[Enter organization name below]
Requirement: Perform maintenance on organizational systems.
Implementation:
Evidence:
Requirement: Provide controls on tools, techniques, mechanisms, and personnel used to conduct system maintenance.
Implementation:
Evidence:
Requirement: Ensure equipment removed for off-site maintenance is sanitized of any CUI.
Implementation:
Evidence:
Requirement: Check media containing diagnostic and test programs for malicious code before use.
Implementation:
Evidence:
Requirement: Require MFA for remote maintenance sessions via external network connections; terminate sessions when complete.
Implementation:
Evidence:
Requirement: Supervise maintenance activities of personnel without required access authorization.
Implementation:
Evidence:
| Activity Type | Scheduled | Completed | Pending | Compliance Rate | Action |
|---|---|---|---|---|---|
| No activities added β click "+ Add Activity" above. | |||||
| Asset Category | Total Count | Active | In Maintenance | End of Life | Replacement Planned | Action |
|---|---|---|---|---|---|---|
| No assets added β click "+ Add Asset Category" above. | ||||||
| Vendor Name | Service Type | Access Level | Last Activity | Compliance Status | Action |
|---|---|---|---|---|---|
| No vendors added β click "+ Add Vendor" above. | |||||
List the security requirements all third-party maintenance vendors must satisfy:
| Tool Name | Version | Purpose | Last Malware Scan | Approval Status | Action |
|---|---|---|---|---|---|
| No tools added β click "+ Add Tool" above. | |||||
| Risk Description | Likelihood | Impact | Risk Level | Mitigation Status | Action |
|---|---|---|---|---|---|
| No risks added β click "+ Add Risk" above. | |||||
This will clear all entered data. This cannot be undone.