Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.11.3

National Institute of Standards and Technology (NIST)

activein force · 2026-08-25 – presentas-observed

(Rev. 15)

The Cyber Security Research and Development Act of 2002 (P.L. 107-305) tasks NIST to

“develop, and revise as necessary, a checklist setting forth settings and option selections that

minimize the security risks associated with each computer hardware or software system that is, or is

likely to become, widely used within the federal government.”

CMS highly encourages business partners to review and incorporate the NIST concepts into their

Medicare security program. Under the Computer Security Act of 1987 (P.L. 100-235), NIST

develops computer security prototypes, tests, standards, and procedures to protect sensitive

information from unauthorized access or modification. Focus areas include cryptographic

technology and applications, advanced authentication, public key infrastructure, internetworking

security, criteria and assurance, and security management and support. These publications present

the results of NIST studies, investigations, and research on IT security issues. The publications are

issued as Federal Information Processing Standards (FIPS) Publications, Special Publications (SP),

NIST Interagency Reports (NISTIRs), and IT Laboratory (ITL) Bulletins.

Publications in the 800 series (SP 800-xx) present documents of general interest to the computer

security community. FIPS are issued by NIST after approval by the Secretary of Commerce

pursuant to Section 5131 of the Information Technology Reform Act of 1996 (P.L. 104-106) and

the Computer Security Act of 1987 (P.L. 100-235). With the passage of FISMA, there is no longer

a statutory provision to allow agencies to waive mandatory FIPS. The waiver provision had been

included in the Computer Security Act of 1987; however, FISMA supersedes that Act. Therefore,

any reference to a “waiver process” included in FIPS publications is no longer valid. Note,

however, that not all FIPS are mandatory; consult the applicability section of each FIPS for details.

CMS does not normally require the verbatim use of NIST SPs for the configuration of Medicare

systems. In cases where verbatim compliance is required, the requirements are specified in this

Business Partners Systems Security Manual (BPSSM) and the MAC ARS. However, CMS highly

encourages business partners to utilize NIST and other guidance documents to develop security

standards, templates, and processes that securely configure Medicare systems as part of their

configuration management program.

The most current NIST publications are available at: http://csrc.nist.gov/publications/index.html.

History

(Rev. 15)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
1b7dca7f4f48f13cc37b201e939e89fc800c2d4dc3c445ed1416209328d6acac
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.