Controlled Maintenance | MA-2
Description
- Information Resource Custodians are responsible for scheduling, performing, documenting, and reviewing records of maintenance and repairs on information system components following manufacturer specifications.
- Information Resource Owners or their designees should be notified of non-routine maintenance.
- The Chief Information & Technology Officer or their designee must approve the removal of information resources or components for off-site maintenance or repairs.
- Storage media containing data classified as Confidential must be removed or sanitized following control MP-6 before an information resource is removed for off-site maintenance, repair, surplus, or other forms of disposal.
- Security related functionality should be checked to ensure proper functionality after maintenance or patching is performed.
- Patching and other forms of maintenance to information resources must be documented.
Last updated: 5/13/2026
Contact Hours or Questions?