MA-1: Policy and Procedures

MA-01 requires organizations to establish a written, owner-assigned maintenance policy and matching procedures that govern every system

Quick-reference card

FieldValue
Control IDMA-01
Control NamePolicy and Procedures
FrameworkNIST SP 800-53, Revision 5
Control FamilyMaintenance
BaselinesLOW MODERATE HIGH
Implementation LevelOrganization
RelevanceOrganization (First Party and Third Party)
Risk SeverityLow

What this control requires

MA-01 requires organizations to establish a written, owner-assigned maintenance policy and matching procedures that govern every system servicing activity. The policy must address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance with applicable laws, regulations, and standards. These procedures define how maintenance activities are planned, approved, performed, and recorded across the organization’s information systems.

Specifically, the control requires designating a senior official who owns the maintenance policy lifecycle. That individual manages the review cadence, coordinates updates triggered by regulatory changes or operational lessons learned, and ensures alignment with the organization’s broader risk management strategy. As part of the NIST SP 800-53 Maintenance family, MA-01 sets the governance baseline for all downstream maintenance controls.

Where organizations routinely stumble is treating a maintenance policy as a restatement of NIST control text. A policy establishes organizational intent, scope, and accountability structures. Procedures, by contrast, describe how each policy requirement is operationalized, including step-by-step workflows, tool configurations, and approval gates. Security and privacy teams should collaborate when drafting these documents to ensure maintenance activities address both security vulnerabilities and privacy-related system components.

Why it matters

Failure to maintain current maintenance policies and procedures introduces audit risk and may result in certification withdrawal, regulatory findings, or conditional authorization to operate decisions. For federal information systems subject to the Federal Information Security Modernization Act and the Federal Risk and Authorization Management Program, MA-01 is a baseline requirement across all impact levels.

In practice, missing or stale maintenance policies rank among the most common findings in NIST-based audits. Assessors flag these gaps early because they indicate broader governance weaknesses. If an organization can’t demonstrate that it has a current, approved maintenance policy with evidence of periodic review, auditors question whether downstream technical controls are being managed at all.

The result is a maintenance environment where activities become ad hoc, inconsistent, and undocumented. Technicians may perform system updates or hardware repairs without proper authorization, bypass change management processes, or fail to log activities that affect system integrity. Risk accumulates invisibly when no formal policy governs who can perform maintenance and under what conditions.

Specifically, MA-01 serves as the foundation for every other control in the MA control family, from MA-02 (Controlled Maintenance) through MA-07 (Field Maintenance). If the policy and procedures established under MA-01 are incomplete or outdated, every dependent control inherits that weakness. Remediating downstream controls without fixing MA-01 first is treating symptoms while ignoring the root cause.

What auditors flag:

  • Maintenance policies with no documented review date or revision history
  • Policies that restate NIST control language without operationalizing requirements for the organization’s environment
  • No designated official responsible for policy development and updates
  • Procedures that exist as standalone documents with no traceable link to the parent policy
  • Review cadences defined in policy but no evidence that reviews actually occurred

How to implement

The most common failure mode for MA-01 is a maintenance policy that copies NIST control text verbatim and calls it done. Auditors recognize this immediately, and it signals that the organization hasn’t translated regulatory requirements into operational practices specific to its environment.

For your organization

  1. Designate a senior official, typically within IT operations or the security leadership team, who is accountable for the maintenance policy lifecycle. This person approves the policy, coordinates reviews, and ensures updates reach all relevant personnel.
  2. Draft the maintenance policy to address purpose, scope, roles and responsibilities, management commitment, coordination among entities, and compliance obligations. Start by defining what “maintenance” means in your environment, covering hardware servicing, software patching, firmware updates, and any physical or logical access required to perform these activities. Be specific about which system categories fall under the policy’s scope.
  3. Align the policy with your risk management strategy. If your risk tolerance emphasizes availability over confidentiality for certain systems, your maintenance policy should define different maintenance windows and approval workflows accordingly.
  4. Develop procedures that operationalize each policy requirement. For every policy statement, create a corresponding procedure that describes who performs the task, what tools they use, what approvals are needed, and how the activity is documented. A policy might state “all maintenance activities require prior authorization.” The matching procedure specifies the authorization form, the approval chain, the lead time required, and the system used to track requests.
  5. Establish a review cadence and triggering events. Define how often policies and procedures are reviewed, commonly annually, and identify events that trigger out-of-cycle reviews such as audit findings, significant security incidents, regulatory changes, or major system architecture changes.
  6. Disseminate the approved policy and procedures to all relevant personnel using document management systems, governance, risk, and compliance platforms, or policy management tools. Maintain version-controlled access so personnel always reference the current edition.

The most common mistakes include copying control text as policy language, defining a review schedule without executing it, creating procedures that aren’t linked to specific policy requirements, and failing to update policies after organizational changes such as mergers or system migrations.

For your vendors

  1. Request the vendor’s current, approved maintenance policy along with associated procedures. A mature vendor will have these documents readily available and version-controlled.
  2. Review the vendor’s policy for purpose, scope, roles and responsibilities, management commitment, coordination, and compliance language. Generic, boilerplate policies that don’t reference the vendor’s specific environment or regulatory obligations are a red flag.
  3. Check for a designated policy owner. The policy should name a specific individual or role responsible for its lifecycle. If no owner is identified, the vendor likely lacks an active governance process for maintenance activities.
  4. Confirm review cadence and evidence of recent reviews. Look for revision history, approval signatures, and dates. A policy last reviewed three or more years ago suggests the document isn’t actively maintained. Ask the vendor to provide evidence of the most recent review cycle and any changes that resulted from it.
  5. Watch for these red flags during assessment: generic policies that could apply to any organization, no named policy owner, no documented review dates, procedures that restate control text rather than describing operational workflows, and an inability to provide revision history when asked.
  6. Verify beyond self-attestation by requesting the vendor’s most recent audit report or third-party assessment findings related to maintenance controls. Review the revision history of their policy documents to confirm active management. A third-party risk management policy guide can help you structure the evaluation criteria and questionnaire language for assessing vendor maintenance governance.

Evidence examples

Evidence TypeExample Artifact
Maintenance policyApproved maintenance policy document defining purpose, scope, roles, responsibilities, management commitment, coordination requirements, and compliance obligations
Maintenance proceduresStep-by-step procedures describing how maintenance activities are authorized, performed, documented, and reviewed
Policy ownership designationMemorandum or organizational charter naming the official responsible for maintaining and updating the maintenance policy
Review and update recordsRevision history log showing dates of policy and procedure reviews, approvals, and changes made
System security planSystem security plan sections referencing the maintenance policy and describing how MA-family controls are implemented
Dissemination evidenceDistribution records, training acknowledgments, or policy management platform logs confirming personnel received current maintenance policy and procedures

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.1 Policies for information securityPartial
ISO 27001:20225.2 Information security roles and responsibilitiesPartial
ISO 27001:20225.3 Segregation of dutiesPartial
ISO 27001:20225.37 Documented operating proceduresPartial
ISO 27001:20225.4 Management responsibilitiesPartial
NIST SP 800-171 Rev 303.15.01 Policy and ProceduresPartial
  • PM-09 — Risk Management Strategy: Defines the risk management approach that shapes maintenance policy priorities and scope.
  • PS-08 — Personnel Sanctions: Establishes consequences for personnel who fail to comply with maintenance policies and procedures.
  • SI-12 — Information Management and Retention: Governs how maintenance records and documentation are retained and disposed of.

The brief for MA-01 identifies three related controls. Additional controls in the MA family (MA-02 through MA-07) depend directly on the policy and procedures established under MA-01, but the NIST catalog doesn’t list them as formal related controls for MA-01.

Frequently asked questions

What is NIST SP 800-53 MA-01?

MA-01 is the foundational maintenance control that requires organizations to develop, document, and disseminate a maintenance policy and supporting procedures covering purpose, scope, roles, responsibilities, and management commitment. It also requires designating an official to manage the policy lifecycle, including periodic reviews triggered by defined events or frequency thresholds. This control applies across all three baselines and sets the governance foundation for every other control in the Maintenance family.

What happens if MA-01 is not implemented?

Without MA-01, organizations lack a formal governance structure for maintenance activities, which means system servicing, patching, and hardware repairs occur without documented authorization workflows or accountability. Auditors consistently flag the absence of a designated maintenance policy owner and missing revision history as high-priority findings. For federal systems, failure to implement MA-01 can result in a conditional or denied authorization to operate, blocking the system from production use.

How do you audit MA-01?

Auditing MA-01 starts with requesting the organization’s approved maintenance policy and verifying it addresses all required elements, including purpose, scope, roles, responsibilities, management commitment, coordination among entities, and compliance with applicable regulations. The assessor then examines the revision history and approval records to confirm the policy has been reviewed within its defined cadence. The assessor evaluates procedures to determine whether they operationalize each policy requirement rather than restate control text, and verifies evidence of dissemination through distribution logs or policy management platform records.

What is the difference between a maintenance policy and maintenance procedures?

A maintenance policy establishes the organizational intent, scope, and accountability framework for how maintenance activities are governed, including who is responsible, what compliance requirements apply, and how coordination occurs across teams. Maintenance procedures, by contrast, describe the step-by-step operational workflows that implement each policy requirement, specifying approval gates, tools, documentation standards, and escalation paths. MA-01 requires both documents and expects them to be explicitly linked so that every policy statement has a corresponding procedural implementation.

Experience superior visibility and a simpler approach to cyber risk management