US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3
IT Systems Security Program Management
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
The Security Program consists of several fundamental components that are all designed
to implement controls and to reduce risk. Key elements of controls include Policies,
Procedures, Technical Implementations, Standards, and Management Reviews.
Required security documentation includes, but is not limited to, the system security and
privacy plan, the information security risk assessment, and the IT systems contingency
plan.
Business partners shall implement an IT Systems Security Program to manage system security
risks. Risks are identified by the business partner in the Information Security Risk Assessment (see
section 3.2) and the security requirements are documented in the System Security and Privacy Plan
(see section 3.1). The underlying support for these documents is the controls implemented by the
business partner. Information system security controls shall be implemented in a consistent manner
everywhere within the system’s accreditation boundary to protect the CIA of sensitive information.
In addition, testing shall be performed to ensure that information security controls are operating as
intended.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
d67c525c1cf781b7e7e457f6d3f85fd492dbfd96dab40124c819d77c32bec4d0
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.