Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.7.6OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.7.6Maintenance personnel supervision

3.7 Maintenance · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Supervise the maintenance activities of maintenance personnel without required access authorization.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

The service technician who holds no access authorization does not roam. Someone who does hold authorization — and can tell whether the work is what it claims to be — watches: an escort on site, a shadowed or recorded session for remote work.

Mapped practices

Brilliant at the Basics practices that support this requirement

Contextual relationshipLow confidence

Why: The practice's supervised or recorded vendor sessions give the organization a working mechanism for overseeing remote maintenance performed by personnel who hold no access authorization — the remote face of what this requirement asks for.

What this does not claim: Directional only. The requirement is an oversight discipline about people — determining who holds access authorization and supervising those who do not, on site as much as remotely — and the practice neither makes that determination nor establishes the on-site escort process. Session recording informs the remote slice; the rest is separate work.

Practice-side activities
  • Record or supervise vendor sessions on critical systems as the practice's governed state prescribes
  • Reconcile session records against the engagement so an unexpected operator is an investigable event
Evidence this produces
  • Recorded or supervised session records for vendor maintenance
  • Session-to-work-order reconciliation notes

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Supervision applies to remote maintenance too: a watched or recorded session is the remote equivalent of the escort walking the technician to the cabinet.
  • Decide in advance which vendors hold access authorization and which are escorted; working it out at the door is how unsupervised access happens.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Visitor and escort logs for maintenance visits
  • Supervised- or recorded-session records for remote maintenance
  • The list distinguishing authorized maintenance providers from escorted ones

Suggested owners, derived from the mapped practices and artifacts: OT / network administrator. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated