CMMC Practices

MP.L2-3.8.1  

Reference: CMMC 2.11

Family: MP

Level Introduced: 2

Title: Media Protection

Practice:
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.

CMMC Clarification:
Physical CUI includes two types of items:
• hardcopy (e.g., paper, microfilm); and
• digital devices (e.g., CD drives, flash drives, video).
You should store physical CUI in a secure location. This location should be accessible only to those people with the proper permissions. All who access CUI should follow the process for checking out and returning it.

Example
Your organization has CUI for a specific Army contract. The Army gave you the CUI on a CD. You store the CD in a locked drawer and you log the CUI CD in an inventory. You also establish a procedure to check out the CD when your employees need to use it.

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

Source: CMMC v2.0