7.3 Maintenance (MA) & Media Protection (MP) Domains: Sanitization & Tool Control
Key Takeaways
- Maintenance has six Level 2 requirements; Media Protection has nine Level 2 requirements, and media sanitization 3.8.3 also maps to Level 1.
- Nonlocal maintenance through external network connections requires MFA and termination when complete; encryption or monitoring may be required by other objectives but are not added words in 3.7.5.
- Off-site equipment sanitization, diagnostic-media malware checks, and supervision of unauthorized maintenance personnel are distinct maintenance requirements.
- Media controls cover physical protection, authorized access, sanitization or destruction, markings, transport accountability, protected digital transport, removable media, identifiable ownership, and backup confidentiality.
- Digital media in transport uses cryptography unless alternative physical safeguards protect it; when cryptography protects CUI, the deployed module must meet the separate FIPS-validation requirement.
Maintenance & Media Protection
Maintenance controls how systems are serviced without exposing CUI or introducing unsafe tools. Media Protection follows CUI on paper, digital media, backups, and portable devices. The MA family has six Level 2 requirements. MP has nine Level 2 requirements, and 3.8.3 also maps to Level 1.
Maintenance requirements
Requirement 3.7.1 performs maintenance on organizational systems. The organization defines planned and corrective work, authorized personnel, records, and system restoration appropriate to its environment.
Requirement 3.7.2 provides controls on the tools, techniques, mechanisms, and personnel used for maintenance. Evidence can include approved tools, technician access, work orders, device controls, and procedures. It does not prescribe one scanning product or require every maintenance action to use identical tooling.
Requirement 3.7.3 ensures that equipment removed for off-site maintenance is sanitized of CUI. The team traces what leaves, the sanitization decision and method, approval, transport, and return. If sanitization is impossible, another authorized arrangement must be evaluated against the governing requirements rather than treated as an informal exception.
Requirement 3.7.4 checks media containing diagnostic and test programs for malicious code before the media are used in organizational systems. This requirement is about the diagnostic/test media, not a blanket claim that every tool must be scanned at every connection regardless of architecture.
Requirement 3.7.5 requires MFA to establish nonlocal maintenance sessions through external network connections and termination of those connections when maintenance is complete. Remote-access confidentiality, monitoring, authorization, and logging may also apply through AC, AU, and SC requirements, but they should be cited accurately rather than inserted into 3.7.5.
Requirement 3.7.6 supervises maintenance activity by personnel who lack the required access authorization. Supervision and technical restriction should prevent unauthorized access to CUI while enabling the work.
Media storage, access, and sanitization
Requirement 3.8.1 physically controls and securely stores paper and digital system media containing CUI. 3.8.2 limits access to authorized users. Storage and access methods depend on the media and environment; CMMC does not mandate one safe rating or cabinet model.
Requirement 3.8.3 sanitizes or destroys media containing CUI before disposal or release for reuse. NIST SP 800-88 is a common authoritative source for selecting clear, purge, or destroy methods, but the chosen method must fit the media, information, agency policy, and contract. The result must prevent unauthorized recovery; there is no universal shred dimension in CMMC.
Requirement 3.8.4 marks media with necessary CUI markings and distribution limitations. Marking follows applicable CUI Program, agency, and contract instructions. Do not assume every internal note has identical markings or that a CUI label creates authority by itself.
Transport and portable media
Requirement 3.8.5 controls access to media containing CUI and maintains accountability during transport outside controlled areas. Custody records, packaging, authorized carriers, receipt, and physical protection may be relevant.
Requirement 3.8.6 uses cryptographic mechanisms to protect CUI stored on digital media during transport unless alternative physical safeguards protect it. Encryption is therefore not the only permitted path in the requirement. When cryptography is used for CUI confidentiality, 3.13.11 requires FIPS-validated cryptography.
Requirement 3.8.7 controls removable-media use on system components. 3.8.8 prohibits portable storage devices when the devices have no identifiable owner. The latter does not categorically ban every owned portable device; authorization, control, scanning, encryption, and accountability may still be required by the full set of objectives.
Requirement 3.8.9 protects the confidentiality of backup CUI at storage locations. The team follows backups across local, off-site, removable, and provider locations and evaluates access, media, scope, and cryptographic claims.
Requirement-to-evidence map
| Event | Primary evidence link |
|---|---|
| Nonlocal maintenance | Approved technician and task, external connection, MFA event, session start and termination |
| Off-site repair | Equipment identity, CUI decision, sanitization record, custody, and return validation |
| Digital-media transport | Media owner, authorization, custody, cryptographic module or alternative physical safeguard, and receipt |
| Disposal or reuse | Media identity, approved method, performer, result, and reconciliation to inventory |
| Backup storage | Backup content and location, provider scope, authorized access, and confidentiality protection |
Evidence sequence
For maintenance, sample work orders and trace authorization, tools, access, remote MFA, termination, off-site handling, diagnostic media, and supervision. For media, trace representative paper, removable media, backup, and disposal or reuse events from creation through storage, transport, and end of life.
A policy that bans unknown USB devices does not prove the endpoint blocks them. A certificate of destruction does not prove the listed media was the media containing CUI. A courier receipt does not prove access was controlled throughout transport. The finding follows the linked artifact, mechanism, activity, and person.
Provider-maintenance example
A vendor uses a provider-owned laptop for remote maintenance and downloads diagnostic output. Determine whether CUI or SPD reached provider assets, whether the service is an ESP, how remote access was authorized and protected, whether MFA and session termination worked, and how downloaded media is controlled. The maintenance ticket alone cannot resolve provider scope or media handling. One event may require evidence across MA, MP, AC, IA, SC, AU, and the CRM.
What does 3.7.5 require for nonlocal maintenance through an external network connection?
How may 3.8.6 protect digital media containing CUI during transport?
What does 3.8.8 prohibit?