800-53|MP-4

Title

MEDIA STORAGE

Description

The organization:

Supplemental

Information system media includes both digital and non-digital media. Digital media includes, for example, diskettes, magnetic tapes, external/removable hard disk drives, flash drives, compact disks, and digital video disks. Non-digital media includes, for example, paper and microfilm. Physically controlling information system media includes, for example, conducting inventories, ensuring procedures are in place to allow individuals to check out and return media to the media library, and maintaining accountability for all stored media. Secure storage includes, for example, a locked drawer, desk, or cabinet, or a controlled media library. The type of media storage is commensurate with the security category and/or classification of the information residing on the media. Controlled areas are areas for which organizations provide sufficient physical and procedural safeguards to meet the requirements established for protecting information and/or information systems. For media containing information determined by organizations to be in the public domain, to be publicly releasable, or to have limited or no adverse impact on organizations or individuals if accessed by other than authorized personnel, fewer safeguards may be needed. In these situations, physical access controls provide adequate protection.

Reference Item Details

Related: CP-6,CP-9,MP-2,MP-7,PE-3

Category: MEDIA PROTECTION

Family: MEDIA PROTECTION

Priority: P1

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2.4.2.3.17 Set 'Deny write access to removable drives not protected by BitLocker' to 'Enabled'WindowsCIS Windows 8 L1 v1.0.0
1.2.4.2.3.20 Set 'Do not allow write access to devices configured in another organization' to 'True'WindowsCIS Windows 8 L1 v1.0.0
18.9.11.3.13 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
18.9.11.3.13 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0
18.9.11.3.13 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Windows 7 Workstation Bitlocker v3.2.0
18.9.11.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0
18.9.11.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
18.9.11.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Windows 7 Workstation Bitlocker v3.2.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 v21H1 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 11 v23H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 11 v22H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 1909 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 v20H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 11 v24H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 11 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 1803 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 1809 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 1903 v1.19.9
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 v2004 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 v1507 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 v22H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyCrossOrgWindowsMSCT Windows 10 v21H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 v1507 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 v20H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 v22H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 11 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 11 v23H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 v2004 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 1903 v1.19.9
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 1909 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 1809 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 v21H1 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 v21H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 11 v22H2 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 10 1803 v1.0.0
Deny write access to removable drives not protected by BitLocker - RDVDenyWriteAccessWindowsMSCT Windows 11 v24H2 v1.0.0