Skip to content

Media Protection (MP)

Domain: Media Protection (MP)
Requirements in this domain: 9
Assessment Objectives in this domain: 15


MP.L2-3.8.1

MP.L2-3.8.1[a]

Assessment Objective

paper media containing CUI is physically controlled.

Collection Approach: Document

Potential Evidence Examples

Media Protection Policy describing physical controls for paper CUI (e.g., locked file cabinets, clean-desk requirements), paired with an access list or inventory record showing the controls are applied.

Assessment Guide – Further Discussion

Is hardcopy media containing CUI handled only by authorized personnel according to defined procedures [a]?


MP.L2-3.8.1[b]

Assessment Objective

digital media containing CUI is physically controlled.

Collection Approach: Document

Potential Evidence Examples

Media Protection Policy describing physical controls for digital CUI media (e.g., locked storage for external drives/backup tapes, encryption requirements), paired with an access list or inventory record.

Assessment Guide – Further Discussion

Is digital media containing CUI handled only by authorized personnel according to defined procedures [b]?


MP.L2-3.8.1[c]

Assessment Objective

paper media containing CUI is securely stored.

Collection Approach: Physical Review

Potential Evidence Examples

Physical inspection (photo or walkthrough) of the secure storage location for paper CUI (e.g., locked cabinet/room), plus a check-out/sign-out log or badge/key access list controlling who can retrieve it.

Assessment Guide – Further Discussion

Is paper media containing CUI physically secured (e.g., in a locked drawer or cabinet) [c]?


MP.L2-3.8.1[d]

Assessment Objective

digital media containing CUI is securely stored.

Collection Approach: Physical Review

Potential Evidence Examples

Physical inspection (photo or walkthrough) of the secure storage location for digital CUI media (e.g., locked media safe, access-controlled server room), plus a check-out/sign-out log or badge/key access list, and confirmation of encryption/password protection where applicable.

Assessment Guide – Further Discussion

Is digital media containing CUI securely stored (e.g., in access-controlled repositories) [d]?


MP.L2-3.8.2

MP.L2-3.8.2[a]

Assessment Objective

access to CUI on system media is limited to authorized users.

Collection Approach: Artifact

Potential Evidence Examples

Media Access Policy describing how access to CUI on system media is limited to authorized users, paired with a screen share of file/share permissions demonstrating least-privilege access is actually configured on the CUI repository.

Assessment Guide – Further Discussion

Is a list of users who are authorized to access the CUI contained on system media maintained [a]?


MP.L2-3.8.3

MP.L2-3.8.3[a]

Assessment Objective

system media containing CUI is sanitized or destroyed before disposal.

Collection Approach: Document

Potential Evidence Examples

Media Sanitization/Destruction Policy plus disposal records — e.g., a destruction log, Certificate of Destruction from a vendor, or shredding/degaussing service SLA — showing CUI media is sanitized or destroyed before disposal.

Assessment Guide – Further Discussion

Is all managed data storage erased, encrypted, or destroyed using mechanisms to ensure that no usable data is retrievable [a,b]?


MP.L2-3.8.3[b]

Assessment Objective

system media containing CUI is sanitized before it is released for reuse.

Collection Approach: Document

Potential Evidence Examples

Media Sanitization Policy identifying the approved sanitization method/tool for media reuse (e.g., NIST SP 800-88-compliant wipe utility) paired with a sample sanitization log or tool output confirming a wipe was completed before reuse.


MP.L2-3.8.4

MP.L2-3.8.4[a]

Assessment Objective

media containing CUI is marked with applicable CUI markings.

Collection Approach: Physical Review

Potential Evidence Examples

Photo or physical sample of CUI media (documents, drives, media labels) showing the applicable CUI markings are applied per the organization's labeling standard.

Assessment Guide – Further Discussion

Are all media containing CUI identified [a,b]?


MP.L2-3.8.4[b]

Assessment Objective

media containing CUI is marked with distribution limitations.

Collection Approach: Physical Review

Potential Evidence Examples

Photo or physical sample of CUI media showing distribution/dissemination limitation markings (e.g., "CUI//SP-[category]//Distribution Statement") are applied per the labeling standard.

Assessment Guide – Further Discussion

Are all media containing CUI identified [a,b]?


MP.L2-3.8.5

MP.L2-3.8.5[a]

Assessment Objective

access to media containing CUI is controlled.

Collection Approach: Document

Potential Evidence Examples

Access-control policy/list for CUI media plus transport tracking records (e.g., chain-of-custody log, courier receipt) showing access to media is controlled during storage and handling.

Assessment Guide – Further Discussion

Do only approved individuals have access to media containing CUI [a]?


MP.L2-3.8.5[b]

Assessment Objective

accountability for media containing CUI is maintained during transport outside of controlled areas.

Collection Approach: Artifact

Potential Evidence Examples

Chain-of-custody log or transport tracking record showing accountability for CUI media is maintained continuously while it is outside controlled areas (e.g., signed transfer log from origin to destination).

Assessment Guide – Further Discussion

  • Is access to the media containing CUI recorded in an audit log [b]?
  • Is all CUI data on media encrypted or physically locked prior to transport outside of secure locations [b]?

MP.L2-3.8.6

MP.L2-3.8.6[a]

Assessment Objective

the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards.

Collection Approach: Artifact

Potential Evidence Examples

Screen share of the encryption mechanism protecting CUI media during transport (e.g., BitLocker-encrypted drive, FIPS-validated encrypted courier case) citing the applicable FIPS 140-2/140-3 certificate, or documentation of the alternative physical safeguard used instead.

Assessment Guide – Further Discussion

  • Are all CUI data on media encrypted or physically protected prior to transport outside of controlled areas [a]?
  • Are cryptographic mechanisms used to protect digital media during transport outside of controlled areas [a]?
  • Do cryptographic mechanisms comply with FIPS 140-2 [a]?

MP.L2-3.8.7

MP.L2-3.8.7[a]

Assessment Objective

the use of removable media on system components containing CUI is controlled.

Collection Approach: Artifact

Potential Evidence Examples

Removable Media Policy stating whether removable media is permitted, paired with a screen share of the technical control (e.g., Group Policy device-control restriction, DLP/endpoint-protection removable-media rule) enforcing that policy, plus the lost/stolen-media reporting procedure.

Assessment Guide – Further Discussion

  • Are removable media allowed [a]?
  • Are policies and/or procedures in use to control the use of removable media [a]?

MP.L2-3.8.8

MP.L2-3.8.8[a]

Assessment Objective

the use of portable storage devices is prohibited when such devices have no identifiable owner.

Collection Approach: Artifact

Potential Evidence Examples

Policy prohibiting use of portable storage devices with no identifiable owner (e.g., only organization-issued, asset-tagged USB devices permitted), paired with a screen share of the endpoint control (e.g., device-control alert or block) that flags/blocks unregistered/unowned removable media.

Assessment Guide – Further Discussion

Do portable storage devices used have identifiable owners [a]?


MP.L2-3.8.9

MP.L2-3.8.9[a]

Assessment Objective

the confidentiality of backup CUI is protected at storage locations.

Collection Approach: Artifact

Potential Evidence Examples

Backup Policy describing how CUI-containing backups are protected, paired with evidence of encryption at the backup storage location (e.g., backup software encryption settings citing FIPS validation) and access-control settings restricting who can access backup media/repositories.

Assessment Guide – Further Discussion

  • Are data backups encrypted on media before removal from a secured facility [a]?
  • Are cryptographic mechanisms FIPS validated [a]?