San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

MA-4 Nonlocal Maintenance

Maintenance family. 27 Control Correlation Identifiers map to this control, and 76 STIG rules implement those CCIs.

11CAT I (high)
64CAT II (medium)
1CAT III (low)
27CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to MA-4
Red Hat Enterprise Linux 9V255
Microsoft Windows 10V36
Microsoft Windows Server 2019V35
Microsoft Windows 11V25
Microsoft Windows Server 2022V25

Control Correlation Identifiers mapped to MA-4

CCIDefinitionRev
CCI-000873Approve nonlocal maintenance and diagnostic activities.5, 4
CCI-000874Monitor nonlocal maintenance and diagnostic activities.5, 4
CCI-000876Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system.5, 4
CCI-000877Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.5, 4
CCI-000878Maintain records for nonlocal maintenance and diagnostic activities.5, 4
CCI-000879The organization terminates sessions and network connections when nonlocal maintenance is completed.4
CCI-000881The organization documents, in the security plan for the information system, the policies and procedures for the establishment and use of nonlocal maintenance and diagnostic connections.4
CCI-000882Require that nonlocal maintenance and diagnostic services be performed from a system that implements a security capability comparable to the capability implemented on the system being serviced.5, 4
CCI-000883Remove the component to be serviced from the system prior to nonlocal maintenance or diagnostic services; sanitize the component (for organizational information).5, 4
CCI-000884Protect nonlocal maintenance sessions by employing organization-defined authenticators that are replay resistant.5, 4
CCI-000886Defines the personnel or roles to be notified of the date and time of planned nonlocal maintenance.5, 4
CCI-000887Require the approval of each nonlocal maintenance session by organization-defined personnel or roles.5, 4
CCI-001631After the service is performed, inspect and sanitize the component (for potentially malicious software) before reconnecting the component to the system.5, 4
CCI-001632Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by either physically separated communications paths or logically separated communications paths based upon encryption.5, 4
CCI-002884Log organization-defined audit events for nonlocal maintenance and diagnostic sessions.5, 4
CCI-002885Defines the audit events for logged for nonlocal maintenance and diagnostic sessions.5, 4
CCI-002886Review the audit records of the maintenance and diagnostic sessions to detect anomalous behavior.5, 4
CCI-002887Defines the authenticators that are replay resistant which will be employed to protect nonlocal maintenance sessions.5, 4
CCI-002888Defines the personnel or roles authorized to approve each nonlocal maintenance session.5, 4
CCI-002889Notify organization-defined personnel or roles of the date and time of planned nonlocal maintenance.5, 4
CCI-002890Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.5, 4
CCI-002891Verify session and network connection termination after the completion of nonlocal maintenance and diagnostic sessions.5, 4
CCI-003123Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.5, 4
CCI-004190Terminate session when nonlocal maintenance is completed.5
CCI-004191Terminate network connection when nonlocal maintenance is completed.5
CCI-004192Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by logically separated communications paths.5
CCI-004193Defines the cryptographic mechanisms for protecting the integrity and confidentiality of nonlocal maintenance and diagnostic communications.5

STIG rules that implement MA-4

RuleSTIG IDSeverityRequirement
V-205711WN19-CC-000470highWindows Server 2019 Windows Remote Management (WinRM) client must not use Basic authentication.
V-205712WN19-CC-000490mediumWindows Server 2019 Windows Remote Management (WinRM) client must not use Digest authentication.
V-205713WN19-CC-000500highWindows Server 2019 Windows Remote Management (WinRM) service must not use Basic authentication.
V-205816WN19-CC-000480mediumWindows Server 2019 Windows Remote Management (WinRM) client must not allow unencrypted traffic.
V-205817WN19-CC-000510mediumWindows Server 2019 Windows Remote Management (WinRM) service must not allow unencrypted traffic.
V-220852WN10-CC-000290mediumRemote Desktop Services must be configured with the client connection encryption set to the required level.
V-220862WN10-CC-000330highThe Windows Remote Management (WinRM) client must not use Basic authentication.
V-220863WN10-CC-000335mediumThe Windows Remote Management (WinRM) client must not allow unencrypted traffic.
V-220865WN10-CC-000345highThe Windows Remote Management (WinRM) service must not use Basic authentication.
V-220866WN10-CC-000350mediumThe Windows Remote Management (WinRM) service must not allow unencrypted traffic.
V-220868WN10-CC-000360mediumThe Windows Remote Management (WinRM) client must not use Digest authentication.
V-253416WN11-CC-000330highThe Windows Remote Management (WinRM) client must not use Basic authentication.
V-253417WN11-CC-000335mediumThe Windows Remote Management (WinRM) client must not allow unencrypted traffic.
V-253418WN11-CC-000345highThe Windows Remote Management (WinRM) service must not use Basic authentication.
V-253419WN11-CC-000350mediumThe Windows Remote Management (WinRM) service must not allow unencrypted traffic.
V-253421WN11-CC-000360mediumThe Windows Remote Management (WinRM) client must not use Digest authentication.
V-254378WN22-CC-000470highWindows Server 2022 Windows Remote Management (WinRM) client must not use Basic authentication.
V-254379WN22-CC-000480mediumWindows Server 2022 Windows Remote Management (WinRM) client must not allow unencrypted traffic.
V-254380WN22-CC-000490mediumWindows Server 2022 Windows Remote Management (WinRM) client must not use Digest authentication.
V-254381WN22-CC-000500highWindows Server 2022 Windows Remote Management (WinRM) service must not use Basic authentication.
V-254382WN22-CC-000510mediumWindows Server 2022 Windows Remote Management (WinRM) service must not allow unencrypted traffic.
V-257796RHEL-09-212055lowRHEL 9 must enable auditing of processes that start prior to the audit daemon.
V-257986RHEL-09-255050highRHEL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
V-257996RHEL-09-255100mediumRHEL 9 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.
V-258151RHEL-09-653010mediumRHEL 9 audit package must be installed.
V-258152RHEL-09-653015mediumRHEL 9 audit service must be enabled.
V-258177RHEL-09-654015mediumRHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls.
V-258178RHEL-09-654020mediumRHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.
V-258179RHEL-09-654025mediumRHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
V-258180RHEL-09-654030mediumRHEL 9 must audit all uses of umount system calls.
V-258181RHEL-09-654035mediumRHEL 9 must audit all uses of the chacl command.
V-258182RHEL-09-654040mediumRHEL 9 must audit all uses of the setfacl command.
V-258183RHEL-09-654045mediumRHEL 9 must audit all uses of the chcon command.
V-258184RHEL-09-654050mediumRHEL 9 must audit all uses of the semanage command.
V-258185RHEL-09-654055mediumRHEL 9 must audit all uses of the setfiles command.
V-258186RHEL-09-654060mediumRHEL 9 must audit all uses of the setsebool command.
V-258187RHEL-09-654065mediumRHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.
V-258188RHEL-09-654070mediumRHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
V-258189RHEL-09-654075mediumRHEL 9 must audit all uses of the delete_module system call.
V-258190RHEL-09-654080mediumRHEL 9 must audit all uses of the init_module and finit_module system calls.
V-258191RHEL-09-654085mediumRHEL 9 must audit all uses of the chage command.
V-258192RHEL-09-654090mediumRHEL 9 must audit all uses of the chsh command.
V-258193RHEL-09-654095mediumRHEL 9 must audit all uses of the crontab command.
V-258194RHEL-09-654100mediumRHEL 9 must audit all uses of the gpasswd command.
V-258195RHEL-09-654105mediumRHEL 9 must audit all uses of the kmod command.
V-258196RHEL-09-654110mediumRHEL 9 must audit all uses of the newgrp command.
V-258197RHEL-09-654115mediumRHEL 9 must audit all uses of the pam_timestamp_check command.
V-258198RHEL-09-654120mediumRHEL 9 must audit all uses of the passwd command.
V-258199RHEL-09-654125mediumRHEL 9 must audit all uses of the postdrop command.
V-258200RHEL-09-654130mediumRHEL 9 must audit all uses of the postqueue command.
V-258201RHEL-09-654135mediumRHEL 9 must audit all uses of the ssh-agent command.
V-258202RHEL-09-654140mediumRHEL 9 must audit all uses of the ssh-keysign command.
V-258203RHEL-09-654145mediumRHEL 9 must audit all uses of the su command.
V-258204RHEL-09-654150mediumRHEL 9 must audit all uses of the sudo command.
V-258205RHEL-09-654155mediumRHEL 9 must audit all uses of the sudoedit command.
V-258206RHEL-09-654160mediumRHEL 9 must audit all uses of the unix_chkpwd command.
V-258207RHEL-09-654165mediumRHEL 9 must audit all uses of the unix_update command.
V-258208RHEL-09-654170mediumRHEL 9 must audit all uses of the userhelper command.
V-258209RHEL-09-654175mediumRHEL 9 must audit all uses of the usermod command.
V-258210RHEL-09-654180mediumRHEL 9 must audit all uses of the mount command.
V-258215RHEL-09-654205mediumSuccessful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record.
V-258216RHEL-09-654210mediumSuccessful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.
V-258217RHEL-09-654215mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
V-258218RHEL-09-654220mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
V-258219RHEL-09-654225mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
V-258220RHEL-09-654230mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
V-258221RHEL-09-654235mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
V-258222RHEL-09-654240mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
V-258223RHEL-09-654245mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
V-258224RHEL-09-654250mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.
V-258225RHEL-09-654255mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.
V-258226RHEL-09-654260mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog.
V-258230RHEL-09-671010highRHEL 9 must enable FIPS mode.
V-258234RHEL-09-215100mediumRHEL 9 must have the crypto-policies package installed.
V-258236RHEL-09-672020highRHEL 9 cryptographic policy must not be overridden.
V-258241RHEL-09-215105mediumRHEL 9 must implement a FIPS 140-3 compliant systemwide cryptographic policy.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/MA-4. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.