A. Establish a process for maintenance personnel authorization. B. Maintain a list of authorized maintenance organizations or personnel. C. Verify that non-escorted personnel who perform maintenance on the system possess the required access authorizations. D. Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.
Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3
In Plain English
You need a formal process to authorize who can perform maintenance on your systems. Keep an up-to-date list of approved maintenance organizations and individuals. Anyone performing maintenance without an escort must have verified access authorizations. If maintenance personnel lack proper authorization, a qualified staff member with the right access must supervise them at all times.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Maintenance personnel authorization and supervision
Implementation Steps
Document a maintenance personnel authorization process defining how individuals and organizations are vetted and approved
Maintain a current list of authorized maintenance organizations and personnel, including vendor and contractor details
Verify access authorizations for all non-escorted maintenance personnel before granting system access
Designate internal personnel with appropriate clearances and technical skills to escort and supervise unauthorized maintenance workers
Tools / Systems
Vendor management platform (ServiceNow, OneTrust Vendorpedia)Access management system (IdP with guest/contractor accounts)Ticketing system for maintenance authorization workflowVisitor/escort management process documentation
Typical Control Maintenance personnel authorization and supervision
Evidence Artifacts
Maintenance personnel authorization policy and process documentation
Current list of authorized maintenance organizations and individuals
Access verification records for non-escorted maintenance personnel
Escort assignment and supervision logs for unauthorized personnel
📅Per-event authorization verification; annual list review and policy update
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
03.08.01
Media storage
Media protection
3 evidence1 control
03.08.02
Media access
Media protection
3 evidence1 control
03.08.03
Media sanitization
Media protection
3 evidence1 control
03.08.04
Media marking
Media protection
3 evidence1 control
03.08.05
Media transport
Media protection
3 evidence1 control
03.08.07
Media use
Media protection
3 evidence1 control
03.08.09
System backup - cryptographic protection
Media protection
3 evidence1 control
03.09.01
Personnel screening
Personnel security
3 evidence1 control
03.09.02
Personnel termination and transfer
Personnel security
3 evidence1 control
03.10.01
Physical access authorizations
Physical protection
3 evidence1 control
03.10.02
Monitoring physical access
Physical protection
3 evidence1 control
03.10.06
Alternate work site
Physical protection
3 evidence1 control
03.10.07
Physical access control
Physical protection
3 evidence1 control
03.10.08
Access control for transmission
Physical protection
3 evidence1 control
03.11.01
Risk assessment
Risk assessment
3 evidence1 control
03.11.02
Vulnerability monitoring and scanning
Risk assessment
3 evidence1 control
03.11.04
Risk response
Risk assessment
3 evidence1 control
03.12.01
Security assessment
Security assessment and monitoring
3 evidence1 control
03.12.02
Plan of action and milestones
Security assessment and monitoring
3 evidence1 control
03.12.03
Continuous monitoring
Security assessment and monitoring
3 evidence1 control
03.12.05
Information exchange
Security assessment and monitoring
3 evidence1 control
03.13.01
Boundary protection
System and communications protection
3 evidence1 control
03.13.04
Information in shared system resources
System and communications protection
3 evidence1 control
03.13.06
Network communications - deny by default - allow by exception
System and communications protection
3 evidence1 control
03.13.08
Transmission and storage confidentiality
System and communications protection
3 evidence1 control
03.13.09
Network disconnect
System and communications protection
3 evidence1 control
03.13.10
Cryptographic key establishment and management
System and communications protection
3 evidence1 control
03.13.11
Cryptographic protection
System and communications protection
3 evidence1 control
03.13.12
Collaborative computing devices and applications
System and communications protection
3 evidence1 control
03.13.13
Mobile code
System and communications protection
3 evidence1 control
03.13.15
Session authenticity
System and communications protection
3 evidence1 control
03.14.01
Flaw remediation
System and information integrity
3 evidence1 control
03.14.02
Malicious code protection
System and information integrity
3 evidence1 control
03.14.03
Security alerts, advisories, and directives
System and information integrity
3 evidence1 control
03.14.06
System monitoring
System and information integrity
3 evidence1 control
03.14.08
Information management and retention
System and information integrity
3 evidence1 control
03.14.09
Dedicated administration workstation
System and information integrity
3 evidence1 control
03.15.01
Policy and procedures
Planning
3 evidence1 control
03.15.02
System security plan
Planning
3 evidence1 control
03.15.03
Rules of behaviour
Planning
3 evidence1 control
03.16.01
Security engineering principles
System and services acquisition
3 evidence1 control
03.16.02
Unsupported system components
System and services acquisition
3 evidence1 control
03.16.03
External system services
System and services acquisition
3 evidence1 control
03.17.01
Supply chain risk management plan
Supply chain risk management
3 evidence1 control
03.17.02
Acquisition strategies, tools, and methods
Supply chain risk management
3 evidence1 control
03.17.03
Supply chain requirements and processes
Supply chain risk management
3 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Maintenance personnel authorization and supervision
Implementation steps
Create and maintain a maintenance personnel authorization policy documenting vetting requirements and approval workflows
Maintain an approved maintenance personnel list including vendor organizations, individual names, and authorized scope of work
Verify credentials and access authorizations for maintenance personnel before granting unescorted access to systems or facilities
Assign designated escorts from internal staff with required access authorizations and technical competency to supervise unauthorized personnel
Tools / systems
Vendor and contractor management system
Physical access control system (badge management)
Maintenance authorization records (spreadsheet or GRC platform)
Escort and supervision log
Evidence artifacts
Maintenance personnel authorization policy with management approval
Approved maintenance personnel list with revision dates
Access authorization verification records for non-escorted personnel