MA-04 Remote Maintenance

Maintenance

Low Moderate High

Description

The organization authorizes, monitors, and controls any remotely executed maintenance and diagnostic activities, if employed.

Supplemental Guidance

Remote maintenance and diagnostic activities are conducted by individuals communicating through an external, non-organization-controlled network (e.g., the Internet). The use of remote maintenance and diagnostic tools is consistent with organizational policy and documented in the security plan for the information system. The organization maintains records for all remote maintenance and diagnostic activities. Other techniques and/or controls to consider for improving the security of remote maintenance include: (i) encryption and decryption of communications; (ii) strong identification and authentication techniques, such as Level 3 or 4 tokens as described in NIST Special Publication 800-63; and (iii) remote disconnect verification. When remote maintenance is completed, the organization (or information system in certain cases) terminates all sessions and remote connections invoked in the performance of that activity. If password-based authentication is used to accomplish remote maintenance, the organization changes the passwords following each remote maintenance service. NIST Special Publication 800-88 provides guidance on media sanitization. The National Security Agency provides a listing of approved media sanitization products at http://www.nsa.gov/ia/government/mdg.cfm. Related security controls: IA-02, MP-06.

Compliance Mappings

ISO 27001:2022

A.7.13

ISO 27002:2022

7.13

COBIT 2019

DSS01

BSI IT-Grundschutz

OPS.1.2.5

ANSSI

Hygiene.16Hygiene.24Hygiene.28Hygiene.34SecNumCloud.13.4

FINMA Circular 2023/1

IV.A(28)IV.B.d(59)IV.C(62)

OSFI B-13

B-13.2.3B-13.3.2

EU GDPR

Art.32(1)(a)Art.32(1)(b)

EU DORA

Art.9(4)(a)Art.9(4)(c)

BIO2

7.13

RBI CSF

Annex1.7ITGRCA.20

FISC Security Guidelines

FISC.F3

MLPS 2.0

8.1.10.2

DNB Good Practice

DNB.18.2

CBE CSF

CTO-10

CBN CSF

Part3.3

CPMI-IOSCO PFMI

CG.PR

ECB CROE

CROE.2.3.4

SEBI CSCRF

PR.MA

BOT Cyber Resilience

Ch10.1

CMMC 2.0

MA

10 CFR 73.54

RG5.71-B-MA

PCI PTS v6

K

ISO 17799 (legacy)

11.4.4

COBIT 4.1 (legacy)

None.