MA-07 Field Maintenance

Maintenance

New in Rev 5

Description

Restrict or prohibit field maintenance on [Assignment: organization-defined parameters] to [Assignment: organization-defined parameters].

Supplemental Guidance

Field maintenance is the type of maintenance conducted on a system or system component after the system or component has been deployed to a specific site (i.e., operational environment). In certain instances, field maintenance (i.e., local maintenance at the site) may not be executed with the same degree of rigor or with the same quality control checks as depot maintenance. For critical systems designated as such by the organization, it may be necessary to restrict or prohibit field maintenance at the local site and require that such maintenance be conducted in trusted facilities with additional controls.

Changes from Rev 4

New control in Rev 5.

Compliance Mappings

ISO 27001:2022

A.7.13

ISO 27002:2022

7.13

COBIT 2019

DSS01

BSI IT-Grundschutz

OPS.1.2.5

ANSSI

Hygiene.28SecNumCloud.13.4

FINMA Circular 2023/1

IV.A(28)

EU DORA

Art.7(1)

BIO2

7.13

RBI CSF

Annex1.7

FISC Security Guidelines

FISC.F3

CMMC 2.0

MA

FCA SYSC 13

SYSC 13.7.2