← Controls / MP

MP-04 Media Storage

Media Protection

Moderate High

Description

a. Physically control and securely store [Assignment: organization-defined types of digital and/or non-digital media] within [Assignment: organization-defined controlled areas]; and b. Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved equipment, techniques, and procedures.

Supplemental Guidance

System media includes digital and non-digital media. Digital media includes flash drives, diskettes, magnetic tapes, external or removable hard disk drives (e.g., solid state, magnetic), compact discs, and digital versatile discs. Non-digital media includes paper and microfilm. Physically controlling stored media includes conducting inventories, ensuring procedures are in place to allow individuals to check out and return media to the library, and maintaining accountability for stored media. Secure storage includes a locked drawer, desk, or cabinet or a controlled media library. The type of media storage is commensurate with the security category or classification of the information on the media. Controlled areas are spaces that provide physical and procedural controls to meet the requirements established for protecting information and systems. Fewer controls may be needed for media that contains information determined to be in the public domain, publicly releasable, or have limited adverse impacts on organizations, operations, or individuals if accessed by other than authorized personnel. In these situations, physical access controls provide adequate protection.

Enhancements (1)

What NIST adds to this control. Select one to read its statement.

MP-04(02) Automated Restricted Access

Restrict access to media storage areas and log access attempts and access granted using [Assignment: organization-defined automated mechanisms].

Withdrawn by NIST:

  • MP-04(01) Cryptographic Protection, now in SC-28(01)

Patterns that use this control (1)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.10A.7.7A.7.10A.8.10

ISO 27002:2022

7.77.10

COBIT 2019

APO14BAI09

CIS Controls v8

CIS 3CIS 3.9

NIST CSF 2.0

PR.DS-01

PCI DSS v4.0.1

9.4

CSA CCM v4

DCS-05

CSA AICM v1

DCS-05

FINOS CCC

CCC-C16

ISO 42001:2023

A.4.3

PRA Operational Resilience

SS2/21-11.1

MAS TRM

11

ANSSI

Hygiene.19Hygiene.37SecNumCloud.9.2SecNumCloud.12.1

FINMA Circular 2023/1

IV.D(78)IV.D(81)IV.D(82)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.32(1)(a)

EU DORA

Art.9(4)(a)Art.9(4)(b)

BIO2

7.77.10

RBI CSF

Annex1.12Annex1.15

FISC Security Guidelines

FISC.F4

LGPD + BCB 4893

LGPD.Art.46

HKMA TM-E-1

TME1.6.5TME1.7.2TME1.9.2

MLPS 2.0

8.1.10.1

DNB Good Practice

DNB.2.2DNB.11.3DNB.12.1DNB.12.3

EU CRA

CRA.I.2e

SWIFT CSCF

SWIFT.3.1

SAMA CSF

3.9

NCA ECC

2-62-72-9

UAE IA

T4

CBB TM

TM-9

Qatar NIA

AM

CBUAE

CR-5

CBE CSF

CTO-2

SA JS2

JS2-8.2

CBN CSF

Part3.4

BoG CISD

CISD-V

POPIA

s19

BCBS 239

Principle 11

CPMI-IOSCO PFMI

CG.PR

FFIEC IS

II.C.5II.C.13II.C.13(a)

NYDFS 500

500.15

HIPAA Security Rule

§164.308(a)(7)(ii)(A)§164.310(d)(1)§164.310(d)(2)(iii)§164.310(d)(2)(iv)

ECB CROE

CROE.2.3.3

SEBI CSCRF

PR.DS

BOT Cyber Resilience

Ch2.3

CMMC 2.0

MP

NERC CIP

CIP-011-3

10 CFR 73.54

RG5.71-B-MA

API 1164

Sec 8

CBEST

CBEST.9

PCI HSM

5

Solvency II

DR.266-DataSec

Lloyd's Minimum Standards

MS8.7

NAIC Insurance Data Security

4-encryption4B

HITRUST CSF v11

07.b09.d09.f

FDA 21 CFR Part 11

§11.10(c)

FDA Cybersecurity Guidance

SA-4

ISO 27799

12.3

NHS DSPT

NDG-1.1

MiCA

Art.40(1)Art.55(1)Art.63(1)Art.97(1)

Basel SCO60

SCO60.61SCO60.63

BSSC Standards

KMS-03KMS-05KMS-09KMS-10NOS-08TIS-07

SEC Custody (Digital Assets)

SEC-CD-04SEC-CD-06SEC-CD-16

ISO 17799 (legacy)

10.7.110.7.210.7.310.7.415.1.3

COBIT 4.1 (legacy)

DS11.2DS11.6