US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.11.3
National Institute of Standards and Technology (NIST)
(Rev. 15)
The Cyber Security Research and Development Act of 2002 (P.L. 107-305) tasks NIST to
“develop, and revise as necessary, a checklist setting forth settings and option selections that
minimize the security risks associated with each computer hardware or software system that is, or is
likely to become, widely used within the federal government.”
CMS highly encourages business partners to review and incorporate the NIST concepts into their
Medicare security program. Under the Computer Security Act of 1987 (P.L. 100-235), NIST
develops computer security prototypes, tests, standards, and procedures to protect sensitive
information from unauthorized access or modification. Focus areas include cryptographic
technology and applications, advanced authentication, public key infrastructure, internetworking
security, criteria and assurance, and security management and support. These publications present
the results of NIST studies, investigations, and research on IT security issues. The publications are
issued as Federal Information Processing Standards (FIPS) Publications, Special Publications (SP),
NIST Interagency Reports (NISTIRs), and IT Laboratory (ITL) Bulletins.
Publications in the 800 series (SP 800-xx) present documents of general interest to the computer
security community. FIPS are issued by NIST after approval by the Secretary of Commerce
pursuant to Section 5131 of the Information Technology Reform Act of 1996 (P.L. 104-106) and
the Computer Security Act of 1987 (P.L. 100-235). With the passage of FISMA, there is no longer
a statutory provision to allow agencies to waive mandatory FIPS. The waiver provision had been
included in the Computer Security Act of 1987; however, FISMA supersedes that Act. Therefore,
any reference to a “waiver process” included in FIPS publications is no longer valid. Note,
however, that not all FIPS are mandatory; consult the applicability section of each FIPS for details.
CMS does not normally require the verbatim use of NIST SPs for the configuration of Medicare
systems. In cases where verbatim compliance is required, the requirements are specified in this
Business Partners Systems Security Manual (BPSSM) and the MAC ARS. However, CMS highly
encourages business partners to utilize NIST and other guidance documents to develop security
standards, templates, and processes that securely configure Medicare systems as part of their
configuration management program.
The most current NIST publications are available at: http://csrc.nist.gov/publications/index.html.
History
(Rev. 15)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
1b7dca7f4f48f13cc37b201e939e89fc800c2d4dc3c445ed1416209328d6acac
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.