{"data":{"id":"MP-07","name":"Media Use","family":"MP","family_name":"Media Protection","withdrawn":false,"description":"a. [Selection (one): Restrict; Prohibit] the use of [Assignment: organization-defined types of system media] on [Assignment: organization-defined systems or system components] using [Assignment: organization-defined controls]; and\nb. Prohibit the use of portable storage devices in organizational systems when such devices have no identifiable owner.","supplemental_guidance":"System media includes both digital and non-digital media. Digital media includes diskettes, magnetic tapes, flash drives, compact discs, digital versatile discs, and removable hard disk drives. Non-digital media includes paper and microfilm. Media use protections also apply to mobile devices with information storage capabilities. In contrast to MP-02, which restricts user access to media, MP-7 restricts the use of certain types of media on systems, for example, restricting or prohibiting the use of flash drives or external hard disk drives. Organizations use technical and nontechnical controls to restrict the use of system media. Organizations may restrict the use of portable storage devices, for example, by using physical cages on workstations to prohibit access to certain external ports or disabling or removing the ability to insert, read, or write to such devices. Organizations may also limit the use of portable storage devices to only approved devices, including devices provided by the organization, devices provided by other approved organizations, and devices that are not personally owned. Finally, organizations may restrict the use of portable storage devices based on the type of device, such as by prohibiting the use of writeable, portable storage devices and implementing this restriction by disabling or removing the capability to write to such devices. Requiring identifiable owners for storage devices reduces the risk of using such devices by allowing organizations to assign responsibility for addressing known vulnerabilities in the devices.","enhancements":[{"id":"MP-07(01)","name":"Prohibit Use Without Owner","withdrawn":true,"incorporated_into":["MP-07"]},{"id":"MP-07(02)","name":"Prohibit Use of Sanitization-resistant Media","statement":"Prohibit the use of sanitization-resistant media in organizational systems.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"MP-07","name":"Media Use","description":"a. [Selection (one): Restrict; Prohibit] the use of [Assignment: organization-defined types of system media] on [Assignment: organization-defined systems or system components] using [Assignment: organization-defined controls]; and\nb. Prohibit the use of portable storage devices in organizational systems when such devices have no identifiable owner.","discussion":"System media includes both digital and non-digital media. Digital media includes diskettes, magnetic tapes, flash drives, compact discs, digital versatile discs, and removable hard disk drives. Non-digital media includes paper and microfilm. Media use protections also apply to mobile devices with information storage capabilities. In contrast to MP-02, which restricts user access to media, MP-7 restricts the use of certain types of media on systems, for example, restricting or prohibiting the use of flash drives or external hard disk drives. Organizations use technical and nontechnical controls to restrict the use of system media. Organizations may restrict the use of portable storage devices, for example, by using physical cages on workstations to prohibit access to certain external ports or disabling or removing the ability to insert, read, or write to such devices. Organizations may also limit the use of portable storage devices to only approved devices, including devices provided by the organization, devices provided by other approved organizations, and devices that are not personally owned. Finally, organizations may restrict the use of portable storage devices based on the type of device, such as by prohibiting the use of writeable, portable storage devices and implementing this restriction by disabling or removing the capability to write to such devices. Requiring identifiable owners for storage devices reduces the risk of using such devices by allowing organizations to assign responsibility for addressing known vulnerabilities in the devices.","related_controls":["AC-19","AC-20","PL-04","PM-12","SC-34","SC-41"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":["A.5.10","A.7.10","A.7.14"],"iso_27002_2022":["5.10","7.10"],"cobit_2019":["APO14","BAI09"],"pci_dss_v4":["9.4"],"nist_csf_2":[],"cis_controls_v8":["CIS 3","CIS 10.3","CIS 10.4"],"soc2_tsc":[],"finos_ccc":["CCC-C16"],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["11"],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["5.10","7.10"],"rbi_csf":["Annex1.12"],"fisc":["FISC.F4"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-9"],"cbuae":["CR-5"],"qatar_nia":["AM"],"sama_csf":["3.9"],"uae_ia":["T4"],"bog_cisd":["CISD-V"],"bom_ctrm":["3.12"],"cbe_csf":["CTO-2"],"cbn_csf":["Part3.4"],"bot_cyber":["Ch2.3"],"ffiec_is":["II.C.13","II.C.13(d)"],"hipaa_sr":["§164.310(d)(1)","§164.310(d)(2)(ii)"],"cmmc_2":["MP"],"nerc_cip":[],"nrc_73_54":["RG5.71-B-MA"],"tsa_psd":[],"ieee_1686":["5.9"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["01.d","09.f"],"iso_27799":["8.3"],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":["NDG-9.7"],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":["2.02.1"],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting or prohibiting the use of removable media on organisational systems directly prevents adversaries from collecting sensitive data onto portable storage devices, as the media either cannot be mounted or is limited to approved, auditable devices."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Media use restrictions that block unauthorised portable storage devices prevent adversaries from physically exfiltrating data via USB drives or other removable media, eliminating this out-of-band exfiltration channel."},{"id":"T1091","name":"Replication Through Removable Media","tactics":["initial-access","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Prohibiting or tightly controlling removable media use prevents adversaries from introducing malware via infected USB drives or other portable media, blocking a common initial access and lateral movement vector used to bridge air-gapped networks."},{"id":"T1092","name":"Communication Through Removable Media","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Restricting removable media usage disrupts adversary command-and-control channels that rely on physically shuttling storage devices between compromised and internet-connected systems, a technique commonly used against air-gapped environments."},{"id":"T1200","name":"Hardware Additions","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Media use controls that prohibit unidentified or unapproved hardware devices prevent adversaries from connecting rogue hardware additions such as network implants, keyloggers, or malicious USB devices to organisational systems."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Explicitly prohibiting or restricting USB device usage on organisational systems directly blocks USB-based exfiltration by preventing unauthorised storage devices from being mounted, copied to, or recognised by endpoint operating systems."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: iso_27001_2022 A.5.10 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}