<Past |
Future> |
2014.1023.0839 |
Approved w/Constraints [2, 3] |
Approved w/Constraints [2, 3] |
Divest [2, 3] |
Divest [2, 3] |
Divest [2, 3, 4, 5] |
Divest [2, 3, 4, 5] |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
2015.x |
Approved w/Constraints [2, 3] |
Approved w/Constraints [2, 3] |
Approved w/Constraints [2, 3] |
Approved w/Constraints [2, 3] |
Approved w/Constraints [2, 3, 4, 5] |
Approved w/Constraints [2, 3, 4, 5] |
Approved w/Constraints [2, 3, 4, 5] |
Approved w/Constraints [2, 5, 6, 7] |
Divest [5, 7, 8, 9] |
Divest [5, 7, 8, 9] |
Divest [5, 7, 8, 9] |
Divest [5, 7, 8, 9] |
2017.x |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Approved w/Constraints [2, 3, 4, 5] |
Approved w/Constraints [2, 3, 4, 5] |
Approved w/Constraints [2, 3, 4, 5] |
Approved w/Constraints [2, 5, 6, 7] |
Approved w/Constraints [5, 7, 8, 9] |
Approved w/Constraints [5, 7, 8, 9] |
Approved w/Constraints [5, 7, 8, 9] |
Divest [5, 7, 8, 9] |
2018.x |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Approved w/Constraints [5, 7, 8, 9] |
Approved w/Constraints [5, 7, 8, 9] |
Approved w/Constraints [5, 7, 8, 9] |
2019.x |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
2020.x |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
| | [1] |
This solution requires that a Cisco AnyConnect VPN session be established to the vendor site. Please refer to that TRM entry for more information. In addition, some data from VA may be stored on the vendor hosted servers. Such storage may require documented Federal Risk and Authorization Management Program (FedRAMP) compliance prior to ESCCB review if sensitive information is involved. | | [2] | In cases where the technology is used for external connections, a full Enterprise Security Change Control Board (ESCCB) review is required in accordance VA Directive 6004 , VA Directive 6517, and VA Directive 6513. The local ISO can advise on the ESCCB review process. | | [3] | Veterans Affairs (VA) users must ensure VA sensitive data is properly protected in compliance with all VA regulations. All instances of deployment using this technology should be reviewed by the local ISO (Information Security Officer) to ensure compliance with VA Handbook 6500. | | [4] | Due to potential information security risks, cloud based technologies may not be used without an Enterprise Security Change Control Board (ESCCB) approval. This body is in part responsible for ensuring organizational information, Personally Identifiable Information (PII), Protected Health Information (PHI), and VA sensitive data are not compromised. (Ref: VA Directive 6004, VA Directive 6517, VA Directive 6513 and VA Directive 6102). | | [5] | Technology must remain patched and operated in accordance with Federal and Department security policies and guidelines in order to mitigate known and future security vulnerabilities. | | [6] | Due to potential information security risks, cloud based technologies may not be used without the approval of the VA Enterprise Cloud Services (ECS) Group. This body is in part responsible for ensuring organizational information, Personally Identifiable Information (PII), Protected Health Information (PHI), and VA sensitive data are not compromised. (Ref: VA Directive 6004, VA Directive 6517, VA Directive 6513 and VA Directive 6102). | | [7] | Veterans Affairs (VA) users must ensure VA sensitive data is properly protected in compliance with all VA regulations. All instances of deployment using this technology should be reviewed by the local ISO (Information Security Officer) to ensure compliance with VA Handbook 6500. | | [8] | Due to potential information security risks, cloud based technologies may not be used without the approval of the Enterprise Cloud Solution Office (ECSO). This body is in part responsible for ensuring organizational information, Personally Identifiable Information (PII), Protected Health Information (PHI), and VA sensitive data are not compromised. (Ref: VA Directive 6004, VA Directive 6517, VA Directive 6513 and VA Directive 6102). | | [9] | In cases where the technology is used for external connections, a full Enterprise Security Change Control Board (ESCCB) review is required in accordance VA Directive 6004 , VA Directive 6517, and VA Directive 6513. The local ISO can advise on the ESCCB review process. |
|
Note: |
At the time of writing, version 2020.0721.0919 is the most current version. |