1Overview
MA.L2-3.7.2 is the family's first five-point requirement and it controls how maintenance is done. It requires that the organization control the tools, techniques, mechanisms, and personnel used to conduct maintenance, so that maintenance itself does not become an avenue for compromise. It is a five-point requirement that cannot be deferred on a plan of action.
Maintenance grants deep access to systems, and that access is a risk if it is uncontrolled. A maintenance tool could carry malware, a maintenance technique could bypass protections, a maintenance mechanism such as a remote session could open a hole, and maintenance personnel could be untrusted. This control asks the organization to control all four, so that the powerful access maintenance requires is exercised safely. Its five-point weight reflects that uncontrolled maintenance is a direct path to the systems it is meant to keep healthy.
Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
The requirement names four things to control. Tools are the software and hardware used in maintenance; techniques are the methods; mechanisms are the means of access, such as maintenance sessions; and personnel are the people performing the work. Each has to be controlled, so that maintenance tools are trusted, techniques are appropriate, mechanisms are secured, and personnel are authorized and, where necessary, supervised. The four assessment objectives correspond directly to these four subjects.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.7.2 into four objectives, one for each of tools, techniques, mechanisms, and personnel.
Tools used to conduct system maintenance are controlled. Maintenance tools are trusted and managed.
Techniques used to conduct system maintenance are controlled. Maintenance methods are appropriate and managed.
Mechanisms used to conduct system maintenance are controlled. The means of maintenance access are secured.
Personnel used to conduct system maintenance are controlled. Maintenance staff are authorized and managed.
The four objectives are the four subjects of control. The common gap is at objectives [a] and [d], tools and personnel, where maintenance is performed with unchecked tools or by people whose access is not controlled. The assessor looks for control across all four subjects.
3Failure Patterns
The failures are about uncontrolled tools, methods, access, or people in maintenance.
Unchecked maintenance tools
A maintenance tool brought in without being checked can carry malware straight into systems. Controlling maintenance tools, so only trusted ones are used, closes this path.
Uncontrolled maintenance access
Maintenance mechanisms such as remote sessions left open or unsecured become an access path for more than maintenance. Securing the mechanisms is part of the control.
Unauthorized maintenance personnel
Where anyone can perform maintenance, untrusted people gain deep system access. Controlling maintenance personnel limits the work to authorized staff, with supervision where needed.
Techniques that bypass protections
Maintenance methods that disable or bypass security to get work done leave systems exposed. Controlling techniques keeps maintenance from weakening the protections around it.
4Ownership
This is an IT-owned technical control with a personnel dimension.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Controls maintenance tools, techniques, and mechanisms, and manages who performs maintenance. Owns the technical evidence. |
| Security or compliance lead | Confirms all four subjects are controlled and that maintenance access is secured. |
| Program lead | Reviews maintenance controls and retains the evidence. |
5Tooling
The control is delivered by managing maintenance tools, methods, access mechanisms, and personnel.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Approved and checked maintenance tools | Control over the tools used in maintenance. |
| [b] | Defined maintenance procedures | Control over the techniques used. |
| [c] | Secured maintenance access, such as controlled remote sessions | Control over the mechanisms of maintenance access. |
| [d] | Authorized maintenance personnel, supervision | Control over who performs maintenance. |
The caveat is that all four subjects have to be controlled, since any one left open undermines the rest. Trusted tools and authorized personnel are the most common gaps, but secured mechanisms and appropriate techniques matter equally. The assessor examines control across tools, techniques, mechanisms, and personnel, so all four have to be addressed.
6Evidence
The satisfied version of 3.7.2 shows control across all four maintenance subjects.
| Evidence | What it demonstrates |
|---|---|
| Maintenance tool controls | Objective [a]. Tools are trusted and managed. |
| Maintenance procedures | Objective [b]. Techniques are controlled. |
| Maintenance access controls | Objective [c]. Mechanisms are secured. |
| Personnel authorization | Objective [d]. Maintenance staff are controlled. |
The evidence should show control over the tools, techniques, mechanisms, and personnel used in maintenance. The controls across all four subjects are the clearest demonstration, and because this control cannot sit on a plan of action, they have to be real at the time of assessment.
Maintenance is trusted access that has to be controlled
The tools, methods, mechanisms, and people involved in maintenance all reach deep into systems, and any one left uncontrolled becomes a path to compromise. Controlling all four is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.7.2[a] through 3.7.2[d]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing MA.L2-3.7.2 among the five-point basic security requirements. ecfr.gov