Organizational Control: Controlled Maintenance
Control ID: MA-2 Controlled Maintenance | Family: Maintenance | Source: NIST 800-53r4 |
Control: The organization:
|
||
Supplemental Guidance: This control addresses the information security aspects of the information system maintenance program and applies to all types of maintenance to any system component (including applications) conducted by any local or nonlocal entity (e.g.,in-contract, warranty, in-house, software maintenance agreement). System maintenance also includes those components not directly associated with information processing and/or data/information retention such as scanners, copiers, and printers. Information necessary for creating effective maintenance records includes, for example: (i) date and time of maintenance; (ii) name of individuals or group performing the maintenance; (iii) name of escort, if necessary; (iv) a description of the maintenance performed; and (v) information system components/equipment removed or replaced (including identification numbers, if applicable). The level of detail included in maintenance records can be informed by the security categories of organizational information systems. Organizations consider supply chain issues associated with replacement components for information systems. Related Controls: CM-3, CM-4, MA-4, MP-6, PE-16, SA-12, SI-2 |
||
Control Enhancements:
(1) Controlled Maintenance | Automated Maintenance Activities The organization:
Supplemental Guidance: Related Controls: CA-7, MA-3 |
||
References: N/A | ||
Mechanisms:
|
||
Protocol Implementation Conformance Statements: N/A |