Nonlocal Maintenance

✓ LOW ✓ MODERATE ✓ HIGH
6 Enhancements 1 Overlay 15 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Nonlocal maintenance and diagnostic activities are conducted by individuals who communicate through either an external or internal network. Local maintenance and diagnostic activities are carried out by individuals who are physically present at the system location and not communicating across a network connection. Authentication techniques used to establish nonlocal maintenance and diagnostic sessions reflect the network access requirements in IA-2 . Strong authentication requires authenticators that are resistant to replay attacks and employ multi-factor authentication. Strong authenticators include PKI where certificates are stored on a token protected by a password, passphrase, or biometric. Enforcing requirements in MA-4 is accomplished, in part, by other controls. SP 800-63B provides additional guidance on strong authentication and authenticators.

Enhancements NIST SOURCE

MA-4(1) Logging and Review LOW MODERATE HIGH
  1. (a) Log [organization-defined audit events] for nonlocal maintenance and diagnostic sessions; and
  2. (b) Review the audit records of the maintenance and diagnostic sessions to detect anomalous behavior.
Discussion

Audit logging for nonlocal maintenance is enforced by AU-2 . Audit events are defined in AU-2a.

Open full page for MA-4(1) →
MA-4(2) Document Nonlocal Maintenance WITHDRAWN

Withdrawn. Incorporated into MA-1, MA-4.

MA-4(3) Comparable Security and Sanitization LOW MODERATE ✓ HIGH
  1. (a) Require that nonlocal maintenance and diagnostic services be performed from a system that implements a security capability comparable to the capability implemented on the system being serviced; or
  2. (b) Remove the component to be serviced from the system prior to nonlocal maintenance or diagnostic services; sanitize the component (for organizational information); and after the service is performed, inspect and sanitize the component (for potentially malicious software) before reconnecting the component to the system.
Discussion

Comparable security capability on systems, diagnostic tools, and equipment providing maintenance services implies that the implemented controls on those systems, tools, and equipment are at least as comprehensive as the controls on the system being serviced.

Open full page for MA-4(3) →
MA-4(4) Authentication and Separation of Maintenance Sessions LOW MODERATE HIGH

Protect nonlocal maintenance sessions by:

  1. (a) Employing [authenticators that are replay resistant] ; and
  2. (b) Separating the maintenance sessions from other network sessions with the system by either:
    1. (1) Physically separated communications paths; or
    2. (2) Logically separated communications paths.
Discussion

Communications paths can be logically separated using encryption.

Open full page for MA-4(4) →
MA-4(5) Approvals and Notifications LOW MODERATE HIGH
  1. (a) Require the approval of each nonlocal maintenance session by [personnel or roles] ; and
  2. (b) Notify the following personnel or roles of the date and time of planned nonlocal maintenance: [personnel and roles].
Discussion

Notification may be performed by maintenance personnel. Approval of nonlocal maintenance is accomplished by personnel with sufficient information security and system knowledge to determine the appropriateness of the proposed maintenance.

Open full page for MA-4(5) →
MA-4(6) Cryptographic Protection LOW MODERATE HIGH

Implement the following cryptographic mechanisms to protect the integrity and confidentiality of nonlocal maintenance and diagnostic communications: [cryptographic mechanisms].

Discussion

Failure to protect nonlocal maintenance and diagnostic communications can result in unauthorized individuals gaining access to organizational information. Unauthorized access during remote maintenance sessions can result in a variety of hostile actions, including malicious code insertion, unauthorized changes to system parameters, and exfiltration of organizational information. Such actions can result in the loss or degradation of mission or business capabilities.

Open full page for MA-4(6) →
MA-4(7) Disconnect Verification LOW MODERATE HIGH

Verify session and network connection termination after the completion of nonlocal maintenance and diagnostic sessions.

Discussion

Verifying the termination of a connection once maintenance is completed ensures that connections established during nonlocal maintenance and diagnostic sessions have been terminated and are no longer available for use.

Open full page for MA-4(7) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for MA-4 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. nonlocal maintenance and diagnostic activities are approved;
  2. nonlocal maintenance and diagnostic activities are monitored;
  3. the use of nonlocal maintenance and diagnostic tools are allowed only as consistent with organizational policy;
  4. the use of nonlocal maintenance and diagnostic tools are documented in the security plan for the system;
  5. strong authentication is employed in the establishment of nonlocal maintenance and diagnostic sessions;
  6. records for nonlocal maintenance and diagnostic activities are maintained;
  7. session connections are terminated when nonlocal maintenance is completed;
  8. network connections are terminated when nonlocal maintenance is completed.

Examine

[SELECT FROM: Maintenance policy; procedures addressing nonlocal system maintenance; remote access policy; remote access procedures; system design documentation; system configuration settings and associated documentation; maintenance records; records of remote access; diagnostic records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with system maintenance responsibilities; organizational personnel with information security responsibilities; system/network administrators].

Test

[SELECT FROM: Organizational processes for managing nonlocal maintenance; mechanisms implementing, supporting, and/or managing nonlocal maintenance; mechanisms for strong authentication of nonlocal maintenance diagnostic sessions; mechanisms for terminating nonlocal maintenance sessions and network connections].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Added: (1)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (3)
  • Added: (1)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for MA-4. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Maintenance policy
  • remote access policy
  • system security plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Organizational processes for managing nonlocal maintenance
  • mechanisms implementing, supporting, and/or managing nonlocal maintenance
  • mechanisms for strong authentication of nonlocal maintenance diagnostic sessions
  • mechanisms for terminating nonlocal maintenance sessions and network connections

Other Records

  • procedures addressing nonlocal system maintenance
  • remote access procedures
  • maintenance records
  • records of remote access
  • diagnostic records
  • other relevant documents or records