Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.01

Control Components

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Business partners shall have policies and procedures and implement controls or plans that fulfill the

MAC ARS controls. The business partner Medicare claims related security program shall be based

on the MAC ARS (IOM 100-17, Attachment 1), the BPSSM (IOM 100-17) and on the collection of

CMS policies, procedures, standards, and guidelines found on the CMS Information Security Web

site at: https://security.cms.gov

Policies are formal, up to date, documented rules that are tailored to the environment, are

communicated as “shall” or “will” statements and are readily available to employees. They

establish a continuing cycle of assessing risk, implementing controls and monitoring for program

effectiveness. Policies are written to cover all major facilities and operations corporate-wide or for a

specific asset (e.g., Medicare claims processing), and they are approved by key affected parties.

Policies delineate the IT security management structure, clearly assign IT security responsibilities,

and lay the foundation necessary to reliably measure progress and compliance. Policies also

identify specific penalties and disciplinary actions to be used in the event that the policy is not

followed.

Procedures are formal, up to date, documented instructions that are provided to implement the

security controls identified by the defined policies. They clarify where the action is to be

performed, how the action is to be performed, when the action is to be performed, who is to

perform the action, and on what the action is to be performed. Procedures clearly define IT security

responsibilities and expected behaviors for: asset owners and users, information resources

management and data processing personnel, management, and IT security administrators.

Procedures also indicate appropriate individuals to be contacted for further information, guidance,

and compliance. Finally, procedures document the implementation of, and the rigor with which, the

control is applied.

Technical Implementations are the acquisition and installation of hardware, software, or assets to

be used for the establishment of a new control, or the improvement of an existing control. The

intention of a technical implementation is to automate or facilitate a control process that would

otherwise be manually performed.

Standards are formal, written, mandatory actions, rules, or specifications designed to support and

conform to a policy or procedure. A standard must include one or more accepted specifications for

configurable items for hardware, software, or behavior. Standards are often required to successfully

complete technical implementations and can be either part of policies and procedures or can be

standalone documents. Standards can result from, either exclusively by or in combination with,

laws promulgated by governing bodies, obtained from known standards organization or developed

by the business partner using industry best practices.

Management Review is the business partners’ formal oversight activity of control implementations

and should be performed at various management levels. Oversight is a regular activity to verify that

the control environment for which management has responsibility is functioning properly.

Management must set benchmarks or other methods to measure the success of controls. Where

appropriate, management should document their review by formally approving evidence supplied.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
1e3f32c0c5c6f67ddc7082df64d34d351ad066af6b8efb99701a4b98bf266110
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.