DKDavid Koran& Associates
Home The CMMC Guide Part III · Maintenance MA.L2-3.7.2
The CMMC Guide · Maintenance Family

MA.L2-3.7.2  Control Maintenance Tools and Personnel

Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

Family
MaintenanceMA, 6 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
FourPer NIST SP 800-171A

1Overview

MA.L2-3.7.2 is the family's first five-point requirement and it controls how maintenance is done. It requires that the organization control the tools, techniques, mechanisms, and personnel used to conduct maintenance, so that maintenance itself does not become an avenue for compromise. It is a five-point requirement that cannot be deferred on a plan of action.

Maintenance grants deep access to systems, and that access is a risk if it is uncontrolled. A maintenance tool could carry malware, a maintenance technique could bypass protections, a maintenance mechanism such as a remote session could open a hole, and maintenance personnel could be untrusted. This control asks the organization to control all four, so that the powerful access maintenance requires is exercised safely. Its five-point weight reflects that uncontrolled maintenance is a direct path to the systems it is meant to keep healthy.

The requirement · NIST SP 800-171 Rev 2, 3.7.2

Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

The requirement names four things to control. Tools are the software and hardware used in maintenance; techniques are the methods; mechanisms are the means of access, such as maintenance sessions; and personnel are the people performing the work. Each has to be controlled, so that maintenance tools are trusted, techniques are appropriate, mechanisms are secured, and personnel are authorized and, where necessary, supervised. The four assessment objectives correspond directly to these four subjects.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.7.2 into four objectives, one for each of tools, techniques, mechanisms, and personnel.

[a]

Tools used to conduct system maintenance are controlled. Maintenance tools are trusted and managed.

MeetsMaintenance tools are controlled, so only trusted, checked tools are used.
FailsAny tool can be used for maintenance, including unchecked ones.
[b]

Techniques used to conduct system maintenance are controlled. Maintenance methods are appropriate and managed.

MeetsMaintenance techniques are controlled, so methods do not bypass protections.
FailsMaintenance techniques are uncontrolled and may weaken security.
[c]

Mechanisms used to conduct system maintenance are controlled. The means of maintenance access are secured.

MeetsMaintenance mechanisms, such as remote sessions, are controlled and secured.
FailsMaintenance mechanisms are open or unsecured.
[d]

Personnel used to conduct system maintenance are controlled. Maintenance staff are authorized and managed.

MeetsMaintenance personnel are controlled, so only authorized people perform maintenance.
FailsAnyone can perform maintenance, including unauthorized people.

The four objectives are the four subjects of control. The common gap is at objectives [a] and [d], tools and personnel, where maintenance is performed with unchecked tools or by people whose access is not controlled. The assessor looks for control across all four subjects.

3Failure Patterns

The failures are about uncontrolled tools, methods, access, or people in maintenance.

Unchecked maintenance tools

A maintenance tool brought in without being checked can carry malware straight into systems. Controlling maintenance tools, so only trusted ones are used, closes this path.

Uncontrolled maintenance access

Maintenance mechanisms such as remote sessions left open or unsecured become an access path for more than maintenance. Securing the mechanisms is part of the control.

Unauthorized maintenance personnel

Where anyone can perform maintenance, untrusted people gain deep system access. Controlling maintenance personnel limits the work to authorized staff, with supervision where needed.

Techniques that bypass protections

Maintenance methods that disable or bypass security to get work done leave systems exposed. Controlling techniques keeps maintenance from weakening the protections around it.

The common root
This control fails because maintenance is trusted access that is easy to leave uncontrolled. The tools, methods, mechanisms, and people involved all reach deep into systems, and any one left uncontrolled turns maintenance into an avenue of compromise. Controlling all four keeps the access safe.

4Ownership

This is an IT-owned technical control with a personnel dimension.

RoleResponsibility for this control
IT and system administratorControls maintenance tools, techniques, and mechanisms, and manages who performs maintenance. Owns the technical evidence.
Security or compliance leadConfirms all four subjects are controlled and that maintenance access is secured.
Program leadReviews maintenance controls and retains the evidence.
See also: This control governs the maintenance performed under MA.L2-3.7.1, and its personnel dimension connects to the supervision of MA.L2-3.7.6 and the media check of MA.L2-3.7.4.

5Tooling

The control is delivered by managing maintenance tools, methods, access mechanisms, and personnel.

ObjectivesToolingWhat it provides
[a]Approved and checked maintenance toolsControl over the tools used in maintenance.
[b]Defined maintenance proceduresControl over the techniques used.
[c]Secured maintenance access, such as controlled remote sessionsControl over the mechanisms of maintenance access.
[d]Authorized maintenance personnel, supervisionControl over who performs maintenance.

The caveat is that all four subjects have to be controlled, since any one left open undermines the rest. Trusted tools and authorized personnel are the most common gaps, but secured mechanisms and appropriate techniques matter equally. The assessor examines control across tools, techniques, mechanisms, and personnel, so all four have to be addressed.

6Evidence

The satisfied version of 3.7.2 shows control across all four maintenance subjects.

EvidenceWhat it demonstrates
Maintenance tool controlsObjective [a]. Tools are trusted and managed.
Maintenance proceduresObjective [b]. Techniques are controlled.
Maintenance access controlsObjective [c]. Mechanisms are secured.
Personnel authorizationObjective [d]. Maintenance staff are controlled.

The evidence should show control over the tools, techniques, mechanisms, and personnel used in maintenance. The controls across all four subjects are the clearest demonstration, and because this control cannot sit on a plan of action, they have to be real at the time of assessment.

Maintenance is trusted access that has to be controlled

The tools, methods, mechanisms, and people involved in maintenance all reach deep into systems, and any one left uncontrolled becomes a path to compromise. Controlling all four is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.7.2[a] through 3.7.2[d]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing MA.L2-3.7.2 among the five-point basic security requirements. ecfr.gov
← Previous in Maintenance
MA.L2-3.7.1 · Perform Maintenance
Next in Maintenance →
MA.L2-3.7.3 · Sanitize Equipment for Off-Site Maintenance
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MA.L2-3.7.2 · Edition 2026.1 · Last reviewed July 12, 2026