Media Protection (MP)¶
Domain: Media Protection (MP)
Requirements in this domain: 9
Assessment Objectives in this domain: 15
MP.L2-3.8.1¶
MP.L2-3.8.1[a]¶
Assessment Objective
paper media containing CUI is physically controlled.
Collection Approach: Document
Potential Evidence Examples
Media Protection Policy describing physical controls for paper CUI (e.g., locked file cabinets, clean-desk requirements), paired with an access list or inventory record showing the controls are applied.
Assessment Guide – Further Discussion
Is hardcopy media containing CUI handled only by authorized personnel according to defined procedures [a]?
MP.L2-3.8.1[b]¶
Assessment Objective
digital media containing CUI is physically controlled.
Collection Approach: Document
Potential Evidence Examples
Media Protection Policy describing physical controls for digital CUI media (e.g., locked storage for external drives/backup tapes, encryption requirements), paired with an access list or inventory record.
Assessment Guide – Further Discussion
Is digital media containing CUI handled only by authorized personnel according to defined procedures [b]?
MP.L2-3.8.1[c]¶
Assessment Objective
paper media containing CUI is securely stored.
Collection Approach: Physical Review
Potential Evidence Examples
Physical inspection (photo or walkthrough) of the secure storage location for paper CUI (e.g., locked cabinet/room), plus a check-out/sign-out log or badge/key access list controlling who can retrieve it.
Assessment Guide – Further Discussion
Is paper media containing CUI physically secured (e.g., in a locked drawer or cabinet) [c]?
MP.L2-3.8.1[d]¶
Assessment Objective
digital media containing CUI is securely stored.
Collection Approach: Physical Review
Potential Evidence Examples
Physical inspection (photo or walkthrough) of the secure storage location for digital CUI media (e.g., locked media safe, access-controlled server room), plus a check-out/sign-out log or badge/key access list, and confirmation of encryption/password protection where applicable.
Assessment Guide – Further Discussion
Is digital media containing CUI securely stored (e.g., in access-controlled repositories) [d]?
MP.L2-3.8.2¶
MP.L2-3.8.2[a]¶
Assessment Objective
access to CUI on system media is limited to authorized users.
Collection Approach: Artifact
Potential Evidence Examples
Media Access Policy describing how access to CUI on system media is limited to authorized users, paired with a screen share of file/share permissions demonstrating least-privilege access is actually configured on the CUI repository.
Assessment Guide – Further Discussion
Is a list of users who are authorized to access the CUI contained on system media maintained [a]?
MP.L2-3.8.3¶
MP.L2-3.8.3[a]¶
Assessment Objective
system media containing CUI is sanitized or destroyed before disposal.
Collection Approach: Document
Potential Evidence Examples
Media Sanitization/Destruction Policy plus disposal records — e.g., a destruction log, Certificate of Destruction from a vendor, or shredding/degaussing service SLA — showing CUI media is sanitized or destroyed before disposal.
Assessment Guide – Further Discussion
Is all managed data storage erased, encrypted, or destroyed using mechanisms to ensure that no usable data is retrievable [a,b]?
MP.L2-3.8.3[b]¶
Assessment Objective
system media containing CUI is sanitized before it is released for reuse.
Collection Approach: Document
Potential Evidence Examples
Media Sanitization Policy identifying the approved sanitization method/tool for media reuse (e.g., NIST SP 800-88-compliant wipe utility) paired with a sample sanitization log or tool output confirming a wipe was completed before reuse.
MP.L2-3.8.4¶
MP.L2-3.8.4[a]¶
Assessment Objective
media containing CUI is marked with applicable CUI markings.
Collection Approach: Physical Review
Potential Evidence Examples
Photo or physical sample of CUI media (documents, drives, media labels) showing the applicable CUI markings are applied per the organization's labeling standard.
Assessment Guide – Further Discussion
Are all media containing CUI identified [a,b]?
MP.L2-3.8.4[b]¶
Assessment Objective
media containing CUI is marked with distribution limitations.
Collection Approach: Physical Review
Potential Evidence Examples
Photo or physical sample of CUI media showing distribution/dissemination limitation markings (e.g., "CUI//SP-[category]//Distribution Statement") are applied per the labeling standard.
Assessment Guide – Further Discussion
Are all media containing CUI identified [a,b]?
MP.L2-3.8.5¶
MP.L2-3.8.5[a]¶
Assessment Objective
access to media containing CUI is controlled.
Collection Approach: Document
Potential Evidence Examples
Access-control policy/list for CUI media plus transport tracking records (e.g., chain-of-custody log, courier receipt) showing access to media is controlled during storage and handling.
Assessment Guide – Further Discussion
Do only approved individuals have access to media containing CUI [a]?
MP.L2-3.8.5[b]¶
Assessment Objective
accountability for media containing CUI is maintained during transport outside of controlled areas.
Collection Approach: Artifact
Potential Evidence Examples
Chain-of-custody log or transport tracking record showing accountability for CUI media is maintained continuously while it is outside controlled areas (e.g., signed transfer log from origin to destination).
Assessment Guide – Further Discussion
- Is access to the media containing CUI recorded in an audit log [b]?
- Is all CUI data on media encrypted or physically locked prior to transport outside of secure locations [b]?
MP.L2-3.8.6¶
MP.L2-3.8.6[a]¶
Assessment Objective
the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards.
Collection Approach: Artifact
Potential Evidence Examples
Screen share of the encryption mechanism protecting CUI media during transport (e.g., BitLocker-encrypted drive, FIPS-validated encrypted courier case) citing the applicable FIPS 140-2/140-3 certificate, or documentation of the alternative physical safeguard used instead.
Assessment Guide – Further Discussion
- Are all CUI data on media encrypted or physically protected prior to transport outside of controlled areas [a]?
- Are cryptographic mechanisms used to protect digital media during transport outside of controlled areas [a]?
- Do cryptographic mechanisms comply with FIPS 140-2 [a]?
MP.L2-3.8.7¶
MP.L2-3.8.7[a]¶
Assessment Objective
the use of removable media on system components containing CUI is controlled.
Collection Approach: Artifact
Potential Evidence Examples
Removable Media Policy stating whether removable media is permitted, paired with a screen share of the technical control (e.g., Group Policy device-control restriction, DLP/endpoint-protection removable-media rule) enforcing that policy, plus the lost/stolen-media reporting procedure.
Assessment Guide – Further Discussion
- Are removable media allowed [a]?
- Are policies and/or procedures in use to control the use of removable media [a]?
MP.L2-3.8.8¶
MP.L2-3.8.8[a]¶
Assessment Objective
the use of portable storage devices is prohibited when such devices have no identifiable owner.
Collection Approach: Artifact
Potential Evidence Examples
Policy prohibiting use of portable storage devices with no identifiable owner (e.g., only organization-issued, asset-tagged USB devices permitted), paired with a screen share of the endpoint control (e.g., device-control alert or block) that flags/blocks unregistered/unowned removable media.
Assessment Guide – Further Discussion
Do portable storage devices used have identifiable owners [a]?
MP.L2-3.8.9¶
MP.L2-3.8.9[a]¶
Assessment Objective
the confidentiality of backup CUI is protected at storage locations.
Collection Approach: Artifact
Potential Evidence Examples
Backup Policy describing how CUI-containing backups are protected, paired with evidence of encryption at the backup storage location (e.g., backup software encryption settings citing FIPS validation) and access-control settings restricting who can access backup media/repositories.
Assessment Guide – Further Discussion
- Are data backups encrypted on media before removal from a secured facility [a]?
- Are cryptographic mechanisms FIPS validated [a]?