Skip to content

Media Protection

Media Protection governs every physical and digital container of CUI — paper documents, USB drives, backup tapes, external drives, and portable devices.

Store & Access (3.8.1–3.8.2) — Lock up CUI media and limit access to need-to-know.

Mark & Track (3.8.4–3.8.5) — Label all CUI media correctly and maintain chain of custody during transport.

Transport & Encrypt (3.8.6–3.8.7) — Encrypt before transport. Control removable media on CUI systems.

Dispose & Protect (3.8.3, 3.8.8–3.8.9) — Destroy properly per NIST 800-88. Don’t plug in unknown drives. Protect backups like production data.


RefShort NameWhat It Covers
3.8.1Lock Up CUIPhysically control and securely store CUI media
3.8.2Need-to-Know for MediaAccess to CUI media limited to authorized users
3.8.3Destroy It ProperlySanitize or destroy per NIST 800-88 before disposal
3.8.4Mark Your CUICUI markings and distribution limitations
3.8.5Track Media in TransitChain of custody during transport
3.8.6Encrypt Media in TransitFIPS-validated encryption before transport
3.8.7Control Removable MediaBlock USB by default, allow by exception
3.8.8No Mystery USB DrivesProhibit unidentified portable storage
3.8.9Protect Your BackupsBackup CUI encrypted and secured like production