Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.11

Security Configuration Management

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Key Requirements

Business partners are required to create a security baseline for the configuration of the

information system components. A baseline is a formal, management approved standard

that documents the customization of Federal or other guidelines.

The process for establishing and maintaining baselines shall allow misconfigurations to

be identified and risk-minimized, including a documented process that supports timely

resolution of misconfigurations.

Federal guidelines should be used to create baselines. If a Federal guideline does not

exist, hardening guides or documented best practices may be used.

DMEMACs and ABMACs are responsible for starting their security configurations with

the Defense Information Systems Agency (DISA) Security Technical Implementation

Guide (STIG) Checklists when creating a baseline. All appropriate or referenced DISA

checklists and guidelines shall be considered for input into each baseline.

FISMA requires each agency to determine minimally acceptable system configuration requirements

and ensure compliance with them. CMS requires business partners to utilize guidance documents to

develop configuration standards, templates, and processes that securely configure Medicare systems

as part of their configuration management program.

Misconfigurations are defined as:

• A setting that violates a configuration policy or that permits or causes unintended behavior

that impacts the security posture of a system.

• An incorrect or suboptimal configuration of an information system or system component

that may lead to vulnerabilities.

In order to effectively protect MAC environments from vulnerabilities produced by incorrectly

configured information system components, any misconfiguration shall be updated/corrected within

30 days from the time of discovery. If the misconfiguration cannot be effectively addressed within

that timeframe, a POA&M shall be opened to track and remediate misconfigured setting(s).

Security configuration guidelines may be developed by different federal agencies, so it is possible

that a guideline could include configuration information that conflicts with another agency or CMS

guideline. To resolve configuration conflicts among multiple security guidelines, the CMS

hierarchy for implementing Federal security configuration guidelines follows. If there is a conflict

between the MAC ARS and a DISA STIG, the MAC ARS takes precedence. See Table 3.4 for

more information. If there are any other questions or concerns about resolving conflicts among

security configuration guidelines, business partner SSOs shall contact their CMS ISSO.

Table 3.4

Business Partners DMEMAC/ABMAC

1. MAC ARS

2. United States Government

Configuration Baseline (USGCB)

3. NIST National Checklist Program

(NCP) / NIST

4. DISA

1. MAC ARS

2. DISA/USGCB

3. NIST National Checklist Program

(NCP) / NIST / Center for Internet

Security (CIS) / Cybersecurity and

Infrastructure Security Agency

(CISA) / Other Federal Guidance

4. Vendor supplied guidance

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
19ed44fa414c5e26779fd94f7c179a5eb5c6ad3e0c7fd232cb16259d9f55621f
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS Pub. 100-17, ch. 117_systems_security, § 3.11 · binding.law