Overview

Security Requirements for 03.07.01 Perform Maintenance

This requirement addresses the information security aspects of the system maintenance program and applies to all types of maintenance to any system component (including hardware, firmware, applications) conducted by any local or nonlocal entity. System maintenance also includes those components not directly associated with information processing and data or information retention such as scanners, copiers, and printers.

Assessment GuidanceExamine 0/8

How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).

Discussion

One common form of computer security maintenance is regular patching of discovered vulnerabilities in software and operating systems, though there are others that require attention. System maintenance includes:

corrective maintenance (e.g., repairing problems with the technology);

preventative maintenance (e.g., updates to prevent potential problems); adaptive maintenance (e.g., changes to the operative environment); and

perfective maintenance (e.g., improve operations).

Examples

  1. Example 1

    You are responsible for maintenance activities on your company’s machines. This includes regular planned maintenance, unscheduled maintenance, reconfigurations when required, and damage repairs [a]. You know that failing to conduct maintenance activities can impact system security and availability, so you ensure that maintenance is regularly performed. You track all maintenance performed to assist with troubleshooting later if needed.

Assessment Methods

Examine
The process of reviewing, inspecting, observing, studying, or analyzing assessment objects (e.g., policies, procedures, plans, system designs, mechanisms) to facilitate understanding, achieve clarification, or obtain evidence.Example: An assessor reads the access control policy and inspects system configuration settings to confirm they match.

Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.

Interview
The process of holding discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or identify the location of evidence.Example: An assessor asks a system administrator to describe how user accounts are approved, reviewed, and disabled.
  • Personnel with system maintenance responsibilities
  • Personnel with information security responsibilities
  • Personnel responsible for media sanitization
  • System or network administrators
Test
The process of exercising assessment objects (e.g., activities, mechanisms) under specified conditions to compare actual behavior with expected behavior.Example: An assessor attempts to sign in with a disabled account to confirm that access is denied.
  • Organizational processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for systems
  • Organizational processes for sanitizing system components
  • Mechanisms supporting or implementing controlled maintenance
  • Mechanisms implementing sanitization of system components

Potential Assessment Considerations

  • Are systems, devices, and supporting systems maintained per manufacturer recommendations or company defined schedules [a]?

Key References

NIST SP 800-171 Rev. 2 3.7.1

Evidence

  1. 03.07.01.a

    System maintenance is performed