Skip to main content

πŸ’Ό MA-2 Controlled Maintenance

  • Contextual name: πŸ’Ό MA-2 Controlled Maintenance
  • ID: /frameworks/nist-sp-800-53-r5/ma/02
  • Located in: πŸ’Ό MA Maintenance

Description​

a. Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements; b. Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location; c. Require that [Assignment: organization-defined personnel or roles] explicitly approve the removal of the system or system components from organizational facilities for off-site maintenance, repair, or replacement; d. Sanitize equipment to remove the following information from associated media prior to removal from organizational facilities for off-site maintenance, repair, or replacement: [Assignment: organization-defined information]; e. Check all potentially impacted controls to verify that the controls are still functioning properly following maintenance, repair, or replacement actions; and f. Include the following information in organizational maintenance records: [Assignment: organization-defined information].

Similar​

  • Internal
    • ID: dec-c-c8432b38

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό MA-2 Controlled Maintenance (L)(M)(H)1
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό MA-2 Controlled Maintenance (L)(M)(H)
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.AM-08: Systems, hardware, software, services, and data are managed throughout their life cycles3

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό MA-2(1) Controlled Maintenance _ Record Content
πŸ’Ό MA-2(2) Controlled Maintenance _ Automated Maintenance Activities