Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-171 CUI Protection Center

03.08 — Media Protection

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

7Active requirements
2Withdrawn records
1Parameters
15Assessment objectives

CUI requirement family

Media Protection

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

7 active2 withdrawnRevision 3
MP

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.08.01Active

Media Storage

System media include digital and non-digital media. Digital media include diskettes, flash drives, magnetic tapes, external or removable solid state or magnetic drives, compact discs, and digital versatile discs. Non-digital media include paper and microfilm. Physically controlling stored media includes conducting inventories, establishing procedures to allow individuals to check out and return media to libraries, an

03.08.02Active

Media Access

System media include digital and non-digital media. Access to CUI on system media can be restricted by physically controlling such media. This includes conducting inventories, ensuring that procedures are in place to allow individuals to check out and return media to the media library, and maintaining accountability for stored media. For digital media, access to CUI can be restricted by using cryptographic means. Enc

03.08.03Active

Media Sanitization

Media sanitization applies to digital and non-digital media that are subject to disposal or reuse, whether or not the media are considered removable. Examples include digital media in scanners, copiers, printers, notebook computers, mobile devices, workstations, network components, and non-digital media. The sanitization process removes CUI from media such that the information cannot be retrieved or reconstructed. Sa

03.08.04Active

Media Marking

System media include digital and non-digital media. Marking refers to the use or application of human-readable security attributes. Labeling refers to the use of security attributes for internal system data structures. Digital media include diskettes, magnetic tapes, external or removable solid state or magnetic drives, flash drives, compact discs, and digital versatile discs. Non-digital media include paper and micr

03.08.05Active

Media Transport

System media include digital and non-digital media. Digital media include flash drives, diskettes, magnetic tapes, external or removable solid state or magnetic drives, compact discs, and digital versatile discs. Non-digital media include microfilm and paper. Controlled areas are spaces for which organizations provide physical or procedural measures to meet the requirements established for protecting CUI and systems.

03.08.06Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.08.06; use the recorded replacement relationships.

03.08.07Active

Media Use

In contrast to requirement 03.08.01, which restricts user access to media, this requirement restricts or prohibits the use of certain types of media, such as external hard drives, flash drives, or smart displays. Organizations can use technical and non-technical measures (e.g., policies, procedures, and rules of behavior) to control the use of system media. For example, organizations may control the use of portable s

03.08.08Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.08.08; use the recorded replacement relationships.

03.08.09Active

System Backup – Cryptographic Protection

The selection of cryptographic mechanisms is based on the need to protect the confidentiality of backup information. Hardware security module (HSM) devices safeguard and manage cryptographic keys and provide cryptographic processing. Cryptographic operations (e.g., encryption, decryption, and signature generation and verification) are typically hosted on the HSM device, and many implementations provide hardware-accel