Quick-reference card
| Field | Value |
|---|---|
| Control ID | MA-05 |
| Control title | Maintenance Personnel |
| Framework | NIST SP 800-53, Revision 5 |
| Control family | Maintenance |
| Baselines | LOW, MODERATE, HIGH |
| Implementation level | Organization |
| Relevance | First Party and Third Party |
| Risk severity | High |
What this control requires
MA-05 requires you to authorize every maintenance worker and supervise anyone who lacks the necessary access clearance. That one sentence captures the full scope of a control that most organizations underestimate until an auditor asks for proof.
In practice, this control breaks into three obligations. You must establish a formal authorization process for maintenance personnel, maintain a current list of approved individuals and organizations, and verify that unescorted maintenance workers actually hold the required access authorizations. When someone doesn’t hold those authorizations, you need designated staff with both the technical competence and clearance to supervise every minute of that maintenance activity.
The supervision requirement is where most teams stumble. Manufacturers, vendors, systems integrators, and consultants regularly need privileged access to production systems with little advance notice. Without a documented process for issuing and revoking temporary credentials, these ad-hoc maintenance windows become the gaps that auditors flag and attackers probe. Your Maintenance family controls work together to close those gaps, but MA-05 is the personnel gatekeeper.
Why it matters
Maintenance personnel represent one of the most under-monitored vectors for unauthorized system access. Organizations that treat maintenance authorization as a checkbox exercise rather than a living access control process consistently fail audits and leave themselves exposed to insider risk.
The core problem is privilege creep in maintenance relationships. A contractor who needed root access for a firmware upgrade six months ago may still hold those credentials today. Without a maintained, current list of authorized personnel, you have no reliable way to distinguish legitimate maintenance access from unauthorized entry.
Where this control becomes especially relevant is with temporary and third-party workers. Vendors, consultants, and integrators frequently require privileged access on short notice. If your organization can’t issue, track, and revoke temporary credentials through a repeatable process, each maintenance event introduces uncontrolled risk. NIST SP 800-53 treats this as a high-severity control across all three baselines for good reason.
The consequences extend beyond technical risk. Failing to demonstrate MA-05 compliance during a federal audit can trigger findings that delay or block authorization to operate (ATO) decisions. For organizations pursuing DFARS compliance, maintenance personnel controls feed directly into the contractor self-assessment scoring methodology.
What attackers exploit
Maintenance access creates specific attack vectors that MA-05 is designed to close:
- Stale credential reuse: Former maintenance personnel or contractors retain valid credentials long after their authorized work period ends, providing a persistent foothold
- Unsupervised privileged sessions: Maintenance workers without proper clearance operate on systems with no qualified supervisor present, enabling undetected modifications
- Undocumented temporary access: Emergency or ad-hoc maintenance grants bypass formal authorization, leaving no audit trail of who accessed what
- Social engineering of maintenance windows: Attackers impersonate scheduled maintenance personnel to gain physical or logical access during expected service periods
- Supply chain compromise through vendor maintenance: Third-party maintenance organizations with persistent access become targets for adversaries seeking indirect entry
How to implement
Most implementation failures trace back to the same root cause: organizations document an authorization process once and never operationalize it. The control requires a living process, not a static policy document.
For your organization
Step 1: Establish a formal authorization process. Define who can approve maintenance personnel, what criteria they must meet, and how approvals are documented. Your maintenance policy should specify the approval authority, required background checks or vetting procedures, and the conditions under which temporary credentials can be issued.
Step 2: Build and maintain your authorized personnel list. Create a centralized record of every individual and organization approved to perform maintenance. This list needs to include the person’s name, organization, the systems they’re authorized to touch, and the expiration date of their authorization. Review this list at least quarterly and after any personnel change.
Step 3: Implement verification procedures for unescorted access. Before any maintenance worker operates on a system without an escort, verify their identity against the authorized list and confirm their access authorizations are current. Document this verification for every maintenance event.
Step 4: Designate qualified supervisors. Identify internal personnel who have both the required security clearance and the technical competence to supervise maintenance activities on each system type. Maintain a mapping of supervisors to systems so you can respond quickly when uncleared personnel need access.
Step 5: Manage temporary credentials. Create a documented process for issuing, tracking, and revoking temporary access credentials. Temporary credentials should be scoped to the minimum access needed, time-limited, and automatically revoked at the end of the maintenance window. Log all temporary credential activity.
Step 6: Conduct periodic reviews. Audit your authorized personnel list, supervisor designations, and temporary credential logs at a defined cadence. Compare maintenance records against access control logs to identify any unauthorized maintenance activity.
For your vendors
Questionnaire questions to ask:
- Do you maintain a formal list of personnel authorized to perform maintenance on systems that process our data?
- What is your process for authorizing and vetting maintenance personnel, including contractors and subcontractors?
- How do you supervise maintenance personnel who lack the required access authorizations?
- What is your process for issuing and revoking temporary maintenance credentials?
Evidence to request:
- Current maintenance personnel authorization policy
- Sample authorized personnel list (redacted as needed)
- Temporary credential issuance and revocation logs from the past quarter
- Records of supervised maintenance sessions for uncleared personnel
Red flags during assessment:
- No documented authorization process exists, or the policy hasn’t been reviewed in over 12 months
- The authorized personnel list hasn’t been updated since initial creation
- No designated supervisors are identified for systems requiring cleared oversight
- Temporary credentials have no defined expiration or revocation procedure
- Nonlocal maintenance activities lack corresponding personnel verification records
Evidence examples
| Evidence Category | Example Artifact |
|---|---|
| Authorization policy | Maintenance Personnel Authorization Policy defining vetting criteria, approval authority, and temporary credential procedures |
| Authorized personnel list | Current register of approved maintenance individuals and organizations with system-level access scope and authorization expiration dates |
| Supervisor designations | Documented mapping of designated supervisors to system types, including their clearance levels and technical competencies |
| Maintenance records | Completed maintenance activity logs capturing personnel identity verification, work performed, and supervisor sign-off |
| Temporary credential logs | Issuance and revocation records for temporary maintenance credentials, including scope, duration, and approving authority |
| Access control records | System access logs correlated with maintenance windows to verify only authorized personnel accessed systems during maintenance |
| Service provider contracts | Vendor and contractor agreements specifying maintenance personnel authorization requirements and supervision obligations |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| NIST SP 800-171 Rev 3 | 03.07.06 Maintenance Personnel | Partial |
Organizations pursuing NIST SP 800-171 compliance should note that 03.07.06 covers the same personnel authorization requirements but with a narrower scope focused on controlled unclassified information (CUI) environments.
Related controls
- AC-02 — Account Management: Governs the lifecycle of system accounts that maintenance personnel use, including creation, modification, and termination
- AC-03 — Access Enforcement: Enforces the approved authorizations that maintenance personnel must hold before gaining system access
- AC-05 — Separation of Duties: Prevents a single maintenance worker from holding conflicting roles that could bypass oversight
- AC-06 — Least Privilege: Restricts maintenance personnel to the minimum access needed for their specific tasks
- IA-02 — Identification and Authentication (Organizational Users): Authenticates internal maintenance staff before granting system access
- IA-08 — Identification and Authentication (Non-organizational Users): Authenticates external maintenance contractors and vendors
- MA-04 — Nonlocal Maintenance: Addresses remote maintenance sessions that MA-05 personnel controls also govern
- MP-02 — Media Access: Restricts maintenance personnel access to system media during maintenance activities
- PE-02 — Physical Access Authorizations: Manages physical access for maintenance workers whose duties place them within the system’s physical protection perimeter
- PE-03 — Physical Access Control: Enforces physical entry restrictions at facilities where maintenance is performed
Frequently asked questions
What is NIST SP 800-53 MA-05?
MA-05 is the NIST SP 800-53 control that requires organizations to authorize every person who performs system maintenance, maintain a list of approved maintenance organizations, and supervise uncleared personnel during maintenance activities. It applies across all three security baselines (LOW, MODERATE, HIGH) and addresses both internal staff and external contractors who need system access for hardware or software maintenance.
What happens if MA-05 is not implemented?
Without MA-05, you have no verifiable way to confirm that the person performing maintenance on your systems is actually authorized to be there. Auditors will flag the absence of an authorized maintenance personnel list and documented supervision procedures as a direct control deficiency. For federal contractors, this gap can stall authorization to operate decisions and trigger corrective action requirements in self-assessment scoring.
How do you audit MA-05?
Auditors verify MA-05 by examining whether a documented maintenance personnel authorization process exists and whether the authorized personnel list is current and actively maintained. They review access control records to confirm that non-escorted maintenance workers held valid authorizations at the time of maintenance, and check supervisor designation records to verify that qualified personnel were assigned to oversee uncleared workers. Temporary credential issuance logs and service provider contracts are also examined to assess the completeness of your personnel authorization controls.
Who qualifies as maintenance personnel under NIST 800-53?
Maintenance personnel includes anyone who performs hardware or software maintenance on organizational systems, whether they’re internal employees, contractors, manufacturers, vendors, systems integrators, or consultants. The distinction that matters for MA-05 is not job title but access requirement. If someone needs system-level access to perform their maintenance duties, they fall within the scope of this control and must appear on your authorized personnel list or be supervised by designated personnel with the proper clearance and technical competence.