13.07.2015 Views

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

RFP MED-12-001 | Technical Proposal<strong>Iowa</strong> <strong>Medicaid</strong> <strong>Enterprise</strong> System Service Procurement | MMIS and Core MMIS Operations• Sarbanes Oxley• National Institute of Standards and Technology (NIST) publicationsTeam Noridian also adheres to standards and procedures to measure security compliance, including butnot limited to NIST 800-53, NIST 800-26, lockdown guides, and other NIST special publications.Team Noridian has strict standards for all locations that we are responsible for, such as the developmentdata centers, the temporary facility in use in Des Moines during the start-up and implementation phase,and any additional physical locations we are asked to provide, should additional room be necessaryoutside of the IME facility. For our temporary facility, we will secure the work area using a swipe cardsystem. This ensures only those with proper authorization can access the building. Team Noridian uses asecurity system at its site and a second set of secured doors for all computer and networking equipmentrooms. This security system generates logs for all entries. Management performs periodic reviews ofaccess to each door across the organization.Employees are issued a photo security badge upon hire, and they are required to wear their badge at alltimes while in the workplace. Employees are required to access all Team Noridian facilities by scanningtheir security badge at proximity card readers located at secured entrances. Access to the computer roomsare controlled by use of a second proximity card reader. Any request by an employee for change of accesshours or for access to restricted areas (e.g. data center) must be approved by the employee’s management,facilities, and the restricted area owner.The security badges are color-coded to indicate the access level of an individual:• White – Team Noridian Employee• Blue – Team Noridian Employee with computer room access• Red – Vendor, Department staff• Green – Vendor with computer room accessEmployees are prohibited from allowing any unauthorized individual access to a secured area, includingfellow employees, government personnel, temporary employees, vendors, members, or providers.Employees are specifically prohibited from following other employees into a secured area without alsoscanning their security badge (i.e., “piggybacking”). Visitors and others without authorized access,including employees who have forgotten or misplaced their security badge, must access the facilitythrough designated visitor entrances that are monitored. Any visitor to the office building who does nothave a security badge for access to the facility must sign a visitor log, obtain a temporary visitor securitybadge, and be escorted at all times by an employee with authorized access to that area.Badge records are kept on Secure Perfect, the security computer system. Employees are required to reportlost or stolen badges to security or building services. All employees must return their badges to TeamNoridian upon termination of employment or upon request.Beyond physical security, Team Noridian has additional security measures to protect systems and data.These measures will be used in the temporary facility during the start-up and implementation phase, andwill follow Team Noridian as best practices into the state-space provided at the IME. Team Noridian hasformal policies and procedures in place regarding segregation of duties to ensure staff only has access todata necessary to perform their job functions. Documented job descriptions accurately reflect assigned jobfunctions and segregation of duties principles. Management is responsible for annually reviewing andupdating job descriptions. During these reviews, management evaluates the essential functions of eachposition to ensure proper segregation of duties. Procedural manuals that evidence proper segregation ofduties are linked to job descriptions.Systems access is granted to staff based on their job description as an additional check and balance to ensurestaff are only able to access the minimum necessary information to perform their job functions. Each7 | 43

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!