Skip to content
ControlVerdict
MA.L2-3.7.4CMMC Level 2Level 2

Media Inspection

Practice statement

Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.7.4.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(1)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    MA.L2-3.7.4Media Inspection
    Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
    • [a]

      media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI.

    Vendor diagnostic media is scanned on an isolated kiosk before it touches anything

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses the Media Inspection objective: media containing diagnostic and test programs is checked for malicious code before use on systems that process, store, or transmit CUI.

    Intake rule. No externally supplied media is inserted into any in-scope system before it clears the kiosk. This applies to vendor drives, customer-supplied test data, and media that came in the box with new hardware — the last category is the one people argue about, and it is included precisely because supply-chain implants arrive shrink-wrapped.

    The kiosk. A dedicated hardened workstation in the receiving area, not joined to the domain, on an isolated segment with outbound access only to the endpoint protection cloud. It runs the endpoint agent with on-demand scanning plus a second scanning engine, both updated daily. Files are scanned in place; executables and firmware images are additionally checked against the vendor's published hash where one exists.

    Transfer. Cleared content is copied from the source media to an organization-owned, asset-tagged transfer drive, and it is that drive — never the vendor's — that touches the target system. The vendor's media goes back in the vendor's pocket. This removes both the malware path and the accidental-copy-of-CUI-onto-a-vendor-drive path in one step.

    Log. Each intake is logged: date, vendor and technician, media type, what it contained, scan result, engine versions, the operator, and the destination system. A detection stops the visit and becomes an incident case.

    Maintenance. Kiosk definitions verified daily and its own baseline reimaged quarterly, because a scanning host that gets infected is worse than no scanning host. Monthly review of the intake log for media that reached a system without a matching entry.

    Accepted gap. One controller vendor's firmware loader must run from their own encrypted media, which our scanners cannot read. That update is performed with the controller disconnected from the network, under escort, and followed by a configuration and integrity comparison against the recorded baseline before it is reconnected.

    What the evidence looks like

    • Media inspection procedure with the transfer-drive rule
    • Kiosk configuration showing isolation, agent versions, and update status
    • Media intake log entries for recent vendor visits
    • Scan result records including engine versions and hash verification
    • Escort and post-update verification record for the encrypted-media exception

    Environment

    Plant with an air-gapped operational technology cell alongside the CUI enclave. Vendors routinely arrive with firmware images, diagnostic suites, and calibration files on USB drives and optical media.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.