April 16, 2018
Function
Category
Maintenance (PR.MA):
Maintenance and repairs of
industrial control and information
system components are performed
consistent with policies and
procedures.
Protective Technology (PR.PT):
Technical security solutions are
managed to ensure the security
and resilience of systems and
assets, consistent with related
policies, procedures, and
agreements.
Cybersecurity Framework
Subcategory
Version 1.1
Informative References
PR.IP-12: A vulnerability management
plan is developed and implemented
CIS CSC 4, 18, 20
COBIT 5 BAI03.10, DSS05.01, DSS05.02
ISO/IEC 27001:2013 A.12.6.1, A.14.2.3,
A.16.1.3, A.18.2.2, A.18.2.3
NIST SP 800-53 Rev. 4 RA-3, RA-5, SI-2
PR.MA-1: Maintenance and repair of
organizational assets are performed and
logged, with approved and controlled tools
COBIT 5 BAI03.10, BAI09.02, BAI09.03,
DSS01.05
ISA 62443-2-1:2009 4.3.3.3.7
ISO/IEC 27001:2013 A.11.1.2, A.11.2.4,
A.11.2.5, A.11.2.6
NIST SP 800-53 Rev. 4 MA-2, MA-3, MA-5,
MA-6
PR.MA-2: Remote maintenance of
organizational assets is approved, logged,
and performed in a manner that prevents
unauthorized access
CIS CSC 3, 5
COBIT 5 DSS05.04
ISA 62443-2-1:2009 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7,
4.3.3.6.8
ISO/IEC 27001:2013 A.11.2.4, A.15.1.1, A.15.2.1
NIST SP 800-53 Rev. 4 MA-4
PR.PT-1: Audit/log records are
determined, documented, implemented,
and reviewed in accordance with policy
CIS CSC 1, 3, 5, 6, 14, 15, 16
COBIT 5 APO11.04, BAI03.05, DSS05.04,
DSS05.07, MEA02.01
ISA 62443-2-1:2009 4.3.3.3.9, 4.3.3.5.8, 4.3.4.4.7,
4.4.2.1, 4.4.2.2, 4.4.2.4
ISA 62443-3-3:2013 SR 2.8, SR 2.9, SR 2.10, SR
2.11, SR 2.12
ISO/IEC 27001:2013 A.12.4.1, A.12.4.2,
A.12.4.3, A.12.4.4, A.12.7.1
NIST SP 800-53 Rev. 4 AU Family
PR.PT-2: Removable media is protected
and its use restricted according to policy
CIS CSC 8, 13
COBIT 5 APO13.01, DSS05.02, DSS05.06
ISA 62443-3-3:2013 SR 2.3
ISO/IEC 27001:2013 A.8.2.1, A.8.2.2, A.8.2.3,
A.8.3.1, A.8.3.3, A.11.2.9
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
36