CMMC MA.2.112 - Control System Maintenance Tools

CMMC MA.2.112 - Control System Maintenance Tools

Requirement text: MA.2.112: Provide controls on the tools, techniques, mechanisms, and personnel
used to conduct system maintenance.

DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2
This requirement addresses security-related issues with maintenance tools that are not
within the organizational system boundaries that process, store, or transmit CUI, but are
used specifically for diagnostic and repair actions on those systems. Organizations have
flexibility in determining the controls in place for maintenance tools, but can include
approving, controlling, and monitoring the use of such tools. Maintenance tools are potential
vehicles for transporting malicious code, either intentionally or unintentionally, into a
facility and into organizational systems. Maintenance tools can include hardware, software,
and firmware items, for example, hardware and software diagnostic test equipment and
hardware and software packet sniffers.

CMMC CLARIFICATION
Protect the tools used to perform maintenance. They must remain secure so they don’t
introduce software viruses or other bugs into your system. Protect your maintenance
processes so they aren’t used to hurt your network. Supervise the people responsible for
maintenance activities. Make sure they don’t behave in a malicious manner.

Example
You are responsible for maintenance activities on your company’s machines. These activities
can introduce software viruses or bugs into your system. To prevent this, make sure your
maintenance tools protect from unauthorized access. Also, confirm that your organization
manages or supervises everyone assigned to perform maintenance.

References
• NIST SP 800-171 Rev 1 3.7.2
• NIST CSF v1.2 PR.MA-1
• CERT RMM v1.2 TM:SG5.SP2
• NIST SP 800-53 Rev 4 MA-3
    • Related Articles

    • CMMC MA.2.111 - Perform System Maintenance

      Requirement text: MA.2.111: Perform maintenance on organizational systems. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 This requirement addresses the information security aspects of the system maintenance program and applies to all types of ...
    • CMMC MA.2.114 - Supervise Maintenance Activities

      Requirement text: MA.2.114: Supervise the maintenance activities of personnel without required access authorization. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 This requirement applies to individuals who are performing hardware or software ...
    • Access Control: SP 800-171 Security Family 3.1

      Access is the ability to make use of any system resource. Access control is the process of granting or denying requests to:       • use information,       • use information processing services, and       • enter company facilities.  System-based ...
    • Maintenance: SP 800-171 Security Family 3.7

      To keep systems in good working order and to minimize risks from hardware and software failures, it is important that companies establish procedures for systems maintenance. There are many ways a company can address these maintenance requirements. ...
    • CMMC Level 1 Overview - Basic Cyber Hygiene

      CMMC Level 1 l focuses on Federal Contract Information (FCI), which is defined as “information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the ...