US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 4.1.7
Minimum Protection Alternatives
The objective of the MPS is to prevent unauthorized access to CMS sensitive information. MPS
requires two barriers to accessing sensitive information under normal security. The reason for the
two barriers is to provide an additional layer of protection to deter, delay, or detect surreptitious
entry. Because local factors may require additional security measures, management shall analyze
local circumstances to determine space, container, and other security needs at individual facilities.
Table 4.1 shall be used to determine the minimum protection alternatives required to protect CMS
sensitive information. Note that any of the three alternative protection standards is acceptable
whenever all of the applicable perimeter, interior area, and/or container standards are met. The
protection alternative methods are not listed in any order of preference or security significance.
Table 4.1. Protection Alternative Chart
Perimeter
Type
Interior Area
Type
Container
Type
Alternative #1 Secured Locked
Alternative #2 Locked Secured
Alternative #3 Locked Security
History
(Rev. 15)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
5b84431667b055c02505745137bf434e38b6e0e7e70f7d5d27f2ba1cefc04ad6
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.