US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.18
Authorized Software
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
MAC ARS CM-7(5) requires that defined software be documented and explicitly authorized to be
allowed to be executed. This authorization of software is known as whitelisting. If the whitelisting
of software is a manual process, then the process to review and update the list of authorized
software programs must be completed no less often than every seventy-two (72) hours. If
automated tools are used to whitelist software, then the automated tools must be updated whenever
the authorized software changes or new software is authorized, and the tool must be programmed to
either perform a scan of the network for unauthorized software no less often than every seventy-two
(72) hours or perform an on-demand evaluation of software every time the software is executed. In
addition, management must review and formally document the list of approved software every 90
days.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
6749cdb1fff702cb50f09b7eb66f80b3a67c5f1536af907d9794b4bf71c5f06c
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.