Maintenance Tools

LOW ✓ MODERATE ✓ HIGH
6 Enhancements 1 Overlay 2 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Approving, controlling, monitoring, and reviewing maintenance tools address security-related issues associated with maintenance tools that are not within system authorization boundaries and are used specifically for diagnostic and repair actions on organizational systems. Organizations have flexibility in determining roles for the approval of maintenance tools and how that approval is documented. A periodic review of maintenance tools facilitates the withdrawal of approval for outdated, unsupported, irrelevant, or no-longer-used tools. Maintenance tools can include hardware, software, and firmware items and may be pre-installed, brought in with maintenance personnel on media, cloud-based, or downloaded from a website. Such tools can be vehicles for transporting malicious code, either intentionally or unintentionally, into a facility and subsequently into systems. Maintenance tools can include hardware and software diagnostic test equipment and packet sniffers. The hardware and software components that support maintenance and are a part of the system (including the software implementing utilities such as "ping,""ls,""ipconfig," or the hardware and software implementing the monitoring port of an Ethernet switch) are not addressed by maintenance tools.

Enhancements NIST SOURCE

MA-3(1) Inspect Tools LOW ✓ MODERATE ✓ HIGH

Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications.

Discussion

Maintenance tools can be directly brought into a facility by maintenance personnel or downloaded from a vendor’s website. If, upon inspection of the maintenance tools, organizations determine that the tools have been modified in an improper manner or the tools contain malicious code, the incident is handled consistent with organizational policies and procedures for incident handling.

Open full page for MA-3(1) →
MA-3(2) Inspect Media LOW ✓ MODERATE ✓ HIGH

Check media containing diagnostic and test programs for malicious code before the media are used in the system.

Discussion

If, upon inspection of media containing maintenance, diagnostic, and test programs, organizations determine that the media contains malicious code, the incident is handled consistent with organizational incident handling policies and procedures.

Open full page for MA-3(2) →
MA-3(3) Prevent Unauthorized Removal LOW ✓ MODERATE ✓ HIGH

Prevent the removal of maintenance equipment containing organizational information by:

  1. (a) Verifying that there is no organizational information contained on the equipment;
  2. (b) Sanitizing or destroying the equipment;
  3. (c) Retaining the equipment within the facility; or
  4. (d) Obtaining an exemption from [personnel or roles] explicitly authorizing removal of the equipment from the facility.
Discussion

Organizational information includes all information owned by organizations and any information provided to organizations for which the organizations serve as information stewards.

Open full page for MA-3(3) →
MA-3(4) Restricted Tool Use LOW MODERATE HIGH

Restrict the use of maintenance tools to authorized personnel only.

Discussion

Restricting the use of maintenance tools to only authorized personnel applies to systems that are used to carry out maintenance functions.

Open full page for MA-3(4) →
MA-3(5) Execution with Privilege LOW MODERATE HIGH

Monitor the use of maintenance tools that execute with increased privilege.

Discussion

Maintenance tools that execute with increased system privilege can result in unauthorized access to organizational information and assets that would otherwise be inaccessible.

Open full page for MA-3(5) →
MA-3(6) Software Updates and Patches LOW MODERATE HIGH

Inspect maintenance tools to ensure the latest software updates and patches are installed.

Discussion

Maintenance tools using outdated and/or unpatched software can provide a threat vector for adversaries and result in a significant vulnerability for organizations.

Open full page for MA-3(6) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for MA-3 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. frequency at which to review previously approved system maintenance tools is defined;
  2. the use of system maintenance tools is approved;
  3. the use of system maintenance tools is controlled;
  4. the use of system maintenance tools is monitored;
  5. previously approved system maintenance tools are reviewed <MA-03_ODP frequency>.

Examine

[SELECT FROM: Maintenance policy; procedures addressing system maintenance tools; system maintenance tools and associated documentation; maintenance records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with system maintenance responsibilities; organizational personnel with information security responsibilities].

Test

[SELECT FROM: Organizational processes for approving, controlling, and monitoring maintenance tools; mechanisms supporting and/or implementing the approval, control, and/or monitoring of maintenance tools].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

Not applicable at this tier.

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1) (2) (3)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2) (3)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for MA-3. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Maintenance policy
  • system security plan

Testing

  • Organizational processes for approving, controlling, and monitoring maintenance tools
  • mechanisms supporting and/or implementing the approval, control, and/or monitoring of maintenance tools

Other Records

  • procedures addressing system maintenance tools
  • system maintenance tools and associated documentation
  • maintenance records
  • other relevant documents or records