support services provided by the vendor. [Organization 2] will be responsible for ensuring that their employees meet the standards set forth in all applicable contracts or requirements and for continuously monitoring and tracking the status of all [Organization 2] employees relevant to this interconnection.

8 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

[Define the [VA Organization 1] and/or [Organization 2] community of users who will transmit, access, exchange, and/or receive data across the interconnection as described in section 2.1]

3.2.7 Information Exchange Security

The security of VA sensitive information (see Appendix B for definition of sensitive information) being transmitted, processed or stored over any system and interconnection in support of this agreement must be FIPS 140-2 (or successor) compliant. The FIPS 140-2 compliance is not required if no VA sensitive data is transmitted. [Will VA sensitive information as defined in Appendix B be transmitted?

Yes or No] If the answer is Yes, the paragraph below and the certificate number needs to be filled in.

The FIPS 140-2 certificate number of [Organization 2]'s gateway cryptographic module for establishing the Virtual Private Network (VPN) tunnel is FIPS# [enter current valid certificate number#]. FIPS compliance will be validated by [VA Organization 1].

The connections at each end must be located within controlled access facilities using physical access control devices and/or guards. Individual users will not have access to the data except through the system security software inherent to the operating system. Access is controlled by authentication methods to validate the approved users.

3.2.8 Trusted Behavior Expectations

[VA Organization 1]'s system and users are expected to protect [Organization 2 System]’s, and [Organization 2]'s system and users are expected to protect [VA Organization 1]'s, in accordance with the Privacy Act and Trade Secrets Act (18 U.S.C. 1905), the Unauthorized Access Act (18 U.S.C. 2701 and 2710), the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and other applicable laws and policies referenced in Section 1.1 of this document.

3.2.9 Formal Security Policy

Policies that govern the protection of the information/data for [VA Organization 1] include but are not limited to VA Directive and Handbook 6500 (or successors). Policies that govern the protection of the information/data for [Organization 2]'s include but are not limited to [Policy Name and Identifier]. All documents are available upon request.

3.2.10 Audit Trail Responsibilities

Both parties are responsible for auditing application processes and user activities involving the interconnection with enough granularity to allow successful investigation of any breaches and security incidents. Activities that will be recorded include event type, date and time of event, user identification, workstation identification, success or failure of access attempts, and security actions taken by system administrators or security officers. Audit logs will be retained for a minimum of one (1) year or as documented in the National Archives and Records Administration (NARA) retention periods, HIPAA legislation or whichever is greater. Audit logs which describe a security breach must be maintained for six (6) years. Those responsible for maintaining audit logs must ensure that audit logs are successfully stored for the required duration.

3.2.11 Security Parameters

The following detailed security measures and controls implemented by each organization to protect the confidentiality, integrity, and availability of the connected systems and the information/data that will pass between them are outlined below;

9 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

[VA Organization 1] implements the following security measures and controls:

• Identification and Authentication - User Access control is managed by strong authentication method and must be assigned on the "Least Privilege" Principal. VA utilizes “two-factor authentication” for general users. A separate token and non-mail enabled account is required for users who require elevated privileges on IT systems.

• Logical Access Controls - VA accounts are separated into domains and the system administrators only manage those accounts within their domain. Accounts are audited every ninety (90) days. VA policy requires account termination within twenty-four (24) hours of an employee/contractor departure. Accounts are terminated immediately in the event of a hostile termination.

• Physical and Environmental Security - Physical and environmental controls are maintained at VA facilities. Badges are required for employees and contract staff. Access to networking closets and computer rooms require authorization from the facility Chief Information Officer (CIO) and a log is maintained. VA computer rooms are environmentally controlled for operation of the equipment is contains. This includes power; network; heating, ventilation, and air conditioning (HVAC); and fire suppression.

• Firewall, IDS, and Encryption - Intrusion detection systems (IDS) are in place at gateways and throughout the VA network. The VA’s Network Security Operations Center monitors the VA network 24x7. Suspicious activity is reviewed and determined recommendations are formulated and assigned to the system administrators. FIPS 140-2 validated encryption is required for transmission of sensitive information.

[Organization 2] implements the following security measures and controls:

• Identification and Authentication - [Detailed description of policy]

• Logical Access Controls - [Detailed description of policy]

• Physical and Environmental Security - [Detailed description of policy]

• Firewall, IDS, and Encryption - [Detailed description of policy as well as confirmation of properly configured firewalls.]

3.2.12 Training and Awareness

The training and rules of behavior requirements for employees who work in support of this interconnection will be determined by the contract(s) or requirements governing the support services provided. [Organization 2] will be responsible for ensuring that their employees meet the standards set forth in all applicable contracts and for continuously monitoring and tracking the status of all [Organization 2] employees relevant to this interconnection.

3.3 TOPOLOGICAL DRAWING

[Insert a topological drawing]

10 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

4 Duration

This agreement will expire when one or both parties determine the interconnection is no longer necessary or if there is no longer a business or contractual justification for it. If the interconnection is no longer necessary or justified, the interconnection will be decommissioned.

Annually, the VA ISSO, along with the System Owner, will review the agreement to ascertain 1) if the interconnection is still necessary and 2) if there are any significant changes to the interconnection (see section 2.2.3 Material Changes to System Configuration). The outcome of the review will be documented in the MOU/ISA Review Form. If there are significant changes to the interconnection at any time or if major changes were noted during the annual review, the agreement must be updated and re-signed.

If one or both of the parties wish to terminate this agreement prematurely, they may do so upon thirty

(30) days advanced notice or in the event of a security incident that necessitates an immediate response. Approval to decommission an interconnection must come from the VA Authorizing Official/System Owner.

11 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

5 SIGNATORY AUTHORITY

We, the undersigned, mutually agree to the terms of this MOU/ISA.

VA Authorizing Official/System Owner

X__________________________ Date __________

[Organization 2] Authorizing Official/System Owner

X__________________________ Date __________

12 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Appendix A: Points of Contact

List of Responsible Parties for Each System:

Name Organization Title Office Phone Email [Name of [VA Organization 1] System Owner]

[Name of [VA

Information System Security Officer]

ISSO

[Name of [VA

Privacy Officer]

PO

[Name of [Organization 2] System Owner]

[Name of [Organization 2] Information System Security Officer]

ISSO

[Name of [Organization 2] Privacy Officer]

PO

List of Responsible Parties to Contact during a Security Incident:

Name Organization Title Office Phone Email Cybersecurity Operations Center*

VA CSOC Support Desk 855-673-4357

* Note: VA-CSOC should only be contacted by VA personnel.

13 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Appendix B: Definitions of Sensitive Information Types

The following discussion defines the various types of personal information collected, maintained, and used within VA and provides an overview of how they inter-relate. Every type is subject to VA security statutes (38 U.S.C. §§ 5721-28), as long as it identifies or could reasonably be used to identify an individual. Depending on the type of information, it may also be protected by the Privacy Act (5 U.S.C. § 552a), the VA confidentiality statutes (38 U.S.C. §§ 5701, 5705, and 7332), and the HIPAA Privacy and Security Rules (45 C.F.R. Parts 160, 164).

VA Sensitive Information/Data - All Department information and/or data on any storage media or in any form or format, which requires protection due to the risk of harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the information. The term includes not only information that identifies an individual but also other information whose improper use or disclosure could adversely affect the ability of an agency to accomplish its mission, proprietary information, and records about individuals requiring protection under applicable confidentiality provisions. SOURCE: 38 U.S.C. § 5727.

Personally Identifiable Information (PII) - Any information which can be used to distinguish or trace an individual's identity, such as their name, social security number, biometric records, etc. alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother’s maiden name, etc. Information does not have to be retrieved by any specific individual or unique identifier (i.e., covered by the Privacy Act) to be personally identifiable information. SOURCE: Office of Management and Budget (OMB) Memorandum 07-16, Safeguarding Against and Responding to Breaches of Personally Identifiable Information (May 22, 2007)

NOTE: The term “Personally Identifiable Information” is synonymous and interchangeable with “Sensitive Personal Information.”

Sensitive Personal Information (SPI) - The term, with respect to an individual, means any information about the individual maintained by VA, including the following: (i) education, financial transactions, medical history, and criminal or employment history; and (ii) information that can be used to distinguish or trace the individual’s identity, including name, social security number, date and place of birth, mother’s maiden name, or biometric records. SPI is a subset of VA Sensitive Information/Data. SOURCE: 38 U.S.C. § 5727.

NOTE: The term “Sensitive Personal Information” is synonymous and interchangeable with “Personally Identifiable Information.”

Health Information - Health Information is any information, whether oral or recorded in any form or medium, created or received by a health care provider, health plan, public health authority, employer, life insurers, school or university, or health care clearinghouse or health plan that relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or payment for the provision of health care to an individual. This encompasses information pertaining to examination, medical history, diagnosis, and findings or treatment, including laboratory examinations, X-rays, microscopic slides, photographs, and prescriptions. SOURCE: 45 C.F.R. § 160.103

Individually Identifiable Information (III) - Individually Identifiable Information is any information pertaining to an individual that is retrieved by the individual’s name or other unique identifier, as well as Individually Identifiable Health Information regardless of how it is retrieved.

14 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Individually Identifiable Information is a subset of Personally Identifiable Information and is protected by the Privacy Act.

Individually Identifiable Health Information (IIHI) - Individually Identifiable Health Information is a subset of Health Information, including demographic information collected from an individual, that: (1) is created or received by a health care provider, health plan, or health care clearinghouse (e.g., a HIPAA-covered entity, such as VHA); (2) relates to the past, present, or future physical or mental condition of an individual, or provision of or payment for health care to an individual; and (3) identifies the individual or where a reasonable basis exists to believe the information can be used to identify the individual.

NOTE: VHA uses the term individually-identifiable health information to define information covered by the Privacy Act and the Title 38 confidentiality statutes in addition to HIPAA.

Protected Health Information (PHI) - The HIPAA Privacy Rule defines PHI as Individually Identifiable Health Information transmitted or maintained in any form or medium by a covered entity, such as VHA.

NOTE: VHA uses the term protected health information to define information that is covered by HIPAA but, unlike individually-identifiable health information, may or may not be covered by the Privacy Act or Title 38 confidentiality statutes. In addition, PHI excludes employment records held by VHA in its role as an employer.

Non-identifiable Information - Non-identifiable Information is information from which all Unique Identifiers have been removed so that the information is no longer protected under the Privacy Act, 38 U.S.C. §5701, or 38 U.S.C. § 7332. However, Non-identifiable Information has not necessarily been de-identified and may still be covered by the HIPAA Privacy Rule unless all 18 Patient Identifiers listed in the Rule’s de-identification standards are removed.

Limited Data Set - A Limited Data Set is protected health information from which certain specified direct identifiers of the individuals and their relatives, household members, and employers have been removed. These identifiers include name, address (other than town or city, state, or zip code), phone number, fax number, e-mail address, Social Security Number (SSN), medical record number, health plan number, account number, certificate and/or license numbers, vehicle identification, device identifiers, web universal resource locators (URL), internet protocol (IP) address numbers, biometric identifiers, and full-face photographic images. The two patient identifiers that can be used are dates and postal address information that is limited to town or city, State or zip code. Thus, a Limited Data Set is not De-identified Information, and it is covered by the HIPAA Privacy Rule. A Limited Data Set may be used and disclosed for research, health care operations, and public health purposes pursuant to a Data Use Agreement. SOURCE: 45 C.F.R. § 164.514(e) (2)

De-identified Information - De-identified Information is health information that is presumed not to identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual because the 18 Patient Identifiers described in the HIPAA Privacy Rule have been removed. De-identified information is no longer covered by the Privacy Act, 38 U.S.C. § 5701, 38 U.S.C. § 7332, or the HIPAA Privacy Rule. SOURCE: 45 C.F.R. § 164.514(b) (2) (i)

Patient Identifiers - Patient identifiers are the 18 data elements attributed to an individual under the HIPAA Privacy Rule that must be removed from health information for it to be de-identified and no longer covered by the HIPAA Privacy Rule. Please see VHA Handbook 1605.1, Privacy and Release of Information, Appendix B, De-identification of Data, for more detail.

15 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Unique Identifier - A Unique Identifier is an individual’s name, address, social security number, or some other identifying number, symbol, or code assigned only to that individual (e.g., medical record number and claim number). If these identifiers are removed, then the information is no longer Individually Identifiable Information and is no longer covered by the Privacy Act, 38 U.S.C. § 5701, or 38 U.S.C. § 7332. However, if the information was originally Individually Identifiable Health Information, then it would still be covered by the HIPAA Privacy Rule unless all 18 Patient Identifiers listed in the de-identification standard have been removed.

NOTE: The VA Office of General Counsel has indicated that the first initial of last name and last four of the social security number (e.g., A2222) is not a unique identifier; therefore, inclusion of this number by itself does not make the information identifiable or sensitive.

Relations among Different Types of Information

VA Sensitive Information/Data is the broadest term and generally encompasses all of the other terms with the exception of de-identified data.

Sensitive Personal Information and Personally Identifiable Information are synonymous and encompass Individually Identifiable Information, Individually Identifiable Health Information and Protected Health Information.

Individually Identifiable Information encompasses Individually-identifiable Health Information. It may or may not be Protected Health Information.

Health Information encompasses Individually Identifiable Health Information. It may or may not be Protected Health Information.

Individually Identified Health Information is maintained by VHA and is protected by the HIPAA Privacy Rule, as well as the Privacy Act and the Title 38 confidentiality statutes.

Non-identifiable Information is no longer protected by the Privacy Act, 38 U.S.C. § 5701, or 38 U.S.C. § 7332, but is covered by the HIPAA Privacy Rule unless it has been de-identified in accordance with the Rule.

De-identified Information may include VA Sensitive Information/Data, but it will not include any of the other types of data defined herein. De-identified Information is not Protected Health Information.

Patient Identifiers encompass Unique Identifiers. Patient Identifiers are the eighteen (18) data elements attributed to an individual under the HIPAA Privacy Rule. Unique Identifiers are those Patient Identifiers that identify or could be used to identify only one individual, such as name, address, or some other number, symbol, or code assigned only to that individual. Unique Identifiers can be used to retrieve information about an individual from a Privacy Act system of records.

Protected Health Information may consist of any of the other types of data defined herein except for De-identified Information. Protected Health Information includes Limited Data Sets and Non-identifiable Information.

16 O F F I C E O F I N F O R M A T I O N S E C U R I T Y

Appendix C: Interconnection Ports and Protocols

[Organization 2] to complete the table below before the MOU/ISA is signed.

Direction Protocol Port Purpose

EXAMPLE

ENTRY

In TCP 5900

VNC remote access protocol for service technicians

INTRODUCTION
1 SUPERSEDES:
1.1 Authority
2 MEMORANDUM OF UNDERSTANDING
2.1 Background
2.2 Communications
2.2.1 Security Incidents
2.2.2 Disasters and Other Contingencies
2.2.3 Material Changes to System Configuration
2.2.4 New Interconnections
2.2.5 Personnel Changes
2.2.6 Security
2.2.7 Cost Considerations
3 INTERCONNECTION SECURITY REQUIREMENTS
3.1 Background
3.1.1 System Description
3.1.2 System Hardware and Software Requirements
3.2 System Security Considerations
3.2.1 General Information/Data Description
3.2.2 Security Assessment
3.2.3 Services Offered
3.2.4 Information System Security Officer at Interconnection Site
3.2.5 Sensitivity Categorization
3.2.6 User Community
3.2.7 Information Exchange Security
3.2.8 Trusted Behavior Expectations
3.2.9 Formal Security Policy
3.2.10 Audit Trail Responsibilities
3.2.11 Security Parameters
3.2.12 Training and Awareness

3.3 TOPOLOGICAL DRAWING

4 Duration
5 SIGNATORY AUTHORITY
Appendix A: Points of Contact
Appendix B: Definitions of Sensitive Information Types
Appendix C: Interconnection Ports and Protocols

File details come from the government source that posted it. Updated .