{"data":{"id":"MA-06","name":"Timely Maintenance","family":"MA","family_name":"Maintenance","withdrawn":false,"description":"Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure.","supplemental_guidance":"Organizations specify the system components that result in increased risk to organizational operations and assets, individuals, other organizations, or the Nation when the functionality provided by those components is not operational. Organizational actions to obtain maintenance support include having appropriate contracts in place.","enhancements":[{"id":"MA-06(01)","name":"Preventive Maintenance","statement":"Perform preventive maintenance on [Assignment: organization-defined system components] at [Assignment: organization-defined time intervals].","baselines":[]},{"id":"MA-06(02)","name":"Predictive Maintenance","statement":"Perform predictive maintenance on [Assignment: organization-defined system components] at [Assignment: organization-defined time intervals].","baselines":[]},{"id":"MA-06(03)","name":"Automated Support for Predictive Maintenance","statement":"Transfer predictive maintenance data to a maintenance management system using [Assignment: organization-defined automated mechanisms].","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"MA-06","name":"Timely Maintenance","description":"Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure.","discussion":"Organizations specify the system components that result in increased risk to organizational operations and assets, individuals, other organizations, or the Nation when the functionality provided by those components is not operational. Organizational actions to obtain maintenance support include having appropriate contracts in place.","related_controls":["CM-08","CP-02","CP-07","RA-07","SA-15","SI-13","SR-02","SR-03","SR-04"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.7.13"],"iso_27002_2022":["7.13"],"cobit_2019":["DSS01"],"pci_dss_v4":[],"nist_csf_2":["ID.AM-08","PR.PS-03"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.6.2.6"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.34","SecNumCloud.13.4"],"osfi_b13":["B-13.2.3","B-13.2.4"],"finma_circular":["IV.A(28)","IV.A(29)","IV.E(89)"],"gdpr":["Art.32(1)(d)"],"dora":["Art.7(1)"],"bio2":["7.13"],"rbi_csf":["Annex1.7","ITGRCA.9"],"fisc":["FISC.F3"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":["DNB.18.2"],"cra":[],"swift_cscf":[],"cbe_csf":["CTO-10"],"bot_cyber":["Ch10.1"],"eba_ict":["3.5(a)","3.5(b)"],"hipaa_sr":["§164.310(a)(2)(iv)"],"sebi_cscrf":["PR.MA"],"cmmc_2":["MA"],"nerc_cip":[],"nrc_73_54":["RG5.71-B-MA"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["K"],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.7.2"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.b"],"iso_27799":["H.3"],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.8"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 ID.AM-08 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-008","SP-019"]}}