Why: Nonlocal maintenance sessions into production equipment are the vendor remote-access pathways this practice exists to govern, and its operating pattern matches the requirement's two clauses directly: sessions open through a brokered jump host with multifactor authentication, are enabled per engagement, and are disabled when the work ends rather than left standing.
What this does not claim: The practice governs pathways into OT; nonlocal maintenance of enterprise systems — vendor support tunnels into servers, RMM platforms, appliance consoles — is outside its scope and needs the same brokered treatment separately. The emergency-access procedure the practice rightly keeps for breakdowns must itself authenticate and terminate to the same standard, or it becomes the standing tunnel the requirement prohibits.
- Route vendor maintenance through the brokered jump host with multifactor authentication at establishment
- Enable access per engagement and disable it at completion, with the standing-access metric driven to zero
- Coordinate pathway changes with operations and the vendor — a vendor cut off from a misbehaving system during a breakdown is a safety problem, not only a support problem
- Broker configuration showing multifactor authentication required for entry
- Session logs with establishment and termination times reconciled against work orders
- The standing-access-outside-engagements count, at or trending to zero
Where this holds: Strongest for vendor and integrator maintenance of OT equipment; contributes nothing for the organization's IT-side nonlocal maintenance paths, which the requirement covers equally.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06