Information Systems Maintenance
BLINN COLLEGE ADMINISTRATIVE REGULATIONS MANUAL
- SUBJECT:
- Information Systems Maintenance
- EFFECTIVE DATE:
- June 1, 2020
- BOARD POLICY REFERENCE:
- CS
PURPOSE
Develop policies and procedures for information system maintenance.
PROCESS
System Maintenance Policy and Procedures (MA-01)
The College District:
- Develops, documents, and disseminates to information system owners:
- A system maintenance policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
- Procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls; and
- Reviews and updates the current:
- System maintenance policy biennially; and
- System maintenance procedures annually.
Controlled Maintenance (MA-01)
The College District:
- Schedules, performs, documents, and reviews records of maintenance and repairs on information system components in accordance with manufacturer or vendor specifications and/or organizational requirements;
- Approves and monitors all maintenance activities, whether performed on site or remotely and whether the equipment is serviced on site or removed to another location;
- Requires that information system owner explicitly approve the removal of the information system or system components from organizational facilities for off-site maintenance or repairs;
- Sanitizes equipment to remove all information from associated media prior to removal from organizational facilities for off-site maintenance or repairs;
- Checks all potentially impacted security controls to verify the controls are still functioning properly following maintenance or repair actions; and
- Includes changes in organizational maintenance and change records using the technology help desk.
Nonlocal Maintenance (MA-04)
The College District:
- Approves and monitors nonlocal maintenance and diagnostic activities;
- Allows the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the information system;
- Employs strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions;
- Maintains records for nonlocal maintenance and diagnostic activities; and
- Terminates session and network connections when nonlocal maintenance is completed.
Maintenance Personnel (MA-05)
The College District:
- Establishes a process for maintenance personnel authorization and maintains a list of authorized maintenance organizations or personnel;
- Nonlocal maintenance personnel and organizations are selected based on vendor authorized qualifications; maintenance agreements and direct vendor support.
- Ensures that non-escorted personnel performing maintenance on the information system have required access authorizations; and
- Designates organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.