Patches and security updates for Operating Systems and critical system components shall be installed.
The organization shall plan, perform and document preventive maintenance and repairs on its critical system components according to approved processes and tools.
The organization shall enforce approval requirements, control, and monitoring of maintenance tools for use on the its critical systems.
The organization shall verify security controls following hardware maintenance or repairs, and take action as appropriate.
The organization shall prevent the unauthorized removal of maintenance equipment containing organization's critical system information.
Maintenance tools and portable storage devices shall be inspected when brought into the facility and shall be protected by anti-malware solutions so that they are scanned for malicious code before they are used on organization's systems.
The organization shall verify security controls following hardware and software maintenance or repairs/patching and take action as appropriate.