- Keep the authorized-maintainer list current and tied to the vendor register; a departure at the vendor should remove the person from your list too.
- Define what supervision means for an unauthorized maintainer: a knowledgeable escort watching the work, not a badge-holder reading email nearby.
- Cover remote maintainers as well — personnel authorization applies to the person on the other end of a nonlocal session, not only to visitors on site.
03.07.06 — Maintenance Personnel
03.07 Maintenance · NIST SP 800-171 Rev. 3
Requires establishing a process for maintenance personnel authorization, maintaining a list of authorized maintenance organizations or personnel, verifying that non-escorted maintenance personnel have required access authorizations, and supervising the maintenance activities of personnel who lack them.
Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.
NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI ↗What this requirement is after
Who may work on the system is decided ahead of time, not at the door. Maintainers are either authorized and on the list, or they work escorted and supervised — which for most contractors is how the copier technician, the HVAC vendor, and the one-off specialist are handled.
Expands Rev. 2's 3.7.6: supervision of unauthorized maintainers carries forward, and Rev. 3 adds the explicit authorization process, the maintained list, and verification of access authorizations for unescorted personnel.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- The authorized maintenance personnel or organization list with review dates
- Escort and supervision records for non-authorized maintainers
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this came from in Rev. 2
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |