STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

MP-4

Media ProtectionRev 5organization

Media Storage

Baselines:ModerateHigh

Control Statement

a. Physically control and securely store [Assignment: organization-defined types of digital and/or non-digital media] within [Assignment: organization-defined controlled areas] ; and b. Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved equipment, techniques, and procedures.

Supplemental Guidance

System media includes digital and non-digital media. Digital media includes flash drives, diskettes, magnetic tapes, external or removable hard disk drives (e.g., solid state, magnetic), compact discs, and digital versatile discs. Non-digital media includes paper and microfilm. Physically controlling stored media includes conducting inventories, ensuring procedures are in place to allow individuals to check out and return media to the library, and maintaining accountability for stored media. Secure storage includes a locked drawer, desk, or cabinet or a controlled media library. The type of media storage is commensurate with the security category or classification of the information on the media. Controlled areas are spaces that provide physical and procedural controls to meet the requirements established for protecting information and systems. Fewer controls may be needed for media that contains information determined to be in the public domain, publicly releasable, or have limited adverse impacts on organizations, operations, or individuals if accessed by other than authorized personnel. In these situations, physical access controls provide adequate protection.

Related Controls (14)

AC-19CP-2CP-6CP-9CP-10MP-2MP-7PE-3PL-2SC-12SC-13SC-28SC-34SI-12

CCI Identifiers (10)

CCI-004212Securely store organization-defined types of digital and/or non-digital media within organization-defined controlled areas.CCI-004213Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved equipment.CCI-004214Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved techniques.CCI-004215Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved procedures.CCI-004211Physically control and securely store organization-defined types of digital and/or non-digital media within organization-defined controlled areas.CCI-001014The organization physically controls and securely stores organization-defined types of digital and/or non-digital media within organization-defined controlled areas.CCI-001015Defines types of digital and/or non-digital media to physically control and securely store within organization-defined controlled areas.CCI-001016Defines controlled areas where organization-defined types of digital and/or non-digital media are physically controlled and securely stored.

Linked STIG Checks (0)

No STIG checks reference this control.

CCI-001017The organization defines security measures for securing media storage.
CCI-001018The organization protects information system media until the media are destroyed or sanitized using approved equipment, techniques, and procedures.