NIST 800-53 REV 5 • MAINTENANCE

MA-4(2)Document Nonlocal Maintenance

CMMC Practice Mapping

NIST 800-171 Mapping

Related Controls

No related controls listed

Practitioner Notes

This enhancement requires you to document all nonlocal maintenance activities — who performed what, when, from where, and what was the outcome. Documentation is your evidence that remote maintenance was authorized and properly conducted.

Example 1: Create a Nonlocal Maintenance Log template in SharePoint with fields for: date, start/end time, technician name, remote IP address, systems accessed, work description, and supervisor approval. Require completion for every remote session.

Example 2: Use your change management system (ServiceNow, Jira) to create a specific ticket type for remote maintenance. The ticket must be approved before work begins and closed out with a summary of actions taken. Link the ticket to session recordings if available.