Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-172 Enhanced CUI Protection Center

03.08 — Media Protection

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

4Active requirements
8Parameters
6Assessment objectives

CUI requirement family

Media Protection

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

4 active0 withdrawnRevision 3
MP

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.08.01EActive

Dual Authorization for Media Sanitization

Dual authorization is also known as two-person control. Dual authorization reduces risk related to insider threats, including adversaries who have obtained credentials. Organizations employ dual authorization to help ensure that the sanitization of system media cannot occur unless two technically qualified individuals conduct the designated task. Individuals who sanitize system media possess sufficient skills and exp

03.08.02EActive

Dual Authorization for System Backup Deletion and Destruction

Dual authorization is also known as two-person control. Dual authorization reduces risk related to insider threats, including adversaries who have obtained credentials. Dual authorization ensures that the deletion or destruction of backup information cannot occur unless two qualified individuals carry out the task. Individuals who delete or destroy backup information possess the knowledge, skills, or expertise to det

03.08.03EActive

Testing System Backups for Reliability and Integrity

Organizations need assurance that backup information can be reliably retrieved. Reliability pertains to the systems and system components in which the backup information is stored, the operations used to retrieve the information, and the integrity of the information being retrieved. Independent and specialized tests can be used for each of these aspects of reliability. For example, decrypting and transporting (or tra

03.08.04EActive

System Recovery and Reconstitution

Recovery is executing contingency plan activities to restore organizational mission and business functions. Reconstitution occurs following recovery operations and includes activities for returning systems to fully operational states. Recovery and reconstitution operations reflect mission and business priorities; recovery point, recovery time, and reconstitution objectives; and organizational metrics consistent with