MA-4(3): Comparable Security and Sanitization
Control Family:
Parent Control:
CSF v1.1 References:
PF v1.0 References:
Threats Addressed:
Baselines:
- High
- OT High (SP 800-82r3)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- MA-4(3): Comparable Security / Sanitization
Control Statement
- Require that nonlocal maintenance and diagnostic services be performed from a system that implements a security capability comparable to the capability implemented on the system being serviced; or
- Remove the component to be serviced from the system prior to nonlocal maintenance or diagnostic services; sanitize the component (for organizational information); and after the service is performed, inspect and sanitize the component (for potentially malicious software) before reconnecting the component to the system.
Supplemental Guidance
Comparable security capability on systems, diagnostic tools, and equipment providing maintenance services implies that the implemented controls on those systems, tools, and equipment are at least as comprehensive as the controls on the system being serviced.
OT Discussion
The organization may need access to nonlocal maintenance and diagnostic services in order to restore essential OT operations or services. Example compensating controls include limiting the extent of the maintenance and diagnostic services to the minimum essential activities and carefully monitoring and auditing the nonlocal maintenance and diagnostic activities.