Risk Management & Reporting

CMS Information System Contingency Plan (ISCP) Exercise Handbook

Contingency Planning at CMS 

Contingency planning at the Center for Medicare and Medicaid Services (CMS) is essential for protecting the organization from potential risks and ensuring the continuity of its operations. An Information System Contingency Plan (ISCP) is the cornerstone document of contingency planning for information systems, and every CMS FISMA system must have one in place.

Risk Management Handbook Chapter 13: Personnel Security (PS)

Introduction

The Risk Management Handbook Chapter 13: Personnel Security discusses how the organization must: ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions prior to issuing any security credentials or providing authorized access to Federal information systems; ensure that organizational information and information systems are protected during and after personnel actions such as terminations and transfers; and employ formal sanction

Risk Management Handbook Chapter 5: Configuration Management (CM)

Introduction

This Handbook outlines procedures to help CMS staff and contractors implement the Configuration Management family of controls taken from the National Institute of Standards and Technology (NIST) Special Publication 800-53 and tailored to the CMS environment in the CMS Acceptable Risk Safeguards (ARS). For more guidance on how to implement CMS policies and standards across many cybersecurity topics, see the CMS Security and Privacy Handbooks.