Information Security Acceptable Risk Safeguards Manual (Pub. 100-25), § 50.2.8
Assurance
50.2.8-Assurance
(Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014-
VMS to Implement the Client Letter Work)
Two fundamental components affecting the trustworthiness of information systems are security
functionality and security assurance. Security functionality is typically defined in terms of the
security features, functions, mechanisms, services, procedures, and architectures implemented
within organizational information systems or the environments in which those systems operate.
Security assurance is the measure of confidence that the security functionality is implemented
correctly, operating as intended, and producing the desired outcome with respect to meeting the
security requirements for the system—thus possessing the capability to accurately mediate and
enforce established security policies. Security controls address both security functionality and
security assurance. Some controls focus primarily on security functionality (e.g., PE-3, Physical
Access Control; IA-2, Identification and Authentication; SC-13, Cryptographic Protection; AC-2,
Account Management). Other controls focus primarily on security assurance (e.g., CA-2,
Security Assessment; SA-17, Developer Security Architecture and Design; CM-3, Configuration
Change Control). Finally, certain security controls can support security functionality and
assurance (e.g., RA-5, Vulnerability Scanning; SC-3, Security Function Isolation; AC-25,
Reference Monitor). Security controls related to functionality are combined to develop a
security capability with the assurance-related controls implemented to provide a degree of
confidence in the capability within the organizational risk tolerance.
The CMSRs specify assurance-related controls with an “A” in the controls header to identify the
security controls that have assurance-related characteristics or properties (i.e., assurance-
related controls). Assurance-related controls are discussed in greater detail in NIST SP 800-53
(as amended), Appendix E, Assurance and Trustworthiness, to include the allocation of such
controls to security control baselines. There is no summary table provided in the NIST SP
800-53 Appendix E for the Program Management (PM) family or the Privacy families since PM
and Privacy controls are not associated with any particular security control baseline.
50.3
Assessment Procedures
(Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014-
VMS to Implement the Client Letter Work)
The Assessment Procedures, including Assessment Objectives, and Assessment Methods and
Objects, help determine if the security control implementations in the information system are
effective (i.e., implemented correctly, operating as intended, and producing the desired
outcome). They provide a foundation to support the security assessment and authorization
process. The Assessment Procedure consists of a set of procedural steps that are designated to
achieve one or more objectives by applying methods to assessment objects.
CMS Information Security (IS) Acceptable Risk Safeguards (ARS)
Page 14
50.3.1
Assessment Objective
(Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014-
VMS to Implement the Client Letter Work)
The Assessment Objectives include a set of determination statements (“Determine if…”) related
to the particular security control under assessment. The determination statements are closely
linked to the content of the security control (i.e., the security control functionality) to ensure
traceability of assessment results back to the fundamental control requirements.
Assessment Objectives establish the expectations for security control assessments based on the
assurance requirements defined in the security control. The assessment expectations provide
assessors with important reference points for the level of assurance (i.e., grounds for confidence)
needed for the determination of security control effectiveness. Each of the Assessment Objective
determination statements is either traceable to requirements within the baseline or enhancement
security control. This ensures that all aspects of the security control are fully assessed and that
any weaknesses or deficiencies in the control can be identified, and corrective actions taken
(usually in the form of a Plan of Actions and Milestones [POA&M]).
50.3.2
Assessment Methods and Objects
(Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014-
VMS to Implement the Client Letter Work)
The assessment methods define the nature of the assessor’s actions and include Examine,
Interview, and Test. The assessment object identifies the specific item being assessed including
specifications, mechanism, activities, and individuals. The application of an assessment
procedure to a security control produces assessment findings. These assessment findings are
subsequently used in helping to determine the overall effectiveness of the control.
60.0
References
(Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014-
VMS to Implement the Client Letter Work)
The CMS information security and privacy assurance program and ARS were developed in
accordance with Federal mandates and CMS requirements for the handling and processing of
CMS’ information and information systems. A list of applicable laws across the program is
provided below:
• Public Law 74-271, Social Security Act, as amended
http://www.ssa.gov/OP_Home/ssact/ssact.htm.
• Public Law 93-579, The Privacy Act of 1974, as amended
http://www.justice.gov/opcl/privstat.htm
CMS Information Security (IS) Acceptable Risk Safeguards (ARS)
Page 15
• Public Law 104-13, Paperwork Reduction Act of 1995, as amended
http://www.fws.gov/policy/library/rgpl104-13.pdf
• Public Law 108–173, Medicare Prescription Drug, Improvement, and Modernization Act of
2003 (MMA), SEC. 912: Requirements for Information Security for Medicare
Administrative Contractors
http://www.gpo.gov/fdsys/pkg/BILLS-108hr1enr/pdf/BILLS-108hr1enr.pdf
• Code of Federal Regulations (CFR), Regulation 5 CFR Part 731 – Suitability,
http://ecfr.gpoaccess.gov/cgi/t/text/text-
idx?c=ecfr&rgn=div5&view=text&node=5:2.0.1.1.7&idno=5
• United States Code Title 44 Chapter 33—Disposal of Records
http://www.archives.gov/about/laws/disposal-of-records.html
• GAO-09-232G, Federal Information System Controls Audit Manual (FISCAM), February 2,
2009
http://www.gao.gov/new.items/d09232g.pdf
• OMB Circulars can be found at the CMS web site or at:
http://www.whitehouse.gov/omb/circulars/index.html
• Homeland Security Presidential Directives can be found at:
http://www.dhs.gov/xabout/laws/.
• Executive Orders can be found at:
http://www.archives.gov/federal-register/executive-orders/disposition.html
• A list of NIST special publications and FIPS publications can be found at:
http://csrc.nist.gov/publications/
• The most recent Internal Revenue Service publication 1075 can be found at:
http://www.irs.gov/pub/irs-pdf/p1075.pdf
• HHS-OCIO Policy for Information Systems Security and Privacy, dated July 7, 2011
http://www.hhs.gov/ocio/policy/index.html#Security
• HHS-OCIO Policy for Information Systems Security and Privacy Handbook, dated July 7,
2011 (available upon request via mailto:ciso@cms.hhs.gov)
Additional CMS documents were used as references in the development of this manual. The
CMS information security web site at http://www.cms.gov/Research-Statistics-Data-and-
Systems/CMS-Information-Technology/InformationSecurity/ provides a list of applicable CMS
documents across the information assurance program.