Bindinglaw

US · guidance

CMS Pub. 100-06, ch. 7, § 30.9.1

A CUECs – Information Systems

activein force · 2026-08-25 – presentas-observed

A – Control

Objective

Number

A – CUEC Description

A.1 CMS maintains, updates, and makes available current CMS

Acceptable Risk Safeguards (ARS), Business Partners Systems

Security Manual (BPSSM), and other applicable policy to provide

Medicare Administrative Contractors (MACs) requirements and

guidance for the establishment of an entity-wide security program.

A.3 CMS, as the Authorizing Official (AO), reviews and approves the

Information System Security Categorization through the Authority

to Operate (ATO) process.

A.7 For shared systems, outside of the MAC’s ATO boundary, CMS or

its contractors update and / or remove user logical access accounts

and system permissions as requested and approved by the MAC for

transferred personnel in a timely fashion. In addition, CMS or its

contractors remove logical access accounts and system permissions

as requested and approved by the MAC for separated personnel in a

timely fashion.

A.9 CMS, as the Authorizing Official (AO), authorizes the information

system for processing prior to commencing operations and

periodically thereafter. In addition, the Information Security and

Privacy Group (ISPG) of CMS inputs, in a timely manner,

POA&Ms into the CMS FISMA Controls Tracking System

(CFACTS).

A – Control

Objective

Number

A – CUEC Description

A.12

For shared systems, outside of the MAC’s ATO boundary, CMS or

its contractors:

• Create MAC and non-MAC user accounts (including remote

access accounts, temporary, emergency, and privileged accounts if

applicable) as requested and approved by the MAC.

• If emergency and / or temporary accounts are utilized they are

automatically removed as required by CMS standards and/or based

on request by the MAC.

• CMS or its contractors update information system accounts in a

timely fashion based on periodic reviews conducted by the MACs.

A.13 For shared systems, outside of the MAC’s ATO boundary, CMS or

its contractors remove logical access accounts and system

permissions as requested and approved by the MAC for separated

personnel in a timely fashion. Further, CMS or its contractors

automatically disable inactive accounts as required by CMS.

A.15 For shared systems, outside of the MAC’s ATO boundary, CMS or

its contractors configure password based authentication for major

applications / information systems in accordance with current CMS

ARS, BPSSM, and other applicable policies.

A.17 For shared systems, outside of the MAC’s ATO boundary, CMS or

its contractors produce and distribute security audit logs to the

MACs for investigation as needed.

A.18 CMS collaborates with the MAC to analyze, respond, and report

security incidents.

A.21 CMS maintains, updates, and makes available the current CMS

Target Life Cycle (TLC) and other applicable policy to provide the

MACs requirements and guidance for the establishment of change

management and SDLC processes.

A.22 For shared systems, outside of the MAC’s ATO boundary, CMS or

its contractors are responsible for software development and

maintenance processes including authorization of changes,

documentation, testing, and approvals in accordance with the

current CMS ARS, BPSSM, and other applicable policy.

A – Control

Objective

Number

A – CUEC Description

A.23 For shared systems, outside of the MAC’s ATO boundary, CMS or

its contractors are responsible for properly restricting and

controlling the movement of code between libraries.

A.27 For shared systems, outside of the MAC’s ATO boundary, CMS or

its contractors have implemented system backup and recovery

procedures including contingency plans, disaster recovery plans,

testing of plans, and corrective action based on lessons learned in

accordance with the current CMS ARS, BPSSM, and other

applicable policy.

End Section 30.9.1 – A CUECs – Information Systems: Back to Table of Contents

History

(Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
a12ad7a4ea330edeb4de9d145a7094f0bc3f0287a6b6ffdff151ac10e2646423
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.