# MA-02 Controlled Maintenance

NIST SP 800-53 control. Family: MA Maintenance. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements; b. Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location; c. Require that [Assignment: organization-defined personnel or roles] explicitly approve the removal of the system or system components from organizational facilities for off-site maintenance, repair, or replacement; d. Sanitize equipment to remove the following information from associated media prior to removal from organizational facilities for off-site maintenance, repair, or replacement: [Assignment: organization-defined information]; e. Check all potentially impacted controls to verify that the controls are still functioning properly following maintenance, repair, or replacement actions; and f. Include the following information in organizational maintenance records: [Assignment: organization-defined information].
Guidance: Controlling system maintenance addresses the information security aspects of the system maintenance program and applies to all types of maintenance to system components conducted by local or nonlocal entities. Maintenance includes peripherals such as scanners, copiers, and printers. Information necessary for creating effective maintenance records includes the date and time of maintenance, a description of the maintenance performed, names of the individuals or group performing the maintenance, name of the escort, and system components or equipment that are removed or replaced. Organizations consider supply chain-related risks associated with replacement components for systems.

## Enhancements (1)
- MA-02(02) Automated Maintenance Activities. Baselines: high
Withdrawn by NIST: MA-02(01) (now in MA-02).
Each enhancement's statement: /api/v1/controls/MA-02?fields=enhancements

## Patterns that use it (5)
- Standard (5): SP-001 Client Module; SP-002 Server Module; SP-008 Public Web Server Pattern; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-023 Industrial Control Systems

## Clauses by framework (34 frameworks)
- iso_27001_2022: A.7.10, A.7.13, A.8.10
- iso_27002_2022: 7.13
- cobit_2019: DSS01
- nist_csf_2: ID.AM-08, PR.PS-03. OSA's own, not in NIST's crosswalk: PR.PS-03
- iso_42001_2023: A.6.2.6
- anssi: Hygiene.34, SecNumCloud.13.4
- osfi_b13: B-13.2.3
- finma_circular: IV.A(28), IV.A(29), IV.A(36)
- gdpr: Art.32(1)(b), Art.32(1)(d)
- dora: Art.7(1)
- bio2: 7.13
- rbi_csf: Annex1.7, ITGRCA.9
- fisc: FISC.F3, FISC.O13
- mlps_2: 8.1.10.2
- dnb_good_practice: DNB.18.2
- cra: CRA.I.2c
- cbe_csf: CTO-10
- cbn_csf: Part3.3
- popia: s19
- bot_cyber: Ch10.1
- cpmi_pfmi: PFMI.P17
- eba_ict: 3.5(a), 3.5(b)
- ecb_croe: CROE.2.3.4
- hipaa_sr: §164.310(a)(2)(iv)
- iosco_cyber: PFMI-17
- sebi_cscrf: PR.MA
- cmmc_2: MA
- nrc_73_54: RG5.71-B-MA
- pci_pts: K
- fca_sysc_13: SYSC 13.7.2
- hitrust_csf: 08.b
- iso_27799: 11.2, H.3
- solvency_ii: EIOPA-ICT-4.8
- sec_custody_digital: SEC-CD-07
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/MA-02
- Clauses only: /api/v1/controls/MA-02?fields=mappings
- Page for people: /controls/ma-02/
