US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.01
Control Components
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Business partners shall have policies and procedures and implement controls or plans that fulfill the
MAC ARS controls. The business partner Medicare claims related security program shall be based
on the MAC ARS (IOM 100-17, Attachment 1), the BPSSM (IOM 100-17) and on the collection of
CMS policies, procedures, standards, and guidelines found on the CMS Information Security Web
site at: https://security.cms.gov
Policies are formal, up to date, documented rules that are tailored to the environment, are
communicated as “shall” or “will” statements and are readily available to employees. They
establish a continuing cycle of assessing risk, implementing controls and monitoring for program
effectiveness. Policies are written to cover all major facilities and operations corporate-wide or for a
specific asset (e.g., Medicare claims processing), and they are approved by key affected parties.
Policies delineate the IT security management structure, clearly assign IT security responsibilities,
and lay the foundation necessary to reliably measure progress and compliance. Policies also
identify specific penalties and disciplinary actions to be used in the event that the policy is not
followed.
Procedures are formal, up to date, documented instructions that are provided to implement the
security controls identified by the defined policies. They clarify where the action is to be
performed, how the action is to be performed, when the action is to be performed, who is to
perform the action, and on what the action is to be performed. Procedures clearly define IT security
responsibilities and expected behaviors for: asset owners and users, information resources
management and data processing personnel, management, and IT security administrators.
Procedures also indicate appropriate individuals to be contacted for further information, guidance,
and compliance. Finally, procedures document the implementation of, and the rigor with which, the
control is applied.
Technical Implementations are the acquisition and installation of hardware, software, or assets to
be used for the establishment of a new control, or the improvement of an existing control. The
intention of a technical implementation is to automate or facilitate a control process that would
otherwise be manually performed.
Standards are formal, written, mandatory actions, rules, or specifications designed to support and
conform to a policy or procedure. A standard must include one or more accepted specifications for
configurable items for hardware, software, or behavior. Standards are often required to successfully
complete technical implementations and can be either part of policies and procedures or can be
standalone documents. Standards can result from, either exclusively by or in combination with,
laws promulgated by governing bodies, obtained from known standards organization or developed
by the business partner using industry best practices.
Management Review is the business partners’ formal oversight activity of control implementations
and should be performed at various management levels. Oversight is a regular activity to verify that
the control environment for which management has responsibility is functioning properly.
Management must set benchmarks or other methods to measure the success of controls. Where
appropriate, management should document their review by formally approving evidence supplied.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
1e3f32c0c5c6f67ddc7082df64d34d351ad066af6b8efb99701a4b98bf266110
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.