ASOM-Fedv6.1Open the explorer
FC-3 · Facilities Terrain

Maintenance Access Control

Control Statement

Vendor and remote maintenance shall occur only within an approved, time-boxed, supervised window, and no maintenance path shall exist outside one.

Purpose. To ensure the maintenance path — authorized, expected, and outside the normal identity plane — is bounded in time and observed while open.

Discussion

Maintenance access is the path that bypasses everything else precisely because it is legitimate. It is often granted outside the agency's own identity plane, frequently at a level of privilege the vendor specifies rather than the agency scopes, and it is renewed indefinitely because removing it risks a support contract. The requirement that no path exist *outside* a window is the whole control; a maintenance account that is disabled between windows and a maintenance account that merely goes unused between windows look identical in a register and behave completely differently under compromise.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

No maintenance path exists outside an approved window.
  • Number of maintenance paths available outside an approved window
  • Proportion of maintenance sessions that were supervised and logged

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Record every vendor and remote maintenance path into the estate.
  2. L2Approve each maintenance occurrence in advance, time-boxed to a defined window.
  3. L2Raise a finding for any standing maintenance path.
  4. L3Verify that maintenance access is technically absent outside its window, not merely unused, and record the mechanism achieving that.
  5. L3Supervise maintenance sessions with a named agency observer for access touching decisive points, and record the supervision.
  6. L3Scope each window to the elements the maintenance requires rather than to the privilege level the vendor requests.
  7. L3Log maintenance session activity to the agency's own record, not only to the vendor's, so the account survives the relationship.
  8. L4Test that a maintenance path is unavailable outside its window, rather than inspecting the configuration that should make it so.
  9. L4Measure the proportion of maintenance sessions with complete agency-side activity records.
  10. L5Negotiate maintenance access terms into contract renewal, so the constraint is a procurement condition rather than a recurring exception fought at each occurrence.

Measurement

Outcome

Number of standing maintenance paths, target zero.

Performance

Percentage of maintenance sessions with agency-side activity records.

Evidence and Assessment

Evidence expected

Maintenance window record with approver and supervision evidence; agency-side session logs; path inventory.

Assessment procedure

Examine the maintenance path inventory for standing access; test that a path is unavailable outside its window; test whether session activity is recorded to the agency's own systems.

Related Guidance

Inherits
  • MA-4
  • MA-5
  • MA-3
Satisfies
  • PR.AA-05
  • PR.PS-03

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Feeds

Nothing downstream — this control terminates a chain.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

Terrain It Is Named On

  • T8FacilitiesMaintenance access control, which is this layer’s decisive point stated as a control.

Artifacts It Stands On

  • producesMaintenance access recordWho may perform maintenance in which zone, under what escort and in what window — including supplier maintenance, which is where standing physical access usually hides.
  • consumesPhysical zone boundary recordZone divisions inside facilities, reconciled against the logical trust zones, with physical approach routes to decisive points enumerated as avenues.
  • consumesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
  • consumesSupplier access constraint recordHow supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.

Roles It Puts to Work