MA-2: Controlled Maintenance

MA-02 requires organizations to schedule, approve, document, and monitor every maintenance action performed on information systems.

Quick-reference card

FieldValue
Control IDMA-02
Control nameControlled Maintenance
FrameworkNIST SP 800-53 Revision 5
Control familyMaintenance
BaselinesLOW MODERATE HIGH
Implementation levelOrganization
RelevanceFirst Party and Third Party
Risk severityMedium

What this control requires

MA-02 requires organizations to schedule, approve, document, and monitor every maintenance action performed on information systems. That single sentence covers a control with far more operational depth than most teams realize. You’re responsible for tracking maintenance from the moment it’s planned through post-maintenance verification that nothing was broken or compromised.

In practice, this control means that all maintenance and repair activities, whether performed on-site or remotely, must be explicitly approved and supervised. A designated official must sign off before any system or component leaves the facility for off-site maintenance. Before that equipment moves, you need to sanitize it to remove all organizational data. This requirement applies to peripherals too, including scanners, copiers, and printers that often get overlooked.

After maintenance is complete, you must verify that all potentially affected security controls still function as intended. Your maintenance records need to capture specific details: the date and time of each activity, a description of the work performed, the names of maintenance personnel, escort names when applicable, and an inventory of components addressed, removed, or replaced. These records form the audit trail that proves your organization treats maintenance as a security activity, not just an IT operations task.

Why it matters

Maintenance activities represent a medium-severity risk class that auditors consistently flag as an area of non-compliance, even in otherwise mature security programs. The gap between having a maintenance policy on paper and actually enforcing controlled maintenance across every system, peripheral, and off-site repair is where most organizations fall short.

From a compliance standpoint, failing to demonstrate controlled maintenance creates audit findings that cascade across multiple control families. Auditors view uncontrolled maintenance as evidence of weak configuration management, poor asset tracking, and insufficient access controls. A single missing maintenance record can call into question the integrity of an entire system’s security posture.

Beyond audit risk, uncontrolled maintenance creates real attack surface. Organizations that don’t verify security controls after maintenance leave themselves exposed to configuration drift. Those that skip sanitization before off-site repairs risk data exposure through equipment that leaves the security boundary with sensitive information still intact.

Supply chain risk compounds the problem when replacement components aren’t verified against approved configurations. A replacement hard drive, network card, or firmware update sourced from an unvetted supplier can introduce compromised code into an otherwise trusted environment. This risk extends to maintenance tools themselves, where diagnostic software or portable media used by technicians can serve as an infection vector if the organization doesn’t control what connects to its systems during service windows.

What attackers exploit

  • Unsanitized equipment sent off-site for repair, where data remnants on storage media or memory are accessible to unauthorized personnel
  • Maintenance windows with relaxed access controls, where technicians receive broader system access than the specific task requires
  • Replacement components from unverified suppliers that introduce compromised firmware or hardware into trusted environments
  • Post-maintenance gaps in control verification, where security settings are inadvertently weakened and remain that way until the next audit cycle
  • Maintenance tools left connected to systems after service is complete, providing a persistent foothold for lateral movement

How to implement

The most common failure mode isn’t the absence of a maintenance policy. It’s the gap between what the policy says and what actually happens when a technician shows up to replace a failed drive or a vendor needs remote access to troubleshoot a system. Closing that gap requires specific processes, designated approvers, and records that capture what the NIST SP 800-53 framework actually requires.

For your organization

Start by building a maintenance schedule that aligns with manufacturer specifications and your own operational requirements. This schedule should cover all systems in your component inventory, including peripherals like networked printers and scanners that teams frequently overlook.

Specifically, designate by name or role the personnel authorized to approve maintenance activities and the separate authority who must approve any off-site removal of equipment. These designations should be documented in your system security plan, not buried in tribal knowledge. Establish a standard maintenance request and approval workflow that captures who requested the work, who approved it, when it was scheduled, and what the scope includes.

For on-site maintenance, define escort procedures for external technicians. Your monitoring process should ensure that maintenance personnel access only the systems and components relevant to the approved work scope. Document what was done, what was replaced, and who was present.

Before any equipment leaves your facility, enforce a sanitization checkpoint. Use media sanitization procedures consistent with MP-06 to ensure all sensitive data is removed. Maintain a chain-of-custody log that tracks the equipment from removal through return.

After every maintenance action, verify that impacted security controls are still functioning. This verification step is the one teams most commonly skip, and it’s the one auditors most commonly flag. Build a post-maintenance checklist specific to each system type that maps the maintenance action to the controls that could be affected.

Where possible, use an automated maintenance tracking system rather than spreadsheets or paper forms. Automated tracking reduces the likelihood of incomplete records and makes it easier to demonstrate compliance during audits. Even a ticketing system with mandatory fields for the required data points is a significant improvement over manual logging.

Common mistakes include treating maintenance as purely an IT operations function without security oversight, failing to maintain records for peripheral devices, and relying on verbal approvals instead of documented authorization. Another frequent gap is neglecting to account for emergency maintenance, where the urgency of restoring a failed system leads teams to skip the approval and documentation steps they’d normally follow for scheduled work.

For your vendors

When assessing vendor compliance with MA-02, your questionnaire should go beyond asking whether a maintenance policy exists. Probe for operational specifics that reveal whether third-party risk management requirements are actually enforced.

Ask vendors these questions during assessment:

  • How do you schedule and document routine and emergency maintenance on systems that process our data?
  • Who is authorized to approve maintenance activities, and how is that approval documented?
  • What is your process for sanitizing equipment before it leaves your facility for off-site repair?
  • How do you verify that security controls are functioning correctly after maintenance is complete?
  • How do you vet replacement components for supply chain integrity?

Request these evidence artifacts: a current maintenance policy, sample maintenance logs showing required fields (date, time, personnel, escort, components), equipment sanitization records for off-site transfers, and post-maintenance security verification checklists. At minimum, maintenance logs should include the specific fields MA-02 requires, so look for completeness rather than just the existence of a log.

Red flags to watch for include vendors who cannot produce maintenance records for the past 12 months, policies that don’t address off-site maintenance or sanitization, no designated approver for equipment removal, and maintenance logs that lack personnel names or component details. A vendor who claims maintenance is “handled by IT” without a documented process is a significant compliance risk.

Verification beyond self-attestation should include requesting screenshots or exports from a maintenance tracking system, asking for a walkthrough of the approval workflow, and confirming that sanitization procedures reference an established standard. Where possible, request evidence of post-maintenance control verification for a recent maintenance event.

Pay particular attention to how vendors handle replacement components. Ask whether they maintain an approved supplier list for hardware and whether replacement parts are verified against baseline configurations before deployment. Vendors operating in supply chain-sensitive environments should be able to demonstrate that their maintenance processes account for the provenance of every component that enters a production system.

Evidence examples

Evidence typeExample artifact
Maintenance policy and proceduresDocumented policy defining maintenance scheduling requirements, approval authorities, off-site removal rules, and sanitization mandates for all system types
Maintenance activity recordsCompleted maintenance logs capturing date, time, description of work, personnel names, escort details, and components removed or replaced
Equipment sanitization recordsChain-of-custody forms and media sanitization certificates for systems sent to off-site repair facilities
Post-maintenance verification checklistsCompleted checklists showing security control testing results after maintenance, mapped to affected controls
Off-site removal authorization formsSigned approval records from designated personnel authorizing equipment removal from the facility
System component inventoryAsset register cross-referenced with maintenance schedules showing coverage of all systems, including peripherals

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20227.10 Storage mediaPartial
ISO 27001:20227.13 Equipment maintenancePartial
ISO 27001:20228.10 Information deletionPartial
  • CM-02 — Baseline Configuration: Maintenance activities must preserve baseline configurations, and post-maintenance verification confirms no unauthorized deviations occurred.
  • CM-03 — Configuration Change Control: Maintenance that modifies system configurations must flow through the organization’s change control process.
  • CM-04 — Impact Analyses: Organizations should analyze the security impact of maintenance actions before they’re performed, particularly when replacing components.
  • CM-05 — Access Restrictions for Change: Maintenance personnel access should be limited to the specific systems and components covered by the approved maintenance scope.
  • CM-08 — System Component Inventory: Accurate component inventories are essential for tracking what was removed, replaced, or modified during maintenance.
  • MA-04 — Nonlocal Maintenance: Remote maintenance sessions require additional controls for authentication, session termination, and audit logging beyond what MA-02 covers for on-site work.
  • MP-06 — Media Sanitization: Equipment sanitization before off-site removal directly depends on the organization’s media sanitization procedures and standards.
  • PE-16 — Delivery and Removal: Physical controls for equipment entering and leaving the facility support MA-02’s off-site maintenance requirements.
  • SI-02 — Flaw Remediation: Maintenance activities often include patching and flaw remediation, connecting routine maintenance to vulnerability management.
  • SR-03 — Supply Chain Controls and Processes: Replacement components sourced during maintenance must be vetted for supply chain integrity to prevent introducing compromised hardware or firmware.

Frequently asked questions

What is NIST SP 800-53 MA-02

MA-02 is the Controlled Maintenance control in the NIST SP 800-53 framework, requiring organizations to schedule, approve, document, and monitor all system maintenance activities. It covers on-site and remote maintenance, mandates equipment sanitization before off-site removal, and requires post-maintenance verification of security controls. The control applies at all three baselines (LOW, MODERATE, HIGH), making it a universal requirement for federal systems and organizations adopting the framework.

What happens if MA-02 is not implemented

Without MA-02, organizations lose visibility into who is performing maintenance on their systems, what components are being modified, and whether security controls remain intact afterward. Audit findings for uncontrolled maintenance often cascade into related control families like configuration management and media sanitization, compounding the compliance impact. Equipment leaving the facility without proper sanitization creates direct data exposure risk, while unverified replacement components introduce potential supply chain vulnerabilities.

How do you audit MA-02

Auditors assess MA-02 by reviewing maintenance policy documentation, examining maintenance activity logs for required fields like date, time, personnel names, and component details, and verifying that designated approval authorities are documented and followed. They check for evidence of equipment sanitization before off-site removal and look for completed post-maintenance security verification checklists. The strongest audit posture combines policy documentation with operational records that demonstrate consistent execution, not just the existence of a process on paper.

What maintenance records are required by NIST 800-53

NIST 800-53 requires maintenance records to include the date and time of each activity, a description of the maintenance performed, the names of the individuals who performed it, escort names when applicable, and a list of components addressed, removed, or replaced. Organizations should also document the approval authorization for each maintenance event and the results of post-maintenance security control verification. These records should be retained according to the organization’s record retention schedule and be readily producible during an audit.

Experience superior visibility and a simpler approach to cyber risk management