Skip to content
ControlVerdict
MA.L2-3.7.4addresses
MA.L2-3.7.4Media Inspection
Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
  • [a]

    media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI.

View full control

Vendor diagnostic media is scanned on an isolated kiosk before it touches anything

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses the Media Inspection objective: media containing diagnostic and test programs is checked for malicious code before use on systems that process, store, or transmit CUI.

Intake rule. No externally supplied media is inserted into any in-scope system before it clears the kiosk. This applies to vendor drives, customer-supplied test data, and media that came in the box with new hardware — the last category is the one people argue about, and it is included precisely because supply-chain implants arrive shrink-wrapped.

The kiosk. A dedicated hardened workstation in the receiving area, not joined to the domain, on an isolated segment with outbound access only to the endpoint protection cloud. It runs the endpoint agent with on-demand scanning plus a second scanning engine, both updated daily. Files are scanned in place; executables and firmware images are additionally checked against the vendor's published hash where one exists.

Transfer. Cleared content is copied from the source media to an organization-owned, asset-tagged transfer drive, and it is that drive — never the vendor's — that touches the target system. The vendor's media goes back in the vendor's pocket. This removes both the malware path and the accidental-copy-of-CUI-onto-a-vendor-drive path in one step.

Log. Each intake is logged: date, vendor and technician, media type, what it contained, scan result, engine versions, the operator, and the destination system. A detection stops the visit and becomes an incident case.

Maintenance. Kiosk definitions verified daily and its own baseline reimaged quarterly, because a scanning host that gets infected is worse than no scanning host. Monthly review of the intake log for media that reached a system without a matching entry.

Accepted gap. One controller vendor's firmware loader must run from their own encrypted media, which our scanners cannot read. That update is performed with the controller disconnected from the network, under escort, and followed by a configuration and integrity comparison against the recorded baseline before it is reconnected.

What the evidence looks like

  • Media inspection procedure with the transfer-drive rule
  • Kiosk configuration showing isolation, agent versions, and update status
  • Media intake log entries for recent vendor visits
  • Scan result records including engine versions and hash verification
  • Escort and post-update verification record for the encrypted-media exception

Environment

Plant with an air-gapped operational technology cell alongside the CUI enclave. Vendors routinely arrive with firmware images, diagnostic suites, and calibration files on USB drives and optical media.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.