Bindinglaw

US · guidance

CMS Pub. 100-06, ch. 7, § 50

List of CMS Contractor Control Objectives

activein force · 2026-08-25 – presentas-observed

Control

Number

Control Objectives

Back to Table of Contents

50.1 – A Controls – Information Systems

((Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25)

Control Objective – Information Systems

A.1 - A.11 Security Management: Controls provide reasonable assurance that

security management is effective.

A.1 Controls provide reasonable assurance that management has

established, documented, and approved an entity-wide security

program in accordance with the current CMS Acceptable Risk

Safeguards (ARS), Business Partners Systems Security Manual

(BPSSM), and other applicable policy including that the security

program:

• Is monitored and kept up-to-date in accordance with the

current ARS requirements.

• Includes requirements to establish a security management

structure that has appropriate independence, authority,

expertise, and resources.

• Clearly assigns security responsibilities throughout the

organization.

• Ensures that management implements, maintains, and

updates the organization security policy and procedures in

accordance with CMS guidance.

A.2 Controls provide reasonable assurance that security risks are

periodically assessed and appropriately mitigated in accordance

with the current CMS ARS, BPSSM, and other applicable policy. A

risk assessment and supporting activities of the criticality and

sensitivity of computer operations, including all network

components, IT platforms and critical applications has been

established and updated periodically based on ARS and Federal

requirements. The assessment includes, but may not be limited to,

identification of threats, known system vulnerabilities, system

flaws, or weaknesses that could be exploited by threat sources.

A.3 Controls provide reasonable assurance that information systems and

resources are categorized based on the potential impact that the loss

of confidentiality, integrity, or availability would have on

operations, assets or individuals in accordance with the current

CMS ARS, BPSSM, and other applicable policy.

Control Objective – Information Systems

A.4 Controls provide reasonable assurance that a system security plan(s)

(SSP) has been documented, approved, and reviewed by

management in accordance with the current CMS ARS, BPSSM,

and other applicable policy. The SSP covers all major facilities and

operations supporting the CMS Medicare program and is updated

and maintained within CFACTS in accordance with the ARS and

current version of the CMS Risk Management Handbook (RMH).

A.5 Controls provide reasonable assurance that management develops

and maintains a current inventory of hardware, software, platforms,

information systems, and other tools / devices that support the

Medicare program in accordance with the current CMS ARS,

BPSSM, and other applicable policy.

A.6 Controls provide reasonable assurance that security related

personnel-policies are implemented that include performance of

background investigations (initial and / or periodic) in accordance

with the current CMS ARS, BPSSM, and other applicable policy.

A.7 Controls provide reasonable assurance that security related

personnel-policies are implemented that include transfer and

separation procedures which require:

• Review and appropriate update, if necessary, of logical and

physical access rights for transferred personnel.

• Exit interviews, return of property, such as keys and ID

cards, timely notification to security management of

separations, removal of physical and logical access to

systems and escorting of separated personnel out of the

facility.

Performance of transfer and separation processes are in accordance

with the current CMS ARS, BPSSM, and other applicable policy.

A.8 Controls provide reasonable assurance that personnel including

employees, contractors, and vendors, are aware of security policies

and procedures. Initial security awareness training, ongoing

security awareness training, and role specific training for

individuals with significant security responsibilities is documented,

completed, and monitored by management. The security training

program and content of training are in accordance with the current

CMS ARS, BPSSM, and other applicable policy.

Control Objective – Information Systems

A.9 Controls provide reasonable assurance that management has

implemented appropriate risk management and security assessment

and authorization (SA&A) processes in accordance with the current

CMS ARS, BPSSM, and other applicable policy including the

following:

• SA&A policies and procedures are documented, kept up-to-date, maintained and approved by management.

• Security Assessments are planned and conducted

• A corrective action management process is in place that

includes planning, implementing, evaluating, and fully

documenting remedial action addressing findings noted from

all security audits and reviews of IT systems, components,

and operations. Plan of Action and Milestones (POA&Ms)

and corrective action plans are developed and monitored to

address weaknesses.

• Authorizing Official (AO) authorizes the information system

for processing prior to commencing any operations and

periodically thereafter.

A.10 Controls provide reasonable assurance that management

continuously monitors the effectiveness of the security program

including security operations and completion of vulnerability

assessments in accordance with the current CMS ARS, BPSSM, and

other applicable policy.

A.11 Controls provide reasonable assurance that external third party

activities of sub-service organizations (i.e. sub-contractors) are

secure, documented, and monitored in accordance with the current

CMS ARS, BPSSM, and other applicable policy.

A.12 - A.20 Access Controls and Segregation of Duties: Controls provide

reasonable assurance that access to computer resources (data,

equipment, and facilities) is reasonable and restricted to authorized

individuals and that incompatible duties are effectively segregated.

A.12 Controls provide reasonable assurance that access, including remote

access, to significant computerized applications (such as claims

processing), accounting systems, systems software, and Medicare

data are appropriately authorized, documented, reviewed, and

monitored and includes approval by resource owners, procedures to

control emergency and temporary access and procedures to share

and properly dispose of data. Procedures are performed timely and

in accordance with the current CMS ARS, BPSSM, and other

applicable policy.

A.13 Controls provide reasonable assurance that inactive logical access

accounts and accounts for separated individuals are disabled and / or

removed in a manner that satisfies the current CMS ARS, BPSSM,

and other applicable policies.

Control Objective – Information Systems

A.14 Controls provide reasonable assurance that multifactor

authentication is implemented in accordance with the current CMS

ARS, BPSSM, and other applicable policy.

A.15 Controls provide reasonable assurance that password based

authentication is configured in accordance with the current CMS

ARS, BPSSM, and other applicable policy.

A.16 Controls provide reasonable assurance that access to sensitive

system resources and privileged accounts / functions are restricted

to individuals with a need-to-know and activities are appropriately

logged and monitored. Additionally, Management segregates

incompatible duties between various system and Medicare

operations functionality which is supported by appropriate

documentation, approvals, and monitoring.

A.17 Controls provide reasonable assurance that management identifies

system functions, events, and access permissions that require audit

logging and implements an effective audit log monitoring capability

in accordance with the current CMS ARS, BPSSM, and other

applicable policy.

A.18 Controls provide reasonable assurance that management has

documented, implemented, and approved an effective security

operations and incident response program which includes processes

to:

a) identify and log suspicious activity, sensitive and

privileged functions, and potential security events /

incidents,

b) monitor systems and networks audit logs, unusual

activity, and / or intrusion attempts,

c) correlate log data,

d) analyze potential incidents, and

e) report on security events, incidents, and intrusions in

accordance with the current CMS ARS, BPSSM, and

other applicable policy.

A.19 Controls provide reasonable assurance that physical access to

sensitive IT areas (such as Medicare facilities, data centers and

system hardware) by all employees, contractors, vendors, and/ or

visitors is appropriately authorized, documented, and reviewed in

accordance with the current CMS MAC ARS, BPSSM, and other

applicable policy.

A.20 Control number A.20 reserved. Control not in use as of this IOM

revision.

A.21 - A.26 Configuration Management: Controls provide reasonable

assurance that changes to information system resources are

authorized and systems are configured and operated securely and as

intended.

Control Objective – Information Systems

A.21 Controls provide reasonable assurance that configuration

management policies, plans, and procedures are established,

documented, kept up-to-date, and approved in accordance with the

current CMS ARS, BPSSM, and other applicable policy including

the following:

• A System Development Life Cycle (SDLC) methodology is

documented and in use and aligns with the CMS Target Life

Cycle (TLC).

• Change management policies and procedures that have been

developed, documented, and implemented include

documented testing and approval of changes for regular and

emergency changes.

A.22 Controls provide reasonable assurance that Medicare application

and related systems software development and maintenance

activities (e.g. quarterly releases, off-quarterly releases, and

emergency changes) are authorized, documented, tested, and

approved in accordance with the current CMS ARS, BPSSM, and

other applicable policy.

A.23 Controls provide reasonable assurance that access to program

libraries is properly restricted and movement of programs among

libraries is controlled.

A.24 Controls provide reasonable assurance that management has

established and consistently monitors information security related

configuration for information technology in accordance with the

current CMS ARS, BPSSM, and other applicable Federal standards

and best practices including the following:

• Develops and maintains a security configuration baseline for

information technology that aligns with CMS requirements

and industry standards.

• Reviews the IT environment against the baseline.

• Remediates misconfigurations in a timely fashion.

• For misconfigurations that cannot be remediated timely, a

plan of action and milestones (POA&M) or other corrective

action plan is created, documented, and approved.

• Deviations from CMS or other standards are analyzed and

approved.

• Results of periodic assessments are reported to CMS.

Control Objective – Information Systems

A.25 Controls provide reasonable assurance that management has

established a vulnerability management program in accordance with

the current CMS ARS, BPSSM, and other applicable policy that

includes:

• Scanning to identify vulnerabilities and unauthorized and

unsupported software.

• Disabling / removing unauthorized and unsupported

software in a timely manner.

• Remediation of vulnerabilities in a timely manner.

• Creation of corrective action plans or POA&Ms if

vulnerabilities cannot be remediated timely.

Further, software is updated (patched) in a timely fashion to protect

against vulnerabilities in accordance with the current CMS ARS,

BPSSM, and other applicable policy.

A.26 Controls provide reasonable assurance that an effective virus, spam

and spyware protection process is documented, approved, and

implemented in accordance with the current CMS ARS, BPSSM,

and other applicable policy.

A.27 - A.28 Contingency Planning: Controls provide reasonable assurance that

contingency planning:

(1) protects information resources and minimizes the risk of

unplanned interruptions and

(2) provides for recovery of critical operations should

interruptions occur.

A.27 Controls provide reasonable assurance that information system

backup and recovery procedures have been implemented in

accordance with the current CMS ARS, BPSSM, and other

applicable policy including:

• Development, approval and maintenance of an up-to-date

contingency plan and / or disaster recovery plan.

• Periodic testing of contingency and / or disaster recovery

plans.

• Updating plans based on lessons learned.

A.28 Controls provide reasonable assurance that appropriate environment

protections for sensitive areas such as data centers are implemented

in accordance with the current CMS ARS, BPSSM, and other

applicable policy.

End Section 50.1 – A Controls – Information Systems: Back to Table of Contents

History

(Rev. 308, Issued: 10-26-18 Effective: 09- 01- 18, Implementation: 11-27-18)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
a197172e9e425843b1e6b1f0bb939328354832078ec370c8e851bf9272195c85
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.