Skip to content

3.7.4 — Scan Maintenance Media

Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.

Any media — USB drives, downloaded diagnostic tools, vendor-provided software — must be scanned for malware before connecting to or running on CUI systems. This applies to both internal and vendor-supplied media. The scan must use current AV/EDR signatures.


Your assessor needs a “yes” to every row:

#QuestionWhat “yes” looks like
1Is maintenance media scanned for malicious code before use?Procedure documented; scan records showing media checked before connecting to CUI systems

Documents they’ll review: Maintenance policy; procedures for scanning maintenance media; scan records showing clean results before CUI system use; hash verification records for vendor tools; system security plan

People they’ll talk to: Maintenance personnel; information security personnel

Live demos they’ll ask for: “Show me how you scan vendor media before use.” “Where do you scan — on the CUI system or a separate station?”


  • “How do you scan maintenance media before use? Show me the procedure.”
  • “Do you verify file hashes for vendor-provided tools?”
  • “Are scan signatures current when you scan maintenance media?”

No scanning. Media plugged directly into CUI systems without scanning. Always scan first — preferably on an isolated workstation.

Vendor media trusted implicitly. “It’s from our vendor so it’s safe.” Trust but verify — scan everything regardless of source.

Outdated scan signatures. Scanning with week-old definitions defeats the purpose. Update signatures before each scan session.



RequirementWhy it matters here
3.7.2 — Control Maintenance ToolsMedia scanning is part of the broader maintenance tool control
3.14.2 — Deploy Anti-MalwareThe AV/EDR used for scanning maintenance media
3.14.5 — Scan RegularlyReal-time scanning for files from external sources

🔒

Step-by-step guides for Microsoft 365, AWS, Azure, and GCP are available to Ancitus clients.

Start a conversation →

CMMC Practice ID: MA.L2-3.7.4 | SPRS Weight: 3 points | POA&M Eligible: No