← Controls / MP

MP-05 Media Transport

Media Protection

Moderate High

Description

a. Protect and control [Assignment: organization-defined types of system media] during transport outside of controlled areas using [Assignment: organization-defined controls]; b. Maintain accountability for system media during transport outside of controlled areas; c. Document activities associated with the transport of system media; and d. Restrict the activities associated with the transport of system media to authorized personnel.

Supplemental Guidance

System media includes digital and non-digital media. Digital media includes flash drives, diskettes, magnetic tapes, external or removable hard disk drives (e.g., solid state and magnetic), compact discs, and digital versatile discs. Non-digital media includes microfilm and paper. Controlled areas are spaces for which organizations provide physical or procedural controls to meet requirements established for protecting information and systems. Controls to protect media during transport include cryptography and locked containers. Cryptographic mechanisms can provide confidentiality and integrity protections depending on the mechanisms implemented. Activities associated with media transport include releasing media for transport, ensuring that media enters the appropriate transport processes, and the actual transport. Authorized transport and courier personnel may include individuals external to the organization. Maintaining accountability of media during transport includes restricting transport activities to authorized personnel and tracking and/or obtaining records of transport activities as the media moves through the transportation system to prevent and detect loss, destruction, or tampering. Organizations establish documentation requirements for activities associated with the transport of system media in accordance with organizational assessments of risk. Organizations maintain the flexibility to define record-keeping methods for the different types of media transport as part of a system of transport-related records.

Enhancements (1)

What NIST adds to this control. Select one to read its statement.

MP-05(03) Custodians

Employ an identified custodian during transport of system media outside of controlled areas.

Withdrawn by NIST:

  • MP-05(01) Protection Outside of Controlled Areas, now in MP-05
  • MP-05(02) Documentation of Activities, now in MP-05
  • MP-05(04) Cryptographic Protection, now in SC-28(01)

Patterns that use this control (1)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.10A.7.9A.7.10

ISO 27002:2022

5.147.97.10

COBIT 2019

APO14BAI09

CIS Controls v8

CIS 3CIS 3.9

NIST CSF 2.0

PR.DS-01

PCI DSS v4.0.1

9.4

CSA CCM v4

DCS-02DCS-04

CSA AICM v1

DCS-02DCS-04

FINOS CCC

CCC-C16

ISO 42001:2023

A.4.3

PRA Operational Resilience

SS2/21-11.1

MAS TRM

11

ANSSI

Hygiene.19SecNumCloud.9.2

FINMA Circular 2023/1

IV.C(63)IV.D(78)IV.D(81)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.32(1)(a)Art.44

EU DORA

Art.9(4)(a)Art.9(4)(b)

BIO2

5.147.97.10

RBI CSF

Annex1.12

FISC Security Guidelines

FISC.F4

LGPD + BCB 4893

BCB.Art.14LGPD.Art.33-36

HKMA TM-E-1

TME1.6.5TME1.7.2TME1.9.2

MLPS 2.0

8.1.4.88.1.10.1

EU CRA

CRA.I.2eCRA.I.2m

SWIFT CSCF

SWIFT.2.5A

SAMA CSF

3.9

NCA ECC

2-62-72-9

UAE IA

T4

CBB TM

TM-9

Qatar NIA

AM

CBUAE

CR-5

CBE CSF

CTO-2

SA JS2

JS2-8.2

CBN CSF

Part3.4

BoG CISD

CISD-V

BCBS 239

Principle 11

FFIEC IS

II.C.13II.C.13(c)II.C.13(d)

NYDFS 500

500.15

HIPAA Security Rule

§164.308(a)(7)(ii)(A)§164.310(d)(1)§164.310(d)(2)(iii)

ECB CROE

CROE.2.3.3

SEBI CSCRF

PR.DS

BOT Cyber Resilience

Ch2.3

CMMC 2.0

MP

CBEST

CBEST.9

Lloyd's Minimum Standards

MS8.7

NAIC Insurance Data Security

4-encryption

HITRUST CSF v11

07.b09.f

ISO 27799

12.313.2

NHS DSPT

NDG-1.1

CCSS v9.0

1.01.4

Basel SCO60

SCO60.61SCO60.63

BSSC Standards

KMS-05KMS-10

SEC Custody (Digital Assets)

SEC-CD-06

ISO 17799 (legacy)

10.8.3

COBIT 4.1 (legacy)

DS11.4DS11.6