Description
a. [Selection: Restrict; Prohibit] the use of [Assignment: organization-defined types of system media] on [Assignment: organization-defined systems or system components] using [Assignment: organization-defined controls]; and b. Prohibit the use of portable storage devices in organizational systems when such devices have no identifiable owner.
Supplemental Guidance
System media includes both digital and non-digital media. Digital media includes flash drives, diskettes, magnetic tapes, external and removable hard disk drives, compact discs, and digital versatile discs. Non-digital media includes paper and microfilm. Media use protections also apply to mobile devices with information storage capabilities. In contrast to MP-02, which restricts user access to media, MP-07 restricts the use of certain types of media on systems.
Changes from Rev 4
No significant changes from Rev 4.
MITRE ATT&CK Techniques (6)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.