MP-04-727 Media Storage

Media Storage

Media Storage
Media Protection
Identify, Protect
Data Classification, Media
February 13, 2018

Confidential information maintained on storage media shall be secured in a locked storage container when not in use. Other storage media shall be secured in a manner deemed to be appropriate by the information resource owner.

The lack of formal procedures for handling, processing, storing and communicating information consistent with its classification scheme, may result in potential mishandling or misuse of information by unauthorized parties.
The organization: a. Physically controls and securely stores [Assignment: organization-defined types of digital and/or non-digital media] within [Assignment: organization-defined controlled areas]; and b. Protects information system media until the media are destroyed or sanitized using approved equipment, techniques, and procedures.
Media is secured in locked storage bins or containers.
No statewide control
Obtain information system media protection policy; procedures addressing media storage; physical and environmental protection policy and procedures; access control policy and procedures; security plan; information system media; other relevant documents or records and ascertain if : (I)the organization selects and documents the media and associated information contained on that media requiring physical protection in accordance with an organizational assessment of risk. (ii)the organization defines the specific measures used to protect the selected media and information contained on that media. (iii)the organization physically controls and securely stores information system media within controlled areas. (iv)the organization protects information system media commensurate with the FIPS 199 security categorization of the information contained on the media.