============================================================================= Run Date: SEP 14, 2021 Designation: PREM*3*3 Package : PREM - MEDICATION ORDER CHECK (MOCH Priority: Mandatory Version : 3 SEQ #3 Status: Released Compliance Date: OCT 15, 2021 ============================================================================= Subject: MOCHA - Fortify and Technical Reference Model (TRM) Compliance Category: - Informational - Other Description: ============ MOCHA application server is a service of the Medication Order Check Healthcare application program that provides the capability services to receive and validate the format of the request. Provided the format is correct, the MOCHA services will triage the request by interacting with FDB's Med Knowledge Framework to perform the requested check and return the results. The purpose of this patch is to comply with the VA Security and Code Quality Standards and the Technical Reference Model (TRM). JIRA Task Id ------------ MOCHA-3237 Problem: -------- MOCHA application contains Java Enterprise components which are subject to compliance with VA security and code quality standards to maintain authority to operate (ATO). Routine Fortify scanning and remediation is performed to maintain compliance. Resolution: ----------- MOCHA patch PREM*3*3 was initiated to remediate code quality and security vulnerabilities issues which helps to bring the MOCHA application into compliance with VA Security Standards in the current Java code. MOCHA application code has been scanned with the latest Fortify software to identify security vulnerabilities and code quality issues. Code fixes have been applied to mitigate these findings and the application has been validated by the VA Software Assurance Team to ensure compliance with the standards. No application functionality has changed. Application frameworks have been upgraded to be compliant with Technical Reference Model (TRM). Test Sites: ----------- VA West Palm Beach VAMC (West Palm Beach, FL) VA Louisville VAMC (Louisville, KY) Software and Documentation Retrieval Instructions: ------------------------------------------------- The PREM*3*3 Informational Patch is available in the FORUM. Documentation can be found in the VA Documentation Library (VDL) at: https://www.domain.ext/vdl/ PREM*3*3 Documentation can also be obtained at: https://download.vista.domain.ext/index.html/SOFTWARE. Other Software Files: --------------------- This release also includes other software files.They can be obtained at location: /srv/vista/patches/SOFTWARE File Title File Name --------------------------------------------------------- Deployment, Installation, PREM_3_P3_DIBR.DOCX Back-Out, and Rollback Guide Release Notes PREM_3_P3_MOCHA_SERVER_RN.PDF Patch Installation: ==================== Installation Instructions: -------------------------- Patch will be installed by AITC. For further information on the installation of the patch, refer to the section 3 (Installation) in the PREM_3_P3_DIBR.DOCX document. Back-Out/Roll Back Plan: ------------------------ Patch will be installed by AITC. For further information on the Roll back plan of the patch, refer to the section 4 (Back-Out Procedure) in the PREM_3_P3_DIBR.DOCX document. Routine Information: ==================== No routines included. ============================================================================= User Information: Entered By : Date Entered : JAN 04, 2021 Completed By: Date Completed: SEP 14, 2021 Released By : Date Released : SEP 14, 2021 ============================================================================= Packman Mail Message: ===================== No routines included