Media Access
Practice statement
Limit access to CUI on system media to authorized users.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.8.2.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(1)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
access to CUI on system media is limited to authorized users.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
MP.L2-3.8.2Media Access
Limit access to CUI on system media to authorized users.
[a]
access to CUI on system media is limited to authorized users.
Only the enclave roster can open the cabinet or mount an encrypted drive
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses the Media Access objective: access to CUI on system media is limited to authorized users.
One authoritative roster. The enclave roster — the same identity group that gates logical access to CUI — is also the list of people permitted to access CUI media. There is no separate media authorization list to drift out of sync, and adding someone to media access requires the same approval and screening as adding them to the enclave group.
Physical access control. The media cabinet key is held by two custodians; anyone else requests media through them and signs it out. The sign-out sheet is checked against the roster at issue, and the custodians have turned down requests on that basis. Media in transit within the facility stays with the person; there is no leaving a drive on a desk while at lunch.
Logical access control. The drives are hardware-encrypted with a credential held only by roster members, so possession alone does not grant access. Endpoint device control allows organization-issued media to mount only on managed devices belonging to enclave users; the same drive in a non-enclave employee's laptop is blocked at the operating system level. Files on the media carry the same sensitivity label as their source, so if they land somewhere they should not, the label restrictions still apply.
Paper. Access to printed CUI is limited by the locked containers and by the requirement that each copy is signed out to a named roster member.
Maintenance. Roster changes propagate to the device control group and the custody list within one business day, and offboarding recovers issued media the same day — an outstanding drive blocks the offboarding ticket from closing. Quarterly reconciliation of the sign-out log against the roster as it stood on each date.
Accepted gap. A customer occasionally ships us media that must be read by a specific engineer who is on the roster, using a drive we do not control. Those reads happen on a designated standalone workstation with the content copied into the labeled library and the customer media returned or destroyed; the drive itself is never enrolled in our controls.
What the evidence looks like
- Enclave roster and the device control group membership derived from it
- Media sign-out log with custodian entries
- Endpoint device control policy showing the allow-list scoped to enclave users
- Offboarding ticket showing media recovery as a closure requirement
- Procedure for handling customer-supplied media on the standalone workstation
Environment
~45 enclave users inside a 300-person company. Removable media is rare but not eliminated; the risk is a well-meaning employee outside the enclave picking up a drive that was left out.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.