Maintenance (MA)¶
Domain: Maintenance (MA)
Requirements in this domain: 6
Assessment Objectives in this domain: 10
MA.L2-3.7.1¶
MA.L2-3.7.1[a]¶
Assessment Objective
system maintenance is performed.
Collection Approach: Artifact
Potential Evidence Examples
System maintenance records, maintenance contracts/SLAs, or a maintenance log covering the relevant infrastructure (e.g., HVAC, UPS, generators, hardware maintenance) showing routine maintenance is performed and tracked. (Distinct from SI.L2-3.14.1 patch/flaw remediation.)
Assessment Guide – Further Discussion
Are systems, devices, and supporting systems maintained per manufacturer recommendations or company defined schedules [a]?
MA.L2-3.7.2¶
MA.L2-3.7.2[a]¶
Assessment Objective
tools used to conduct system maintenance are controlled.
Collection Approach: Artifact
Potential Evidence Examples
Tool inventory/checkout log (or photo of a secured storage location) for maintenance tools (e.g., diagnostic laptops, network test equipment) showing responsible personnel and checkout dates/times are tracked.
Assessment Guide – Further Discussion
Are physical or logical access controls used to limit access to maintenance tools to authorized personnel [a]?
MA.L2-3.7.2[b]¶
Assessment Objective
techniques used to conduct system maintenance are controlled.
Collection Approach: Artifact
Potential Evidence Examples
Maintenance SOP describing the process for scheduling, performing, documenting, reviewing, and approving maintenance techniques used on organizational systems.
Assessment Guide – Further Discussion
Are physical or logical access controls used to limit access to system documentation and organizational maintenance process documentation to authorized personnel [b]?
MA.L2-3.7.2[c]¶
Assessment Objective
mechanisms used to conduct system maintenance are controlled.
Collection Approach: Artifact
Potential Evidence Examples
Maintenance SOP or ITSM record describing the mechanisms (tools/systems) used to schedule, perform, document, review, and monitor maintenance and repair activity.
Assessment Guide – Further Discussion
Are physical or logical access controls used to limit access to automated mechanisms (e.g., automated scripts, scheduled jobs) to authorized personnel [c]?
MA.L2-3.7.2[d]¶
Assessment Objective
personnel used to conduct system maintenance are controlled.
Collection Approach: Physical Review
Potential Evidence Examples
List of personnel authorized to perform system maintenance (internal staff or vendor), paired with any required maintenance-specific training or vetting record for those individuals.
Assessment Guide – Further Discussion
Are physical or logical access controls used to limit access to the system entry points that enable maintenance (e.g., administrative portals, local and remote console access, and physical equipment panels) to authorized personnel [d]?
MA.L2-3.7.3¶
MA.L2-3.7.3[a]¶
Assessment Objective
equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI.
Collection Approach: Artifact
Potential Evidence Examples
Media sanitization record/log showing equipment was sanitized of CUI prior to leaving organizational spaces for off-site maintenance, referencing the sanitization method/standard used (e.g., NIST SP 800-88).
Assessment Guide – Further Discussion
Is there a process for sanitizing (e.g., erasing, wiping, degaussing) equipment that was used to store, process, or transmit CUI before it is removed from the facility for off-site maintenance (e.g., manufacturer or contracted maintenance support) [a]?
MA.L2-3.7.4¶
MA.L2-3.7.4[a]¶
Assessment Objective
media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI.
Collection Approach: Artifact
Potential Evidence Examples
Screen share of endpoint anti-malware console showing diagnostic/test media or programs are scanned for malicious code (e.g., on-access/on-insert scan) before use on CUI systems.
Assessment Guide – Further Discussion
Are media containing diagnostic and test programs (e.g., downloaded or copied utilities or tools from manufacturer, third-party, or in-house support teams) checked for malicious code (e.g., using antivirus or antimalware scans) before the media are used on organizational systems [a]?
MA.L2-3.7.5¶
MA.L2-3.7.5[a]¶
Assessment Objective
multifactor authentication is required to establish nonlocal maintenance sessions via external network connections.
Collection Approach: Screen Share
Potential Evidence Examples
Screen share of the MFA enforcement configuration for nonlocal (remote) maintenance connections established via external network connections, demonstrating MFA is required before a remote maintenance session can be established.
Assessment Guide – Further Discussion
Is multifactor authentication required prior to maintenance of a system when connecting remotely from outside the system boundary [a]?
MA.L2-3.7.5[b]¶
Assessment Objective
nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete.
Collection Approach: Screen Share
Potential Evidence Examples
Screen share of VPN/remote-session timeout configuration or session log showing nonlocal maintenance connections are terminated once the maintenance activity is complete (e.g., automatic session teardown, explicit disconnect logged).
Assessment Guide – Further Discussion
Are personnel required to manually terminate remote maintenance sessions established via external network connections when maintenance is complete, or are connections terminated automatically through system session management mechanisms [b]?
MA.L2-3.7.6¶
MA.L2-3.7.6[a]¶
Assessment Objective
maintenance personnel without required access authorization are supervised during maintenance activities.
Collection Approach: Document
Potential Evidence Examples
Maintenance Policy/SOP, escort log, or supervision record showing maintenance personnel without the required access authorization (e.g., third-party vendor technicians) are supervised by an authorized individual for the duration of the maintenance activity.
Assessment Guide – Further Discussion
Are there processes for escorting and supervising maintenance personnel without required access authorization (e.g., vendor support personnel, short-term maintenance contractors) during system maintenance [a]?