Cybersecurity | | 26 min read
NIST 800-171 Media Protection: Controls and Evidence
Key Takeaways
Media Protection is a custody system, not a disposal form
Seven active requirements cover the full lifecycle
Revision 3 joins storage, access, sanitization, marking, transport, use, and cryptographic protection for backups.
Media Transport scores 91
Transport leads the GS proof load model because movement combines custody, route, recipient, protection, receipt, and recurring records.
Every copy needs a traceable state
The team should be able to name what the media holds, where it is, who controls it, what may happen next, and how the record closes.
NIST 800-171 Media Protection is not a disposal checklist. It is the custody system for every CUI copy that can leave the application, move between people, survive in a backup, or return through an old device.
The hard part is not writing a sentence that says media will be protected. The hard part is finding every form of media, assigning an owner, controlling access and movement, preserving the handling context, protecting backup copies, and proving that release or destruction actually closed the record.
A contractor can have strong endpoint security and still fail this family. A printed drawing sits in an unlocked room. An encrypted drive travels without a recipient record. A backup survives after the source system leaves scope. A disposal certificate names a pallet but not the devices. Each gap creates a CUI copy the operating record cannot explain.
This guide turns the family into an operating model. It connects to the NIST 800-171 hub, the companion Configuration Management guide, the CUI data flow map guide, the Access Control guide, and GS Consulting services for secure AI automation.
Trace every CUI copy from creation to release.
GS Consulting helps contractors define media scope, control custody, test sanitization, reconcile backups, and build assessment evidence around the real workflow.
Plan the Media ReviewNIST 800-171 Media Protection: The Short Answer
NIST SP 800-171 Revision 3 contains seven active Media Protection requirements. They cover Media Storage, Media Access, Media Sanitization, Media Marking, Media Transport, Media Use, and System Backup Cryptographic Protection.
GS counted 15 determination statements and one organization defined parameter in the official NIST SP 800-171A Revision 3 assessment procedures. Media Transport contains four statements, the largest formal assessment surface in this family.
The implementation test is direct. For a selected CUI item, device, paper file, removable drive, export, or backup, can the team show its media type, owner, location, authorized users, marking, movement history, protection, current state, and final disposition? If the answer depends on memory, the control is not yet operating.
Let the Contract Set the Revision
NIST publication does not rewrite an award by itself. The DFARS 252.204-7012 clause, when included, connects the required NIST publication to the covered contractor system and the governing acquisition. The solicitation, contract, subcontract, modifications, information terms, and authorized customer direction determine the applicable baseline.
That distinction matters because a governing program or award may use a different revision from the newest publication. Revision 3 reorganizes the Media Protection family. Two identifiers in its sequence are withdrawn because their outcomes moved or were incorporated elsewhere. A missing number is not permission to discard the behavior.
Keep one applicability record for each affected award. Name the contract, clause, required publication, revision, system, CUI category, customer direction, decision owner, approval date, and review trigger. Prepare for a newer revision where prudent, but describe a requirement as mandatory only when the governing source makes it so.
The Seven Media Protection Requirements
| Requirement | Operating question | Proof to expect |
|---|---|---|
| 03.08.01 Media Storage | Where can CUI media exist and how is it physically controlled? | Inventory, location, custodian, storage rule, access record, and inspection |
| 03.08.02 Media Access | Who may access CUI on media and how is that decision enforced? | Role basis, approval, media access method, denied test, and review |
| 03.08.03 Media Sanitization | How is CUI made infeasible to recover before disposal, release, or reuse? | Media type, method, operator, validation, approval, and disposition |
| 03.08.04 Media Marking | Does the media carry the applicable CUI marking and distribution limit? | Marking rule, sample, exception, review, correction, and owner |
| 03.08.05 Media Transport | How is CUI protected and tracked while it moves outside controlled areas? | Custody, route, container, recipient, receipt, exception, and reconciliation |
| 03.08.07 Media Use | Which media types may be used, restricted, or prohibited on covered systems? | Allowed media register, technical restriction, approval, event record, and test |
| 03.08.09 System Backup Cryptographic Protection | Are backup copies of CUI protected at storage locations? | Backup scope, encryption, key control, access, restore test, and monitoring |
The official language governs. The table translates each requirement into the operating question an owner and assessor should be able to follow. It does not replace the publication, assessment procedure, contract, agency direction, or a facts based legal review.
Original Research: The GS Media Protection Proof Load Index
Seven requirements do not create seven equal work packages. Movement creates the most coordination.
GS Consulting built a derived planning model across the seven active Revision 3 requirements. The public inputs are the NIST SP 800-171A determination statement count divided by the family maximum of four and the organization defined parameter count divided by one. Five GS ratings from one to five capture physical exposure, movement exposure, failure consequence, recurring evidence demand, and coordination demand.
The base model weights statement count at 15 percent, parameter count at 5 percent, physical exposure at 15 percent, movement exposure at 20 percent, failure consequence at 20 percent, recurring evidence at 15 percent, and coordination demand at 10 percent. The sensitivity case moves five points from statement count to failure consequence.
Media Transport scores 91.0. Media Use scores 75.5. Media Sanitization scores 70.8, and System Backup Cryptographic Protection scores 70.5. Transport stands apart because custody, route, protection, recipient, receipt, and exception evidence must stay connected while the media crosses people and locations.
The alternate weights preserve Media Transport in first place and move no score by more than 3.8 points. That stability supports a practical sequence: settle transport and custody early, then prove the controls that govern use, sanitization, and backup copies.
This is a GS Consulting derived planning tool. It is not an official NIST score, audit result, legal opinion, contract interpretation, CMMC result, or compliance determination. The source register, observations, ratings, formulas, sensitivity analysis, figure data, and caveats are preserved in the repository research package.
Build the Media Record Around the Full Lifecycle
Identify. Record the media type, identifier or class, CUI status, information owner, custodian, location, approved purpose, source, and current state. Include paper, removable storage, devices, exports, images, backups, and provider managed copies where they store or carry CUI.
Mark. Apply the relevant CUI marking and dissemination context. The NARA CUI Marking Handbook provides federal marking examples and handling context. Agency and contract direction can add details, so preserve the source of the decision.
Store and access. Name approved locations, physical controls, authorized roles, checkout rules, monitoring, and review timing. A locked cabinet is not complete proof if the team cannot identify the key holders or reconcile the contents.
Move and back up. Connect custody, route, container, recipient, receipt, encryption, key control, restore access, and exceptions. The record should explain both the original and every surviving copy.
Sanitize and close. Select a method suited to the media and intended disposition, validate the outcome, approve release, and preserve the final record. Closure means the inventory, movement history, backup state, and sanitization evidence tell the same story.
Control Custody Before Media Leaves a Controlled Area
Transport failure usually begins before transport. The sender has not confirmed the item, recipient, route, container, destination, receipt method, or exception path. Once the package or device moves, the team tries to reconstruct those decisions from email.
Use a transport record that names the media identifier, CUI status, sender, approving owner, carrier or internal mover, route, departure, protection method, container, recipient, expected arrival, receipt confirmation, discrepancy, and closure. Where the process relies on encryption, prove the approved mechanism, key control, and recipient capability. Encryption does not replace custody.
Test the process with an exception. Ask what happens when a recipient changes, a package is delayed, a seal is damaged, a device is lost, or receipt is not confirmed. The response should name who decides, who reports, what evidence is preserved, and when the Incident Response process takes control.
Physical and logical records should reconcile. The inventory says the device is at Site B. The transport record proves how it arrived. The access record identifies who may use it. The endpoint record confirms protection. A contradiction is a control signal, not an administrative nuisance.
Treat Backups as CUI Media With Their Own Access Path
Backup copies often outlive the system description. A workload changes provider, a contract ends, or an application leaves the boundary, but historical copies remain in snapshots, archives, removable sets, recovery vaults, or provider retention tiers.
Map backup scope by system and CUI type. Record the destination, retention rule, encryption status, key owner, administrative roles, restore roles, monitoring, recovery test, replication path, provider duty, exception, and deletion process. Then select a sample and trace it from source to protected copy to restore result.
Cryptographic protection is not proved by a provider feature page. Show the customer setting, affected repository, key arrangement, enforcement status, access path, recent evidence, and a representative restore. Link changes in backup design to the Configuration Management process so a new destination or retention rule cannot drift outside the evidence record.
Sanitization Is a Method and Validation Decision
NIST SP 800-88 Revision 2 is the current NIST guidance for media sanitization. It connects sanitization decisions to the media type, confidentiality, intended disposition, available method, validation, and program records.
A generic destruction certificate is useful only when it can be reconciled to the actual media. Record identifiers or a controlled batch, media type, CUI status, selected method, tool or service, operator, date, validation technique, validation result, failed attempt, witness where used, release approval, and final disposition.
Reuse raises a different question from disposal. The team is not merely destroying an object. It is making a reasoned claim that the prior CUI cannot be recovered under the selected release condition. Keep the rationale with the evidence. If the method cannot be validated for that media, do not call the record closed.
A Practical Media Protection Decision Path
- Find every CUI copy. Trace entry, creation, print, export, removable storage, device storage, image, backup, provider copy, recovery, and final exit.
- Set allowed media. Name approved and prohibited types, owners, markings, storage locations, technical restrictions, and exceptions.
- Control custody and access. Connect authorization, physical control, checkout, movement, recipient, receipt, and inventory.
- Protect backups and movement. Prove encryption, key control, route, container, restore access, monitoring, and response.
- Sanitize and verify release. Select the method, validate the result, reconcile copies, approve disposition, and preserve the record.
Six Media Protection Failure Modes
- Unknown owner. The inventory names an asset but no custodian can explain its purpose, access, or disposition.
- Missing marking. The next person receives the media without the handling context needed to protect it.
- Transport gap. The route, recipient, receipt, or exception cannot be proved after movement.
- Backup blind spot. Copies survive changes to systems, contracts, providers, or retention without a current owner.
- Weak sanitization. The method is assumed from a vendor label and the actual result is not validated.
- Broken chain. Inventory, access, movement, backup, and disposition records disagree.
A 60 Day Media Protection Plan
Days 1 through 10: settle applicability and ownership. Read the governing awards and information terms. Name the security owner, information owners, media custodians, facilities lead, backup owner, provider contacts, contracts lead, and response owner.
Days 11 through 20: discover the media. Walk the CUI workflow. Sample paper, endpoints, removable media, exports, images, backups, recovery sets, provider copies, and disposal staging. Reconcile what people describe with inventories and system records.
Days 21 through 30: set the allowed states. Approve media types, prohibited uses, marking rules, storage locations, access roles, transport methods, backup controls, sanitization methods, exceptions, and review timing.
Days 31 through 45: implement and connect evidence. Configure restrictions, close storage gaps, create custody records, validate encryption and key ownership, improve inventory identifiers, and connect provider evidence. Repair the process before collecting a large evidence folder.
Days 46 through 55: test transitions. Select samples for checkout, denied access, transport, receipt, backup restore, exception handling, sanitization validation, and inventory reconciliation. Record expected result, actual result, defect, owner, correction, and retest.
Days 56 through 60: review and sustain. Map evidence to the applicable assessment objectives. Resolve contradictions. Put media review into system change, contract closure, employee departure, provider change, incident response, and annual assessment routines.
Minimum Media Protection Evidence Packet
Keep the media inventory, allowed media register, marking record, storage and access proof, transport record, backup protection proof, sanitization record, and reconciliation test file under change control. Every item should have a scope, owner, date, source, result, exception path, and review trigger.
Do not confuse file count with evidence strength. One current transport record linked to an inventory, recipient receipt, and tested exception can prove more than a folder of undated policies. The assessment question is whether the evidence explains the real media and the real action.
Sources, Method, and Caveats
The research package uses primary public sources from NIST, NARA, DoD, and Acquisition.gov. It separates public observations from GS analyst ratings. The source register records publication, access date, relevant finding, model use, and limitation for each source.
The GS Media Protection Proof Load Index supports planning. It does not determine contract applicability, legal duties, audit results, CMMC status, or compliance. Use the actual award, current Government direction, CUI facts, system behavior, and assessment evidence for those decisions.
Frequently Asked Questions About NIST 800-171 Media Protection
What is NIST 800-171 Media Protection?
It is the requirement family that governs how CUI media is stored, accessed, marked, transported, used, backed up, sanitized, and released. A complete implementation connects each copy to an owner, approved state, protection, movement history, and disposition.
How many Revision 3 Media Protection requirements are active?
Revision 3 has seven active requirements. GS counted 15 determination statements and one organization defined parameter in NIST SP 800-171A Revision 3. The governing contract or program determines the required revision.
What counts as media for NIST 800-171?
Media can include paper, removable storage, devices, servers, virtual media, images, exports, backups, and provider managed copies. Follow every object or service that can store or carry CUI.
Does NIST 800-171 require CUI media to be marked?
Revision 3 requires media containing CUI to carry applicable CUI markings and distribution limitations. The exact marking depends on the information, agency direction, medium, contract, and approved handling process.
How should a contractor sanitize CUI media?
Choose a method from the media type, confidentiality, intended disposition, available technique, and validation method. NIST SP 800-88 Revision 2 provides current federal guidance. Preserve the decision, action, validation, approval, and disposition.
What evidence supports Media Protection?
Use a media inventory, allowed media register, marking record, storage and access proof, transport record, backup protection proof, sanitization record, and reconciliation tests. Tie each item to the media, owner, action, date, result, and authority.
Make Every CUI Copy Explainable
Do not end the control at the application boundary. Follow paper, drives, devices, exports, backups, providers, movement, reuse, and destruction. Reconcile every transition. Test the exceptions that make people improvise.
Not a disposal checklist. A custody record that closes only when every CUI copy has a controlled state and a defensible disposition.
Build a Media Protection record that survives assessment.
GS Consulting can help your team discover CUI media, set handling rules, test custody and sanitization, and organize evidence around the actual operation.
Discuss Media Protection