US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.11
Security Configuration Management
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
Business partners are required to create a security baseline for the configuration of the
information system components. A baseline is a formal, management approved standard
that documents the customization of Federal or other guidelines.
The process for establishing and maintaining baselines shall allow misconfigurations to
be identified and risk-minimized, including a documented process that supports timely
resolution of misconfigurations.
Federal guidelines should be used to create baselines. If a Federal guideline does not
exist, hardening guides or documented best practices may be used.
DMEMACs and ABMACs are responsible for starting their security configurations with
the Defense Information Systems Agency (DISA) Security Technical Implementation
Guide (STIG) Checklists when creating a baseline. All appropriate or referenced DISA
checklists and guidelines shall be considered for input into each baseline.
FISMA requires each agency to determine minimally acceptable system configuration requirements
and ensure compliance with them. CMS requires business partners to utilize guidance documents to
develop configuration standards, templates, and processes that securely configure Medicare systems
as part of their configuration management program.
Misconfigurations are defined as:
• A setting that violates a configuration policy or that permits or causes unintended behavior
that impacts the security posture of a system.
• An incorrect or suboptimal configuration of an information system or system component
that may lead to vulnerabilities.
In order to effectively protect MAC environments from vulnerabilities produced by incorrectly
configured information system components, any misconfiguration shall be updated/corrected within
30 days from the time of discovery. If the misconfiguration cannot be effectively addressed within
that timeframe, a POA&M shall be opened to track and remediate misconfigured setting(s).
Security configuration guidelines may be developed by different federal agencies, so it is possible
that a guideline could include configuration information that conflicts with another agency or CMS
guideline. To resolve configuration conflicts among multiple security guidelines, the CMS
hierarchy for implementing Federal security configuration guidelines follows. If there is a conflict
between the MAC ARS and a DISA STIG, the MAC ARS takes precedence. See Table 3.4 for
more information. If there are any other questions or concerns about resolving conflicts among
security configuration guidelines, business partner SSOs shall contact their CMS ISSO.
Table 3.4
Business Partners DMEMAC/ABMAC
1. MAC ARS
2. United States Government
Configuration Baseline (USGCB)
3. NIST National Checklist Program
(NCP) / NIST
4. DISA
1. MAC ARS
2. DISA/USGCB
3. NIST National Checklist Program
(NCP) / NIST / Center for Internet
Security (CIS) / Cybersecurity and
Infrastructure Security Agency
(CISA) / Other Federal Guidance
4. Vendor supplied guidance
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
19ed44fa414c5e26779fd94f7c179a5eb5c6ad3e0c7fd232cb16259d9f55621f
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.