CMMC Practice Requirement:

Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

CMMC Requirement Explanation:

Unapproved tools may be malicious and can damage your environment. Only use tools approved by your company to conduct maintenance.

Example CMMC Implementation:

Establish a list of approved maintenance tools. This can be specified in your IT standard operating procedures. Examples of maintenance tools include network packet sniffers and software used to deploy updates to your systems. Only allow your system admins to use approved tools. Unapproved tools may be malicious and can damage your environment.


- Scenario 1:

Alice, a system administrator wants to update the drivers on an employees Dell laptop. She decides to use a "driver update" tool she found online. After using the tool she documents it in a ticket. The IT manager notices that Alice didn't use the approved driver update tool from Dell. He warns Alice to only use approved maintenance tools.

- Scenario 2:

Joe is a security analyst and needs to capture packets on his network. The approved tool for capturing packets is WireShark however Joe decides to use another too. Joe's manager discovers that Joe has used an approved tool and warns him not to do so going forward.

Discover Our NIST SP 800-171 Solutions:


Compliance Accelerator

For contractors seeking compliance

Quantum Assessor

For IT service providers

Supply Chain Verifier

For contractors seeking to verify partner compliance