<?xml version="1.0" encoding="UTF-8"?><!--Serialized by the GTRI Trustmark Framework API, version: 1.4.74--><tf:TrustInteroperabilityProfile xmlns:tf="https://trustmarkinitiative.org/specifications/trustmark-framework/1.4/schema/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tips/nist-sp-800-53-r4-security-control-ma-2_-controlled-maintenance/4/</tf:Identifier><tf:Name>NIST SP 800-53 r4 Security Control MA-2: Controlled Maintenance</tf:Name><tf:Version>4</tf:Version><tf:Description>Profile of requirements corresponding to NIST Special Publication 800-53, r4, Security Control MA-2: Controlled Maintenance. Applicable to LOW impact, MODERATE impact, and HIGH impact systems.</tf:Description><tf:PublicationDateTime>2021-04-26T00:00:00.000Z</tf:PublicationDateTime><tf:Primary>false</tf:Primary><tf:LegalNotice>This document and the information contained herein is provided on an "AS IS" basis, and the Georgia Tech Research Institute disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, the Georgia Tech Research Institute disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.</tf:LegalNotice><tf:Issuer><tf:Identifier>https://trustmarkinitiative.org/</tf:Identifier><tf:Name>TMI</tf:Name><tf:Contact><tf:Kind>PRIMARY</tf:Kind><tf:Responder></tf:Responder><tf:Email>help@trustmarkinitiative.org</tf:Email><tf:Telephone>555-555-5555</tf:Telephone><tf:WebsiteURL>https://trustmarkinitiative.org/</tf:WebsiteURL></tf:Contact></tf:Issuer><tf:Keywords><tf:Keyword>800-53</tf:Keyword><tf:Keyword>Controlled Maintenance</tf:Keyword><tf:Keyword>High</tf:Keyword><tf:Keyword>Low</tf:Keyword><tf:Keyword>Maintenance</tf:Keyword><tf:Keyword>Moderate</tf:Keyword><tf:Keyword>NIST</tf:Keyword><tf:Keyword>P2</tf:Keyword><tf:Keyword>Security</tf:Keyword></tf:Keywords><tf:References><tf:TrustmarkDefinitionRequirement tf:id="TD_ref1"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/documentation-of-system-maintenance/1.0/</tf:Identifier><tf:Number>1</tf:Number><tf:Name>Documentation of System Maintenance</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for documentation of system maintenance as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref2"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/approval-of-system-maintenance-activities/1.0/</tf:Identifier><tf:Number>2</tf:Number><tf:Name>Approval of System Maintenance Activities</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for approval of system maintenance activities as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref3"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/monitoring-of-system-maintenance-activity/1.0/</tf:Identifier><tf:Number>3</tf:Number><tf:Name>Monitoring of System Maintenance Activity</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for monitoring of system maintenance activity as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref4"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/removal-of-systems-or-components-for-maintenance/1.0/</tf:Identifier><tf:Number>4</tf:Number><tf:Name>Removal of Systems or Components for Maintenance</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for removal of systems or components for maintenance as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref5"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/defined-system-maintenance-record-content/1.0/</tf:Identifier><tf:Number>5</tf:Number><tf:Name>Defined System Maintenance Record Content</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for defined system maintenance record content as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref6"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/scheduling-of-system-maintenance/1.0/</tf:Identifier><tf:Number>6</tf:Number><tf:Name>Scheduling of System Maintenance</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for scheduling of system maintenance as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref7"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/review-of-system-maintenance-records/1.0/</tf:Identifier><tf:Number>7</tf:Number><tf:Name>Review of System Maintenance Records</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for review of system maintenance records as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref8"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/performance-of-system-maintenance/1.0/</tf:Identifier><tf:Number>8</tf:Number><tf:Name>Performance of System Maintenance</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for performance of system maintenance as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref9"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/verification-of-security-controls-following-system-maintenance/1.0/</tf:Identifier><tf:Number>9</tf:Number><tf:Name>Verification of Security Controls Following System Maintenance</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for verification of security controls following system maintenance as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement><tf:TrustmarkDefinitionRequirement tf:id="TD_ref10"><tf:TrustmarkDefinitionReference><tf:Identifier>https://artifacts.trustmarkinitiative.org/lib/tds/sanitization-of-equipment-to-be-removed-for-maintenance/1.0/</tf:Identifier><tf:Number>10</tf:Number><tf:Name>Sanitization of Equipment to be Removed for Maintenance</tf:Name><tf:Version>1.0</tf:Version><tf:Description>Defines conformance and assessment criteria for compliance with minimum security requirements for sanitization of equipment to be removed for maintenance as related to overall maintenance requirements.</tf:Description></tf:TrustmarkDefinitionReference></tf:TrustmarkDefinitionRequirement></tf:References><tf:TrustExpression><![CDATA[TD_ref1 and TD_ref2 and TD_ref3 and TD_ref4 and TD_ref5 and TD_ref6 and TD_ref7 and TD_ref8 and TD_ref9 and TD_ref10]]></tf:TrustExpression><tf:Sources><tf:Source tf:id="Source-2112165102"><tf:Identifier>SP800-53R4</tf:Identifier><tf:Reference>NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology, April 2013 (Includes updates as of 01-15-2014). Available at &lt;a href="http://dx.doi.org/10.6028/NIST.SP.800-53r4"&gt;http://dx.doi.org/10.6028/NIST.SP.800-53r4&lt;/a&gt;.</tf:Reference></tf:Source></tf:Sources></tf:TrustInteroperabilityProfile>