NIST 800-53 REV 5 • MAINTENANCE
MA-4(2) — Document Nonlocal Maintenance
CMMC Practice Mapping
NIST 800-171 Mapping
Related Controls
No related controls listed
Practitioner Notes
This enhancement requires you to document all nonlocal maintenance activities — who performed what, when, from where, and what was the outcome. Documentation is your evidence that remote maintenance was authorized and properly conducted.
Example 1: Create a Nonlocal Maintenance Log template in SharePoint with fields for: date, start/end time, technician name, remote IP address, systems accessed, work description, and supervisor approval. Require completion for every remote session.
Example 2: Use your change management system (ServiceNow, Jira) to create a specific ticket type for remote maintenance. The ticket must be approved before work begins and closed out with a summary of actions taken. Link the ticket to session recordings if available.