MA.L2-3.7.1 – Perform maintenance on organizational systems.

This control requires your organization to regularly perform maintenance on its systems, including hardware and software updates, patches, configuration changes, and preventive care to ensure secure and stable operation—especially for systems that store or process Controlled Unclassified Information (CUI).

MA.L2-3.7.2[d] – Determine if system maintenance controls are enforced.

This objective confirms that your organization doesn’t just have maintenance controls in place—it actively enforces those controls through technical safeguards, policy compliance, and oversight. The focus is on preventing unauthorized or noncompliant maintenance activities, not just trusting people to follow procedures.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.