1Overview
MA.L2-3.7.3 protects CUI when equipment leaves for repair. It requires that equipment removed for off-site maintenance be sanitized of any CUI first, so that data does not walk out the door on a device sent to a third party. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.
When a device is sent off-site for maintenance, it passes out of the organization's control and into a repair shop or vendor, and any CUI still on it goes along. This control requires that such equipment be sanitized of CUI before it leaves, so the data does not travel with the hardware to a place the organization cannot protect. It is a straightforward but important safeguard against an easily overlooked leak, the hard drive sent out for repair with sensitive data still on it.
Ensure equipment removed for off-site maintenance is sanitized of any CUI.
The requirement is specific: before equipment leaves organizational spaces for off-site maintenance, any CUI on it is sanitized. Sanitization means removing the data so it cannot be recovered, whether by securely wiping storage, removing the storage entirely, or another effective method. The point is that the device carries no CUI when it leaves the organization's control.
2The Assessment Objective
NIST SP 800-171A frames 3.7.3 as a single objective: sanitize equipment of CUI before off-site maintenance.
Equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. Devices leaving for repair carry no CUI.
The single objective is sanitizing equipment before off-site maintenance. The common failure is a device sent for repair without its CUI removed. The assessor looks for a process that sanitizes equipment before it leaves.
3Failure Patterns
The failures are about CUI leaving on equipment sent for repair.
Devices sent out with data intact
A device sent to a repair shop with CUI still on its storage exposes that data to whoever handles the device. Sanitizing before it leaves prevents the exposure.
Incomplete sanitization
Deleting files without securely wiping storage can leave recoverable data. Sanitization has to remove CUI so it cannot be recovered, or the storage has to be removed entirely.
No process for off-site maintenance
Without a defined step to sanitize equipment before off-site maintenance, devices go out ad hoc and CUI slips through. A process tied to sending equipment out closes this.
4Ownership
This is an IT-owned control tied to the process for sending equipment out.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Sanitizes equipment of CUI before it leaves for off-site maintenance. Owns the sanitization evidence. |
| Security or compliance lead | Confirms sanitization is a required step and is effective. |
| Program lead | Includes off-site maintenance in the equipment handling process and retains the records. |
5Tooling
The control is delivered by sanitization before equipment leaves for maintenance.
| Objective | Tooling | What it provides |
|---|---|---|
| sanitize | Secure wipe, storage removal | Removal of CUI so it cannot be recovered. |
| process | Off-site maintenance procedure | A required sanitization step before equipment leaves. |
The caveat is that sanitization has to be effective and a required step, not an afterthought. Deleting files is not the same as securely removing recoverable data, and without a required step in the off-site process, devices leave with data intact. The assessor examines whether equipment is sanitized before off-site maintenance, so an effective, required process is what demonstrates the control.
6Evidence
The satisfied version of 3.7.3 shows equipment sanitized before off-site maintenance.
| Evidence | What it demonstrates |
|---|---|
| Sanitization records | The objective. Equipment sanitized of CUI before leaving. |
| Off-site maintenance procedure | The objective. Sanitization required before off-site maintenance. |
The evidence should show equipment sanitized of CUI before it leaves for off-site maintenance, tied to a required process. The sanitization records and the off-site procedure are the clearest demonstration of the control.
Do not let data leave on a device sent for repair
Equipment sent off-site passes out of the organization's control, and any CUI on it goes along unless it is removed first. Building sanitization into the process for sending equipment out is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.7.3. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov