Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.7.3OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.7.3Off-site maintenance sanitization

3.7 Maintenance · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Ensure equipment removed for off-site maintenance is sanitized of any CUI.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

A server sent for repair, a copier returned to the leasing company, a laptop shipped back under warranty — anything leaving for off-site service is scrubbed of CUI first. The failure mode is the storage nobody thought about inside the device.

Across revisions

The standalone slot (03.07.03) is withdrawn in Rev. 3; equipment sanitization before off-site maintenance travels with the consolidated Maintenance Tools requirement, 03.07.04.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Make sanitization a gate in the RMA and service workflow, not a memory test: no equipment leaves without a sanitization or media-removal record attached to the ticket.
  • Hunt the non-obvious storage — printer and copier drives, controller SD cards, appliance flash — which is where this requirement actually fails.
  • Where a failed drive cannot be wiped, keep-your-drive contract clauses or documented destruction do the work instead.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Sanitization records tied to service and RMA tickets
  • A documented procedure naming approved sanitization methods per media type
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated