Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.
DiscussionSystem media includes digital and non-digital media. Digital media includes diskettes, magnetic tapes, external and removable hard disk drives, flash drives, compact disks, and digital video disks. Non-digital media includes paper and microfilm. Protecting digital media includes limiting access to design specifications stored on compact disks or flash drives in the media library to the project leader and any individuals on the development team. Physically controlling system media includes conducting inventories, maintaining accountability for stored media, and ensuring procedures are in place to allow individuals to check out and return media to the media library. Secure storage includes a locked drawer, desk, or cabinet, or a controlled media library. Access to CUI on system media can be limited by physically controlling such media, which includes conducting inventories, ensuring procedures are in place to allow individuals to check out and return media to the media library, and maintaining accountability for all stored media. NIST SP 800-111 provides guidance on storage encryption technologies for end user devices.
Further DiscussionCUI can be contained on two types of physical media:
- hardcopy (e.g., CD drives, USB drives, magnetic tape); and
- digital devices (e.g., CD drives, USB drives, video).
ExampleYour company has CUI for a specific Army contract contained on a USB drive. You store the drive in a locked drawer, and you log it on an inventory [d]. You establish a procedure to check out the USB drive so you have a history of who is accessing it. These procedures help to maintain the confidentiality, integrity, and availability of the data.
Potential Assessment Considerations
- Is hardcopy media containing CUI handled only by authorized personnel according to defined procedures [a]?
- Is digital media containing CUI handled only by authorized personnel according to defined procedures [b]?
- Is paper media containing CUI physically secured (e.g., in a locked drawer or cabinet)[c]?
- Is digital media containing CUI securely stored (e.g., in access-controlled repositories) [d]?