manage.get.gov/docs/compliance/dist/system-security-plans/ato/mp-4.md
Logan McDonald 8d493d2e44
Document things cloud.gov CRM fully supports (#122)
* document things cloud.gov crm fully supports

* run make assemble
2022-10-13 10:36:44 -04:00

2.7 KiB

implementation-status control-origination
c-implemented
c-inherited-cloud-gov

mp-4 - [catalog] Media Storage

Control Statement

  • [a] Physically control and securely store organization-defined types of digital and/or non-digital media within organization-defined controlled areas ; and

  • [b] Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved equipment, techniques, and procedures.

Control guidance

System media includes digital and non-digital media. Digital media includes flash drives, diskettes, magnetic tapes, external or removable hard disk drives (e.g., solid state, magnetic), compact discs, and digital versatile discs. Non-digital media includes paper and microfilm. Physically controlling stored media includes conducting inventories, ensuring procedures are in place to allow individuals to check out and return media to the library, and maintaining accountability for stored media. Secure storage includes a locked drawer, desk, or cabinet or a controlled media library. The type of media storage is commensurate with the security category or classification of the information on the media. Controlled areas are spaces that provide physical and procedural controls to meet the requirements established for protecting information and systems. Fewer controls may be needed for media that contains information determined to be in the public domain, publicly releasable, or have limited adverse impacts on organizations, operations, or individuals if accessed by other than authorized personnel. In these situations, physical access controls provide adequate protection.

Control assessment-objective

types of digital media are physically controlled; types of non-digital media are physically controlled; types of digital media are securely stored within controlled areas; types of non-digital media are securely stored within controlled areas; system media types (defined in MP-04_ODP[01], MP-04_ODP[02], MP-04_ODP[03], MP-04_ODP[04]) are protected until the media are destroyed or sanitized using approved equipment, techniques, and procedures.


What is the solution and how is it implemented?


Implementation a.

Customer applications fully inherit this control from cloud.gov.


Implementation b.

Customer applications fully inherit this control from cloud.gov.