NIST 800-53 REV 5 • MAINTENANCE
MA-6 — Timely Maintenance
Obtain maintenance support and/or spare parts for {{ insert: param, ma-06_odp.01 }} within {{ insert: param, ma-06_odp.02 }} of failure.
Supplemental Guidance
Organizations specify the system components that result in increased risk to organizational operations and assets, individuals, other organizations, or the Nation when the functionality provided by those components is not operational. Organizational actions to obtain maintenance support include having appropriate contracts in place.
Practitioner Notes
When critical systems fail, you need to get them fixed fast. This control requires you to have maintenance support and spare parts available within defined timeframes based on how critical each system is.
Example 1: Purchase hardware support contracts (Dell ProSupport, HPE Pointnext, or Lenovo Premier Support) with next-business-day or 4-hour response SLAs for your critical servers and network equipment. Keep the contract details and support contact numbers readily accessible.
Example 2: Stock critical spare parts on-site — extra hard drives, power supplies, network switches, and memory modules for your most important systems. Maintain a spare parts inventory list and reorder when stock drops below your minimum threshold.