Controlled Maintenance | MA-2

Description

  • Information Resource Custodians are responsible for scheduling, performing, documenting, and reviewing records of maintenance and repairs on information system components following manufacturer specifications.
  • Information Resource Owners or their designees should be notified of non-routine maintenance.
  • The Chief Information & Technology Officer or their designee must approve the removal of information resources or components for off-site maintenance or repairs.
  • Storage media containing data classified as Confidential must be removed or sanitized following control MP-6 before an information resource is removed for off-site maintenance, repair, surplus, or other forms of disposal.
  • Security related functionality should be checked to ensure proper functionality after maintenance or patching is performed.
  • Patching and other forms of maintenance to information resources must be documented.

Last updated: 5/13/2026

Contact Hours or Questions?