id: "MA-04(04)" title: "Authentication and Separation of Maintenance Sessions" family: "MA" family_name: "Maintenance" sort_id: "ma-04.04" priority: "P2" implementation_level: "organization" parent: "MA-04" enhancement: True
Statement
Protect nonlocal maintenance sessions by:
Employing {{ insert: param, ma-04.04_odp }} ; and
Separating the maintenance sessions from other network sessions with the system by either:
Physically separated communications paths; or
Logically separated communications paths.
Guidance
Communications paths can be logically separated using encryption.
Assessment Objective: nonlocal maintenance sessions are protected by employing {{ insert: param, ma-04.04_odp }};
Assessment Objective: nonlocal maintenance sessions are protected by separating maintenance sessions from other network sessions with the system by physically separated communication paths; or
Assessment Objective: nonlocal maintenance sessions are protected by logically separated communication paths.
Maintenance policy
procedures addressing nonlocal system maintenance
system design documentation
system configuration settings and associated documentation
maintenance records
audit records
system security plan
other relevant documents or records
Organizational personnel with system maintenance responsibilities
network engineers
organizational personnel with information security responsibilities
system/network administrators
Organizational processes for protecting nonlocal maintenance sessions
mechanisms implementing replay-resistant authenticators
mechanisms implementing logically separated/encrypted communication paths