id: "MA-04(04)" title: "Authentication and Separation of Maintenance Sessions" family: "MA" family_name: "Maintenance" sort_id: "ma-04.04" priority: "P2" implementation_level: "organization" parent: "MA-04" enhancement: True


Statement

Protect nonlocal maintenance sessions by:

Employing {{ insert: param, ma-04.04_odp }} ; and

Separating the maintenance sessions from other network sessions with the system by either:

Physically separated communications paths; or

Logically separated communications paths.

Guidance

Communications paths can be logically separated using encryption.

Assessment Objective: nonlocal maintenance sessions are protected by employing {{ insert: param, ma-04.04_odp }};

Assessment Objective: nonlocal maintenance sessions are protected by separating maintenance sessions from other network sessions with the system by physically separated communication paths; or

Assessment Objective: nonlocal maintenance sessions are protected by logically separated communication paths.

Maintenance policy

procedures addressing nonlocal system maintenance

system design documentation

system configuration settings and associated documentation

maintenance records

audit records

system security plan

other relevant documents or records

Organizational personnel with system maintenance responsibilities

network engineers

organizational personnel with information security responsibilities

system/network administrators

Organizational processes for protecting nonlocal maintenance sessions

mechanisms implementing replay-resistant authenticators

mechanisms implementing logically separated/encrypted communication paths