Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

MA-2 — Controlled Maintenance

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

2Enhancements
3Parameters
3Baseline memberships
3Assessment methods

MA — Maintenance · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements;
  2. b.Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location;
  3. c.Require that [Organization-defined: personnel or roles] explicitly approve the removal of the system or system components from organizational facilities for off-site maintenance, repair, or replacement;
  4. d.Sanitize equipment to remove the following information from associated media prior to removal from organizational facilities for off-site maintenance, repair, or replacement: [Organization-defined: information];
  5. e.Check all potentially impacted controls to verify that the controls are still functioning properly following maintenance, repair, or replacement actions; and
  6. f.Include the following information in organizational maintenance records: [Organization-defined: information].
Official NIST discussion

Discussion

Controlling system maintenance addresses the information security aspects of the system maintenance program and applies to all types of maintenance to system components conducted by local or nonlocal entities. Maintenance includes peripherals such as scanners, copiers, and printers. Information necessary for creating effective maintenance records includes the date and time of maintenance, a description of the maintenance performed, names of the individuals or group performing the maintenance, name of the escort, and system components or equipment that are removed or replaced. Organizations consider supply chain-related risks associated with replacement components for systems.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

personnel or rolespersonnel or roles required to explicitly approve the removal of the system or system components from organizational facilities for off-site maintenance or repairs is/are defined;
informationinformation to be removed from associated media prior to removal from organizational facilities for off-site maintenance, repair, or replacement is defined;
informationinformation to be included in organizational maintenance records is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Controlled Maintenance as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to controlled maintenance, trusted tools, authorized personnel, and monitored support access.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • maintenance schedules and tickets
  • tool approval records
  • remote maintenance session logs
  • maintenance personnel authorization

Common failure patterns

  • vendor access left enabled permanently
  • unapproved diagnostic tools introduced
  • maintenance bypasses normal change control
  • remote sessions not monitored or terminated

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. MA-02a.
    1. MA-02a.[01]maintenance, repair, and replacement of system components are scheduled in accordance with manufacturer or vendor specifications and/or organizational requirements;
    2. MA-02a.[02]maintenance, repair, and replacement of system components are documented in accordance with manufacturer or vendor specifications and/or organizational requirements;
    3. MA-02a.[03]records of maintenance, repair, and replacement of system components are reviewed in accordance with manufacturer or vendor specifications and/or organizational requirements;
  2. MA-02b.
    1. MA-02b.[01]all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location, are approved;
    2. MA-02b.[02]all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location, are monitored;
  3. MA-02c.[Organization-defined: personnel or roles] is/are required to explicitly approve the removal of the system or system components from organizational facilities for off-site maintenance, repair, or replacement;
  4. MA-02d.equipment is sanitized to remove [Organization-defined: information] from associated media prior to removal from organizational facilities for off-site maintenance, repair, or replacement;
  5. MA-02e.all potentially impacted controls are checked to verify that the controls are still functioning properly following maintenance, repair, or replacement actions;
  6. MA-02f.[Organization-defined: information] is included in organizational maintenance records.

Examine

  • Maintenance policy
  • procedures addressing controlled system maintenance
  • maintenance records
  • manufacturer/vendor maintenance specifications
  • equipment sanitization records
  • media sanitization records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system maintenance responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel responsible for media sanitization
  • system/network administrators

Test

  • Organizational processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the system
  • organizational processes for sanitizing system components
  • mechanisms supporting and/or implementing controlled maintenance
  • mechanisms implementing the sanitization of system components
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

MA-2(1) — Record Content

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

MA-2(2) — Automated Maintenance Activities

High
  1. (a)Schedule, conduct, and document maintenance, repair, and replacement actions for the system using [Organization-defined: organization-defined automated mechanisms] ; and
  2. (b)Produce up-to date, accurate, and complete records of all maintenance, repair, and replacement actions requested, scheduled, in process, and completed.
Official discussion

The use of automated mechanisms to manage and control system maintenance programs and activities helps to ensure the generation of timely, accurate, complete, and consistent maintenance records.

Organization-defined parameters (4)
organization-defined automated mechanisms
automated mechanismsautomated mechanisms used to schedule maintenance, repair, and replacement actions for the system are defined;
automated mechanismsautomated mechanisms used to conduct maintenance, repair, and replacement actions for the system are defined;
automated mechanismsautomated mechanisms used to document maintenance, repair, and replacement actions for the system are defined;
Assessment objectives and methods
  1. MA-02(02)(a)
    1. MA-02(02)(a)[01][Organization-defined: automated mechanisms] are used to schedule maintenance, repair, and replacement actions for the system;
    2. MA-02(02)(a)[02][Organization-defined: automated mechanisms] are used to conduct maintenance, repair, and replacement actions for the system;
    3. MA-02(02)(a)[03][Organization-defined: automated mechanisms] are used to document maintenance, repair, and replacement actions for the system;
  2. MA-02(02)(b)
    1. MA-02(02)(b)[01]up-to date, accurate, and complete records of all maintenance actions requested, scheduled, in process, and completed are produced.
    2. MA-02(02)(b)[02]up-to date, accurate, and complete records of all repair actions requested, scheduled, in process, and completed are produced.
    3. MA-02(02)(b)[03]up-to date, accurate, and complete records of all replacement actions requested, scheduled, in process, and completed are produced.

Examine

  • Maintenance policy
  • procedures addressing controlled system maintenance
  • automated mechanisms supporting system maintenance activities
  • system configuration settings and associated documentation
  • maintenance records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system maintenance responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Automated mechanisms supporting and/or implementing controlled maintenance
  • automated mechanisms supporting and/or implementing the production of records of maintenance and repair actions
Related controls
Source record

Authoritative sources