PR.MA-P1: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools
CSF v1.1 References:
Threats Addressed:
Description
[csf.tools Note: Subcategories do not have detailed descriptions.]
Note: This Privacy Framework Subcategory is identical to the Cybersecurity Framework Subcategory.
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
MA-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] maintenance policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation of…
MA-2: Controlled Maintenance
Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements; Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location; Require that [Assignment: organization-defined…
MA-3: Maintenance Tools
Approve, control, and monitor the use of system maintenance tools; and Review previously approved system maintenance tools [Assignment: organization-defined frequency].
MA-5: Maintenance Personnel
Establish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel; Verify that non-escorted personnel performing maintenance on the system possess the required access authorizations; and Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required…
MA-6: Timely Maintenance
Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure.
Cloud Controls Matrix v4.0
CCC-04: Unauthorized Change Protection
Restrict the unauthorized addition, removal, update, and management of organization assets.
CCC-07: Detection of Baseline Deviation
Implement detection measures with proactive notification in case of changes deviating from the established baseline.
DCS-02: Off-Site Transfer Authorization Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable authorization. Review and update the policies and procedures at least annually.
LOG-01: Logging and Monitoring Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for logging and monitoring. Review and update the policies and procedures at least annually.
NIST Special Publication 800-53 Revision 4
MA-1: System Maintenance Policy And Procedures
The organization: Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]: A system maintenance policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls; and Reviews and updates the current: System maintenance policy…
MA-2: Controlled Maintenance
The organization: Schedules, performs, documents, and reviews records of maintenance and repairs on information system components in accordance with manufacturer or vendor specifications and/or organizational requirements; Approves and monitors all maintenance activities, whether performed on site or remotely and whether the equipment is serviced on site or removed to another location; Requires that [Assignment: organization-defined…
MA-3: Maintenance Tools
The organization approves, controls, and monitors information system maintenance tools.
MA-5: Maintenance Personnel
The organization: Establishes a process for maintenance personnel authorization and maintains a list of authorized maintenance organizations or personnel; Ensures that non-escorted personnel performing maintenance on the information system have required access authorizations; and Designates organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess…
MA-6: Timely Maintenance
The organization obtains maintenance support and/or spare parts for [Assignment: organization-defined information system components] within [Assignment: organization-defined time period] of failure.
Cloud Controls Matrix v3.0.1
BCR-07: Equipment Maintenance
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for equipment maintenance ensuring continuity and availability of operations and support personnel.
IAM-03: Diagnostic / Configuration Ports Access
User access to diagnostic and configuration ports shall be restricted to authorized individuals and applications.
IAM-13: Utility Programs Access
Utility programs capable of potentially overriding system, object, network, virtual machine, and application controls shall be restricted.
Critical Security Controls Version 7.1
4: Controlled Use of Administrative Privileges
The processes and tools used to track/control/prevent/correct the use, assignment, and configuration of administrative privileges on computers, networks, and applications.
4.7: Limit Access to Script Tools
Limit access to scripting tools (such as Microsoft® PowerShell and Python) to only administrative or development users with the need to access those capabilities.