Maintenance Tools
LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of MA-3 — Maintenance Tools. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of MA-3 — Maintenance Tools. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Approving, controlling, monitoring, and reviewing maintenance tools address security-related issues associated with maintenance tools that are not within system authorization boundaries and are used specifically for diagnostic and repair actions on organizational systems. Organizations have flexibility in determining roles for the approval of maintenance tools and how that approval is documented. A periodic review of maintenance tools facilitates the withdrawal of approval for outdated, unsupported, irrelevant, or no-longer-used tools. Maintenance tools can include hardware, software, and firmware items and may be pre-installed, brought in with maintenance personnel on media, cloud-based, or downloaded from a website. Such tools can be vehicles for transporting malicious code, either intentionally or unintentionally, into a facility and subsequently into systems. Maintenance tools can include hardware and software diagnostic test equipment and packet sniffers. The hardware and software components that support maintenance and are a part of the system (including the software implementing utilities such as "ping,""ls,""ipconfig," or the hardware and software implementing the monitoring port of an Ethernet switch) are not addressed by maintenance tools.
Enhancements NIST SOURCE
MA-3(1) Inspect Tools LOW ✓ MODERATE ✓ HIGH
Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications.
Discussion
Maintenance tools can be directly brought into a facility by maintenance personnel or downloaded from a vendor’s website. If, upon inspection of the maintenance tools, organizations determine that the tools have been modified in an improper manner or the tools contain malicious code, the incident is handled consistent with organizational policies and procedures for incident handling.
MA-3(2) Inspect Media LOW ✓ MODERATE ✓ HIGH
Check media containing diagnostic and test programs for malicious code before the media are used in the system.
Discussion
If, upon inspection of media containing maintenance, diagnostic, and test programs, organizations determine that the media contains malicious code, the incident is handled consistent with organizational incident handling policies and procedures.
MA-3(3) Prevent Unauthorized Removal LOW ✓ MODERATE ✓ HIGH
Prevent the removal of maintenance equipment containing organizational information by:
- (a) Verifying that there is no organizational information contained on the equipment;
- (b) Sanitizing or destroying the equipment;
- (c) Retaining the equipment within the facility; or
- (d) Obtaining an exemption from [personnel or roles] explicitly authorizing removal of the equipment from the facility.
Discussion
Organizational information includes all information owned by organizations and any information provided to organizations for which the organizations serve as information stewards.
MA-3(4) Restricted Tool Use LOW MODERATE HIGH
Restrict the use of maintenance tools to authorized personnel only.
Discussion
Restricting the use of maintenance tools to only authorized personnel applies to systems that are used to carry out maintenance functions.
MA-3(5) Execution with Privilege LOW MODERATE HIGH
Monitor the use of maintenance tools that execute with increased privilege.
Discussion
Maintenance tools that execute with increased system privilege can result in unauthorized access to organizational information and assets that would otherwise be inaccessible.
MA-3(6) Software Updates and Patches LOW MODERATE HIGH
Inspect maintenance tools to ensure the latest software updates and patches are installed.
Discussion
Maintenance tools using outdated and/or unpatched software can provide a threat vector for adversaries and result in a significant vulnerability for organizations.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for MA-3 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- frequency at which to review previously approved system maintenance tools is defined;
- the use of system maintenance tools is approved;
- the use of system maintenance tools is controlled;
- the use of system maintenance tools is monitored;
- previously approved system maintenance tools are reviewed <MA-03_ODP frequency>.
Examine
[SELECT FROM: Maintenance policy; procedures addressing system maintenance tools; system maintenance tools and associated documentation; maintenance records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with system maintenance responsibilities; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Organizational processes for approving, controlling, and monitoring maintenance tools; mechanisms supporting and/or implementing the approval, control, and/or monitoring of maintenance tools].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for MA-3. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Maintenance policy
- system security plan
Testing
- Organizational processes for approving, controlling, and monitoring maintenance tools
- mechanisms supporting and/or implementing the approval, control, and/or monitoring of maintenance tools
Other Records
- procedures addressing system maintenance tools
- system maintenance tools and associated documentation
- maintenance records
- other relevant documents or records