Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.07.06OFFICIAL TITLEPENDING NIST SME REVIEW

03.07.06Maintenance Personnel

03.07 Maintenance · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires establishing a process for maintenance personnel authorization, maintaining a list of authorized maintenance organizations or personnel, verifying that non-escorted maintenance personnel have required access authorizations, and supervising the maintenance activities of personnel who lack them.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Who may work on the system is decided ahead of time, not at the door. Maintainers are either authorized and on the list, or they work escorted and supervised — which for most contractors is how the copier technician, the HVAC vendor, and the one-off specialist are handled.

Across revisions

Expands Rev. 2's 3.7.6: supervision of unauthorized maintainers carries forward, and Rev. 3 adds the explicit authorization process, the maintained list, and verification of access authorizations for unescorted personnel.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Keep the authorized-maintainer list current and tied to the vendor register; a departure at the vendor should remove the person from your list too.
  • Define what supervision means for an unauthorized maintainer: a knowledgeable escort watching the work, not a badge-holder reading email nearby.
  • Cover remote maintainers as well — personnel authorization applies to the person on the other end of a nonlocal session, not only to visitors on site.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The authorized maintenance personnel or organization list with review dates
  • Escort and supervision records for non-authorized maintainers
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated