CMMC Domain MA Maintenance
100% of computer systems will fail, eventually. These practices define a strategy to limit opportunities which may expose critical data and services to intentional, or unintentional, misconfiguration, malicious code, and outages.
- MA.L2-3.7.1
- Perform Maintenance: Perform maintenance on organizational systems.
- MA.L2-3.7.5
- Nonlocal Maintenance: Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.
- MA.L2-3.7.6
- Maintenance Personnel: Supervise the maintenance activities of maintenance personnel without required access authorization.
- MA.L2-3.7.3
- Equipment Sanitization: Ensure equipment removed for off-site maintenance is sanitized of any CUI.
- MA.L2-3.7.2
- System Maintenance Control: Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
- MA.L2-3.7.4
- Media Inspection: Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.