https://www.kaseya.com/blog/patch-management-policy/
In this blog, Kaseya will discuss patch management policy best practices and explain how they contribute to a better patching environment for large and small organizations alike.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-147B.pdf
This NIST Special Publication is designed to provide guidelines for BIOS protections in server-class systems.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-209.pdf
This NIST Special Publication is designed to provide a comprehensive set of security recommendations for the current landscape of the storage infrastructure.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf
This NIST Special Publication is designed to assist organizations in understanding the basics of enterprise patch management technologies.
NIST SP 800-53 Rev 5: MA–2 Controlled Maintenance
3.7 3.7.1 3.7.2 Maintenance
https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-02
NIST resources that defines requirement for controlled maintenance.
https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03
NIST resources that defines requirements for review, assessment, and approval of system maintenance tools
NIST SP 800-53 Rev 5: MA–4 Nonlocal Maintenance
3.7 3.7.1 3.7.5 Maintenance
https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-04
NIST resources that define requirements for nonlocal system maintenance activities
YouTube – CMMC 2.0 Control MA L2-3.7.2 – Provide controls on the tools, techniques, mechanisms, and personnel
3.7 3.7.1 3.7.2 Maintenance
https://www.youtube.com/watch?v=JVookLZAqCk
In this video, Mike breaks down CMMC 2.0 Control MA L2-3.7.2. You need written procedures, you need documentation on your process for allowing access to your systems, you are going to have to justify every step of how you run your system on paper through written procedure and that includes your IT team and who gets access to what and how they get that access.
https://www.youtube.com/watch?v=QQ8oo_bstR8
In this video, Mike breaks down CMMC 2.0 Control MA.L2-3.7.1. Yes, you are required to perform proper maintenance on your systems… and they had to make this dummy proof so they made an entire control just for this.