NIST 800-171 Control 3.7.6 - Supervise maintenance activities
NIST 800-171 Control 3.7.3 - Ensure equipment removed for off-site maintenance is sanitized of CUI
NIST 800-171 Control 3.7.2 - Provide controls used to conduct system maintenance
NIST 800-171 Control 3.10.6 - Enforce safeguarding measures for CUI at alternate work sites
CMMC 2.0 Control MA.L2-3.7.6 - Supervise the maintenance activities of maintenance personnel without
NIST 800-171 Control 3.4.6 Employ the principle of least functionality.
NIST 800-171 Control 3.8.2 - Limit access to CUI on system media to authorized users
NIST 800-171 Checklist: CONTROL #7 Maintenance
Maintenance
NIST 800-171 Control 3.7.1 - Perform maintenance on organizational systems
NIST 800-171 Control 3.8.1 - Protect system media containing CUI, both paper and digital.
NIST 800-171 Control 3.8.7 - Control the Use of Removable Media
NIST 800-171 Control 3.7.5 - Require multifactor authentication
NIST 800-171 Control 3.8.3 - Sanitize/destroy system media containing CUI before disposal/release
NIST 800-171 Control 3.7.4 - Check media for malicious code before the media is used in systems
Understanding Maintenance in NIST 800-171 & CMMC
CMMC 2.0 Control MA-L2-3.7.3 - Ensure equipment removed for off-site maintenance is sanitized of any
NIST 800-171 Control 3.12.3 – Monitor Security Controls on an Ongoing Basis to Ensure Effectiveness
NIST 800-171 Control 3.8.6 - Implement cryptographic mechanisms to protect confidentiality of CUI
NIST 800-171 Control 3.5.6 Disable identifiers after a defined period of inactivity.