PR.PT-2: Removable media is protected and its use restricted according to policy
PF v1.0 References:
Threats Addressed:
Subcategory is withdrawn in the next version of this framework and incorporated into: PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected, PR.PS-01: Configuration management practices are established and applied.
Description
[csf.tools Note: Subcategories do not have detailed descriptions.]
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
MP-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] media protection policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation…
MP-2: Media Access
Restrict access to [Assignment: organization-defined types of digital and/or non-digital media] to [Assignment: organization-defined personnel or roles].
MP-3: Media Marking
Mark system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information; and Exempt [Assignment: organization-defined types of media exempted from marking] from marking if the media remain within [Assignment: organization-defined controlled areas].
MP-4: Media Storage
Physically control and securely store [Assignment: organization-defined types of digital and/or non-digital media] within [Assignment: organization-defined controlled areas] ; and Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved equipment, techniques, and procedures.
MP-5: Media Transport
Protect and control [Assignment: organization-defined types of system media] during transport outside of controlled areas using [Assignment: organization-defined controls]; Maintain accountability for system media during transport outside of controlled areas; Document activities associated with the transport of system media; and Restrict the activities associated with the transport of system media to authorized personnel.
MP-7: Media Use
[Assignment: restrict, prohibit] the use of [Assignment: organization-defined types of system media] on [Assignment: organization-defined systems or system components] using [Assignment: organization-defined controls] ; and Prohibit the use of portable storage devices in organizational systems when such devices have no identifiable owner.
MP-8: Media Downgrading
Establish [Assignment: organization-defined system media downgrading process] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category or classification of the information; Verify that the system media downgrading process is commensurate with the security category and/or classification level of the information to be removed and the access authorizations of the potential…
NIST SP 800-171 Revision 3.0
03.08.01: Media Storage
Physically control and securely store system media that contain CUI.
03.08.02: Media Access
Restrict access to CUI on system media to authorized personnel or roles.
03.08.04: Media Marking
Mark system media that contain CUI to indicate distribution limitations, handling caveats, and applicable CUI markings.
03.08.05: Media Transport
Protect and control system media that contain CUI during transport outside of controlled areas. Maintain accountability of system media that contain CUI during transport outside of controlled areas. Document activities associated with the transport of system media that contain CUI.
03.08.07: Media Use
Restrict or prohibit the use of [Assignment: organization-defined types of system media]. Prohibit the use of removable system media without an identifiable owner.
03.15.01: Policy and Procedures
Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for the protection of CUI. Review and update policies and procedures [Assignment: organization-defined frequency].
Cloud Controls Matrix v4.0
DCS-02: Off-Site Transfer Authorization Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable authorization. Review and update the policies and procedures at least annually.
DCS-04: Secure Media Transportation Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure transportation of physical media. Review and update the policies and procedures at least annually.
HRS-02: Acceptable Use of Technology Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets. Review and update the policies and procedures at least annually.
Critical Security Controls Version 8.1
3: Data Protection
Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.
3.9: Encrypt Data on Removable Media
Encrypt data on removable media.
10: Malware Defenses
Prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets.
10.3: Disable Autorun and Autoplay for Removable Media
Disable autorun and autoplay auto-execute functionality for removable media.
NIST Special Publication 800-53 Revision 4
MP-2: Media Access
The organization restricts access to [Assignment: organization-defined types of digital and/or non-digital media] to [Assignment: organization-defined personnel or roles].
MP-3: Media Marking
The organization: Marks information system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information; and Exempts [Assignment: organization-defined types of information system media] from marking as long as the media remain within [Assignment: organization-defined controlled areas].
MP-4: Media Storage
The organization: Physically controls and securely stores [Assignment: organization-defined types of digital and/or non-digital media] within [Assignment: organization-defined controlled areas]; and Protects information system media until the media are destroyed or sanitized using approved equipment, techniques, and procedures.
MP-5: Media Transport
The organization: Protects and controls [Assignment: organization-defined types of information system media] during transport outside of controlled areas using [Assignment: organization-defined security safeguards]; Maintains accountability for information system media during transport outside of controlled areas; Documents activities associated with the transport of information system media; and Restricts the activities associated with the transport of information…
MP-7: Media Use
The organization [Selection: restricts; prohibits] the use of [Assignment: organization-defined types of information system media] on [Assignment: organization-defined information systems or system components] using [Assignment: organization-defined security safeguards].
MP-8: Media Downgrading
The organization: Establishes [Assignment: organization-defined information system media downgrading process] that includes employing downgrading mechanisms with [Assignment: organization-defined strength and integrity]; Ensures that the information system media downgrading process is commensurate with the security category and/or classification level of the information to be removed and the access authorizations of the potential recipients of the downgraded…
NIST Special Publication 800-171 Revision 2
3.8.1: Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
System media includes digital and non-digital media. Digital media includes diskettes, magnetic tapes, external and removable hard disk drives, flash drives, compact disks, and digital video disks. Non-digital media includes paper and microfilm. Protecting digital media includes limiting access to design specifications stored on compact disks or flash drives in the media library to the…
3.8.2: Limit access to CUI on system media to authorized users
Access can be limited by physically controlling system media and secure storage areas. Physically controlling system media includes conducting inventories, ensuring procedures are in place to allow individuals to check out and return system media to the media library, and maintaining accountability for all stored media. Secure storage includes a locked drawer, desk, or cabinet,…
3.8.3: Sanitize or destroy system media containing CUI before disposal or release for reuse
This requirement applies to all system media, digital and non-digital, subject to disposal or reuse. Examples include: digital media found in workstations, network components, scanners, copiers, printers, notebook computers, and mobile devices; and non-digital media such as paper and microfilm. The sanitization process removes information from the media such that the information cannot be retrieved…
3.8.4: Mark media with necessary CUI markings and distribution limitations
The term security marking refers to the application or use of human-readable security attributes. System media includes digital and non-digital media. Marking of system media reflects applicable federal laws, Executive Orders, directives, policies, and regulations. See [NARA MARK].
3.8.5: Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas
Controlled areas are areas or spaces for which organizations provide physical or procedural controls to meet the requirements established for protecting systems and information. Controls to maintain accountability for media during transport include locked containers and cryptography. Cryptographic mechanisms can provide confidentiality and integrity protections depending upon the mechanisms used. Activities associated with transport include…
3.8.6: Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards
This requirement applies to portable storage devices (e.g., USB memory sticks, digital video disks, compact disks, external or removable hard disk drives). See [NIST CRYPTO]. [SP 800-111] provides guidance on storage encryption technologies for end user devices.
3.8.7: Control the use of removable media on system components
In contrast to requirement 3.8.1, which restricts user access to media, this requirement restricts the use of certain types of media on systems, for example, restricting or prohibiting the use of flash drives or external hard disk drives. Organizations can employ technical and nontechnical controls (e.g., policies, procedures, and rules of behavior) to control the…
3.8.8: Prohibit the use of portable storage devices when such devices have no identifiable owner
Requiring identifiable owners (e.g., individuals, organizations, or projects) for portable storage devices reduces the overall risk of using such technologies by allowing organizations to assign responsibility and accountability for addressing known vulnerabilities in the devices (e.g., insertion of malicious code).
Cloud Controls Matrix v3.0.1
DSI-04: Handling / Labeling / Security Policy
Policies and procedures shall be established for the labeling, handling, and security of data and objects which contain data. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data.
DCS-04: Off-Site Authorization
Authorization must be obtained prior to relocation or transfer of hardware, software, or data to an offsite premises.
HRS-11: Workspace
Policies and procedures shall be established to require that unattended workspaces do not have openly visible (e.g., on a desktop) sensitive documents and user computing sessions are disabled after an established period of inactivity.
MOS-08: Device Eligibility
The BYOD policy shall define the device and eligibility requirements to allow for BYOD usage.
MOS-10: Device Management
A centralized, mobile device management solution shall be deployed to all mobile devices permitted to store, transmit, or process customer data.
MOS-11: Encryption
The mobile device policy shall require the use of encryption either for the entire device or for data identified as sensitive on all mobile devices, and shall be enforced through technology controls.
Critical Security Controls Version 7.1
8: Malware Defenses
Control the installation, spread, and execution of malicious code at multiple points in the enterprise, while optimizing the use of automation to enable rapid updating of defense, data gathering, and corrective action.
8.5: Configure Devices to Not Auto-Run Content
Configure devices to not auto-run content from removable media.
13: Data Protection
The processes and tools used to prevent data exfiltration, mitigate the effects of exfiltrated data, and ensure the privacy and integrity of sensitive information.
13.7: Manage USB Devices
If USB storage devices are required, enterprise software should be used that can configure systems to allow the use of specific devices. An inventory of such devices should be maintained.
13.8: Manage System’s External Removable Media’s Read/Write Configurations
Configure systems not to write data to external removable media, if there is no business need for supporting such devices.
13.9: Encrypt Data on USB Storage Devices
If USB storage devices are required, all data stored on such devices must be encrypted while at rest.