MARS-E
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access Control and Identity Authentication - MARS-E v2.0
Implement NIST 800-53 AC Access Control family + IA Identification and Authentication family per MARS-E v2.0 catalog. NIST 800-63-3 Identity Assurance Level 2 (IAL2) + Authenticator Assurance Level 2 (AAL2) + Federation Assurance Level 2 (FAL2) for Exchange consumer authentication + IAL3 + AAL3 for administrative access. Identity proofing via Experian + LexisNexis + manual document review + biometric verification. Multi-Factor Authentication (MFA) mandatory for all administrative access + remote access + privileged operations. Role-Based Access Control (RBAC) with separation of duties (Eligibility Adjudicator + System Administrator + Privacy Officer + Security Officer). Least privilege enforcement. Account management lifecycle (provisioning + recertification + deprovisioning) with quarterly recertification. Privileged Access Management (PAM) with session recording for privileged users. R
- NIST 800-63-3 IAL2 + AAL2 evidence for consumers + IAL3 + AAL3 for admin
- MFA enforcement evidence (all admin + remote + privileged)
- RBAC matrix with separation of duties (Eligibility Adjudicator + Sysadmin + Privacy Officer + Security Officer)
- Quarterly access recertification records
- Privileged Access Management (PAM) tooling and session recording evidence
- Federal Data Services Hub + IRS + SSA + DHS trust documentation
- IAL2/AAL2 identity proofing relies on knowledge-based authentication (KBA) only - non-compliant post NIST 800-63-3 Rev 4
- MFA not enforced for all admin paths (e.g. break-glass accounts)
- Quarterly recertification missed
- PAM session recording not retained 7 years
Audit Accountability and Continuous Monitoring - MARS-E v2.0
Implement NIST 800-53 AU Audit and Accountability family + CM Configuration Management family + Information System Continuous Monitoring (ISCM) program per MARS-E v2.0. Audit events include logon + logoff + privileged operations + access to PII or PHI or FTI + administrative actions + configuration changes + security tool events + suspected unauthorised activity. Audit log retention minimum 90 days online + 7 years offline (1 year HIPAA + 6 years HIPAA-extended + IRS Pub 1075 minimum 6 years + state retention). Centralised SIEM (Security Information and Event Management) with SOC monitoring. Audit log integrity protection via cryptographic hashing + WORM (Write Once Read Many) storage + access restrictions. Configuration management with approved baseline + change control board + drift detection. Continuous monitoring under NIST 800-137 ISCM with monthly reporting to CMS. Vulnerability sc
- Audit event coverage matrix mapped to MARS-E AU-1 to AU-12
- SIEM correlation rules + 24x7 SOC monitoring evidence
- Audit log retention proof (90-day online + 7-year offline)
- Log integrity protection (cryptographic hashing + WORM)
- Configuration management baseline + change control board records + drift detection
- Vulnerability scanning records (weekly internal + monthly external)
- Annual 3PAO assessment report
- IRS Pub 1075 Section 5 separate FTI audit trail
- Audit retention under 7 years (IRS Pub 1075 violation)
- SIEM has no FTI-specific rules
- Configuration baseline not maintained
- 3PAO assessment lapsed
Contingency Media Protection System Integrity - MARS-E v2.0
Implement NIST 800-53 CP Contingency Planning + MP Media Protection + SI System and Information Integrity families per MARS-E v2.0. Contingency Planning with Business Impact Analysis (BIA) + Recovery Time Objective (RTO) of 24 hours for Exchange consumer-facing systems + 48 hours for administrative + Recovery Point Objective (RPO) of 4 hours. Backup strategy with daily incremental + weekly full + off-site replication + tested restore quarterly. Disaster Recovery (DR) site geographically separated + tested annually full-scale. Continuity of Operations Plan (COOP) for Exchange essential functions during open enrolment + special enrolment periods. Media Protection with media marking + access controls + sanitisation per NIST 800-88 (clear + purge + destroy) + media transport protections + media accountability. Encryption FIPS 140-2 / 140-3 validated cryptographic modules for PII + PHI + FTI
- BIA + RTO 24-hour consumer / 48-hour admin + RPO 4-hour evidence
- Backup strategy + quarterly restore test logs + off-site replication
- Annual DR full-scale test report
- COOP for open enrolment + special enrolment
- FIPS 140-2/140-3 cryptographic module inventory
- TLS 1.2+ enforcement (TLS 1.3 preferred) + AES-256 at rest
- Media sanitisation records per NIST 800-88
- Flaw remediation SLA evidence (30-day critical + 90-day high)
- DR test annual but not full-scale
- FIPS 140 modules expired or end-of-life
- TLS 1.1 still enabled on some endpoints
- Critical flaw remediation exceeds 30 days
Cross-Program Coordination - MARS-E v2.0
Coordinate MARS-E compliance with adjacent federal programmes and audit regimes. IRS Publication 1075 (Safeguarding Federal Tax Information) compliance for Federal Tax Information (FTI) processing under IRC Section 6103 + Safeguard Procedures Report (SPR) every 6 years + Safeguard Activity Report (SAFER) annually + IRS Safeguard Review (on-site) every 3 years + IRS Office of Safeguards coordination. FedRAMP Moderate Baseline for cloud-hosted Exchange components + Joint Authorization Board (JAB) Provisional ATO or Agency-issued ATO + continuous monitoring through FedRAMP Continuous Monitoring + annual 3PAO assessment + monthly POAM updates. CMS Acceptable Risk Safeguards (ARS) v3.1 / v5.0 alignment for parallel Medicare and Medicaid systems. CMS Cybersecurity and Risk Assessment Program (CRISP) integration. HHS OIG Office of Inspector General oversight authority + GAO Government Accountab
- IRS Pub 1075 Safeguard Procedures Report (SPR) every 6 years + SAFER annual + IRS Safeguard Review every 3 years
- FedRAMP Moderate ATO (JAB Provisional or Agency-issued) + continuous monitoring evidence
- CMS ARS v3.1/v5.0 cross-walk
- HHS OIG audit cooperation records
- GAO audit response records
- SBM-to-FFM Data Sharing Agreements + Computer Matching Agreements under Privacy Act 1974
- State Medicaid + CHIP MOU coordination
- Joint MARS-E + IRS Pub 1075 + HIPAA + FedRAMP audit calendar
- IRS SPR overdue
- FedRAMP ConMon monthly POAM not submitted
- CMS ARS cross-walk not maintained
- Computer Matching Agreement (CMA) under Privacy Act not in place
Incident Response and Breach Notification - MARS-E v2.0
Implement NIST 800-53 IR Incident Response family + breach notification process integrated across HIPAA + ACA + IRS Pub 1075. Incident response capability with 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incident response plan + tabletop and live exercises annually. Categorisation per US-CERT incident categories + CMS Incident Response Team (IRT) coordination + DHS/CISA reporting for major incidents. HIPAA Breach Notification Rule 45 CFR 164.400-414 (60 days to affected individuals + 60 days to HHS + media notification if 500+ residents in state). Risk Assessment (Acquisition + Unauthorised Access + Disposition + Identification) for PHI breaches per HHS guidance. ACA Section 1411 breach notification to CMS + affected consumers. IRS Pub 1075 Section 10 incident reporting (within 1 hour for known + 24 hours for suspected disclosure of FTI). State breach notification law c
- Incident Response Plan + tabletop and live exercise records (annual)
- 24x7 SOC + CSIRT structure documentation
- HIPAA breach notification 60-day timeline evidence (individuals + HHS + media)
- ACA Section 1411 CMS breach notification process + CMS IRT coordination protocol
- IRS Pub 1075 Section 10 incident reporting (1-hour known + 24-hour suspected)
- State breach notification compliance matrix (47 states + DC)
- DHS/CISA reporting for major incidents
- Post-incident review and lessons learned
- No IRS Pub 1075 1-hour reporting workflow
- Multi-state notification not pre-mapped
- CMS IRT escalation contact stale
- Annual tabletop not conducted
Privacy PII PHI Protection - MARS-E v2.0
Protect Personally Identifiable Information (PII) and Protected Health Information (PHI) handled by Exchanges. Apply NIST 800-122 PII Confidentiality Impact Level determination + minimum necessary standard for use disclosure and request + HIPAA Privacy Rule 45 CFR 164 Subpart E (Privacy of Individually Identifiable Health Information) where applicable + ACA Section 1411 information requirements + 45 CFR 155.260(a)(3) privacy and security requirements. Implement notice of privacy practices for Exchange consumers. Honor opt-out and choice mechanisms. De-identification under HIPAA Safe Harbor or Expert Determination. Limited Data Set procedures with Data Use Agreements. Tax Filing Status disclosure restrictions. Beneficiary consent for information sharing across Exchange + Medicaid + CHIP + plan issuers. Strict controls for sharing with Federal Data Services Hub. Annual privacy training. Pr
- Notice of Privacy Practices for Exchange consumers
- PII/PHI inventory + Confidentiality Impact Level per NIST 800-122
- Minimum necessary standard documentation per use disclosure and request
- Privacy Officer designation + Privacy Impact Assessment per OMB M-03-22 + CMS PIA template
- De-identification procedures (Safe Harbor + Expert Determination)
- Data Use Agreements for Limited Data Sets
- Annual privacy training records
- NIST 800-122 PII confidentiality impact level not determined
- No CMS PIA on file
- Limited Data Set procedures missing for research uses
- Privacy training not annual or not all-hands
Scope and Authority - MARS-E v2.0
Establish MARS-E applicability scope for ACA Affordable Care Act Section 1311 Health Insurance Exchanges. CMS Centers for Medicare and Medicaid Services + CCIIO Center for Consumer Information and Insurance Oversight under HHS Department of Health and Human Services is the issuing and oversight authority. Required for all State-Based Marketplaces (SBM) + State-Based Exchanges on Federal Platform (SBE-FP) + Federally-Facilitated Marketplace (FFM) HealthCare.gov + Exchange agents and brokers + non-Exchange entities receiving Exchange data. 45 CFR 155.260 Privacy and Security Standards + 45 CFR 155.270 Use of Standards and Protocols for Electronic Transactions + 45 CFR 155.280 Oversight and Monitoring. ACA Section 1311(d)(4)(B) + Section 1411 + Section 1412 + Section 1413 statutory anchors. CMS Federal Data Services Hub interface authorization required. State Medicaid Modernization projects
- MARS-E applicability assessment + Exchange categorisation (SBM + SBE-FP + FFM)
- CMS Federal Data Services Hub Interconnection Security Agreement (ISA)
- Authorization to Operate (ATO) Letter + System Security Plan (SSP) + Security Assessment Report (SAR) + Plan of Action and Milestones (POAM)
- 45 CFR 155.260 / 155.270 / 155.280 compliance evidence
- State Medicaid Modernization MARS-E cross-walk where applicable
- No ATO letter or expired
- Federal Data Services Hub ISA not refreshed
- v2.0 to v2.2 upgrade gap analysis missing
- State Medicaid Modernization scope not assessed
Security Control Catalog NIST 800-53 Moderate Baseline - MARS-E v2.0
Implement the MARS-E v2.0 Volume III Catalog of Minimum Acceptable Risk Security and Privacy Controls aligned with NIST 800-53 Moderate Baseline. FIPS 199 Security Categorization with Confidentiality Moderate + Integrity Moderate + Availability Moderate as default for Exchange systems. NIST 800-37 Risk Management Framework (RMF) 7-step process (Prepare + Categorize + Select + Implement + Assess + Authorize + Monitor). NIST 800-30 Risk Assessment + NIST 800-39 Risk Management. CMS-specific tailoring with MARS-E supplemental controls + parameter values + privacy controls overlay (Appendix J Privacy Control Families AP + AR + DI + DM + IP + SE + TR + UL based on NIST 800-53 Appendix J or NIST 800-53 Rev 5 integrated privacy). Coordination with CMS Acceptable Risk Safeguards (ARS) v3.1 + v5.0 for Medicare and Medicaid systems + FedRAMP Moderate Baseline for cloud-hosted Exchange components.
- MARS-E v2.0 Volume III Catalog implementation matrix with NIST 800-53 Moderate Baseline tailoring
- NIST 800-37 RMF 7-step process evidence (Prepare + Categorize + Select + Implement + Assess + Authorize + Monitor)
- FIPS 199 Security Categorization documentation (C-Mod + I-Mod + A-Mod default)
- Risk Assessment per NIST 800-30 + Risk Treatment Plan
- CMS ARS cross-walk for hybrid systems
- FedRAMP Moderate Baseline alignment evidence for cloud components
- FIPS 199 categorization not refreshed annually
- MARS-E v2.0 catalog not fully implemented (POAM-driven)
- FedRAMP Moderate alignment claimed but not 3PAO-attested
- Risk Treatment Plan not board-approved
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the MARS-E framework page.