Implement the MARS-E v2.0 Volume III Catalog of Minimum Acceptable Risk Security and Privacy Controls aligned with NIST 800-53 Moderate Baseline. FIPS 199 Security Categorization with Confidentiality Moderate + Integrity Moderate + Availability Moderate as default for Exchange systems. NIST 800-37 Risk Management Framework (RMF) 7-step process (Prepare + Categorize + Select + Implement + Assess + Authorize + Monitor). NIST 800-30 Risk Assessment + NIST 800-39 Risk Management. CMS-specific tailoring with MARS-E supplemental controls + parameter values + privacy controls overlay (Appendix J Privacy Control Families AP + AR + DI + DM + IP + SE + TR + UL based on NIST 800-53 Appendix J or NIST 800-53 Rev 5 integrated privacy). Coordination with CMS Acceptable Risk Safeguards (ARS) v3.1 + v5.0 for Medicare and Medicaid systems + FedRAMP Moderate Baseline for cloud-hosted Exchange components. ARS deviates from MARS-E on tailoring specific parameters but baseline alignment.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.