US · guidance
CMS Pub. 100-06, ch. 7, § 50
List of CMS Contractor Control Objectives
Control
Number
Control Objectives
Back to Table of Contents
50.1 – A Controls – Information Systems
((Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25)
Control Objective – Information Systems
A.1 - A.11 Security Management: Controls provide reasonable assurance that
security management is effective.
A.1 Controls provide reasonable assurance that management has
established, documented, and approved an entity-wide security
program in accordance with the current CMS Acceptable Risk
Safeguards (ARS), Business Partners Systems Security Manual
(BPSSM), and other applicable policy including that the security
program:
• Is monitored and kept up-to-date in accordance with the
current ARS requirements.
• Includes requirements to establish a security management
structure that has appropriate independence, authority,
expertise, and resources.
• Clearly assigns security responsibilities throughout the
organization.
• Ensures that management implements, maintains, and
updates the organization security policy and procedures in
accordance with CMS guidance.
A.2 Controls provide reasonable assurance that security risks are
periodically assessed and appropriately mitigated in accordance
with the current CMS ARS, BPSSM, and other applicable policy. A
risk assessment and supporting activities of the criticality and
sensitivity of computer operations, including all network
components, IT platforms and critical applications has been
established and updated periodically based on ARS and Federal
requirements. The assessment includes, but may not be limited to,
identification of threats, known system vulnerabilities, system
flaws, or weaknesses that could be exploited by threat sources.
A.3 Controls provide reasonable assurance that information systems and
resources are categorized based on the potential impact that the loss
of confidentiality, integrity, or availability would have on
operations, assets or individuals in accordance with the current
CMS ARS, BPSSM, and other applicable policy.
Control Objective – Information Systems
A.4 Controls provide reasonable assurance that a system security plan(s)
(SSP) has been documented, approved, and reviewed by
management in accordance with the current CMS ARS, BPSSM,
and other applicable policy. The SSP covers all major facilities and
operations supporting the CMS Medicare program and is updated
and maintained within CFACTS in accordance with the ARS and
current version of the CMS Risk Management Handbook (RMH).
A.5 Controls provide reasonable assurance that management develops
and maintains a current inventory of hardware, software, platforms,
information systems, and other tools / devices that support the
Medicare program in accordance with the current CMS ARS,
BPSSM, and other applicable policy.
A.6 Controls provide reasonable assurance that security related
personnel-policies are implemented that include performance of
background investigations (initial and / or periodic) in accordance
with the current CMS ARS, BPSSM, and other applicable policy.
A.7 Controls provide reasonable assurance that security related
personnel-policies are implemented that include transfer and
separation procedures which require:
• Review and appropriate update, if necessary, of logical and
physical access rights for transferred personnel.
• Exit interviews, return of property, such as keys and ID
cards, timely notification to security management of
separations, removal of physical and logical access to
systems and escorting of separated personnel out of the
facility.
Performance of transfer and separation processes are in accordance
with the current CMS ARS, BPSSM, and other applicable policy.
A.8 Controls provide reasonable assurance that personnel including
employees, contractors, and vendors, are aware of security policies
and procedures. Initial security awareness training, ongoing
security awareness training, and role specific training for
individuals with significant security responsibilities is documented,
completed, and monitored by management. The security training
program and content of training are in accordance with the current
CMS ARS, BPSSM, and other applicable policy.
Control Objective – Information Systems
A.9 Controls provide reasonable assurance that management has
implemented appropriate risk management and security assessment
and authorization (SA&A) processes in accordance with the current
CMS ARS, BPSSM, and other applicable policy including the
following:
• SA&A policies and procedures are documented, kept up-to-date, maintained and approved by management.
• Security Assessments are planned and conducted
• A corrective action management process is in place that
includes planning, implementing, evaluating, and fully
documenting remedial action addressing findings noted from
all security audits and reviews of IT systems, components,
and operations. Plan of Action and Milestones (POA&Ms)
and corrective action plans are developed and monitored to
address weaknesses.
• Authorizing Official (AO) authorizes the information system
for processing prior to commencing any operations and
periodically thereafter.
A.10 Controls provide reasonable assurance that management
continuously monitors the effectiveness of the security program
including security operations and completion of vulnerability
assessments in accordance with the current CMS ARS, BPSSM, and
other applicable policy.
A.11 Controls provide reasonable assurance that external third party
activities of sub-service organizations (i.e. sub-contractors) are
secure, documented, and monitored in accordance with the current
CMS ARS, BPSSM, and other applicable policy.
A.12 - A.20 Access Controls and Segregation of Duties: Controls provide
reasonable assurance that access to computer resources (data,
equipment, and facilities) is reasonable and restricted to authorized
individuals and that incompatible duties are effectively segregated.
A.12 Controls provide reasonable assurance that access, including remote
access, to significant computerized applications (such as claims
processing), accounting systems, systems software, and Medicare
data are appropriately authorized, documented, reviewed, and
monitored and includes approval by resource owners, procedures to
control emergency and temporary access and procedures to share
and properly dispose of data. Procedures are performed timely and
in accordance with the current CMS ARS, BPSSM, and other
applicable policy.
A.13 Controls provide reasonable assurance that inactive logical access
accounts and accounts for separated individuals are disabled and / or
removed in a manner that satisfies the current CMS ARS, BPSSM,
and other applicable policies.
Control Objective – Information Systems
A.14 Controls provide reasonable assurance that multifactor
authentication is implemented in accordance with the current CMS
ARS, BPSSM, and other applicable policy.
A.15 Controls provide reasonable assurance that password based
authentication is configured in accordance with the current CMS
ARS, BPSSM, and other applicable policy.
A.16 Controls provide reasonable assurance that access to sensitive
system resources and privileged accounts / functions are restricted
to individuals with a need-to-know and activities are appropriately
logged and monitored. Additionally, Management segregates
incompatible duties between various system and Medicare
operations functionality which is supported by appropriate
documentation, approvals, and monitoring.
A.17 Controls provide reasonable assurance that management identifies
system functions, events, and access permissions that require audit
logging and implements an effective audit log monitoring capability
in accordance with the current CMS ARS, BPSSM, and other
applicable policy.
A.18 Controls provide reasonable assurance that management has
documented, implemented, and approved an effective security
operations and incident response program which includes processes
to:
a) identify and log suspicious activity, sensitive and
privileged functions, and potential security events /
incidents,
b) monitor systems and networks audit logs, unusual
activity, and / or intrusion attempts,
c) correlate log data,
d) analyze potential incidents, and
e) report on security events, incidents, and intrusions in
accordance with the current CMS ARS, BPSSM, and
other applicable policy.
A.19 Controls provide reasonable assurance that physical access to
sensitive IT areas (such as Medicare facilities, data centers and
system hardware) by all employees, contractors, vendors, and/ or
visitors is appropriately authorized, documented, and reviewed in
accordance with the current CMS MAC ARS, BPSSM, and other
applicable policy.
A.20 Control number A.20 reserved. Control not in use as of this IOM
revision.
A.21 - A.26 Configuration Management: Controls provide reasonable
assurance that changes to information system resources are
authorized and systems are configured and operated securely and as
intended.
Control Objective – Information Systems
A.21 Controls provide reasonable assurance that configuration
management policies, plans, and procedures are established,
documented, kept up-to-date, and approved in accordance with the
current CMS ARS, BPSSM, and other applicable policy including
the following:
• A System Development Life Cycle (SDLC) methodology is
documented and in use and aligns with the CMS Target Life
Cycle (TLC).
• Change management policies and procedures that have been
developed, documented, and implemented include
documented testing and approval of changes for regular and
emergency changes.
A.22 Controls provide reasonable assurance that Medicare application
and related systems software development and maintenance
activities (e.g. quarterly releases, off-quarterly releases, and
emergency changes) are authorized, documented, tested, and
approved in accordance with the current CMS ARS, BPSSM, and
other applicable policy.
A.23 Controls provide reasonable assurance that access to program
libraries is properly restricted and movement of programs among
libraries is controlled.
A.24 Controls provide reasonable assurance that management has
established and consistently monitors information security related
configuration for information technology in accordance with the
current CMS ARS, BPSSM, and other applicable Federal standards
and best practices including the following:
• Develops and maintains a security configuration baseline for
information technology that aligns with CMS requirements
and industry standards.
• Reviews the IT environment against the baseline.
• Remediates misconfigurations in a timely fashion.
• For misconfigurations that cannot be remediated timely, a
plan of action and milestones (POA&M) or other corrective
action plan is created, documented, and approved.
• Deviations from CMS or other standards are analyzed and
approved.
• Results of periodic assessments are reported to CMS.
Control Objective – Information Systems
A.25 Controls provide reasonable assurance that management has
established a vulnerability management program in accordance with
the current CMS ARS, BPSSM, and other applicable policy that
includes:
• Scanning to identify vulnerabilities and unauthorized and
unsupported software.
• Disabling / removing unauthorized and unsupported
software in a timely manner.
• Remediation of vulnerabilities in a timely manner.
• Creation of corrective action plans or POA&Ms if
vulnerabilities cannot be remediated timely.
Further, software is updated (patched) in a timely fashion to protect
against vulnerabilities in accordance with the current CMS ARS,
BPSSM, and other applicable policy.
A.26 Controls provide reasonable assurance that an effective virus, spam
and spyware protection process is documented, approved, and
implemented in accordance with the current CMS ARS, BPSSM,
and other applicable policy.
A.27 - A.28 Contingency Planning: Controls provide reasonable assurance that
contingency planning:
(1) protects information resources and minimizes the risk of
unplanned interruptions and
(2) provides for recovery of critical operations should
interruptions occur.
A.27 Controls provide reasonable assurance that information system
backup and recovery procedures have been implemented in
accordance with the current CMS ARS, BPSSM, and other
applicable policy including:
• Development, approval and maintenance of an up-to-date
contingency plan and / or disaster recovery plan.
• Periodic testing of contingency and / or disaster recovery
plans.
• Updating plans based on lessons learned.
A.28 Controls provide reasonable assurance that appropriate environment
protections for sensitive areas such as data centers are implemented
in accordance with the current CMS ARS, BPSSM, and other
applicable policy.
End Section 50.1 – A Controls – Information Systems: Back to Table of Contents
History
(Rev. 308, Issued: 10-26-18 Effective: 09- 01- 18, Implementation: 11-27-18)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
a197172e9e425843b1e6b1f0bb939328354832078ec370c8e851bf9272195c85
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.