<section title="12.5. Product Maintenance and Repairs"><subsection title="Objective"><paragraph
    title="12.5.1."


><![CDATA[<p>Products are repaired by cleared or appropriately escorted personnel.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="12.5.2."


><![CDATA[<p>This section covers information on maintaining and repairing both evaluated and non-evaluated IT equipment.</p>]]></paragraph>
</block>
</subsection>
<subsection title="Rationale &amp; Controls"> <block title="Maintenance and repairs"><paragraph
    title="12.5.3.R.01."

    tags="Technical,High Assurance Products,Product Security"


><![CDATA[<p>Making unauthorised repairs to high assurance products or HACE can impact the integrity of the product or equipment.</p>]]></paragraph>
<paragraph
    title="12.5.3.R.02."

    tags="Technical,Product Security"


><![CDATA[<p>Using cleared technicians on-site at an agency’s facilities is considered the most desired approach to maintaining and repairing IT equipment. This ensures that if classified information is disclosed during the course of maintenance or repairs, the technicians are aware of the protection requirements for the information.</p>]]></paragraph>
<paragraph
    title="12.5.3.C.01."

    tags="Technical,High Assurance Products,Product Security"


    classification="All Classifications"
    compliance="Must"
    cid="3481"
><![CDATA[<p>Agencies MUST seek GCSB approval before undertaking any repairs to high assurance products or HACE.</p>]]></paragraph>
<paragraph
    title="12.5.3.C.02."

    tags="Technical,Product Security"


    classification="All Classifications"
    compliance="Should"
    cid="3483"
><![CDATA[<p>Maintenance and repairs of IT equipment containing media SHOULD be carried out on-site by an appropriately cleared technician.</p>]]></paragraph>
</block>
<block title="Maintenance and repairs by an uncleared technician"><paragraph
    title="12.5.4.R.01."

    tags="Technical,Product Security"


><![CDATA[<p>Agencies choosing to use uncleared technicians to maintain or repair IT equipment on-site at an agency’s facilities, or off-site at a company’s facilities, should be aware of the requirement for cleared personnel to escort the uncleared technicians during maintenance or repair activities.</p>]]></paragraph>
<paragraph
    title="12.5.4.C.01."

    tags="Technical,Product Security"


    classification="All Classifications"
    compliance="Must"
    cid="3492"
><![CDATA[<p>If an uncleared technician is used to undertake maintenance or repairs of IT equipment, the technician MUST be escorted by someone who:</p><ul>
<li>is appropriately cleared and briefed;</li>
<li>takes due care to ensure that classified information is not disclosed;</li>
<li>takes all responsible measures to ensure the integrity of the equipment; and</li>
<li>has the authority to direct the technician.</li>
</ul>]]></paragraph>
<paragraph
    title="12.5.4.C.02."

    tags="Technical,Product Security"


    classification="All Classifications"
    compliance="Should"
    cid="3493"
><![CDATA[<p>If an uncleared technician is used to undertake maintenance or repairs of IT equipment, agencies SHOULD sanitise and reclassify or declassify the equipment and associated media before maintenance or repair work is undertaken.</p>]]></paragraph>
<paragraph
    title="12.5.4.C.03."

    tags="Technical,Product Security"


    classification="All Classifications"
    compliance="Should"
    cid="3494"
><![CDATA[<p>Agencies SHOULD ensure that the ratio of escorts to uncleared technicians allows for appropriate oversight of all activities.</p>]]></paragraph>
<paragraph
    title="12.5.4.C.04."

    tags="Technical,Product Security"


    classification="All Classifications"
    compliance="Should"
    cid="3495"
><![CDATA[<p>If an uncleared technician is used to undertake maintenance or repairs of IT equipment, the technician SHOULD be escorted by someone who is sufficiently familiar with the product to understand the work being performed.</p>]]></paragraph>
</block>
<block title="Off-site maintenance and repairs"><paragraph
    title="12.5.5.R.01."

    tags="Technical,Product Security"


><![CDATA[<p>Agencies choosing to have IT equipment maintained or repaired off-site need to be aware of requirements for the company’s off-site facilities to be approved to process and store the products at the appropriate classification.</p>]]></paragraph>
<paragraph
    title="12.5.5.R.02."

    tags="Technical,Product Security"


><![CDATA[<p>Agencies choosing to have IT equipment maintained or repaired off-site can sanitise, declassify or lower the classification of the product prior to transport and subsequent maintenance or repair activities, to lower the physical transfer, processing and storage requirements.</p>]]></paragraph>
<paragraph
    title="12.5.5.C.01."

    tags="Technical,Product Security"


    classification="All Classifications"
    compliance="Must"
    cid="3498"
><![CDATA[<p>Agencies having IT equipment maintained or repaired off-site MUST ensure that the physical transfer, processing and storage requirements are appropriate for the classification of the product and are maintained at all times.</p>]]></paragraph>
</block>
<block title="Maintenance and repair of IT equipment from secure areas"><paragraph
    title="12.5.6.R.01."

    tags="Technical,Product Security,Secure Area"


><![CDATA[<p>Where equipment is maintained or repaired offsite, agencies should identify any co-located equipment of a higher classification. This higher classification equipment may be at risk of compromise from modifications or repairs to the lower classification equipment.</p>]]></paragraph>
<paragraph
    title="12.5.6.C.01."

    tags="Technical,Product Security,Secure Area"


    classification="All Classifications"
    compliance="Should"
    cid="3504"
><![CDATA[<p>Offsite repairs and maintenance SHOULD treat all equipment in accordance with the requirements for the highest classification of information processed, stored or communicated in the area that the equipment will be returned to.</p>]]></paragraph>
<paragraph
    title="12.5.6.C.02."

    tags="Technical,Product Security,Secure Area"


    classification="All Classifications"
    compliance="Should"
    cid="3507"
><![CDATA[<p>Agencies SHOULD conduct or arrange to have technical inspections conducted on all equipment returned to the secure area after maintenance or repair.</p>]]></paragraph>
</block>
</subsection>
</section>
