Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.7.2OFFICIAL STATEMENT BELOWBASIC REQUIREMENTPENDING NIST SME REVIEW

3.7.2Maintenance controls

3.7 Maintenance · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

The tools and people that maintain systems are themselves an attack path — a technician's laptop, a vendor's USB stick, a diagnostic utility running with deep privilege. This requirement puts deliberate oversight on who and what is allowed to perform maintenance, and how.

Across revisions

Rev. 3 withdraws 03.07.01 through 03.07.03 and splits this requirement's substance: oversight of tools, techniques, and mechanisms goes to Maintenance Tools (03.07.04); oversight of maintenance personnel goes to Maintenance Personnel (03.07.06).

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Keep an approved-tools list and treat unfamiliar vendor kit arriving on site as untrusted until inspected — the diagnostic laptop that has visited fifty other plants is the classic carrier.
  • Third parties count: integrators and service technicians are maintenance personnel even when they are badged as visitors, and their access deserves the same oversight as an employee's.
  • In OT environments, vendor maintenance is frequently the least-governed pathway into production equipment; align this requirement's oversight with brokered remote access and supervised sessions.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • An approved maintenance tool list with an owner
  • Maintenance session records naming the personnel and tools involved
  • Vendor maintenance agreements and the access records behind them
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated