MP-02 Media Access

Media Protection

Low Moderate High

Description

The organization restricts access to information system media to authorized individuals.\n

Supplemental Guidance

Information system media includes both digital media (e.g., diskettes, magnetic tapes, external/removable hard drives, flash/thumb drives, compact disks, digital video disks) and non-digital media (e.g., paper, microfilm). This control also applies to portable and mobile computing and communications devices with information storage capability (e.g., notebook computers, personal digital assistants, cellular telephones). An organizational assessment of risk guides the selection of media and associated information contained on that media requiring restricted access. Organizations document in policy and procedures, the media requiring restricted access, individuals authorized to access the media, and the specific measures taken to restrict access. The rigor with which this control is applied is commensurate with the FIPS 199 security categorization of the information contained on the media. For example, fewer protection measures are needed for media containing information determined by the organization to be in the public domain, to be publicly releasable, or to have limited or no adverse impact on the organization or individuals if accessed by other than authorized personnel. In these situations, it is assumed that the physical access controls where the media resides provide adequate protection.\n

Enhancements

\n

Compliance Mappings

ISO 27002:2022

7.107.78.18.5

COBIT 2019

DSS05.01DSS05.02DSS05.03DSS05.04DSS05.05DSS05.06DSS05.07

CIS Controls v8

103.13.3

NIST CSF 2.0

DE.CM-09PR.DS

SOC 2 TSC

C1.1CC6.7-POF4

ISO 17799 (legacy)

10.7.3

COBIT 4.1 (legacy)

DS11.6