MP.L2-3.8.2Media Access
Limit access to CUI on system media to authorized users.
[a]
access to CUI on system media is limited to authorized users.
Only the enclave roster can open the cabinet or mount an encrypted drive
Implementation
AO coverage. Addresses the Media Access objective: access to CUI on system media is limited to authorized users.
One authoritative roster. The enclave roster — the same identity group that gates logical access to CUI — is also the list of people permitted to access CUI media. There is no separate media authorization list to drift out of sync, and adding someone to media access requires the same approval and screening as adding them to the enclave group.
Physical access control. The media cabinet key is held by two custodians; anyone else requests media through them and signs it out. The sign-out sheet is checked against the roster at issue, and the custodians have turned down requests on that basis. Media in transit within the facility stays with the person; there is no leaving a drive on a desk while at lunch.
Logical access control. The drives are hardware-encrypted with a credential held only by roster members, so possession alone does not grant access. Endpoint device control allows organization-issued media to mount only on managed devices belonging to enclave users; the same drive in a non-enclave employee's laptop is blocked at the operating system level. Files on the media carry the same sensitivity label as their source, so if they land somewhere they should not, the label restrictions still apply.
Paper. Access to printed CUI is limited by the locked containers and by the requirement that each copy is signed out to a named roster member.
Maintenance. Roster changes propagate to the device control group and the custody list within one business day, and offboarding recovers issued media the same day — an outstanding drive blocks the offboarding ticket from closing. Quarterly reconciliation of the sign-out log against the roster as it stood on each date.
Accepted gap. A customer occasionally ships us media that must be read by a specific engineer who is on the roster, using a drive we do not control. Those reads happen on a designated standalone workstation with the content copied into the labeled library and the customer media returned or destroyed; the drive itself is never enrolled in our controls.
What the evidence looks like
- Enclave roster and the device control group membership derived from it
- Media sign-out log with custodian entries
- Endpoint device control policy showing the allow-list scoped to enclave users
- Offboarding ticket showing media recovery as a closure requirement
- Procedure for handling customer-supplied media on the standalone workstation
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.