Per-Asset Maintenance Records
Each maintenance log entry is linked to a specific asset from the Asset Inventory and captures the maintenance type, date and time, technician name and organization, description of work performed, and authorization status. The asset linkage means the full maintenance history for any in-scope system is accessible from the asset record. relevant for both routine audits and incident investigation.
Maintenance types distinguish between scheduled preventive maintenance, emergency corrective maintenance, remote sessions, and on-site vendor visits. Each type has different documentation requirements under the MA domain, and the log captures the type-specific fields for each.
Remote Session Controls and Sanitization Documentation
MA.L2-3.7.5 requires multi-factor authentication for remote maintenance sessions. The log captures whether MFA was enforced for each remote session, who initiated the session, the duration, and whether the session was terminated on completion. This record is what assessors look for when verifying the practice. not just a policy that says MFA is required, but a log showing it was actually used.
When equipment is removed from the facility for off-site maintenance, MA.L2-3.7.3 requires documenting that the equipment was sanitized of CUI before leaving. The Maintenance Log includes a sanitization confirmation field with the sanitization method and a named responsible party. creating the record the practice requires and that most organizations don't have.
What You See Inside
- *Maintenance entry linked to specific asset from the Asset Inventory
- *Maintenance type: scheduled, emergency, remote session, on-site vendor, off-site repair
- *Technician name, organization, and authorization record. who performed the work and whether they were authorized
- *Date, time, and duration. complete temporal record of the maintenance event
- *Remote session MFA confirmation. whether MFA was enforced and session was terminated on completion
- *Off-site equipment flag. when equipment leaves the facility, triggers sanitization documentation requirement
- *Sanitization record. method, responsible party, and confirmation date for equipment leaving the facility
- *Supplier Management linkage. vendor maintenance visits connect to the supplier record for that organization
Practices Satisfied
| Practice ID | Description |
|---|---|
| MA.L2-3.7.1 | Perform maintenance on organizational systems. |
| MA.L2-3.7.2 | Provide controls on the tools, techniques, mechanisms, and personnel for the maintenance of organizational systems. |
| MA.L2-3.7.3 | Ensure equipment removed for off-site maintenance is sanitized of any CUI. |
| MA.L2-3.7.4 | Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. |
| MA.L2-3.7.5 | Require MFA to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. |
| MA.L2-3.7.6 | Supervise the maintenance activities of maintenance personnel without required access authorization. |
What this replaces
- *No maintenance log at all. the most common MA domain gap and a straightforward assessor finding
- *Vendor remote access sessions with no MFA record. a policy that requires MFA but no log showing it was enforced
- *Equipment removed for off-site repair with no sanitization documentation. the MA.L2-3.7.3 requirement most commonly missed
- *IT helpdesk tickets used as de facto maintenance records. no asset linkage, no MA-specific fields, not connected to the compliance program
- *Vendor maintenance visits without documented authorization. no record of whether the technician was authorized to access the systems they worked on
Related Modules
Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.