Policy and Procedures MA-1
Maintenance · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds MA-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Maintenance family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
MA-1 (Policy and Procedures) is the written foundation for maintenance: a maintenance policy that says why maintenance is controlled, who is responsible, and how it is done — plus the procedures that put the policy into practice. It is a documentation control that anchors the rest of the MA (Maintenance) family, and it sits in the Low baseline.
What good looks like
- Write a maintenance policy that states purpose, scope, roles, responsibilities, and how compliance is enforced.
- Back the policy with procedures — the actual steps for scheduling, approving, and recording maintenance on the server.
- Name an owner — one person or role responsible for keeping the policy and procedures current.
- Disseminate the documents to the people who do or approve maintenance, so nobody is guessing.
- Review and update on a schedule (for example, yearly) and after big changes — a new operating system, a new hosting location, or an incident.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established, communicated, and enforced
How to move it toward Implemented
- Write a one- to two-page maintenance policy: purpose, scope, roles, who approves maintenance, and a review cadence.
- Add a short procedure that points at the concrete tasks — how
MA-2maintenance is logged, howMA-4remote sessions are handled, and who is on theMA-5authorized list. - Put an owner name and a ‘next review’ date at the top of the document, and store it where the team can find it.
- Attach the signed policy and procedures as hardening evidence on the asset, naming
MA-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.