Media Protection (MP)¶
MP.L2-3.8.1 – Media Protection¶
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 41.
Determine if:
- [a] paper media containing CUI is physically controlled;
- [b] digital media containing CUI is physically controlled;
- [c] paper media containing CUI is securely stored; and
- [d] digital media containing CUI is securely stored.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 41.
Examine: [SELECT FROM: System media protection policy; procedures addressing media storage; procedures addressing media access restrictions; access control policy and procedures; physical and environmental protection policy and procedures; system security plan; media storage facilities; access control records; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system media protection responsibilities; personnel with information security responsibilities; system or network administrators].
Test: [SELECT FROM: Organizational processes for restricting information media; mechanisms supporting or implementing media access restrictions].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 29.
System media includes digital and non-digital media. Digital media includes diskettes, magnetic tapes, external and removable hard disk drives, flash drives, compact disks, and digital video disks. Non-digital media includes paper and microfilm. Protecting digital media includes limiting access to design specifications stored on compact disks or flash drives in the media library to the project leader and any individuals on the development team. Physically controlling system media includes conducting inventories, maintaining accountability for stored media, and ensuring procedures are in place to allow individuals to check out and return media to the media library. Secure storage includes a locked drawer, desk, or cabinet, or a controlled media library. Access to CUI on system media can be limited by physically controlling such media, which includes conducting inventories, ensuring procedures are in place to allow individuals to check out and return media to the media library, and maintaining accountability for all stored media. NIST SP 800-111 provides guidance on storage encryption technologies for end user devices.
Further Discussion¶
CUI can be contained on two types of physical media:
- hardcopy (e.g., CD drives, USB drives, magnetic tape); and
- digital devices (e.g., CD drives, USB drives, video).
You should store physical media containing CUI in a secure location. This location should be accessible only to those people with the proper permissions. All who access CUI should follow the process for checking it out and returning it.
Examples¶
- Your company has CUI for a specific Army contract contained on a USB drive. You store the drive in a locked drawer, and you log it on an inventory [d]. You establish a procedure to check out the USB drive so you have a history of who is accessing it. These procedures help to maintain the confidentiality, integrity, and availability of the data.
Potential Assessment Considerations¶
- Is hardcopy media containing CUI handled only by authorized personnel according to defined procedures [a]?
- Is digital media containing CUI handled only by authorized personnel according to defined procedures [b]?
- Is paper media containing CUI physically secured (e.g., in a locked drawer or cabinet) [c]?
- Is digital media containing CUI securely stored (e.g., in access-controlled repositories) [d]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.1
MP.L2-3.8.2 – Media Access¶
Limit access to CUI on system media to authorized users.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 41.
Determine if:
- [a] access to CUI on system media is limited to authorized users.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 41.
Examine: [SELECT FROM: System media protection policy; procedures addressing media storage; physical and environmental protection policy and procedures; access control policy and procedures; system security plan; system media; designated controlled areas; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system media protection and storage responsibilities; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for storing media; mechanisms supporting or implementing secure media storage and media protection].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 29.
Access can be limited by physically controlling system media and secure storage areas. Physically controlling system media includes conducting inventories, ensuring procedures are in place to allow individuals to check out and return system media to the media library, and maintaining accountability for all stored media. Secure storage includes a locked drawer, desk, or cabinet, or a controlled media library.
Further Discussion¶
Limit physical access to CUI to people permitted to access CUI. Use locked or controlled storage areas and limit access to only those allowed to access CUI. Keep track of who accesses physical CUI in an audit log.
Examples¶
- Your company has CUI for a specific Army contract contained on a USB drive. In order to control the data, you establish specific procedures for handling the drive. You designate the project manager as the owner of the data and require anyone who needs access to the data to get permission from the data owner [a]. The data owner maintains a list of users that are authorized to access the information. Before an authorized individual can get access to the USB drive that contains the CUI they have to fill out a log and check out the drive. When they are done with the data, they check in the drive and return it to its secure storage location.
Potential Assessment Considerations¶
- Is a list of users who are authorized to access the CUI contained on system media maintained [a]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.2
MP.L2-3.8.3 – Media Disposal [CUI Data]¶
Sanitize or destroy system media containing CUI before disposal or release for reuse.
Assessment Objectives¶
Source: NIST SP 800-171A, pp. 41-42.
Determine if:
- [a] system media containing CUI is sanitized or destroyed before disposal; and
- [b] system media containing CUI is sanitized before it is released for reuse.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, pp. 41-42.
Examine: [SELECT FROM: System media protection policy; procedures addressing media sanitization and disposal; applicable standards and policies addressing media sanitization; system security plan; media sanitization records; system audit logs and records; system design documentation; system configuration settings and associated documentation; other relevant documents or records].
Interview: [SELECT FROM: Personnel with media sanitization responsibilities; personnel with information security responsibilities; system or network administrators].
Test: [SELECT FROM: Organizational processes for media sanitization; mechanisms supporting or implementing media sanitization].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 29.
This requirement applies to all system media, digital and non-digital, subject to disposal or reuse. Examples include: digital media found in workstations, network components, scanners, copiers, printers, notebook computers, and mobile devices; and non-digital media such as paper and microfilm. The sanitization process removes information from the media such that the information cannot be retrieved or reconstructed. Sanitization techniques, including clearing, purging, cryptographic erase, and destruction, prevent the disclosure of information to unauthorized individuals when such media is released for reuse or disposal. Organizations determine the appropriate sanitization methods, recognizing that destruction may be necessary when other methods cannot be applied to the media requiring sanitization. Organizations use discretion on the employment of sanitization techniques and procedures for media containing information that is in the public domain or publicly releasable or deemed to have no adverse impact on organizations or individuals if released for reuse or disposal. Sanitization of non-digital media includes destruction, removing CUI from documents, or redacting selected sections or words from a document by obscuring the redacted sections or words in a manner equivalent in effectiveness to removing the words or sections from the document. NARA policy and guidance control sanitization processes. NIST SP 800-88 provides guidance on media sanitization.
Further Discussion¶
“Media” refers to a broad range of items that store information, including paper documents, disks, tapes, digital photography, USB drives, CDs, DVDs, and mobile phones. It is important to know what information is on media so that you can handle it properly. If there is CUI, you or someone in your company should either:
- shred or destroy the device before disposal so it cannot be read; or
- clean or purge the information, if you want to reuse the device.
See NIST Special Publication 800-88, Revision 1, Guidelines for Media Sanitization, for more information.
Examples¶
- As you pack for an office move, you find some old CDs in a file cabinet. You determine that one has information about an old project your company did for the DoD. You shred the CD rather than simply throwing it in the trash [a].
Potential Assessment Considerations¶
- Is all managed data storage erased, encrypted, or destroyed using mechanisms to ensure that no usable data is retrievable [a,b]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.3
- FAR Clause 52.204-21 b.1.vii
MP.L2-3.8.4 – Media Markings¶
Mark media with necessary CUI markings and distribution limitations.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 42.
Determine if:
- [a] media containing CUI is marked with applicable CUI markings; and
- [b] media containing CUI is marked with distribution limitations.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 42.
Examine: [SELECT FROM: System media protection policy; procedures addressing media marking; physical and environmental protection policy and procedures; system security plan; list of system media marking security attributes; designated controlled areas; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system media protection and marking responsibilities; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for marking information media; mechanisms supporting or implementing media marking].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 30.
The term security marking refers to the application or use of human-readable security attributes. System media includes digital and non-digital media. Marking of system media reflects applicable federal laws, Executive Orders, directives, policies, and regulations.
Further Discussion¶
All media, hardcopy and digital, must be properly marked to alert individuals to the presence of CUI stored on the media. The National Archives and Records Administration (NARA) has published guidelines for labeling media of different sizes. 146 MP.L2-3.8.8 requires that media have an identifiable owner, so organizations may find it desirable to include ownership information on the device label as well.
146 NARA, CUI Notice 2019-01: Controlled Unclassified Information (CUI) Coversheets and Labels
Examples¶
- You were recently contacted by the project team for a new DoD program. The team said they wanted the CUI in use for the program to be properly protected. When speaking with them, you realize that most of the protections will be provided as part of existing enterprise cybersecurity capabilities. They also mentioned that the project team will use several USB drives to share specific data. You explain that the team must ensure the USB drives are externally marked to indicate the presence of CUI [a]. The project team labels the outside of each USB drive with an appropriate CUI label following NARA guidance [a]. Further, the labels indicate that distribution is limited to those employees supporting the DoD program [a].
Potential Assessment Considerations¶
- Are all media containing CUI identified [a,b]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.4
MP.L2-3.8.5 – Media Accountability¶
Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 42.
Determine if:
- [a] access to media containing CUI is controlled; and
- [b] accountability for media containing CUI is maintained during transport outside of controlled areas.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 42.
Examine: [SELECT FROM: System media protection policy; procedures addressing media storage; physical and environmental protection policy and procedures; access control policy and procedures; system security plan; system media; designated controlled areas; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system media protection and storage responsibilities; personnel with information security responsibilities; system or network administrators].
Test: [SELECT FROM: Organizational processes for storing media; mechanisms supporting or implementing media storage and media protection].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 30.
Controlled areas are areas or spaces for which organizations provide physical or procedural controls to meet the requirements established for protecting systems and information. Controls to maintain accountability for media during transport include locked containers and cryptography. Cryptographic mechanisms can provide confidentiality and integrity protections depending upon the mechanisms used. Activities associated with transport include the actual transport as well as those activities such as releasing media for transport and ensuring that media enters the appropriate transport processes. For the actual transport, authorized transport and courier personnel may include individuals external to the organization. Maintaining accountability of media during transport includes restricting transport activities to authorized personnel and tracking and obtaining explicit records of transport activities as the media moves through the transportation system to prevent and detect loss, destruction, or tampering.
Further Discussion¶
CUI is protected in both physical and digital formats. Physical control can be accomplished using traditional concepts like restricted access to physical locations or locking papers in a desk or filing cabinet. The digitization of data makes access to CUI much easier. CUI can be stored and transported on magnetic disks, tapes, USB drives, CD-ROMs, and so on. This makes digital CUI data very portable. It is important for an organization to apply mechanisms to prevent unauthorized access to CUI due to ease of transport.
Examples¶
- Your team has recently completed configuring a server for a DoD customer. The customer has asked that it be ready to plug in and use. An application installed on the server contains data that is considered CUI. You box the server for shipment using tamper-evident packaging and label it with the specific recipient for the shipment [b]. You select a reputable shipping service so you will get a tracking number to monitor the progress. Once the item is shipped, you send the recipients the tracking number so they can monitor and ensure prompt delivery at their facility.
Potential Assessment Considerations¶
- Do only approved individuals have access to media containing CUI [a]?
- Is access to the media containing CUI recorded in an audit log [b]?
- Is all CUI data on media encrypted or physically locked prior to transport outside of secure locations [b]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.5
MP.L2-3.8.6 – Portable Storage Encryption¶
Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 43.
Determine if:
- [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 43.
Examine: [SELECT FROM: System media protection policy; procedures addressing media transport; system design documentation; system security plan; system configuration settings and associated documentation; system media transport records; system audit logs and records; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system media transport responsibilities; personnel with information security responsibilities].
Test: [SELECT FROM: Cryptographic mechanisms protecting information on digital media during transportation outside controlled areas].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 30.
This requirement applies to portable storage devices (e.g., USB memory sticks, digital video disks, compact disks, external or removable hard disk drives). NIST SP 800-111 provides guidance on storage encryption technologies for end user devices.
Further Discussion¶
CUI can be stored and transported on a variety of portable media, which increases the chance that the CUI can be lost. When identifying the paths CUI flows through your company, identify devices to include in this requirement.
To mitigate the risk of losing or exposing CUI, implement an encryption scheme to protect the data. Even if the media are lost, proper encryption renders the data inaccessible. When encryption is not an option, apply alternative physical safeguards during transport. Because the use of cryptography in this requirement is to protect the confidentiality of CUI, the cryptography used must meet the criteria specified in requirement SC.L2-3.13.11. This requirement, MP.L2-3.8.6, provides additional protections to those provided by MP.L2-3.8.5. This requirement is intended to protect against situations where control of media access fails, such as through the loss of the media.
Examples¶
- You manage the backups for file servers in your datacenter. You know that in addition to the company’s sensitive information, CUI is stored on the file servers. As part of a broader plan to protect data, you send the backup tapes off site to a vendor. You are aware that your backup software provides the option to encrypt data onto tape. You develop a plan to test and enable backup encryption for the data sent off site. This encryption provides additional protections for the data on the backup tapes during transport and offsite storage [a].
Potential Assessment Considerations¶
- Are all CUI data on media encrypted or physically protected prior to transport outside of controlled areas [a]?
- Are cryptographic mechanisms used to protect digital media during transport outside of controlled areas [a]?
- Do cryptographic mechanisms comply with FIPS 140-2 [a]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.6
MP.L2-3.8.7 – Removeable Media¶
Control the use of removable media on system components.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 43.
Determine if:
- [a] the use of removable media on system components is controlled.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 43.
Examine: [SELECT FROM: System media protection policy; system use policy; procedures addressing media usage restrictions; system security plan; rules of behavior; system design documentation; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system media use responsibilities; personnel with information security responsibilities; system or network administrators].
Test: [SELECT FROM: Organizational processes for media use; mechanisms restricting or prohibiting use of system media on systems or system components].
Discussion¶
Source: NIST SP 800-171 Rev. 2, pp. 30-31.
In contrast to requirement MP.L2-3.8.1, which restricts user access to media, this requirement restricts the use of certain types of media on systems, for example, restricting or prohibiting the use of flash drives or external hard disk drives. Organizations can employ technical and nontechnical controls (e.g., policies, procedures, and rules of behavior) to control the use of system media. Organizations may control the use of portable storage devices, for example, by using physical cages on workstations to prohibit access to certain external ports, or disabling or removing the ability to insert, read, or write to such devices. Organizations may also limit the use of portable storage devices to only approved devices including devices provided by the organization, devices provided by other approved organizations, and devices that are not personally owned. Finally, organizations may control the use of portable storage devices based on the type of device, prohibiting the use of writeable, portable devices, and implementing this restriction by disabling or removing the capability to write to such devices. Malicious code protection mechanisms include anti-virus signature definitions and reputation-based technologies. Many technologies and methods exist to limit or eliminate the effects of malicious code. Pervasive configuration management and comprehensive software integrity controls may be effective in preventing execution of unauthorized code. In addition to commercial off-the-shelf software, malicious code may also be present in custom-built software. This could include logic bombs, back doors, and other types of cyber-attacks that could affect organizational missions/business functions. Traditional malicious code protection mechanisms cannot always detect such code. In these situations, organizations rely instead on other safeguards including secure coding practices, configuration management and control, trusted procurement processes, and monitoring technologies to help ensure that software does not perform functions other than the functions intended.
Further Discussion¶
Removable media are any type of media storage that you can remove from your computer or machine (e.g., CDs, DVDs, diskettes, and USB drives). Write a specific policy for removable media. The policy should cover the various types of removable media (e.g., write-once media and rewritable media) and should discuss the company’s approach to removable media. Ensure the following controls are considered and included in the policy:
- limit the use of removable media to the smallest number needed; and
- scan all removable media for viruses.
Examples¶
-
You are in charge of IT operations. You establish a policy for removable media that includes USB drives [a]. The policy information such as:
-
only USB drives issued by the organization may be used; and
- USB drives are to be used for work purposes only [a].
You set up a separate computer to scan these drives before anyone uses them on the network. This computer has anti-virus software installed that is kept up to date.
Potential Assessment Considerations¶
- Are removable media allowed [a]?
- Are policies and/or procedures in use to control the use of removable media [a]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.7
MP.L2-3.8.8 – Shared Media¶
Prohibit the use of portable storage devices when such devices have no identifiable owner.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 43.
Determine if:
- [a] the use of portable storage devices is prohibited when such devices have no identifiable owner.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 43.
Examine: [SELECT FROM: System media protection policy; system use policy; procedures addressing media usage restrictions; system security plan; rules of behavior; system configuration settings and associated documentation; system design documentation; system audit logs and records; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system media use responsibilities; personnel with information security responsibilities; system or network administrators].
Test: [SELECT FROM: Organizational processes for media use; mechanisms prohibiting use of media on systems or system components].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 31.
Requiring identifiable owners (e.g., individuals, organizations, or projects) for portable storage devices reduces the overall risk of using such technologies by allowing organizations to assign responsibility and accountability for addressing known vulnerabilities in the devices (e.g., insertion of malicious code).
Further Discussion¶
A portable storage device is a system component that can be inserted into and removed from a system and is used to store data or information. It typically plugs into a laptop or desktop port (e.g., USB port). These devices can contain malicious files that can lead to a compromise of a connected system. Therefore, use should be prohibited if the device cannot be traced to an owner who is responsible and accountable for its security.
This requirement, MP.L2-3.8.8, furthers the protections provided by MP.L2-3.8.7 by prohibiting unidentified media use even if that media type is allowable.
Examples¶
- You are the IT manager. One day, a staff member reports finding a USB drive in the parking lot. You investigate and learn that there are no labels on the outside of the drive to indicate who might be responsible for it. You send an email to all employees to remind them that IT policies expressly prohibit plugging unknown devices into company computers. You also direct staff members to turn in to the IT help desk any devices that have no identifiable owner [a].
Potential Assessment Considerations¶
- Do portable storage devices used have identifiable owners [a]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.8
MP.L2-3.8.9 – Protect Backups¶
Protect the confidentiality of backup CUI at storage locations.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 44.
Determine if:
- [a] the confidentiality of backup CUI is protected at storage locations.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 44.
Examine: [SELECT FROM: Procedures addressing system backup; system configuration settings and associated documentation; security plan; backup storage locations; system backup logs or records; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system backup responsibilities; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for conducting system backups; mechanisms supporting or implementing system backups].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 31.
Organizations can employ cryptographic mechanisms or alternative physical controls to protect the confidentiality of backup information at designated storage locations. Backed-up information containing CUI may include system-level information and user-level information. System-level information includes system-state information, operating system software, application software, and licenses. User-level information includes information other than system-level information.
Further Discussion¶
You protect CUI to ensure that it remains private (confidentiality) and unchanged (integrity). Methods to ensure confidentiality may include:
- encrypting files or media;
- managing who has access to the information; and
- physically securing devices and media that contain CUI.
Storage locations for information are varied, and may include:
- external hard drives;
- USB drives;
- magnetic media (tape cartridge);
- optical disk (CD, DVD);
- Networked Attached Storage (NAS);
- servers; and
- cloud backup.
This requirement, MP.L2-3.8.9, requires the confidentiality of backup information at storage locations.
Examples¶
- You are in charge of protecting CUI for your company. Because the company’s backups contain CUI, you work with IT to protect the confidentiality of backup data. You agree to encrypt all CUI data as it is saved to an external hard drive [a].
Potential Assessment Considerations¶
- Are data backups encrypted on media before removal from a secured facility [a]?
- Are cryptographic mechanisms FIPS validated [a]?
Key References¶
- NIST SP 800-171 Rev. 2 3.8.9