manage.get.gov/docs/compliance/dist/system-security-plans/ato/ma-3.3.md
Logan McDonald 1d3dfdb8d5
Add compliance documentation to source control (#116)
* add initial setup of compliance-trestle
2022-09-14 08:46:43 -04:00

2.4 KiB

implementation-status control-origination
c-not-implemented
c-inherited-cloud-gov
c-inherited-cisa
c-common-control
c-system-specific-control

ma-3.3 - [catalog] Prevent Unauthorized Removal

Control Statement

Prevent the removal of maintenance equipment containing organizational information by:

  • [a] Verifying that there is no organizational information contained on the equipment;

  • [b] Sanitizing or destroying the equipment;

  • [c] Retaining the equipment within the facility; or

  • [d] Obtaining an exemption from personnel or roles explicitly authorizing removal of the equipment from the facility.

Control guidance

Organizational information includes all information owned by organizations and any information provided to organizations for which the organizations serve as information stewards.

Control assessment-objective

the removal of maintenance equipment containing organizational information is prevented by verifying that there is no organizational information contained on the equipment; or the removal of maintenance equipment containing organizational information is prevented by sanitizing or destroying the equipment; or the removal of maintenance equipment containing organizational information is prevented by retaining the equipment within the facility; or the removal of maintenance equipment containing organizational information is prevented by obtaining an exemption from personnel or roles explicitly authorizing removal of the equipment from the facility.


What is the solution and how is it implemented?


Implementation (a)

Add control implementation description here for item ma-3.3_smt.a


Implementation (b)

Add control implementation description here for item ma-3.3_smt.b


Implementation (c)

Add control implementation description here for item ma-3.3_smt.c


Implementation (d)

Add control implementation description here for item ma-3.3_smt.d