MA-4: NONLOCAL MAINTENANCE

TAILORED FOR INDUSTRIAL CONTROL SYSTEMS

  • ICS Control Baselines:
  • Low
  • Moderate
  • High

The organization:

    • a. Approves and monitors nonlocal maintenance and diagnostic activities;
    • b. Allows the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the information system;
    • c. Employs strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions;
    • d. Maintains records for nonlocal maintenance and diagnostic activities; and
    • e. Terminates session and network connections when nonlocal maintenance is completed.

SUPPLEMENTAL GUIDANCE

Nonlocal maintenance and diagnostic activities are those activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network. Local maintenance and diagnostic activities are those activities carried out by individuals physically present at the information system or information system component and not communicating across a network connection. Authentication techniques used in the establishment of nonlocal maintenance and diagnostic sessions reflect the network access requirements in IA-2. Typically, strong authentication requires authenticators that are resistant to replay attacks and employ multifactor authentication. Strong authenticators include, for example, PKI where certificates are stored on a token protected by a password, passphrase, or biometric. Enforcing requirements in MA-4 is accomplished in part by other controls.

ICS SUPPLEMENTAL GUIDANCE

No ICS Supplemental Guidance.

CONTROL ENHANCEMENTS

MA-4 (1) NONLOCAL MAINTENANCE | AUDITING AND REVIEW

NOT SELECTED FOR THE NIST ISC CONTROL SET

The organization:

    • (a) Audits nonlocal maintenance and diagnostic sessions [Assignment: organization-defined audit events]; and
    • (b) Reviews the records of the maintenance and diagnostic sessions.

Supplemental Guidance: NONE

RELATED CONTROLS: MA-4 (1)

MA-4 (2) NONLOCAL MAINTENANCE | DOCUMENT NONLOCAL MAINTENANCE
  • ICS Control Baselines:
  • Moderate
  • High

The organization documents in the security plan for the information system, the policies and procedures for the establishment and use of nonlocal maintenance and diagnostic connections.

Supplemental Guidance: NONE

No ICS Supplemental Guidance.

MA-4 (3) NONLOCAL MAINTENANCE
  • ISC Control Baseline:
  • High

The organization:

    • (a) Requires that nonlocal maintenance and diagnostic services be performed from an information system that implements a security capability comparable to the capability implemented on the system being serviced; or
    • (b) Removes the component to be serviced from the information system prior to nonlocal maintenance or diagnostic services, sanitizes the component (with regard to organizational information) before removal from organizational facilities, and after the service is performed, inspects and sanitizes the component (with regard to potentially malicious software) before reconnecting the component to the information system.

Supplemental Guidance: NONE

In crisis or emergency situations, the organization may need immediate access to non-local maintenance and diagnostic services in order to restore essential ICS operations or services. Example compensating controls include limiting the extent of the maintenance and diagnostic services to the minimum essential activities, carefully monitoring and auditing the non-local maintenance and diagnostic activities.

RELATED CONTROLS: MA-4 (3)

Supplemental Guidance:

Comparable security capability on information systems, diagnostic tools, and equipment providing maintenance services implies that the implemented security controls on those systems, tools, and equipment are at least as comprehensive as the controls on the information system being serviced.

MA-4 (4) NONLOCAL MAINTENANCE | AUTHENTICATION / SEPARATION OF MAINTENANCE SESSIONS

NOT SELECTED FOR THE NIST ISC CONTROL SET

The organization protects nonlocal maintenance sessions by:

    • (a) Employing [Assignment: organization-defined authenticators that are replay resistant]; and
    • (b) Separating the maintenance sessions from other network sessions with the information system by either:
      1. Physically separated communications paths; or
      2. Logically separated communications paths based upon encryption.

Supplemental Guidance: NONE

RELATED CONTROLS: MA-4 (4)

MA-4 (5) NONLOCAL MAINTENANCE | APPROVALS AND NOTIFICATIONS

NOT SELECTED FOR THE NIST ISC CONTROL SET

The organization:

    • (a) Requires the approval of each nonlocal maintenance session by [Assignment: organization-defined personnel or roles]; and
    • (b) Notifies [Assignment: organization-defined personnel or roles] of the date and time of planned nonlocal maintenance.

Supplemental Guidance:

Notification may be performed by maintenance personnel. Approval of nonlocal maintenance sessions is accomplished by organizational personnel with sufficient information security and information system knowledge to determine the appropriateness of the proposed maintenance.

MA-4 (6) NONLOCAL MAINTENANCE | CRYPTOGRAPHIC PROTECTION

NOT SELECTED FOR THE NIST ISC CONTROL SET

The information system implements cryptographic mechanisms to protect the integrity and confidentiality of nonlocal maintenance and diagnostic communications.

Supplemental Guidance: NONE

RELATED CONTROLS: MA-4 (6)

MA-4 (7) NONLOCAL MAINTENANCE | REMOTE DISCONNECT VERIFICATION

NOT SELECTED FOR THE NIST ISC CONTROL SET

The information system implements remote disconnect verification at the termination of nonlocal maintenance and diagnostic sessions.

Supplemental Guidance:

Remote disconnect verification ensures that remote connections from nonlocal maintenance sessions have been terminated and are no longer available for use.

RELATED CONTROLS: MA-4 (7)

REFERENCES:

  • NIST Special Publication 800-82
  • CNSS Policy 15
  • FIPS Publication 140-2
  • FIPS Publication 197
  • FIPS Publication 201
  • NIST Special Publication 800-63
  • NIST Special Publication 800-88