CMS Implementation Guidance
CMS SSP 'guidance' text has been omitted from the Strike Graph framework 'tree'. Use this document as a reference for relevant guidance.
Written By Micah
Control guidance is not provided for most controls so the organization should leverage the most current NIST SP 800-53 for guidance. However, for the following controls, control guidance has been provided specific to the CMS SSP:
AC-2: Account Management: EDE Program - The EDE Entity must prohibit multiple accounts associated with one FFE User ID. The EDE Entity account management must demonstrate that an attempt to create another account using the same FFE User ID is blocked.
AC-10: Concurrent Session Control - A session is defined as an encounter between an end-user interface device (e.g., computer, terminal, process) and an application, including a network logon. One user session is the time between starting the application and quitting.
EDE Program - The EDE Entity must prohibit concurrent session using a single set of agent/broker credentials. See AC-2: Account Management EDE Program guidance.
AC-17: Remote Access - Remote access is access to organizational information systems by users (or processes acting on behalf of users) communicating through external networks (e.g., the Internet). Remote access methods include, for example, dial-up, broadband, and wireless. Organizations often employ encrypted virtual private networks (VPN) to enhance confidentiality and integrity over remote connections. The use of encrypted VPNs does not make the access non-remote; however, when adequately provisioned with appropriate security controls (e.g., employing appropriate encryption techniques for confidentiality and integrity protection) VPNs may provide sufficient assurance to the organization that it can effectively treat such connections as internal networks.
VPN connections traverse external networks, and the encrypted VPN does not enhance the availability of remote connections. VPNs with encrypted tunnels can affect the organizational capability to adequately monitor network communications traffic for malicious code. Remote access controls apply to information systems other than public web servers or systems designed for public access. This control addresses authorization prior to allowing remote access without specifying the formats for such authorization. Although organizations may use interconnection security agreements to authorize remote access connections, this control does not require such agreements. Enforcing access restrictions for remote connections is addressed in AC-3.
Limiting access to personally identifiable information (PII) from remote networks and/or restricting activities that can be conducted with PII remotely reduces the risk of intentional and unintentional disclosures of PII that may not exist on an internal network. Allow remote access to PII only with multi-factor authentication where one of the factors is provided by a device separate from the computer granting access.
Implement technical security measures to guard against unauthorized remote access to PII transmitted over an electronic communications network.
EDE Program – Access to the FFEs and SBE-FPs. EDE Entity and its assignees or subcontractors—including, employees, developers, agents, representatives, or contractors—cannot remotely connect or transmit data to the FFE, SBE-FP or its testing environments, nor remotely connect or transmit data to EDE Entity’s systems that maintain connections to the FFE, SBE-FP or its testing environments, from locations outside of the United States of America or its territories, embassies, or military installations. This includes any such connection through VPN.
TR-1: Privacy Notice - In keeping with the standards and implementation specifications used by the FFEs, a Non-Exchange Entity must ensure openness and transparency about policies, procedures, and technologies that directly affect Consumers, Applicants, Qualified Individuals, and Enrollees and their PII.
Prior to collecting PII, the Non-Exchange Entity must provide a notice that is prominently and conspicuously displayed on a public-facing website, if applicable, or on the electronic and/or paper form the Non-Exchange Entity will use to gather and/or request PII.
The statement must be written in plain language and provided in a manner that is timely and accessible to people living with disabilities and with limited English proficiency.
The statement must contain at a minimum the following information:
a. Legal authority to collect PII;
b. Purpose of the information collection;
c. To whom PII might be disclosed, and for what purposes;
d. Authorized uses and disclosures of any collected information;
e. Whether the request to collect PII is voluntary or mandatory under the applicable law; and
f. Effects of non-disclosure if an individual chooses not to provide the requested information.
The Non-Exchange Entity shall maintain its Privacy Notice Statement content by reviewing and revising as necessary on an annual basis, at a minimum, and before or as soon as possible after any change to its privacy policies and procedures.
If the Non-Exchange Entity operates a website, it shall ensure that descriptions of its privacy and security practices, and information on how to file complaints with CMS and the Non-Exchange Entity, are publicly available through its website.