STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

MA-4

MaintenanceRev 5organization

Nonlocal Maintenance

Baselines:LowModerateHigh

Control Statement

a. Approve and monitor nonlocal maintenance and diagnostic activities; b. Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system; c. Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions; d. Maintain records for nonlocal maintenance and diagnostic activities; and e. Terminate session and network connections when nonlocal maintenance is completed.

Supplemental Guidance

Nonlocal maintenance and diagnostic activities are conducted by individuals who communicate through either an external or internal network. Local maintenance and diagnostic activities are carried out by individuals who are physically present at the system location and not communicating across a network connection. Authentication techniques used to establish nonlocal maintenance and diagnostic sessions reflect the network access requirements in [IA-2](#ia-2) . Strong authentication requires authenticators that are resistant to replay attacks and employ multi-factor authentication. Strong authenticators include PKI where certificates are stored on a token protected by a password, passphrase, or biometric. Enforcing requirements in [MA-4](#ma-4) is accomplished, in part, by other controls. [SP 800-63B](#e59c5a7c-8b1f-49ca-8de0-6ee0882180ce) provides additional guidance on strong authentication and authenticators.

Related Controls (15)

AC-2AC-3AC-6AC-17AU-2AU-3IA-2IA-4IA-5IA-8MA-2MA-5PL-2SC-7SC-10

CCI Identifiers (9)

CCI-000875The organization controls non-local maintenance and diagnostic activities.CCI-000876Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system.CCI-000873Approve nonlocal maintenance and diagnostic activities.CCI-000874Monitor nonlocal maintenance and diagnostic activities.CCI-000877Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.CCI-000878Maintain records for nonlocal maintenance and diagnostic activities.CCI-000879The organization terminates sessions and network connections when nonlocal maintenance is completed.CCI-004190Terminate session when nonlocal maintenance is completed.CCI-004191

Linked STIG Checks (118)

Across 66 STIGs. Click to expand.

Terminate network connection when nonlocal maintenance is completed.