Security Operations
Overview
Security Operations at CMS is focused on identifying and responding to cyber threats or incidents, while helping CMS teams follow best practices in continuous monitoring, risk management, and cybersecurity.
The CMS Cybersecurity Integration Center (CCIC) and Security Operations Center (SOC) offer a variety of services and assessments to help your team comply with federal information security standards and make risk-based decisions to protect sensitive information.
All resources in Security Operations
General Information
Policies and Handbooks
Latest articles and updates
- 12/3/2025ArticlesFrom Zero Trust
Linking encryption to power Zero Trust
Linking network and data encryption with programmatic Key Management Service (KMS) alerts is essential for CMS to achieve advanced Zero Trust maturity
- 8/20/2025UpdatesFrom Zero Trust
Bridging the Gap: Introducing the CMS Zero Trust Forge
An introduction to a new tool to scope granular, least privilege Kion Cloud AWS IAM Policies and Roles
- 8/18/2025ArticlesFrom Zero Trust
Privileged Access Management (PAM) at CMS
Least-privilege is critical to securely managing privileged access to data. CMS ADOs should manage privileged access (PAM) for humans and non-humans.