Why: Brokered, logged, time-bound vendor remote access is nonlocal maintenance discipline by another name: the practice's gateway enforces authentication at session establishment, its approval-per-window model is the requirement's 'approve and monitor' in operation, and time-bound access makes termination structural rather than trusted.
What this does not claim: The requirement covers nonlocal maintenance across the whole environment — IT infrastructure, network gear, and business systems maintained remotely, not only OT pathways — and those channels need the same treatment separately. Replay-resistant multi-factor authentication at session establishment is a specific technical bar the chosen gateway must actually clear; a jump host with passwords and a timer does not.
- Route all vendor and remote maintenance into OT through a single brokered gateway with MFA and session recording
- Grant access per approved maintenance window and let it expire automatically
- Review session recordings or logs for sensitive maintenance activities
- Gateway configuration showing MFA and session expiry
- Per-window access approvals
- Session logs or recordings with start and end times
Where this holds: Strongest where vendor remote access into production is the dominant nonlocal-maintenance path; enterprise-IT remote maintenance needs parallel treatment.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06