Skip to content

Maintenance

Maintenance covers how you keep systems running without creating security gaps. Patching, vendor repairs, remote maintenance, and physical servicing all need controls.

Maintenance Operations (3.7.1–3.7.4) — Perform maintenance on schedule, control the tools and media used, wipe CUI before off-site repair, and scan vendor media before use.

Personnel & Access (3.7.5–3.7.6) — Require MFA for remote maintenance sessions and supervise uncleared maintenance technicians at all times.


RefShort NameWhat It Covers
3.7.1Maintain on ScheduleRegular documented maintenance
3.7.2Control Maintenance ToolsApproved tools, inspected vendor equipment
3.7.3Wipe Before RepairSanitize CUI before off-site maintenance
3.7.4Scan Maintenance MediaCheck diagnostic media for malware
3.7.5MFA for Remote MaintenanceMFA required, session terminated when done
3.7.6Escort Uncleared TechsSupervise unauthorized maintenance personnel