Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 30.9.1

A CUECs – Information Systems

Last amended: 2024Year: 2024Length: 591 wordsOfficial source
30.9.1 – A CUECs – Information Systems (Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25) A – Control Objective Number A – CUEC Description A.1 CMS maintains, updates, and makes available current CMS Acceptable Risk Safeguards (ARS), Business Partners Systems Security Manual (BPSSM), and other applicable policy to provide Medicare Administrative Contractors (MACs) requirements and guidance for the establishment of an entity-wide security program. A.3 CMS, as the Authorizing Official (AO), reviews and approves the Information System Security Categorization through the Authority to Operate (ATO) process. A.7 For shared systems, outside of the MAC’s ATO boundary, CMS or its contractors update and / or remove user logical access accounts and system permissions as requested and approved by the MAC for transferred personnel in a timely fashion. In addition, CMS or its contractors remove logical access accounts and system permissions as requested and approved by the MAC for separated personnel in a timely fashion. A.9 CMS, as the Authorizing Official (AO), authorizes the information system for processing prior to commencing operations and periodically thereafter. In addition, the Information Security and Privacy Group (ISPG) of CMS inputs, in a timely manner, POA&Ms into the CMS FISMA Controls Tracking System (CFACTS). A – Control Objective Number A – CUEC Description A.12 For shared systems, outside of the MAC’s ATO boundary, CMS or its contractors: • Create MAC and non-MAC user accounts (including remote access accounts, temporary, emergency, and privileged accounts if applicable) as requested and approved by the MAC. • If emergency and / or temporary accounts are utilized they are automatically removed as required by CMS standards and/or based on request by the MAC. • CMS or its contractors update information system accounts in a timely fashion based on periodic reviews conducted by the MACs. A.13 For shared systems, outside of the MAC’s ATO boundary, CMS or its contractors remove logical access accounts and system permissions as requested and approved by the MAC for separated personnel in a timely fashion. Further, CMS or its contractors automatically disable inactive accounts as required by CMS. A.15 For shared systems, outside of the MAC’s ATO boundary, CMS or its contractors configure password based authentication for major applications / information systems in accordance with current CMS ARS, BPSSM, and other applicable policies. A.17 For shared systems, outside of the MAC’s ATO boundary, CMS or its contractors produce and distribute security audit logs to the MACs for investigation as needed. A.18 CMS collaborates with the MAC to analyze, respond, and report security incidents. A.21 CMS maintains, updates, and makes available the current CMS Target Life Cycle (TLC) and other applicable policy to provide the MACs requirements and guidance for the establishment of change management and SDLC processes. A.22 For shared systems, outside of the MAC’s ATO boundary, CMS or its contractors are responsible for software development and maintenance processes including authorization of changes, documentation, testing, and approvals in accordance with the current CMS ARS, BPSSM, and other applicable policy. A – Control Objective Number A – CUEC Description A.23 For shared systems, outside of the MAC’s ATO boundary, CMS or its contractors are responsible for properly restricting and controlling the movement of code between libraries. A.27 For shared systems, outside of the MAC’s ATO boundary, CMS or its contractors have implemented system backup and recovery procedures including contingency plans, disaster recovery plans, testing of plans, and corrective action based on lessons learned in accordance with the current CMS ARS, BPSSM, and other applicable policy. End Section 30.9.1 – A CUECs – Information Systems: Back to Table of Contents
Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 30.9.1: A CUECs – Information Systems | Justis AI