Skip to content

MA-4: Nonlocal Maintenance

An OSCAL Control

Statement

    • a.

      Approve and monitor nonlocal maintenance and diagnostic activities;

    • b.

      Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system;

    • c.

      Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions;

    • d.

      Maintain records for nonlocal maintenance and diagnostic activities; and

    • e.

      Terminate session and network connections when nonlocal maintenance is completed.