CMMCpedia Download

Requirements / Maintenance (MA)

MA.L2-3.7.2

System Maintenance Control

Official Source Material

Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

Determine if:

  1. [a] tools used to conduct system maintenance are controlled;
  2. [b] techniques used to conduct system maintenance are controlled;
  3. [c] mechanisms used to conduct system maintenance are controlled; and
  4. [d] personnel used to conduct system maintenance are controlled.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Answer four questions in the maintenance policy: which tools, which procedures, which automated jobs, which people.

Objective [a] is a list of approved maintenance tools. Objective [b] covers techniques, the documented procedures for how maintenance is done. Objective [c] covers mechanisms, the scripts, scheduled jobs, and remote management platforms that perform maintenance automatically. Objective [d] names the people authorized to do any of it. A page that answers all four is the core of this requirement.

The scope is tools brought in for diagnosis and repair, not the operating system's own commands.

The requirement's discussion aims at maintenance tools brought in from outside the system boundary for diagnostic and repair actions. Hardware and software test equipment, packet sniffers that capture network traffic, and vendor utilities are the kind it means. Built-in commands such as ping and ipconfig are part of the system and are governed by your access controls, so they need no inventory here.

Control means limiting who can reach the tools and watching their use.

Approve tools before they are used. Restrict maintenance consoles and administrative portals to the authorized people from [d]. Keep automated jobs where only administrators can edit them, and log what runs. Physical or logical access control on each of the four fronts is what the objectives look for.

Your MSP's remote management platform is the maintenance tool to control most carefully.

An MSP is a managed service provider, the outside firm that runs IT for you. Name its platform in your system security plan, the document that says how each requirement is met, and approve it deliberately. Put in the service agreement which of the MSP's staff may use the platform against your systems and what it is allowed to do. An agent on every endpoint with an unnamed operator pool is the opposite of controlled personnel under [d].

Keep it proportional in a small shop.

One administrator, a documented toolset, and administrative credentials nobody else holds satisfy all four objectives. The requirement asks for control, not a maintenance department.

What falls short

  • A policy that authorizes IT staff to perform maintenance without naming who that is. Objective [d] controls personnel, and an undefined group controls nobody.

Edge cases

  • An MSP whose management tooling is documented inside your system boundary is operating part of the system, not visiting it. Its tools and operators still get the [a] through [d] treatment: named, restricted, and logged.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.