Skip to content

Maintenance (MA)

Domain: Maintenance (MA)
Requirements in this domain: 6
Assessment Objectives in this domain: 10


MA.L2-3.7.1

MA.L2-3.7.1[a]

Assessment Objective

system maintenance is performed.

Collection Approach: Artifact

Potential Evidence Examples

System maintenance records, maintenance contracts/SLAs, or a maintenance log covering the relevant infrastructure (e.g., HVAC, UPS, generators, hardware maintenance) showing routine maintenance is performed and tracked. (Distinct from SI.L2-3.14.1 patch/flaw remediation.)

Assessment Guide – Further Discussion

Are systems, devices, and supporting systems maintained per manufacturer recommendations or company defined schedules [a]?


MA.L2-3.7.2

MA.L2-3.7.2[a]

Assessment Objective

tools used to conduct system maintenance are controlled.

Collection Approach: Artifact

Potential Evidence Examples

Tool inventory/checkout log (or photo of a secured storage location) for maintenance tools (e.g., diagnostic laptops, network test equipment) showing responsible personnel and checkout dates/times are tracked.

Assessment Guide – Further Discussion

Are physical or logical access controls used to limit access to maintenance tools to authorized personnel [a]?


MA.L2-3.7.2[b]

Assessment Objective

techniques used to conduct system maintenance are controlled.

Collection Approach: Artifact

Potential Evidence Examples

Maintenance SOP describing the process for scheduling, performing, documenting, reviewing, and approving maintenance techniques used on organizational systems.

Assessment Guide – Further Discussion

Are physical or logical access controls used to limit access to system documentation and organizational maintenance process documentation to authorized personnel [b]?


MA.L2-3.7.2[c]

Assessment Objective

mechanisms used to conduct system maintenance are controlled.

Collection Approach: Artifact

Potential Evidence Examples

Maintenance SOP or ITSM record describing the mechanisms (tools/systems) used to schedule, perform, document, review, and monitor maintenance and repair activity.

Assessment Guide – Further Discussion

Are physical or logical access controls used to limit access to automated mechanisms (e.g., automated scripts, scheduled jobs) to authorized personnel [c]?


MA.L2-3.7.2[d]

Assessment Objective

personnel used to conduct system maintenance are controlled.

Collection Approach: Physical Review

Potential Evidence Examples

List of personnel authorized to perform system maintenance (internal staff or vendor), paired with any required maintenance-specific training or vetting record for those individuals.

Assessment Guide – Further Discussion

Are physical or logical access controls used to limit access to the system entry points that enable maintenance (e.g., administrative portals, local and remote console access, and physical equipment panels) to authorized personnel [d]?


MA.L2-3.7.3

MA.L2-3.7.3[a]

Assessment Objective

equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI.

Collection Approach: Artifact

Potential Evidence Examples

Media sanitization record/log showing equipment was sanitized of CUI prior to leaving organizational spaces for off-site maintenance, referencing the sanitization method/standard used (e.g., NIST SP 800-88).

Assessment Guide – Further Discussion

Is there a process for sanitizing (e.g., erasing, wiping, degaussing) equipment that was used to store, process, or transmit CUI before it is removed from the facility for off-site maintenance (e.g., manufacturer or contracted maintenance support) [a]?


MA.L2-3.7.4

MA.L2-3.7.4[a]

Assessment Objective

media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI.

Collection Approach: Artifact

Potential Evidence Examples

Screen share of endpoint anti-malware console showing diagnostic/test media or programs are scanned for malicious code (e.g., on-access/on-insert scan) before use on CUI systems.

Assessment Guide – Further Discussion

Are media containing diagnostic and test programs (e.g., downloaded or copied utilities or tools from manufacturer, third-party, or in-house support teams) checked for malicious code (e.g., using antivirus or antimalware scans) before the media are used on organizational systems [a]?


MA.L2-3.7.5

MA.L2-3.7.5[a]

Assessment Objective

multifactor authentication is required to establish nonlocal maintenance sessions via external network connections.

Collection Approach: Screen Share

Potential Evidence Examples

Screen share of the MFA enforcement configuration for nonlocal (remote) maintenance connections established via external network connections, demonstrating MFA is required before a remote maintenance session can be established.

Assessment Guide – Further Discussion

Is multifactor authentication required prior to maintenance of a system when connecting remotely from outside the system boundary [a]?


MA.L2-3.7.5[b]

Assessment Objective

nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete.

Collection Approach: Screen Share

Potential Evidence Examples

Screen share of VPN/remote-session timeout configuration or session log showing nonlocal maintenance connections are terminated once the maintenance activity is complete (e.g., automatic session teardown, explicit disconnect logged).

Assessment Guide – Further Discussion

Are personnel required to manually terminate remote maintenance sessions established via external network connections when maintenance is complete, or are connections terminated automatically through system session management mechanisms [b]?


MA.L2-3.7.6

MA.L2-3.7.6[a]

Assessment Objective

maintenance personnel without required access authorization are supervised during maintenance activities.

Collection Approach: Document

Potential Evidence Examples

Maintenance Policy/SOP, escort log, or supervision record showing maintenance personnel without the required access authorization (e.g., third-party vendor technicians) are supervised by an authorized individual for the duration of the maintenance activity.

Assessment Guide – Further Discussion

Are there processes for escorting and supervising maintenance personnel without required access authorization (e.g., vendor support personnel, short-term maintenance contractors) during system maintenance [a]?