3.7.1: Perform maintenance on organizational systems

Control Family:

Maintenance

Control Type:

Basic

CSF v1.1 References:

Discussion

This requirement addresses the information security aspects of the system maintenance program and applies to all types of maintenance to any system component (including hardware, firmware, applications) conducted by any local or nonlocal entity. System maintenance also includes those components not directly associated with information processing and data or information retention such as scanners, copiers, and printers.