Under active development Content is continuously updated and improved

MA-3Maintenance Tools

IL4 Mod
IL4 High
IL5
IL6

>Control Description

a

Approve, control, and monitor the use of system maintenance tools; and

b

Review previously approved system maintenance tools organization-defined frequency.

>DoD Impact Level Requirements

FedRAMP Parameter Values

MA-3 (b) [at least annually]

>Discussion

Approving, controlling, monitoring, and reviewing maintenance tools address security-related issues associated with maintenance tools that are not within system authorization boundaries and are used specifically for diagnostic and repair actions on organizational systems. Organizations have flexibility in determining roles for the approval of maintenance tools and how that approval is documented. A periodic review of maintenance tools facilitates the withdrawal of approval for outdated, unsupported, irrelevant, or no-longer-used tools.

Maintenance tools can include hardware, software, and firmware items and may be pre-installed, brought in with maintenance personnel on media, cloud-based, or downloaded from a website. Such tools can be vehicles for transporting malicious code, either intentionally or unintentionally, into a facility and subsequently into systems. Maintenance tools can include hardware and software diagnostic test equipment and packet sniffers.

The hardware and software components that support maintenance and are a part of the system (including the software implementing utilities such as ping, ls, ipconfig, or the hardware and software implementing the monitoring port of an Ethernet switch) are not addressed by maintenance tools.

>Programmatic Queries

Beta

Related Services

AWS Systems Manager
AWS Patch Manager
AWS Session Manager

CLI Commands

List Systems Manager managed instances
aws ssm describe-instance-information --query 'InstanceInformationList[].{Id:InstanceId,Platform:PlatformName,Agent:AgentVersion}'
List SSM documents (maintenance automation)
aws ssm list-documents --document-filter-list key=DocumentType,value=Command
Describe available patches for instances
aws ssm describe-available-patches --filters 'Key=PRODUCT,Values=AmazonLinux2'
List active Session Manager sessions
aws ssm describe-sessions --state Active

>Related Controls

>Assessment Interview Topics

Questions assessors commonly ask

Process & Governance:

  • What formal policies and procedures govern the implementation of MA-3 (Maintenance Tools)?
  • Who are the designated roles responsible for implementing, maintaining, and monitoring MA-3?
  • How frequently is the MA-3 policy reviewed and updated, and what triggers policy changes?
  • What governance structure ensures MA-3 requirements are consistently applied across all systems?

Technical Implementation:

  • Describe the specific technical mechanisms or controls used to enforce MA-3 requirements.
  • What automated tools, systems, or technologies are deployed to implement MA-3?
  • How is MA-3 integrated into your system architecture and overall security posture?
  • What configuration settings, parameters, or technical specifications enforce MA-3 requirements?

Evidence & Documentation:

  • What documentation demonstrates the complete implementation of MA-3?
  • What audit logs, records, reports, or monitoring data validate MA-3 compliance?
  • Can you provide evidence of periodic reviews, assessments, or testing of MA-3 effectiveness?
  • What artifacts would you present during a FedRAMP assessment to demonstrate MA-3 compliance?

Ask AI

Configure your API key to use AI features.