NIST 800-171 Controls · Maintenance
MA.2.113 — Ensure equipment removed for offsite maintenance is sanitized
Ensure equipment removed for offsite maintenance is sanitized to remove the following information from equipment prior to removal: CUI and FCI.
What MA.2.113 means in plain English
If a laptop or server needs to leave your office for repair — whether sent to a manufacturer, a repair shop, or your MSP — you must first remove all CUI (Controlled Unclassified Information) from it before it leaves. This means wiping the hard drive or using BitLocker to encrypt the data so the repair technician cannot read your government contract files even if they tried. If you cannot sanitize a device before it leaves (e.g., the hard drive is broken and that is why it is being repaired), you must document this as a risk and take compensating measures like requiring an escort or NDA.
The assessment question
“Is there a documented procedure requiring CUI and FCI to be removed or cryptographically protected before any system equipment leaves the organization's premises for offsite maintenance — and is compliance tracked per equipment removal?”
How to implement MA.2.113
- Create an Equipment Removal Procedure that requires: (1) review whether the device contains CUI, (2) if yes, either delete CUI files and verify deletion, or use BitLocker to encrypt the drive before the device leaves, (3) document the removal in an Equipment Removal Log.
- Enable BitLocker full-disk encryption on all Windows workstations and laptops (built-in, free on Windows Pro/Enterprise) — this means even if a laptop goes offsite, the data is cryptographically protected.
- For devices where data cannot be removed (broken hard drive going to repair), require a signed NDA and data handling agreement from the repair vendor before releasing the device.
- Maintain an Equipment Removal Log: Device Name/Serial, Date Removed, Destination, Purpose, CUI Present (Y/N), Sanitization Method, Return Date.
- Train your team: never send a work laptop to a repair shop without first checking with the owner/manager and completing the Equipment Removal Procedure.
Evidence your assessor will ask for
- Equipment Removal Procedure document
- Equipment Removal Log showing all offsite maintenance events for the past 12 months
- BitLocker encryption status report showing all laptops/workstations are encrypted
- Signed vendor NDA/data handling agreement for any third-party repair vendors used
Does AI prompt monitoring help with this control? Honestly, no.
MA.2.113 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Maintenance controls
Perform maintenance on organizational systems
MA.2.112Provide controls on tools and personnel for maintenance
MA.2.114Check media containing diagnostic programs for malicious code
MA.2.115Require multifactor authentication for nonlocal maintenance
MA.2.116Supervise maintenance activities without required access authorization
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.