What is VA-101-13-I-0132?
VA-101-13-I-0132 is a policy directive issued by the Department of Veterans Affairs (VA) that establishes standards for the handling, storage, and disposition of classified and sensitive information within VA facilities. The directive was released in 2013 and has been updated several times to align with evolving security requirements and emerging threats.
Purpose and Scope
The primary purpose of VA-101-13-I-0132 is to protect the confidentiality, integrity, and availability of information that could affect veterans, VA employees, and national security. The directive applies to:
- All VA civilian and military personnel.
- Contractors, consultants, and other thirdparty entities with access to VA data.
- All VA installations, regional offices, and field sites.
- Electronic and physical information systems, including paper records.
Key Requirements
VA-101-13-I-0132 outlines several mandatory controls:
- Classification Markings: All documents must be clearly marked with the appropriate classification level (e.g., Confidential, Secret, Top Secret).
- Access Controls: Access to classified material must be limited to individuals with a current security clearance and a needtoknow.
- Physical Security: Storage areas for classified information must meet minimum construction standards, including approved locks, alarms, and controlled entry.
- Electronic Security: Systems handling sensitive data must employ encryption, intrusion detection, and regular vulnerability assessments.
- Transmission: Secure methods (e.g., encrypted email, secure file transfer protocols) must be used when transmitting classified information.
- Disposition: Destruction of classified material must follow approved sanitization methods, such as shredding, degaussing, or incineration.
- Incident Reporting: Any suspected compromise must be reported immediately to the VA Office of Information Security.
Implementation Responsibilities
Implementation is a shared responsibility across several roles:
- Chief Information Officer (CIO): Oversees policy integration into IT infrastructure.
- Security Manager: Conducts risk assessments, audits compliance, and coordinates training.
- Facility Managers: Ensure physical safeguards meet directive standards.
- Employees & Contractors: Follow handling procedures, attend mandatory training, and report incidents.
Training and Awareness
All personnel with access to classified information must complete an annual VA Classified Information Handling course. Training covers:
- Classification levels and markings.
- Secure storage and handling.
- Proper use of secure communication tools.
- Procedures for reporting a security breach.
Compliance and Auditing
The VA conducts periodic audits to verify compliance with VA-101-13-I-0132. Findings are documented in an Audit Findings Report (AFR) and may result in corrective action plans, additional training, or disciplinary measures for noncompliance.
Recent Updates (2024)
In response to heightened cyber threats, the 2024 amendment introduced:
- Mandatory multifactor authentication (MFA) for all systems accessing classified data.
- Expanded requirements for cloudbased environments, including specific encryption standards.
- New incident response timelines: initial reporting within 2 hours of detection.
How to Access the Full Directive
The complete text of VA-101-13-I-0132 is available on the official VA policy portal. Access requires a valid VA network login and applicable clearance level.
Visit the VA Policy Portal for the latest version and related guidance documents.
FAQs
Q: Who determines the classification level of a document?
A: The originating office, in consultation with the VA Information Security Office, assigns the appropriate classification based on the contents sensitivity.
Q: What should I do if I receive a misclassified document?
A: Immediately notify your supervisor and the Information Security Office. Do not disseminate the document until the issue is resolved.
Q: Are there any exemptions?
A: Only information explicitly declassified by the appropriate authority is exempt. All other classified material must comply with the directive.
