Media Disposal [CUI Data]
Practice statement
Sanitize or destroy system media containing CUI before disposal or release for reuse.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.8.3.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(2)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
system media containing CUI is sanitized or destroyed before disposal; and
1 example covers this
- [b]
system media containing CUI is sanitized before it is released for reuse.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
MP.L2-3.8.3Media Disposal [CUI Data]
Sanitize or destroy system media containing CUI before disposal or release for reuse.
[a]
system media containing CUI is sanitized or destroyed before disposal; and[b]
system media containing CUI is sanitized before it is released for reuse.
Full-disk encryption plus cryptographic erase; destroy when CE cannot be verified
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses all media sanitization objectives for this practice.
Prerequisite. All in-scope endpoints use full-disk encryption with keys escrowed to the directory/MDM. Removable media that may hold CUI must use hardware-encrypted drives issued by IT; consumer USB is blocked by MDM.
Decision matrix (SOP).
- Reuse inside org, CE verified: Cryptographic erase — destroy/wipe recovery keys in escrow, confirm device cannot unlock, then redeploy.
- Leaving org control, or CE not verified (failed TPM, unknown prior ownership): Physical destruction via approved vendor; certificate of destruction required.
- Paper / optical: Cross-cut shred to policy particle size; bin logs retained.
SSD note. Do not rely on a single “quick format.” Prefer CE on encrypted volumes; if a drive was never encrypted under org keys, treat as destroy or vendor purge with verification.
Maintenance. Asset retirement tickets cannot close without sanitization method, operator, timestamp, and either key-destruction screenshot or CoD attachment. Quarterly sample: pick three retired assets and verify evidence completeness.
Accepted gap. One CNC controller disk cannot run org FDE. It is air-gapped; at end of life it is always physically destroyed (no CE path).
What the evidence looks like
- Media sanitization SOP with 800-88 Clear/Purge/Destroy mapping
- FDE policy + escrow configuration export
- Closed retirement tickets with key-destruction proof or CoD
- USB block MDM profile
- Quarterly evidence sampling checklist
Environment
~200 endpoints, removable media rare and discouraged; CUI primarily on encrypted volumes.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.