MA-5 Maintenance Personnel
Establish process for authorizing maintenance personnel; maintain list of authorized personnel; supervise unauthorized.
5
artefacts
3
held by a system
0
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Maintenance ticket records with approvals and post change verification · Ticketing / ITSM
- Maintenance personnel access list with background check status · Identity provider / directory
- Remote maintenance session logs with MFA and supervision evidence · Identity provider / directory
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Control implementation statement for MA-5 citing the system mission and inheritance from common controls · Document repository
- System maintenance policy and approved maintenance windows · Policy repository / GRC workspace
First move
Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.
Common gaps auditors find
- Vendor engineers granted standing access rather than session based access
- Remote maintenance sessions unmonitored after initial authentication
- Maintenance tools not sanitised before removal from secure areas
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMA-4 Nonlocal Maintenance · MA-5(1) Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1)