Under active development Content is continuously updated and improved

MA-3Maintenance Tools

PBMM (P3)
Secret (P3)
Operational

>Control Description

(A) The organization approves, controls, and monitors information system maintenance tools.

>Supplemental Guidance

This control addresses security-related issues associated with maintenance tools used specifically for diagnostic and repair actions on organizational information systems. Maintenance tools can include hardware, software, and firmware items. Maintenance tools are potential vehicles for transporting malicious code, either intentionally or unintentionally, into a facility and subsequently into organizational information systems.

Maintenance tools can include, for example, hardware/software diagnostic test equipment and hardware/software packet sniffers. This control does not cover hardware/software components that may support information system maintenance, yet are a part of the system, such as the software implementing “ping,” “ls,” “ipconfig,” or the hardware and software implementing the monitoring port of an Ethernet switch. Related controls: MA-2, MA-5, MP-6

Ask AI

Configure your API key to use AI features.