Security requirement
Sanitize system media that contain CUI prior to disposal, release out of organizational control, or release for reuse.
Discussion
Media sanitization applies to digital and non-digital media that are subject to disposal or reuse, whether or not the media are considered removable. Examples include digital media in scanners, copiers, printers, notebook computers, mobile devices, workstations, network components, and non-digital media. The sanitization process removes CUI from media such that the information cannot be retrieved or reconstructed. Sanitization techniques (e.g., cryptographically erasing, clearing, purging, and destroying) prevent the disclosure of CUI to unauthorized individuals when such media are reused or released for disposal. NARA policies control the sanitization process for media that contain CUI and may require destruction when other methods cannot be applied to the media.
Implementation perspective
Treat Media Sanitization as a CUI protection outcome that must be reflected in the system boundary, documented implementation, operational behavior, and assessment evidence. Pay particular attention to CUI media accountability, access, marking, storage, transport, sanitization, and disposal.
- Confirm the requirement is in scope for the CUI system components, services, users, and external connections being assessed.
- Resolve every organization-defined parameter through an approved governance and tailoring process.
- Map each clause of the requirement to an accountable owner, implementation mechanism, and evidence source.
- Verify that inherited and shared implementations are supported by current provider evidence and responsibility boundaries.
- Collect evidence during normal operation and review changes, exceptions, and deficiencies on a risk-based cadence.
Questions to ask
- Which CUI assets, data flows, users, and services are protected by this requirement?
- Which portions are implemented locally, inherited, shared, or not applicable, and what evidence supports that determination?
- Do the system security plan, deployed configuration, operating process, and assessment evidence tell the same story?
- What change, incident, or threshold should trigger reassessment?
Evidence and validation
- media inventories and chain-of-custody records
- sanitization certificates
- transport and storage procedures
- removable-media control logs
Common failure patterns
- cloud snapshots and virtual media excluded
- sanitization method not matched to media type
- untracked removable media
- disposal vendors accepted without verification
Assessment objectives and methods
Assessment objectives (1)
- SR-03.8.3.
system media that contain CUI are sanitized prior to disposal, release out of organizational control, or release for reuse.
Examine
- media protection policy and procedures
- procedures for media sanitization and disposal
- applicable standards and policies that address media sanitization policy
- system audit records
- media sanitization records
- system design documentation
- system configuration settings
- records retention and disposition policy
- records retention and disposition procedures
- system security plan
- other relevant documents or records
Interview
- personnel with media sanitization responsibilities
- personnel with records retention and disposition responsibilities
- personnel with information security responsibilities
- system administrators
Test
- processes for media sanitization
- mechanisms for supporting or implementing media sanitization
Source NIST SP 800-53 controls
These controls are referenced by the official SP 800-171 Rev. 3 OSCAL record. Open the corresponding control pages for complete control text, enhancements, D3FEND mappings, and related learning.
Authoritative sources
- NIST SP 800-171 Revision 3 official publication ↗
- NIST SP 800-171A Revision 3 official publication ↗
- NIST OSCAL Content release used for this import ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. The official publications, the responsible federal agency, and the governing contract or agreement determine applicability, tailoring, assessment depth, and required implementation.