Maintenance
Maintenance covers how systems are serviced without opening a door to CUI, including remote maintenance and the tools and people who perform it. Service access is a classic overlooked risk.
The 6 Maintenance requirements
10 assessment objectives across this family.
- 3.7.1Perform MaintenancePerform maintenance on organizational systems.3 pt✕ POA&M
- 3.7.2System Maintenance ControlProvide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.5 pt✕ POA&M
- 3.7.3Equipment SanitizationEnsure equipment removed for off-site maintenance is sanitized of any CUI.1 pt
- 3.7.4Media InspectionCheck media containing diagnostic and test programs for malicious code before the media are used in organizational systems.3 pt✕ POA&M
- 3.7.5Nonlocal MaintenanceRequire multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.5 pt✕ POA&M
- 3.7.6Maintenance PersonnelSupervise the maintenance activities of maintenance personnel without required access authorization.1 pt
Build Maintenance, and all 14 families, with an officer
The Level 2 workspace walks all 110 requirements with you at the objective level, generates your SSP, POA&M, and Audit Room from real evidence, gives your assessor a read only seat, and puts a Registered Practitioner alongside you year round.
No credit card, and Level 1 and Level 2 are both open, so sign up for the level your contracts call for. Self assessment and self attestation are law today, DFARS 252.204-7012 is unaffected, and the NIST SP 800-171 Rev 2 baseline is unchanged, so the Level 2 work counts either way.
Questions, answered
How many CMMC Level 2 requirements are in Maintenance?+
The Maintenance family (MA) has 6 of the 110 CMMC Level 2 requirements, assessed against 10 objectives from NIST SP 800-171A.
What is the Maintenance family about?+
Maintenance covers how systems are serviced without opening a door to CUI, including remote maintenance and the tools and people who perform it. Service access is a classic overlooked risk.