CMMC MA.2.114 - Supervise Maintenance Activities

CMMC MA.2.114 - Supervise Maintenance Activities

Requirement text: MA.2.114: Supervise the maintenance activities of personnel without required access
authorization.

DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2
This requirement applies to individuals who are performing hardware or software
maintenance on organizational systems, while PE.1.131 addresses physical access for
individuals whose maintenance duties place them within the physical protection perimeter
of the systems (e.g., custodial staff, physical plant maintenance personnel). Individuals not
previously identified as authorized maintenance personnel, such as information technology
manufacturers, vendors, consultants, and systems integrators, may require privileged access
to organizational systems, for example, when required to conduct maintenance activities
with little or no notice. Organizations may choose to issue temporary credentials to these
individuals based on organizational risk assessments. Temporary credentials may be for
one-time use or for very limited time periods.

CMMC CLARIFICATION
You must supervise everyone who performs maintenance activities. Sometimes a person
without proper permissions has to perform maintenance on your machines. Give that
individual a logon that is active only once or for a very limited time, to limit system access.

Example
You are in charge of IT operations for your company. One of your software providers has to
come on-site to update the software on your company’s machines. You give the individual a
temporary logon and password that expires in 12 hours. This gives him access long enough
to perform the update. When he is on site, you remain with him. You supervise his activities.
This ensures that he performs only the maintenance activities you directed.

References
• NIST SP 800-171 Rev 1 3.7.6
• CERT RMM v1.2 TM:SG5.SP2
• NIST SP 800-53 Rev 4 MA-5
    • Related Articles

    • CMMC MA.2.112 - Control System Maintenance Tools

      Requirement text: MA.2.112: Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 This requirement addresses security-related issues with maintenance ...
    • CMMC MA.2.113 - Require Multifactor Authentication for Maintenance Sessions

      Requirement text: MA.2.113: Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. DISCUSSION FROM SOURCE: DRAFT NIST SP ...
    • CMMC MA.2.111 - Perform System Maintenance

      Requirement text: MA.2.111: Perform maintenance on organizational systems. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 This requirement addresses the information security aspects of the system maintenance program and applies to all types of ...
    • CMMC MA.3.116 - Check Maintenance Media for Malicious Code

      Requirement text: MA.3.116: Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 If, upon inspection of media containing ...
    • Maintenance: SP 800-171 Security Family 3.7

      To keep systems in good working order and to minimize risks from hardware and software failures, it is important that companies establish procedures for systems maintenance. There are many ways a company can address these maintenance requirements. ...