CMMC Practice Number: MA.L2-3.7.1
CMMC Level: 2 CMMC Domain: Maintenance (MA)
Practice Summary:
Perform maintenance on organizational systems.
Contents:
CMMC Practice Implementation |
Assessment Objectives
Determine if:
[a] system maintenance is performed.
Practice Clarification (DOD, CMU)
One common form of computer security maintenance is regular patching of discovered vulnerabilities in software and operating systems, though there are others that require attention.
System maintenance includes:
• corrective maintenance (e.g., repairing problems with the technology),
• preventative maintenance (e.g., updates to prevent potential problems),
• adaptive maintenance (e.g., changes to the operative environment), and
• perfective maintenance (e.g., improve operations) [a].
Example
You are responsible for maintenance activities on your company’s machines. This includes regular planned maintenance, unscheduled maintenance, reconfigurations when required, and damage repairs [a]. You know that failing to conduct maintenance activities can impact system security and availability, so you ensure that maintenance is regularly performed. You track all maintenance performed to assist with troubleshooting later if needed.
Potential Assessment Considerations
• Are systems, devices, and supporting systems maintained per manufacturer recommendations or company defined schedules [a]?
Where To Look
- System maintenance policy;
- procedures addressing controlled system maintenance;
- maintenance records;
- manufacturer or vendor maintenance specifications;
- equipment sanitization records;
- media sanitization records;
- system security plan;
- other relevant documents or records.
Who To Talk To
- Personnel with system maintenance responsibilities;
- personnel with information security responsibilities;
- personnel responsible for media sanitization;
- system or network administrators.
Perform Test On
- Organizational processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for systems;
- organizational processes for sanitizing system components;
- mechanisms supporting or implementing controlled maintenance;
- mechanisms implementing sanitization of system components.
Additional Information
In general, system maintenance requirements tend to support the security objective of availability.
However, improper system maintenance or a failure to perform maintenance can result in the unauthorized disclosure of CUI, thus compromising confidentiality of that information.
This requirement refers to the maintenance of company IT systems.
CMMC Practice Background and References (DOD, CMU) |
Practice Discussion:
DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2
This requirement addresses the information security aspects of the system maintenance program and applies to all types of maintenance to any system component (including hardware, firmware, applications) conducted by any local or nonlocal entity. System maintenance also includes those components not directly associated with information processing and data or information retention such as scanners, copiers, and printers.
CMMC References:
· NIST SP 800-171 Rev 1 3.7.1
· NIST CSF v1.1 PR.MA-1
· CERT RMM v1.2 TM:SG5.SP2
· NIST SP 800-53 Rev 4 MA-2