Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 4

Information And Information Systems Security

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

4.1 - Sensitive Information Protection Requirement

Business partners are responsible for implementing Minimum Protection Standards (MPS) for all

CMS sensitive information (digital and non-digital) and information systems categorized at the

“HIGH” security level designation. The MPS establishes a uniform method for protecting data and

items that require safeguarding. The MPS applies to all IT facilities, areas, or systems processing,

storing, or transmitting CMS sensitive information (i.e., any information categorized as “HIGH”) in

any form or on any media.

Care must be taken to deny unauthorized access to areas containing sensitive systems and

information during working and non-working hours. This can be accomplished by creating

restricted areas, security rooms, or locked rooms. Additionally, sensitive information in any form

(computer printout, photocopies, tapes, notes, etc.) must be protected during non-duty hours. This

can be done through a combination of methods: secured or locked perimeter, secured area, or

containerization.

4.1.1 - Restricted Area

A restricted area is a secured area whose entry is restricted to authorized personnel (individuals

assigned to the area). All restricted areas shall either meet secured area criteria or provisions shall

be made to store CMS sensitive items in appropriate containers during non-working hours. The use

of restricted areas is an effective method for eliminating unnecessary traffic through critical areas,

thereby reducing the opportunity for unauthorized disclosure or theft of sensitive information. All

of the following procedures must be implemented to qualify as a restricted area.

Restricted areas shall be indicated by prominently posted signs and separated from non-restricted

areas by physical barriers that control access. The number of entrances should be kept to a

minimum and each entrance shall have controlled access (e.g., electronic access control, key access,

door monitor) to prevent unauthorized entry. The main entrance should be controlled by a

responsible employee positioned at the entrance to enforce the restriction of access to authorized

personnel accompanied by one or more business partner officials.

When unescorted, a restricted area register shall be maintained at a designated entrance to the

restricted area and all visitors (persons not assigned to the area) entering the area shall be directed

to the designated entrance. Visitors entering the area shall sign the register, providing their name,

signature, assigned work area, escort, purpose of entry, and time and date of entry.

The entry control monitor shall verify the identity of visitors by comparing the name and signature

entered in the register with the name and signature of some type of photo identification card, such

as a driver’s license. When leaving the area, the entry control monitor or escort shall enter the

visitor's time of departure. Each restricted area register shall be closed out at the end of each month

and reviewed by the area supervisor/manager.

To facilitate the entry of employees who have a frequent and continuing need to enter a restricted

area, but are not assigned to the area, an authorized access list (AAL) can be maintained. Each

month a new AAL shall be posted, and vendors shall be required to sign the register. If there is any

doubt on the identity of the individual prior to permitting entry, their identity shall be verified prior

to permitting entry.

4.1.2 - Security Room

A security room is a room that has been constructed to resist forced entry. The primary purpose of a

security room is to store protectable material. The entire room shall be enclosed by slab-to-slab

walls constructed of approved materials (e.g., masonry brick, dry wall, etc.) and supplemented by

periodic inspection. All doors for entering the security room shall be locked with locking systems

meeting the requirements set forth below (section 4.2.5, Locking Systems). Entry is limited to

specifically authorized personnel.

Door hinge pins shall be non-removable or installed on the inside of the room. Any glass in doors

or walls shall be security glass (a minimum of two layers of 1/8 inch plate glass with .060 inch

[1/32] vinyl interlayer, nominal thickness shall be 5/16 inch). Plastic glazing material is not

acceptable. Vents and louvers shall be protected by an Underwriters' Laboratory (UL)-approved

electronic Intrusion Detection System (IDS) that annunciates at a protection console, UL-approved

central station, or local police station; and the IDS shall be given top priority for guard/police

response during any alarm situation.

Whenever cleaning and/or maintenance are performed, and sensitive systems and/or information

may be accessible, the cleaning and/or maintenance shall be done in the presence of an authorized

employee.

4.1.3 - Secured Area (Secured Interior/Secured Perimeter)

Secured areas are interior areas or exterior perimeters which have been designed to prevent

undetected entry by unauthorized persons during working and non-working hours. Personnel shall

not be in computer rooms and/or areas containing sensitive information unless that individual is

authorized to access that sensitive information. To qualify as a secured area, the area shall meet the

following minimum standards:

• Enclosed by slab-to-slab walls constructed of approved materials and supplemented by

periodic inspection or other approved protection methods, or any lesser-type partition

supplemented by UL-approved electronic IDS and fire detection systems.

• Unless electronic IDS devices are used, all doors entering the space shall be locked and

strict key or combination controls should be exercised.

• In the case of a fence/gate, the fence shall have IDS devices or be continually guarded, and

the gate shall be either guarded or locked with intrusion alarms.

• The space shall be cleaned during working hours in the presence of a regularly assigned

employee.

4.1.4 - Container

The term container includes all file cabinets (both vertical and lateral), safes, supply cabinets, open

and closed shelving, desk and credenza drawers, carts, or any other piece of office equipment

designed for the storage of files, documents, papers, or equipment. Some of these containers are

designed for storage only and do not provide any protection value (e.g., open shelving). Acceptable

containers for providing protection can be grouped into three general categories: locked containers,

security containers, and safes or vaults.

4.1.4.1 - Locked Container

A locked container is a commercially available or prefabricated metal cabinet or box with riveted or

welded seams, or metal desks with lockable drawers. The lock mechanism may be either a built-in

key, or a hasp and lock. A hasp is a hinged metal fastening attached to the cabinet, drawer, etc. that

is held in place by a pin or padlock.

4.1.4.2 - Security Container

Security containers are metal containers that are lockable and have a tested resistance to

penetration. To maintain the integrity of the security container, key locks should have only two

keys and strict control of the keys is mandatory. If combinations are used, they shall be given only

to those individuals who have a need to access the container. Security containers include the

following:

• Metal lateral key lock files

• Metal lateral files equipped with lock bars on both sides and secured with security padlocks

• Metal pull drawer cabinets with center or off-center lock bars secured by security padlocks

• Key lock “Mini Safes” properly mounted with appropriate key control

If the central core of a security container lock is replaced with a non-security lock core, then the

container no longer qualifies as a security container.

4.1.4.3 - Safe/Vault

A safe/vault is not required for storage of CMS sensitive information. However, if used, they shall

meet the following requirements:

• A safe is a GSA-approved container of Class I, IV, or V, or UL listings of TRTL-30 or

TRTL-60.

• A vault is a hardened room with typical construction of reinforced concrete floors, walls,

and ceilings that uses UL-approved vault doors and meets GSA specifications.

4.1.5 - Locking System

The lock is the most accepted and widely used security device for protecting installations and

activities, personnel data, sensitive data, classified material and government and personal property.

All containers, rooms, buildings, and facilities containing vulnerable or sensitive items shall be

locked when not in actual use. However, regardless of their quality or cost, locks should be

considered as delay devices only and not complete deterrents. Therefore, locking system must be

planned and used in conjunction with other security measures.

Minimum requirements for locking systems for secured areas and security rooms are high-security

pin-tumbler cylinder locks that meet the following requirements:

• Key-operated mortised or rim-mounted deadbolt lock

• Have a deadbolt throw of one inch or longer

• Double-cylinder design; cylinders have five or more pin tumblers

• Contains hardened inserts or inserts made of steel if bolt is visible when locked

• Both the key and lock shall be “off-master”

Convenience-type locking devices such as card keys, sequenced button-activated locks used in

conjunction with electric strikes, etc., are authorized for use only during working hours. Keys to

secured areas not in the personal custody of an authorized employee and any combinations shall be

stored in a security container. The number of keys or persons with knowledge of the combination to

a secured area shall be kept to a minimum.

4.1.6 - Physical Intrusion Detection System (IDS)

Physical IDSs are designed to detect attempted breaches of perimeter areas. Physical IDS devices

can be used in conjunction with other measures to provide forced entry protection for after-hours

security. Additionally, alarms for individual and document safety (fire), and other physical hazards

(water pipe breaks) are recommended. Alarms shall annunciate at an on-site protection console, a

central station, or local police station. Physical IDS devices include but are not limited to: door and

window contacts, magnetic switches, motion detectors, and sound detectors, that are designed to set

off an alarm at a given location when the sensor is disturbed.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
2a981b770962aa08b31fe287631fa5ee64aa3db8031fe79e53385f13bd168e67
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS Pub. 100-17, ch. 117_systems_security, § 4 · binding.law