03.08.03: Media Sanitization
Control Familly: Media Protection
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
SP 800-88 [50]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.08.03
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
MP-06
Sanitize system media that contain CUI prior to disposal, release out of organizational control, or release for reuse.
Discussion:
Media sanitization applies to digital and non-digital media that are subject to disposal or reuse, whether or not the media are considered removable. Examples include digital media in scanners, copiers, printers, notebook computers, mobile devices, workstations, network components, and non-digital media. The sanitization process removes CUI from media such that the information cannot be retrieved or reconstructed. Sanitization techniques (e.g., cryptographically erasing, clearing, purging, and destroying) prevent the disclosure of CUI to unauthorized individuals when such media are reused or released for disposal. NARA policies control the sanitization process for media that contain CUI and may require destruction when other methods cannot be applied to the media.
Assessment Methods and Objectives
Examine [SELECT FROM: media protection policy and procedures; procedures for media sanitization and disposal; applicable standards and policies that address media sanitization policy; system audit records; media sanitization records; system design documentation; system configuration settings; records retention and disposition policy; records retention and disposition procedures; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with media sanitization responsibilities; personnel with records retention and disposition responsibilities; personnel with information security responsibilities; system administrators]
Test [SELECT FROM: processes for media sanitization; mechanisms for supporting or implementing media sanitization]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.08.03: system media that contain CUI are sanitized prior to disposal, release out of organizational control, or release for reuse.
The Security Requirements
NIST SP 800-171r3 (USA) & ITSP.10.171 (Canada)
3.5. Identification and Authentication
3.12. Security Assessment and Monitoring
3.13. System and Communications Protection
3.14. System and Information Integrity
3.16. System and Services Acquisition
3.17. Supply Chain Risk Management
CMMC 3.0 - N/A
CPCSC - N/A