We’ve mentioned three of the nine Media Protection controls already, MP.L2-3.8.3, MP.L2-3.8.4, and MP.L2-3.8.5 got a preview in Nugget #16 as part of asset tracking. This nugget gives the full Media Protection (MP) family the dedicated treatment it deserves. All nine controls, because “media” in CMMC terms covers a lot more than the USB drive you’re picturing right now. Paper, laptops, external hard drives, backup tapes, and yes, that multifunction printer quietly holding a cache of scanned documents in its internal memory. All of it is media. All of it needs a plan.
MP.L2-3.8.1: Protect (physically control and securely store) system media containing CUI, both paper and digital
This is the foundational control, and it applies to everything: paper documents, USB drives, external hard drives, optical media, laptops, servers, and printers. If it stores CUI, it needs a home that isn’t “wherever it happened to end up.”
Organizations are required to:
- Establish procedures for physically controlling and securely storing CUI-bearing media, locked cabinets or safes for physical media, encrypted storage for digital media
- Implement access controls, locks, or encryption to prevent unauthorized access
- Develop handling, transport, and disposal guidelines that carry security through the entire media lifecycle
- Conduct regular assessments and audits to confirm the procedures are actually being followed
Example failure: A USB drive with CUI sits on an unattended desk overnight. No locking drawer, no cabinet, nothing standing between it and anyone who walks by after hours. Storage security that only exists during business hours isn’t storage security.
MP.L2-3.8.2: Limit access to CUI on system media to authorized users
Storing media securely doesn’t mean much if everyone in the building can open it. This control is about restricting access to people with an actual, legitimate need.
Organizations are required to:
- Define who is authorized to access CUI on system media and under what circumstances
- Implement technical controls, encryption, access permissions, authentication, to enforce that restriction
- Establish user roles and permissions tied to legitimate business need, not convenience
- Train employees on their responsibilities and the consequences of unauthorized access
- Monitor and log access events, and actually review those logs
- Revoke access promptly when someone changes roles or leaves
Example failure: Access controls exist on a network drive, but the permissions were configured once, years ago, and never revisited. Half the department can now open a folder they have no reason to touch.
MP.L2-3.8.3: Sanitize or destroy system media before disposal or release for reuse
This is where the disposal story actually belongs, not under 3.8.1. Throwing paper CUI in the regular trash, or handing off a hard drive for reuse without wiping it, is a 3.8.3 failure, distinct from how you stored the media while it was in active use.
Example failure: A company disposes of paper documents containing CUI by tossing them straight in the office trash can. No shredder, no locked disposal bin, just a direct path from filing cabinet to dumpster to anyone willing to dig. Sanitize or destroy, every time, no exceptions for “it’s probably fine.”
MP.L2-3.8.4 and MP.L2-3.8.5: Marking and Transport Accountability
Covered in depth in Nugget #16: consistent CUI labeling across all media types, and maintaining an accountability inventory plus secure transport procedures when media leaves controlled areas. Worth a quick recap here since they’re part of the same family: unmarked media is media nobody can correctly handle, and unaccounted-for media is media nobody can prove wasn’t lost.
MP.L2-3.8.6: Implement cryptographic mechanisms to protect the confidentiality of CUI on digital media during transport
This is the technical backbone that makes MP.L2-3.8.5 actually defensible. Physical safeguards like locked containers or a trusted courier are acceptable, but encryption is the preferred approach because it protects you even if the physical safeguard fails, a bag gets left in a car, a courier makes an unplanned stop, etc.
Requirements:
- All portable media containing CUI must be encrypted using FIPS-validated cryptographic modules (not just a strong algorithm; the module itself needs to be validated, see the FIPS-validated vs. FIPS-compliant distinction covered in Nugget #18)
- Encryption applied before the media leaves the controlled environment, not somewhere en route
- A documented process for approving, logging, and tracking media transport
MP.L2-3.8.7: Control the use of removable media on system components
USB drives are convenient. That’s exactly the problem. This control requires organizations to define and technically enforce which removable media can connect to which systems.
Assessor Reality Check: “We have a policy against unauthorized USB drives” is not the same as USB ports being technically blocked or monitored. Assessors look for enforcement, endpoint controls, group policy, or MDM, not just a line in the employee handbook nobody reads twice.
MP.L2-3.8.8: Prohibit the use of portable storage devices when such devices have no identifiable owner
The unlabeled USB drive someone found in the parking lot is not a lucky find, it’s an unknown risk with an unknown history plugged into your network. This control requires that portable storage devices have a traceable, identifiable owner before they’re permitted anywhere near your systems.
MP.L2-3.8.9: Protect the confidentiality of backup CUI at storage locations
Your backups contain CUI too, and they need the same level of protection as the live data, sometimes more, because backups often sit untouched for long stretches with less day-to-day oversight. This means encryption at rest, access controls on backup storage locations, and the same physical security expectations that apply to your primary environment, whether backups live on-site, off-site, or in the cloud.
Common Failures Across This Control Set
MP.L2-3.8.1 Media stored securely during business hours only, unattended overnight
MP.L2-3.8.2 Access permissions configured once and never reviewed
MP.L2-3.8.3 CUI disposed of in regular trash instead of shredded or sanitized
MP.L2-3.8.4 No consistent labeling system across media types
MP.L2-3.8.5 No accountability inventory for media in transport
MP.L2-3.8.6 Media encrypted with a strong algorithm, but the module isn’t FIPS-validated
MP.L2-3.8.7 USB restriction exists in policy only, not technically enforced
MP.L2-3.8.8 Found or unlabeled portable media allowed to connect
MP.L2-3.8.9 Backup CUI protection overlooked entirely
SSP Mapping Note
All nine controls in this nugget belong under the Media Protection (MP) section of your SSP, along with the three previewed in Nugget #16. A frequent gap: organizations document their live production media handling thoroughly and then completely forget backups fall under the same family. MP.L2-3.8.9 gets left out more often than any other control here.
For each control your SSP should document:
- The specific technical or procedural implementation
- The policy governing it, storage locations, retention, transport procedures
- Who owns enforcement (IT, facilities, records management, varies by control)
- How compliance is verified, and how often
Media protection is the control family most likely to get treated as an afterthought, right up until an assessor asks to see your disposal log and there isn’t one. Reach out to DTC’s C3PAO team if you want a second set of eyes on your media handling procedures before that conversation happens during your actual assessment.