MA-03 Maintenance Tools

Maintenance

Low Moderate High

Description

The organization approves, controls, and monitors the use of information system maintenance tools and maintains the tools on an ongoing basis.

Supplemental Guidance

The intent of this control is to address hardware and software brought into the information system specifically for diagnostic/repair actions (e.g., a hardware or software packet sniffer that is introduced for the purpose of a particular maintenance activity). Hardware and/or software components that may support information system maintenance, yet are a part of the system (e.g., the software implementing “ping,” “ls,” “ipconfig,” or the hardware and software implementing the monitoring port of an Ethernet switch) are not covered by this control.

Changes from Rev 4

Adds control text and parameter to review previously approved maintenance tools at a specified frequency Discussion expanded regarding approving, controlling, monitoring, and reviewing maintenance tools

Compliance Mappings

ISO 27001:2022

A.7.13

ISO 27002:2022

7.13

COBIT 2019

DSS01

ISO 42001:2023

A.4.4

ANSSI

Hygiene.20Hygiene.34SecNumCloud.13.4

FINMA Circular 2023/1

IV.A(28)IV.A(29)

OSFI B-13

B-13.2.3

EU GDPR

Art.32(1)(b)

EU DORA

Art.7(1)Art.9(4)(e)

BIO2

7.13

RBI CSF

Annex1.7

FISC Security Guidelines

FISC.F3

MLPS 2.0

8.1.10.2

DNB Good Practice

DNB.18.2

CBE CSF

CTO-10

CBN CSF

Part3.3

HIPAA Security Rule

§164.310(a)(2)(iv)

SEBI CSCRF

PR.MA

BOT Cyber Resilience

Ch10.1

CMMC 2.0

MA

10 CFR 73.54

RG5.71-B-MA

PCI PTS v6

K

Solvency II

EIOPA-ICT-4.8

FCA SYSC 13

SYSC 13.7.2

ISO 17799 (legacy)

None.

COBIT 4.1 (legacy)

None.