US · guidance
CMS Pub. 100-06, ch. 7, § 30.9.1
A CUECs – Information Systems
A – Control
Objective
Number
A – CUEC Description
A.1 CMS maintains, updates, and makes available current CMS
Acceptable Risk Safeguards (ARS), Business Partners Systems
Security Manual (BPSSM), and other applicable policy to provide
Medicare Administrative Contractors (MACs) requirements and
guidance for the establishment of an entity-wide security program.
A.3 CMS, as the Authorizing Official (AO), reviews and approves the
Information System Security Categorization through the Authority
to Operate (ATO) process.
A.7 For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors update and / or remove user logical access accounts
and system permissions as requested and approved by the MAC for
transferred personnel in a timely fashion. In addition, CMS or its
contractors remove logical access accounts and system permissions
as requested and approved by the MAC for separated personnel in a
timely fashion.
A.9 CMS, as the Authorizing Official (AO), authorizes the information
system for processing prior to commencing operations and
periodically thereafter. In addition, the Information Security and
Privacy Group (ISPG) of CMS inputs, in a timely manner,
POA&Ms into the CMS FISMA Controls Tracking System
(CFACTS).
A – Control
Objective
Number
A – CUEC Description
A.12
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors:
• Create MAC and non-MAC user accounts (including remote
access accounts, temporary, emergency, and privileged accounts if
applicable) as requested and approved by the MAC.
• If emergency and / or temporary accounts are utilized they are
automatically removed as required by CMS standards and/or based
on request by the MAC.
• CMS or its contractors update information system accounts in a
timely fashion based on periodic reviews conducted by the MACs.
A.13 For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors remove logical access accounts and system
permissions as requested and approved by the MAC for separated
personnel in a timely fashion. Further, CMS or its contractors
automatically disable inactive accounts as required by CMS.
A.15 For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors configure password based authentication for major
applications / information systems in accordance with current CMS
ARS, BPSSM, and other applicable policies.
A.17 For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors produce and distribute security audit logs to the
MACs for investigation as needed.
A.18 CMS collaborates with the MAC to analyze, respond, and report
security incidents.
A.21 CMS maintains, updates, and makes available the current CMS
Target Life Cycle (TLC) and other applicable policy to provide the
MACs requirements and guidance for the establishment of change
management and SDLC processes.
A.22 For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors are responsible for software development and
maintenance processes including authorization of changes,
documentation, testing, and approvals in accordance with the
current CMS ARS, BPSSM, and other applicable policy.
A – Control
Objective
Number
A – CUEC Description
A.23 For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors are responsible for properly restricting and
controlling the movement of code between libraries.
A.27 For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors have implemented system backup and recovery
procedures including contingency plans, disaster recovery plans,
testing of plans, and corrective action based on lessons learned in
accordance with the current CMS ARS, BPSSM, and other
applicable policy.
End Section 30.9.1 – A CUECs – Information Systems: Back to Table of Contents
History
(Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
a12ad7a4ea330edeb4de9d145a7094f0bc3f0287a6b6ffdff151ac10e2646423
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.