Media protection

Estimated reading time: 5 minutes

MP-1 Media Protection Policy And Procedures


The organization:

  1. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:
    1. A media protection policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
    2. Procedures to facilitate the implementation of the media protection policy and associated media protection controls; and
  2. Reviews and updates the current:
    1. Media protection policy [Assignment: organization-defined frequency]; and
    2. Media protection procedures [Assignment: organization-defined frequency].

Control Information

Responsible role(s) - Organization

MP-2 Media Access


The organization restricts access to [Assignment: organization-defined types of digital and/or non-digital media] to [Assignment: organization-defined personnel or roles].

Control Information

Responsible role(s) - Organization

MP-3 Media Marking


The organization:

  1. Marks information system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information; and
  2. Exempts [Assignment: organization-defined types of information system media] from marking as long as the media remain within [Assignment: organization-defined controlled areas].

Control Information

Responsible role(s) - Organization

MP-4 Media Storage


The organization:

  1. Physically controls and securely stores [Assignment: organization-defined types of digital and/or non-digital media] within [Assignment: organization-defined controlled areas]; and
  2. Protects information system media until the media are destroyed or sanitized using approved equipment, techniques, and procedures.

Control Information

Responsible role(s) - Organization

MP-4 (2) Automated Restricted Access


The organization employs automated mechanisms to restrict access to media storage areas and to audit access attempts and access granted.

Control Information

Responsible role(s) - Organization

MP-5 Media Transport


The organization:

  1. Protects and controls [Assignment: organization-defined types of information system media] during transport outside of controlled areas using [Assignment: organization-defined security safeguards];
  2. Maintains accountability for information system media during transport outside of controlled areas;
  3. Documents activities associated with the transport of information system media; and
  4. Restricts the activities associated with the transport of information system media to authorized personnel.

Control Information

Responsible role(s) - Organization

MP-5 (3) Custodians


The organization employs an identified custodian during transport of information system media outside of controlled areas.

Control Information

Responsible role(s) - Organization

MP-5 (4) Cryptographic Protection


The information system implements cryptographic mechanisms to protect the confidentiality and integrity of information stored on digital media during transport outside of controlled areas.

Control Information

Responsible role(s) - Organization

MP-6 Media Sanitization


The organization:

  1. Sanitizes [Assignment: organization-defined information system media] prior to disposal, release out of organizational control, or release for reuse using [Assignment: organization-defined sanitization techniques and procedures] in accordance with applicable federal and organizational standards and policies; and
  2. Employs sanitization mechanisms with the strength and integrity commensurate with the security category or classification of the information.

Control Information

Responsible role(s) - Organization

MP-6 (1) Review / Approve / Track / Document / Verify


The organization reviews, approves, tracks, documents, and verifies media sanitization and disposal actions.

Control Information

Responsible role(s) - Organization

MP-6 (2) Equipment Testing


The organization tests sanitization equipment and procedures [Assignment: organization-defined frequency] to verify that the intended sanitization is being achieved.

Control Information

Responsible role(s) - Organization

MP-6 (3) Nondestructive Techniques


The organization applies nondestructive sanitization techniques to portable storage devices prior to connecting such devices to the information system under the following circumstances: [Assignment: organization-defined circumstances requiring sanitization of portable storage devices].

Control Information

Responsible role(s) - Organization

MP-6 (7) Dual Authorization


The organization enforces dual authorization for the sanitization of [Assignment: organization-defined information system media].

Control Information

Responsible role(s) - Organization

MP-6 (8) Remote Purging / Wiping Of Information


The organization provides the capability to purge/wipe information from [Assignment: organization-defined information systems, system components, or devices] either remotely or under the following conditions: [Assignment: organization-defined conditions].

Control Information

Responsible role(s) - Organization

MP-7 Media Use


The organization [Selection: restricts; prohibits] the use of [Assignment: organization-defined types of information system media] on [Assignment: organization-defined information systems or system components] using [Assignment: organization-defined security safeguards].

Control Information

Responsible role(s) - Organization

MP-7 (1) Prohibit Use Without Owner


The organization prohibits the use of portable storage devices in organizational information systems when such devices have no identifiable owner.

Control Information

Responsible role(s) - Organization

MP-7 (2) Prohibit Use Of Sanitization-Resistant Media


The organization prohibits the use of sanitization-resistant media in organizational information systems.

Control Information

Responsible role(s) - Organization

MP-8 Media Downgrading


The organization:

  1. Establishes [Assignment: organization-defined information system media downgrading process] that includes employing downgrading mechanisms with [Assignment: organization-defined strength and integrity];
  2. Ensures that the information system media downgrading process is commensurate with the security category and/or classification level of the information to be removed and the access authorizations of the potential recipients of the downgraded information;
  3. Identifies [Assignment: organization-defined information system media requiring downgrading]; and
  4. Downgrades the identified information system media using the established process.

Control Information

Responsible role(s) - Organization

MP-8 (1) Documentation Of Process


The organization documents information system media downgrading actions.

Control Information

Responsible role(s) - Organization

MP-8 (2) Equipment Testing


The organization employs [Assignment: organization-defined tests] of downgrading equipment and procedures to verify correct performance [Assignment: organization-defined frequency].

Control Information

Responsible role(s) - Organization

MP-8 (3) Controlled Unclassified Information


The organization downgrades information system media containing [Assignment: organization-defined Controlled Unclassified Information (CUI)] prior to public release in accordance with applicable federal and organizational standards and policies.

Control Information

Responsible role(s) - Organization

MP-8 (4) Classified Information


The organization downgrades information system media containing classified information prior to release to individuals without required access authorizations in accordance with NSA standards and policies.

Control Information

Responsible role(s) - Organization

standards, compliance, security, 800-53, Media protection