1Overview
MA.L2-3.7.4 guards against malware arriving through maintenance media. It requires that media containing diagnostic and test programs be checked for malicious code before it is used in organizational systems, so that a maintenance tool does not become the delivery vehicle for an infection. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.
Diagnostic and test media, the USB drives, discs, and tools that technicians bring to service systems, connect directly to the environment and often with elevated access. If that media carries malicious code, maintenance becomes the path by which malware enters, bypassing many of the defenses at the network edge. This control requires that such media be checked for malicious code before use, so a maintenance tool is verified clean rather than trusted blindly. Its three-point weight reflects that maintenance media is a direct, privileged route into systems.
Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
The requirement is specific to diagnostic and test media and requires a malicious-code check before that media touches organizational systems. The check is typically an antimalware scan of the media, performed on every occasion before use, so that whatever a technician brings in is verified. It applies whether the media comes from staff or an outside vendor, since either can carry an infection unknowingly.
2The Assessment Objective
NIST SP 800-171A frames 3.7.4 as a single objective: check diagnostic and test media for malicious code before use.
Media containing diagnostic and test programs are checked for malicious code before the media are used in organizational systems. Maintenance media is verified clean before use.
The single objective is the malicious-code check before use. The common failure is trusting a technician's media without scanning it. The assessor looks for a check performed before diagnostic and test media are used.
3Failure Patterns
The failures are about unchecked maintenance media.
Vendor media trusted without a check
Media brought by an outside technician is often trusted implicitly, yet it can carry an infection the technician is unaware of. Scanning it before use verifies it regardless of source.
No scanning step before use
Where there is no required check, diagnostic and test media are used directly, and any malware on them enters the system. A required scan before use closes this path.
Inconsistent checking
Checking media sometimes but not always leaves gaps on the occasions it is skipped. The check has to happen every time media is used.
4Ownership
This is an IT-owned technical control tied to the maintenance process.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Checks diagnostic and test media for malicious code before use. Owns the technical evidence. |
| Security or compliance lead | Confirms the check is required and performed on all maintenance media, including vendor media. |
| Program lead | Includes the media check in the maintenance process and retains the records. |
5Tooling
The control is delivered by scanning maintenance media before use.
| Objective | Tooling | What it provides |
|---|---|---|
| scan | Antimalware scanning of media | A malicious-code check of diagnostic and test media. |
| process | Required check before use | A step that verifies media before it touches systems. |
The caveat is that the check has to happen every time and cover media from any source. A scan performed inconsistently, or skipped for trusted vendors, leaves the gap the control addresses. The assessor examines whether diagnostic and test media are checked before use, so the check has to be a consistent, required step.
6Evidence
The satisfied version of 3.7.4 shows maintenance media checked before use.
| Evidence | What it demonstrates |
|---|---|
| Media check procedure | The objective. A required malicious-code check before use. |
| Scan records | The objective. Evidence media is checked before use. |
The evidence should show diagnostic and test media checked for malicious code before use, as a required step. The check procedure and scan records are the clearest demonstration, and because this control cannot sit on a plan of action, the check has to be a real practice at the time of assessment.
A maintenance tool should be verified, not trusted
Diagnostic media connects with privileged access, and if it carries malware, maintenance becomes the way in, so this control asks for a malicious-code check before use. Building that check into the maintenance process, for vendor media too, is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.4. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.7.4. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing MA.L2-3.7.4 among the three-point derived security requirements. ecfr.gov