{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Secure Configuration & Change Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CONFIG-08","description":"Approve, inspect, and control maintenance tools and media brought into facilities, checking them for improper modification and malicious code. Authorize and supervise maintenance personnel against a current list of approved individuals, with escorts for those lacking required access authorizations. Require nonlocal maintenance sessions to use approved connections and strong authentication, record the session, and terminate connections when maintenance is complete.","details":{"control_category":"administrative","control_type":"preventive","domain":"Secure Configuration & Change Management","guidance":[],"members":[{"control_id":"MA-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"MA-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"MA-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Approve, inspect, and control maintenance tools and media brought into facilities, checking them for improper modification and malicious code. Authorize and supervise maintenance personnel against a current list of approved individuals, with escorts for those lacking required access authorizations. Require nonlocal maintenance sessions to use approved connections and strong authentication, record the session, and terminate connections when maintenance is complete.","title":"Control maintenance tools, personnel, and remote sessions","unified_id":"UC-CONFIG-08"},"id":"uc:UC-CONFIG-08","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CONFIG-08","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-CONFIG-08 — Control maintenance tools, personnel, and remote sessions","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1ebb00b3f0dd3045b31612052817526c50fe9eaa2243a3c69bd3fe401bba60d0","properties":{"rationale":"Inspecting maintenance tools/media for tampering blocks one narrow injection vector, but broad authenticity/integrity verification of acquired hardware and software (UC-CONFIG-06) is the operative supply-chain-injection defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","sourceId":"uc:UC-CONFIG-08","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ebf21110b9932582be6513a500ca6708f85bc247708ad7418fd99bd4630a82a","properties":{"rationale":"Controlling and scanning maintenance media for malicious code contributes to preventing malicious-code introduction via removable media.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","sourceId":"uc:UC-CONFIG-08","targetDetailPath":"/data/v1/records/risk-asset-uncontrolled-copying-removable-media-4a9604c7.json","targetId":"risk:asset-uncontrolled-copying-removable-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:66b3d3aad91497c34fbf2759a01d50a1872a5c3b0a00bc4fb7a7ea0a60d7ef30","properties":{"control_id":"MA-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","sourceId":"uc:UC-CONFIG-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ma-3-1dc1f1d5.json","targetId":"ctrl:nist-800-53:MA-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8fb27186fb1ba1f35ead830154fc2ace7105757a1e1e1f9b5126a8a07db24ff7","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","targetId":"uc:UC-CONFIG-08","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cab6ba33ac56be560b1cd2bff9850337e61f2317f17526303973d0a8d5e23fde","properties":{},"sourceDetailPath":"/data/v1/records/wf-c47-ef7838c6.json","sourceId":"wf:C47","targetDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","targetId":"uc:UC-CONFIG-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7572b6ed0ed0866d061309cf329cc9fbcf271d557a78269399bd03b168b0180","properties":{"control_id":"MA-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","sourceId":"uc:UC-CONFIG-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ma-5-6368e475.json","targetId":"ctrl:nist-800-53:MA-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e90a8dc6d37249e0039f8735c8498145dc9e3f793446956ecb11e1c502f09805","properties":{"control_id":"MA-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","sourceId":"uc:UC-CONFIG-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ma-4-37364968.json","targetId":"ctrl:nist-800-53:MA-4","type":"maps_to"}],"schemaVersion":1}
