NIST 800-171 Controls · Maintenance
MA.2.116 — Supervise maintenance activities without required access authorization
Supervise the maintenance activities of maintenance personnel without required access authorization.
What MA.2.116 means in plain English
If a maintenance technician does not have a security clearance or formal authorization to access your CUI systems, you must have an authorized employee physically present with them while they work — or at minimum watching their remote session in real time. A repairman who comes to fix a broken hard drive in your server has no clearance and no authorization to see your government files; an authorized employee must watch them the entire time. This is about accountability: you are responsible for what happens on your systems, so when an uncleared person is working on them, one of your cleared people stays with them.
The assessment question
“Is there a documented procedure requiring that an authorized employee supervises any maintenance technician who does not have the required access authorization — and is this supervision actually occurring and being logged?”
How to implement MA.2.116
- Define "authorized maintenance personnel" in your Maintenance Policy: people who have been background-checked, trained, and formally granted access to systems containing CUI.
- For all other maintenance personnel (repair technicians, hardware vendors, building contractors who must access server rooms), create a "Supervised Maintenance" procedure: an authorized employee must escort and observe the technician for the entire duration.
- For remote supervision, use your remote access tool's session recording feature — the authorized employee watches the live session and the recording is retained for audit.
- Create a Supervision Log entry for every supervised maintenance event: Date, Technician Name/Company, Work Performed, Authorized Supervisor Name, Duration, and any concerns noted.
- Train all employees on the rule: if an uncleared vendor or contractor needs access to company IT systems, they must call an authorized employee to supervise — no exceptions.
Evidence your assessor will ask for
- Maintenance Policy defining authorized vs. unauthorized maintenance personnel
- Supervised Maintenance Procedure document
- Supervision Log with entries for the past 12 months
- Session recording files or screenshots for remote supervised maintenance sessions
- Physical visitor log showing escorted access for any on-premises maintenance visits
Does AI prompt monitoring help with this control? Honestly, no.
MA.2.116 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Maintenance controls
Perform maintenance on organizational systems
MA.2.112Provide controls on tools and personnel for maintenance
MA.2.113Ensure equipment removed for offsite maintenance is sanitized
MA.2.114Check media containing diagnostic programs for malicious code
MA.2.115Require multifactor authentication for nonlocal maintenance
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.