CMMC Domain MA Maintenance
100% of computer systems will fail, eventually. These practices define a strategy to limit opportunities which may expose critical data and services to intentional, or unintentional, misconfiguration, malicious code, and outages.
- MA.L2-3.7.1
- Perform maintenance on organizational systems.
- MA.L2-3.7.5
- Require multifactor authentication to establish non-local maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.
- MA.L2-3.7.4
- Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
- MA.L2-3.7.6
- Supervise the maintenance activities of personnel without required access authorization.
- MA.L2-3.7.2
- Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
- MA.L2-3.7.3
- Ensure equipment removed for off-site maintenance is sanitized of any CUI.