MARS-E
Cross-Program Coordination - MARS-E v2.0

MARS-E MARS-E-Cross-Program-Coordination-IRS-Pub-1075-FedRAMP-CMS-ARS-HHS-OIG-Joint-Audit-3PAO: MARS-E Cross-Program + IRS Pub 1075 + FedRAMP + CMS ARS + HHS OIG + Joint Audit + 3PAO

Coordinate MARS-E compliance with adjacent federal programmes and audit regimes. IRS Publication 1075 (Safeguarding Federal Tax Information) compliance for Federal Tax Information (FTI) processing under IRC Section 6103 + Safeguard Procedures Report (SPR) every 6 years + Safeguard Activity Report (SAFER) annually + IRS Safeguard Review (on-site) every 3 years + IRS Office of Safeguards coordination. FedRAMP Moderate Baseline for cloud-hosted Exchange components + Joint Authorization Board (JAB) Provisional ATO or Agency-issued ATO + continuous monitoring through FedRAMP Continuous Monitoring + annual 3PAO assessment + monthly POAM updates. CMS Acceptable Risk Safeguards (ARS) v3.1 / v5.0 alignment for parallel Medicare and Medicaid systems. CMS Cybersecurity and Risk Assessment Program (CRISP) integration. HHS OIG Office of Inspector General oversight authority + GAO Government Accountability Office audit cooperation. Joint MARS-E + IRS Pub 1075 + HIPAA + FedRAMP audit coordination to reduce duplication. SBM-to-FFM data exchange agreements + Data Sharing Agreements (DSAs) + Computer Matching Agreements (CMAs) under Privacy Act of 1974. State Medicaid + CHIP coordination via CMS-state Memoranda of Understanding (MOUs). State Attorney General notification for state-specific breach laws. CMS quarterly status reporting + annual ATO recertification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 165 controls across 53 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 8 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-24 Logging and monitoring

ISO/SAE 21434 · 8 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-24 Logging and monitoring

BSI IT-Grundschutz · 7 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

ISO 27799:2025 · 6 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-05 Audit trail for ePHI access
  • ISO27799-08 Information access management
  • ISO27799-16 Transmission security and encryption
  • ISO27799-17 Facility access controls
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.4 Audit Logging and Monitoring

OWASP ASVS · 5 controls

ISO/IEC 27011:2024 · 4 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices
  • 27011-8.3 Cryptography and key management
  • 27011-8.4 Logging and monitoring
  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response

OWASP Top 10:2025 · 4 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

South Korea ISMS-P · 4 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-03 Security Monitoring and Log Management

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • CAT-D3-1 Preventative controls
  • CAT-D3-2 Detective controls
  • CAT-D4-3 Third-party access controls

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity
  • 62351-14 Cyber security event logging
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27010:2015 · 3 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

APPI · 2 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 2 controls

  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

MITRE D3FEND · 2 controls

Malaysia PDPA 2010 · 2 controls

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing
  • MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.2 Access Control
  • ASD37-17 TLS encryption between email servers (Limited)
  • CA-ITSG33-SC-01 Security Control Catalogue
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services
  • ISO-25012-4.11 Traceability

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • 29115-7.4 Level of Assurance 4 (LoA4)

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 165 it maps to, and the evidence behind each claim, over MCP and REST.