Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 30.9.1
A CUECs – Information Systems
30.9.1 – A CUECs – Information Systems
(Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25)
A – Control
Objective
Number
A – CUEC Description
A.1
CMS maintains, updates, and makes available current CMS
Acceptable Risk Safeguards (ARS), Business Partners Systems
Security Manual (BPSSM), and other applicable policy to provide
Medicare Administrative Contractors (MACs) requirements and
guidance for the establishment of an entity-wide security program.
A.3
CMS, as the Authorizing Official (AO), reviews and approves the
Information System Security Categorization through the Authority
to Operate (ATO) process.
A.7
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors update and / or remove user logical access accounts
and system permissions as requested and approved by the MAC for
transferred personnel in a timely fashion. In addition, CMS or its
contractors remove logical access accounts and system permissions
as requested and approved by the MAC for separated personnel in a
timely fashion.
A.9
CMS, as the Authorizing Official (AO), authorizes the information
system for processing prior to commencing operations and
periodically thereafter. In addition, the Information Security and
Privacy Group (ISPG) of CMS inputs, in a timely manner,
POA&Ms into the CMS FISMA Controls Tracking System
(CFACTS).
A – Control
Objective
Number
A – CUEC Description
A.12
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors:
• Create MAC and non-MAC user accounts (including remote
access accounts, temporary, emergency, and privileged accounts if
applicable) as requested and approved by the MAC.
• If emergency and / or temporary accounts are utilized they are
automatically removed as required by CMS standards and/or based
on request by the MAC.
• CMS or its contractors update information system accounts in a
timely fashion based on periodic reviews conducted by the MACs.
A.13
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors remove logical access accounts and system
permissions as requested and approved by the MAC for separated
personnel in a timely fashion. Further, CMS or its contractors
automatically disable inactive accounts as required by CMS.
A.15
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors configure password based authentication for major
applications / information systems in accordance with current CMS
ARS, BPSSM, and other applicable policies.
A.17
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors produce and distribute security audit logs to the
MACs for investigation as needed.
A.18
CMS collaborates with the MAC to analyze, respond, and report
security incidents.
A.21
CMS maintains, updates, and makes available the current CMS
Target Life Cycle (TLC) and other applicable policy to provide the
MACs requirements and guidance for the establishment of change
management and SDLC processes.
A.22
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors are responsible for software development and
maintenance processes including authorization of changes,
documentation, testing, and approvals in accordance with the
current CMS ARS, BPSSM, and other applicable policy.
A – Control
Objective
Number
A – CUEC Description
A.23
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors are responsible for properly restricting and
controlling the movement of code between libraries.
A.27
For shared systems, outside of the MAC’s ATO boundary, CMS or
its contractors have implemented system backup and recovery
procedures including contingency plans, disaster recovery plans,
testing of plans, and corrective action based on lessons learned in
accordance with the current CMS ARS, BPSSM, and other
applicable policy.
End Section 30.9.1 – A CUECs – Information Systems: Back to Table of Contents