NIST SP 800-53 Rev 5
MA - Maintenance

NIST SP 800-53 Rev 5 NIST800-MA-2: MA-2 Controlled Maintenance

a. Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements; b. Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location; c. Require that [Assignment: organization-defined personnel or roles] explicitly approve the removal of the system or system components from organizational facilities for off-site maintenance, repair, or replacement; d. Sanitize equipment to remove the following information from associated media prior to removal from organizational facilities for off-site maintenance, repair, or replacement: [Assignment: organization-defined information]; e. Check all potentially impacted controls to verify that the controls are still functioning properly following maintenance, repair, or replacement actions; and f. Include the following information in organizational maintenance records: [Assignment: organization-defined information].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 30 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

CMMC 2.0 · 3 controls

CIS Controls v8 · 2 controls

  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management

PCI DSS 4.0 · 2 controls

  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change

SOC 2 · 2 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

C5 (Germany) · 1 control

FedRAMP High · 1 control

  • MA-2 Controlled Maintenance

FedRAMP Moderate · 1 control

  • MA-2 Controlled Maintenance

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 7.13 Equipment maintenance

ISO 27002:2022 · 1 control

  • 7.13 Equipment maintenance

ISO 27701:2019 · 1 control

NIST SP 800-160 · 1 control

NIST SP 800-171 · 1 control

  • MA-2 MA-2 Controlled Maintenance
  • MA-2 MA-2 Controlled Maintenance
  • MA-2 MA-2 Controlled Maintenance

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in MA - Maintenance

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-MA-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 30 it maps to, and the evidence behind each claim, over MCP and REST.