Quick-reference card
| Field | Value |
|---|---|
| Control ID | MA-07 |
| Control Name | Field Maintenance |
| Framework | NIST SP 800-53, Revision 5 |
| Control Family | Maintenance |
| Baselines | --- |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Low |
What This Control Requires
MA-07 requires organizations to restrict or prohibit maintenance performed on systems at their deployed location, directing that work instead to trusted maintenance facilities. This isn’t about stopping maintenance altogether — it’s about controlling where and how that maintenance happens for systems the organization has designated as critical.
The core issue is quality control. Field maintenance — work done on-site after a system is deployed — doesn’t always meet the same rigor as depot maintenance performed in a controlled facility. When a technician services a system in a data center hallway or a remote branch office, the environment introduces variables that a purpose-built facility eliminates: limited tooling, fewer oversight controls, and reduced ability to verify the integrity of replacement components. For systems that handle sensitive data or support critical operations, those variables represent unacceptable risk.
Your organization needs to identify which systems or components require this restriction and designate the trusted maintenance facilities where servicing must occur. This decision should align with the broader maintenance requirements defined across the NIST SP 800-53 framework and flow from your risk assessment process. Not every asset needs depot-level maintenance — but for the ones that do, MA-07 formalizes the requirement and gives auditors a control to verify against.
Why It Matters
Failure to restrict field maintenance on critical systems introduces audit risk and may result in certification withdrawal or regulatory findings. MA-07 sits at the intersection of physical security and system integrity, and auditors treat gaps here as evidence that an organization hasn’t fully thought through its maintenance posture.
The risk isn’t dramatic — it’s procedural. An organization that allows unrestricted field maintenance on critical systems can’t demonstrate that those systems were serviced under conditions that preserve confidentiality, integrity, and availability. That’s a documentation problem, a process problem, and ultimately a compliance problem. Organizations subject to both NIST SP 800-53 and NIST SP 800-171 requirements face compounded scrutiny, since both frameworks expect maintenance practices to be deliberate and well-documented.
For organizations managing third-party risk, the exposure compounds. If your vendors perform field maintenance on systems that process your data, you need assurance that their maintenance practices meet the same standard you’d apply internally.
What auditors flag:
- No documented criteria for which systems require restricted maintenance
- Missing or incomplete records showing maintenance was performed at a trusted facility
- Absence of a designated list of approved maintenance facilities
- Field maintenance performed on critical systems with no compensating controls documented
- Vendor maintenance agreements that don’t address facility requirements
How to Implement
Implementing MA-07 starts with a classification decision: which systems are critical enough to warrant restricted field maintenance? That determination drives everything else — your facility designations, your maintenance procedures, and your vendor requirements.
For Your Organization
Begin by reviewing your system inventory and identifying assets where field maintenance presents an unacceptable risk to system integrity. These are typically systems handling classified data, critical infrastructure components, or assets where unauthorized physical access during maintenance could compromise security controls.
Once you’ve identified the systems in scope, designate your trusted maintenance facilities. A trusted facility isn’t just any repair shop — it’s a location with physical access controls, personnel vetting, parts integrity verification, and documented maintenance procedures that meet your security requirements. Document these designations in your maintenance policy and ensure they’re referenced in your system security plans.
Build the operational workflow. When a system designated under MA-07 requires maintenance, your process should route that work to an approved facility rather than dispatching a technician to the deployment site. This means your help desk, operations center, and field teams all need to know which assets carry this restriction. Tagging systems in your asset management tool with a maintenance restriction flag makes this practical at scale.
Maintain detailed records for every maintenance event on restricted systems. Those records should capture the facility where work was performed, the personnel involved, the work completed, and any parts replaced. These records are your primary evidence during an audit.
Common mistakes to avoid:
- Defining the restricted system list once and never revisiting it as your environment changes
- Designating facilities without documenting the security controls that qualify them as “trusted”
- Allowing emergency field maintenance exceptions without a documented approval and review process
- Failing to train operations staff on which systems carry field maintenance restrictions
For Your Vendors
When your vendors maintain systems or components that process your data, MA-07 compliance extends into your third-party risk management program. You need visibility into where and how vendor maintenance occurs, particularly for systems you’ve classified as critical.
Start with your vendor agreements. Contracts and service-level agreements should specify that maintenance on designated systems must occur at facilities that meet your security requirements. Don’t leave this to assumption — if a vendor’s default practice is to dispatch a field technician, your agreement needs to override that default for in-scope systems.
During vendor assessments, ask specifically about maintenance facility controls. A physical security questionnaire can help you evaluate whether a vendor’s maintenance locations meet your standards. You’re looking for physical access controls, personnel screening, parts provenance tracking, and documented maintenance procedures.
Monitor ongoing compliance. Vendors should provide maintenance records that demonstrate restricted systems were serviced at approved facilities. Build this reporting requirement into your vendor management workflow so gaps surface during regular reviews rather than during an audit.
Common mistakes to avoid:
- Assuming vendor maintenance practices meet your requirements without verification
- Omitting maintenance facility requirements from vendor contracts
- Accepting vendor self-attestation without reviewing supporting evidence
- Not including field maintenance restrictions in your vendor risk assessment criteria
Evidence Examples
| Evidence Type | Example Artifact |
|---|---|
| Policy documentation | Maintenance policy specifying systems subject to field maintenance restrictions and designated trusted facilities |
| Procedural documentation | Step-by-step procedures for routing maintenance to trusted facilities, including exception handling |
| System design records | System design documentation and security plans identifying components designated for restricted maintenance |
| Configuration records | System configuration settings enforcing maintenance routing controls and asset tagging for restricted systems |
| Maintenance and diagnostic logs | Maintenance records and diagnostic logs documenting facility location, personnel, and work performed for each event |
| Facility designation records | Documentation of trusted maintenance facilities, including the security controls that qualify each facility |
Cross-Framework Mapping Table
No cross-framework mappings have been configured for this control.
Related Controls
- MA-02 --- Controlled Maintenance: Establishes the broader requirement to schedule, document, and review all maintenance activities, which MA-07 narrows to facility-level restrictions for critical systems.
- MA-04 --- Nonlocal Maintenance: Addresses maintenance performed remotely rather than on-site, covering a different access vector than the physical field maintenance MA-07 restricts.
- MA-05 --- Maintenance Personnel: Governs who is authorized to perform maintenance, complementing MA-07’s focus on where that maintenance occurs.
Frequently Asked Questions
What Is NIST SP 800-53 MA-07
MA-07 is a NIST SP 800-53 control that requires organizations to restrict or prohibit field maintenance on designated systems, directing that work to trusted maintenance facilities instead. The control exists because field maintenance — servicing performed at a system’s deployed location — may not provide the same quality control rigor as maintenance performed in a controlled depot environment. Organizations must identify which systems warrant this restriction and designate facilities that meet their security requirements for performing that maintenance.
What Happens if MA-07 Is Not Implemented
Organizations that don’t implement MA-07 risk audit findings related to insufficient maintenance controls on critical systems. Without designated trusted maintenance facilities and documented restrictions, you can’t demonstrate that critical systems were maintained under conditions that preserve their security posture. Auditors will look for evidence that field maintenance decisions are deliberate and risk-informed, and the absence of that evidence creates a compliance gap that can affect your broader NIST SP 800-53 authorization.
How Do You Audit MA-07
Auditing MA-07 starts with verifying that the organization has documented which systems require restricted field maintenance and which trusted maintenance facilities are approved. Auditors review maintenance records to confirm that work on designated systems occurred at approved facilities rather than at deployment sites. They also examine whether exception processes exist for emergency field maintenance and whether those exceptions were properly authorized and documented. Your maintenance policy, facility designation records, and individual maintenance logs form the primary evidence chain.
What Is the Difference Between Field Maintenance and Depot Maintenance
Field maintenance is servicing performed at a system’s operational location — the data center, branch office, or deployment site where the system runs. Depot maintenance, by contrast, occurs at a dedicated facility designed for controlled repair and servicing, with established quality assurance processes, vetted personnel, and verified replacement parts. MA-07 exists because the gap in rigor between these two approaches can introduce risk for critical systems, making it necessary to route certain maintenance activities to trusted maintenance facilities that provide depot-level controls.