US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.11.2
United States Government Configuration Baseline (USGCB) Standard
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
The purpose of the United States Government Configuration Baseline (USGCB) initiative is to
create security configuration baselines for Information Technology products widely deployed
across federal agencies. The USGCB baseline evolved from the Federal Desktop Core
Configuration (FDCC) mandate. While not addressed specifically as the FDCC, the process (now
coined the USGCB process) for creating, vetting, and providing baseline configurations settings
was originally described in a 22 March 2007 memorandum from OMB to all Federal agencies and
department heads and a corresponding memorandum from OMB to all Federal agency and
department Chief Information Officers (CIO).
Business Partners have the choice of using the USGCB configurations or the STIGs for the
platforms listed on the USGCB Web site at https://csrc.nist.gov/projects/united-states-government-
configuration-baseline.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
6628e12235faf3e41a56e15d876d3d12d652578b06aad2590f32e37bf1b138be
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.