Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 50.1

A Controls – Information Systems

Last amended: 2024Year: 2024Length: 1,752 wordsOfficial source
50.1 – A Controls – Information Systems ((Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25) Control Objective – Information Systems A.1 - A.11 Security Management: Controls provide reasonable assurance that security management is effective. A.1 Controls provide reasonable assurance that management has established, documented, and approved an entity-wide security program in accordance with the current CMS Acceptable Risk Safeguards (ARS), Business Partners Systems Security Manual (BPSSM), and other applicable policy including that the security program: • Is monitored and kept up-to-date in accordance with the current ARS requirements. • Includes requirements to establish a security management structure that has appropriate independence, authority, expertise, and resources. • Clearly assigns security responsibilities throughout the organization. • Ensures that management implements, maintains, and updates the organization security policy and procedures in accordance with CMS guidance. A.2 Controls provide reasonable assurance that security risks are periodically assessed and appropriately mitigated in accordance with the current CMS ARS, BPSSM, and other applicable policy. A risk assessment and supporting activities of the criticality and sensitivity of computer operations, including all network components, IT platforms and critical applications has been established and updated periodically based on ARS and Federal requirements. The assessment includes, but may not be limited to, identification of threats, known system vulnerabilities, system flaws, or weaknesses that could be exploited by threat sources. A.3 Controls provide reasonable assurance that information systems and resources are categorized based on the potential impact that the loss of confidentiality, integrity, or availability would have on operations, assets or individuals in accordance with the current CMS ARS, BPSSM, and other applicable policy. Control Objective – Information Systems A.4 Controls provide reasonable assurance that a system security plan(s) (SSP) has been documented, approved, and reviewed by management in accordance with the current CMS ARS, BPSSM, and other applicable policy. The SSP covers all major facilities and operations supporting the CMS Medicare program and is updated and maintained within CFACTS in accordance with the ARS and current version of the CMS Risk Management Handbook (RMH). A.5 Controls provide reasonable assurance that management develops and maintains a current inventory of hardware, software, platforms, information systems, and other tools / devices that support the Medicare program in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.6 Controls provide reasonable assurance that security related personnel-policies are implemented that include performance of background investigations (initial and / or periodic) in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.7 Controls provide reasonable assurance that security related personnel-policies are implemented that include transfer and separation procedures which require: • Review and appropriate update, if necessary, of logical and physical access rights for transferred personnel. • Exit interviews, return of property, such as keys and ID cards, timely notification to security management of separations, removal of physical and logical access to systems and escorting of separated personnel out of the facility. Performance of transfer and separation processes are in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.8 Controls provide reasonable assurance that personnel including employees, contractors, and vendors, are aware of security policies and procedures. Initial security awareness training, ongoing security awareness training, and role specific training for individuals with significant security responsibilities is documented, completed, and monitored by management. The security training program and content of training are in accordance with the current CMS ARS, BPSSM, and other applicable policy. Control Objective – Information Systems A.9 Controls provide reasonable assurance that management has implemented appropriate risk management and security assessment and authorization (SA&A) processes in accordance with the current CMS ARS, BPSSM, and other applicable policy including the following: • SA&A policies and procedures are documented, kept up-to- date, maintained and approved by management. • Security Assessments are planned and conducted • A corrective action management process is in place that includes planning, implementing, evaluating, and fully documenting remedial action addressing findings noted from all security audits and reviews of IT systems, components, and operations. Plan of Action and Milestones (POA&Ms) and corrective action plans are developed and monitored to address weaknesses. • Authorizing Official (AO) authorizes the information system for processing prior to commencing any operations and periodically thereafter. A.10 Controls provide reasonable assurance that management continuously monitors the effectiveness of the security program including security operations and completion of vulnerability assessments in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.11 Controls provide reasonable assurance that external third party activities of sub-service organizations (i.e. sub-contractors) are secure, documented, and monitored in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.12 - A.20 Access Controls and Segregation of Duties: Controls provide reasonable assurance that access to computer resources (data, equipment, and facilities) is reasonable and restricted to authorized individuals and that incompatible duties are effectively segregated. A.12 Controls provide reasonable assurance that access, including remote access, to significant computerized applications (such as claims processing), accounting systems, systems software, and Medicare data are appropriately authorized, documented, reviewed, and monitored and includes approval by resource owners, procedures to control emergency and temporary access and procedures to share and properly dispose of data. Procedures are performed timely and in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.13 Controls provide reasonable assurance that inactive logical access accounts and accounts for separated individuals are disabled and / or removed in a manner that satisfies the current CMS ARS, BPSSM, and other applicable policies. Control Objective – Information Systems A.14 Controls provide reasonable assurance that multifactor authentication is implemented in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.15 Controls provide reasonable assurance that password based authentication is configured in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.16 Controls provide reasonable assurance that access to sensitive system resources and privileged accounts / functions are restricted to individuals with a need-to-know and activities are appropriately logged and monitored. Additionally, Management segregates incompatible duties between various system and Medicare operations functionality which is supported by appropriate documentation, approvals, and monitoring. A.17 Controls provide reasonable assurance that management identifies system functions, events, and access permissions that require audit logging and implements an effective audit log monitoring capability in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.18 Controls provide reasonable assurance that management has documented, implemented, and approved an effective security operations and incident response program which includes processes to: a) identify and log suspicious activity, sensitive and privileged functions, and potential security events / incidents, b) monitor systems and networks audit logs, unusual activity, and / or intrusion attempts, c) correlate log data, d) analyze potential incidents, and e) report on security events, incidents, and intrusions in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.19 Controls provide reasonable assurance that physical access to sensitive IT areas (such as Medicare facilities, data centers and system hardware) by all employees, contractors, vendors, and/ or visitors is appropriately authorized, documented, and reviewed in accordance with the current CMS MAC ARS, BPSSM, and other applicable policy. A.20 Control number A.20 reserved. Control not in use as of this IOM revision. A.21 - A.26 Configuration Management: Controls provide reasonable assurance that changes to information system resources are authorized and systems are configured and operated securely and as intended. Control Objective – Information Systems A.21 Controls provide reasonable assurance that configuration management policies, plans, and procedures are established, documented, kept up-to-date, and approved in accordance with the current CMS ARS, BPSSM, and other applicable policy including the following: • A System Development Life Cycle (SDLC) methodology is documented and in use and aligns with the CMS Target Life Cycle (TLC). • Change management policies and procedures that have been developed, documented, and implemented include documented testing and approval of changes for regular and emergency changes. A.22 Controls provide reasonable assurance that Medicare application and related systems software development and maintenance activities (e.g. quarterly releases, off-quarterly releases, and emergency changes) are authorized, documented, tested, and approved in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.23 Controls provide reasonable assurance that access to program libraries is properly restricted and movement of programs among libraries is controlled. A.24 Controls provide reasonable assurance that management has established and consistently monitors information security related configuration for information technology in accordance with the current CMS ARS, BPSSM, and other applicable Federal standards and best practices including the following: • Develops and maintains a security configuration baseline for information technology that aligns with CMS requirements and industry standards. • Reviews the IT environment against the baseline. • Remediates misconfigurations in a timely fashion. • For misconfigurations that cannot be remediated timely, a plan of action and milestones (POA&M) or other corrective action plan is created, documented, and approved. • Deviations from CMS or other standards are analyzed and approved. • Results of periodic assessments are reported to CMS. Control Objective – Information Systems A.25 Controls provide reasonable assurance that management has established a vulnerability management program in accordance with the current CMS ARS, BPSSM, and other applicable policy that includes: • Scanning to identify vulnerabilities and unauthorized and unsupported software. • Disabling / removing unauthorized and unsupported software in a timely manner. • Remediation of vulnerabilities in a timely manner. • Creation of corrective action plans or POA&Ms if vulnerabilities cannot be remediated timely. Further, software is updated (patched) in a timely fashion to protect against vulnerabilities in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.26 Controls provide reasonable assurance that an effective virus, spam and spyware protection process is documented, approved, and implemented in accordance with the current CMS ARS, BPSSM, and other applicable policy. A.27 - A.28 Contingency Planning: Controls provide reasonable assurance that contingency planning: (1) protects information resources and minimizes the risk of unplanned interruptions and (2) provides for recovery of critical operations should interruptions occur. A.27 Controls provide reasonable assurance that information system backup and recovery procedures have been implemented in accordance with the current CMS ARS, BPSSM, and other applicable policy including: • Development, approval and maintenance of an up-to-date contingency plan and / or disaster recovery plan. • Periodic testing of contingency and / or disaster recovery plans. • Updating plans based on lessons learned. A.28 Controls provide reasonable assurance that appropriate environment protections for sensitive areas such as data centers are implemented in accordance with the current CMS ARS, BPSSM, and other applicable policy. End Section 50.1 – A Controls – Information Systems: Back to Table of Contents
Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 50.1: A Controls – Information Systems | Justis AI