Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.07.05OFFICIAL TITLEPENDING NIST SME REVIEW

03.07.05Nonlocal Maintenance

03.07 Maintenance · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires approving and monitoring nonlocal maintenance and diagnostic activities, implementing multi-factor authentication and replay resistance when establishing nonlocal maintenance and diagnostic sessions, and terminating session and network connections when the maintenance is complete.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Remote maintenance is remote access with elevated privileges — often a vendor's. Every such session needs prior approval, strong authentication on the way in, observation while it runs, and a hard end when the work is done. The standing vendor tunnel that is 'always there when needed' is exactly what this rules out.

Across revisions

Carried from Rev. 2's 3.7.5 and broadened: multifactor authentication and session termination remain, and Rev. 3 adds explicit approval and monitoring of the activity plus replay resistance for session establishment.

Mapped practices

Brilliant at the Basics practices that support this requirement

Direct implementation supportModerate confidence

Why: Brokered, logged, time-bound vendor remote access is nonlocal maintenance discipline by another name: the practice's gateway enforces authentication at session establishment, its approval-per-window model is the requirement's 'approve and monitor' in operation, and time-bound access makes termination structural rather than trusted.

What this does not claim: The requirement covers nonlocal maintenance across the whole environment — IT infrastructure, network gear, and business systems maintained remotely, not only OT pathways — and those channels need the same treatment separately. Replay-resistant multi-factor authentication at session establishment is a specific technical bar the chosen gateway must actually clear; a jump host with passwords and a timer does not.

Practice-side activities
  • Route all vendor and remote maintenance into OT through a single brokered gateway with MFA and session recording
  • Grant access per approved maintenance window and let it expire automatically
  • Review session recordings or logs for sensitive maintenance activities
Evidence this produces
  • Gateway configuration showing MFA and session expiry
  • Per-window access approvals
  • Session logs or recordings with start and end times

Where this holds: Strongest where vendor remote access into production is the dominant nonlocal-maintenance path; enterprise-IT remote maintenance needs parallel treatment.

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Partial implementation supportModerate confidence

Why: The requirement makes multi-factor authentication a condition of establishing nonlocal maintenance sessions, and the practice's phishing-resistant MFA rollout — privileged and remote access first — covers exactly those sessions wherever they authenticate through the identity provider.

What this does not claim: Authentication is one clause of three: approval and monitoring of the maintenance activity and verified termination of sessions are process obligations the MFA rollout does not create. Maintenance paths that bypass the identity provider — appliance-local logins, vendor tools with their own authentication — stay outside the practice's enforcement, and those are precisely where nonlocal maintenance tends to happen.

Practice-side activities
  • Put remote administrative and maintenance access paths behind identity-provider MFA enforcement
  • Inventory maintenance channels that authenticate outside the identity provider and assign each an owner
Evidence this produces
  • MFA enforcement policy covering remote administrative access
  • The exception list of locally-authenticating maintenance paths

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Broker vendor and remote maintenance through a controlled gateway that enforces multi-factor authentication, records sessions, and expires access on a schedule — not vendor-managed remote tools or a forgotten modem.
  • Make approval an event: a ticket or authorization per maintenance window, so 'approve and monitor' is demonstrable per session rather than asserted in general.
  • Verify termination is real — the account disabled, the tunnel closed — rather than trusting the far end to log out.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Per-window approval records for nonlocal maintenance
  • Gateway or session logs showing authentication method and session end times
  • The register of vendors and pathways authorized for nonlocal maintenance

Suggested owners, derived from the mapped practices and artifacts: OT / network administrator · Identity administrator · Network admin. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated