VA uses three Department of Veterans Affairs Acquisition Regulation (VAAR) contract clauses to ensure security when a contractor has access to VA information or information systems, as follows:
⢠Clause 852.239-70, Security Requirements for Information Technology Resources, is required in all solicitations, contracts and orders exceeding the micro-purchase threshold that include information technology services. This clause requires the contractor to be responsible for information technology security for all systems connected to a VA network or operated by the contractor for VA, regardless of location.
⢠Clause 852.239-72, Information System Design and Development, is required in all solicitations, contracts, orders and agreements where services to perform information system design and development are required.
⢠Clause 852.239-73, Information System Hosting, Operation, Maintenance, or Use, is required in all solicitations, contracts, orders and agreements where services to perform information system hosting, operation, or maintenance are required.
Clauses 852.239-72 and 852.239-73 are intended to protect VA sensitive information and information technology by requiring contractor and subcontractor personnel to be subject to the same Federal laws, regulations, standards, and VA directives and handbooks as VA and VA personnel regarding information and information system security.
This revision changes the title from âDepartment of Veterans Affairs Acquisition Regulation Clause 852.239-70, VA Information and Information System Security and Privacyâ to âDepartment of Veterans Affairs Acquisition Regulation (VAAR)âInformation Security and Privacy Contract Clausesâ. The previous title implied that this OMB Control Number covered a single clause instead of multiple clauses. The title change is the only revision to the currently approved collection.
PL:
Pub.L. 113 - 283 2521
Name of Law: Federal Information Security Modernization Act of 2014
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.