Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.11.2

United States Government Configuration Baseline (USGCB) Standard

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

The purpose of the United States Government Configuration Baseline (USGCB) initiative is to

create security configuration baselines for Information Technology products widely deployed

across federal agencies. The USGCB baseline evolved from the Federal Desktop Core

Configuration (FDCC) mandate. While not addressed specifically as the FDCC, the process (now

coined the USGCB process) for creating, vetting, and providing baseline configurations settings

was originally described in a 22 March 2007 memorandum from OMB to all Federal agencies and

department heads and a corresponding memorandum from OMB to all Federal agency and

department Chief Information Officers (CIO).

Business Partners have the choice of using the USGCB configurations or the STIGs for the

platforms listed on the USGCB Web site at https://csrc.nist.gov/projects/united-states-government-

configuration-baseline.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
6628e12235faf3e41a56e15d876d3d12d652578b06aad2590f32e37bf1b138be
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS Pub. 100-17, ch. 117_systems_security, § 3.11.2 · binding.law