Security Catapult logo

Security Catapult

  • Pricing
  • CMMC Docs
    CMMC Overview & FAQ CMMC Level 1 Reference CMMC Level 2 Reference
  • Sign in
  • Sign up
  • Overview
  • Level 1
  • Level 2

CMMC Domain MA Maintenance

100% of computer systems will fail, eventually. These practices define a strategy to limit opportunities which may expose critical data and services to intentional, or unintentional, misconfiguration, malicious code, and outages.

MA.L2-3.7.6
Maintenance Personnel: Supervise the maintenance activities of maintenance personnel without required access authorization.
MA.L2-3.7.1
Perform Maintenance: Perform maintenance on organizational systems.
MA.L2-3.7.5
Nonlocal Maintenance: Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.
MA.L2-3.7.3
Equipment Sanitization: Ensure equipment removed for off-site maintenance is sanitized of any CUI.
MA.L2-3.7.2
System Maintenance Control: Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
MA.L2-3.7.4
Media Inspection: Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
Security Catapult logo Security Catapult
Site
  • Pricing
  • Sign in
  • Sign up
CMMC Docs
  • Maturity Level 1
  • Maturity Level 2
  • Maturity Level 3
SPRS and NIST
  • Get your SPRS score
About
  • Assessments
  • Security Advisors
  • Terms of Use
  • Privacy Policy
© 2025 Monarch ISC, Inc. All Rights Reserved.
Contact Us

Sign up for free or enter your email address below and we'll get in touch.

We respect your privacy and will not remarket your information.