800-53|MP-2

Title

MEDIA ACCESS

Description

The organization restricts access to [Assignment: organization-defined types of digital and/or non-digital media] to [Assignment: organization-defined personnel or roles].

Supplemental

Information system media includes both digital and non-digital media. Digital media includes, for example, diskettes, magnetic tapes, external/removable hard disk drives, flash drives, compact disks, and digital video disks. Non-digital media includes, for example, paper and microfilm. Restricting non-digital media access includes, for example, denying access to patient medical records in a community hospital unless the individuals seeking access to such records are authorized healthcare providers. Restricting access to digital media includes, for example, limiting access to design specifications stored on compact disks in the media library to the project leader and the individuals on the development team.

Reference Item Details

Related: AC-3,IA-2,MP-4,PE-2,PE-3,PL-2

Category: MEDIA PROTECTION

Family: MEDIA PROTECTION

Priority: P1

Baseline Impact: LOW,MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictiveUnixCIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master
1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictiveUnixCIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master
1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictiveUnixCIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master
1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictiveUnixCIS Kubernetes Benchmark v1.9.0 L1 Master
1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictiveOpenShiftCIS RedHat OpenShift Container Platform v1.6.0 L1
1.1.1.2.1.23 Configure 'Devices: Restrict CD-ROM access to locally logged-on user only'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.1.23 Configure 'Devices: Restrict CD-ROM access to locally logged-on user only'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.1.35 Set 'Devices: Allowed to format and eject removable media' to 'Administrators'WindowsCIS Windows 2003 MS v3.1.0
1.1.1.2.1.35 Set 'Devices: Allowed to format and eject removable media' to 'Administrators'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.1.67 Configure 'Devices: Restrict floppy access to locally logged-on user only'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.2.1.67 Configure 'Devices: Restrict floppy access to locally logged-on user only'WindowsCIS Windows 2003 MS v3.1.0
1.1.10 Ensure nodev option set on /dev/shm partitionUnixCIS Google Container-Optimized OS L1 Server v1.1.0
1.1.10 Ensure noexec option set on /var/tmp partitionUnixCIS SUSE Linux Enterprise Server 11 L1 v2.1.1
1.1.10 Ensure noexec option set on /var/tmp partitionUnixCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1
1.1.10 Ensure separate partition exists for /varUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 Server
1.1.10 Ensure separate partition exists for /varUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 Workstation
1.1.11 Ensure nosuid option set on /dev/shm partitionUnixCIS Google Container-Optimized OS L1 Server v1.1.0
1.1.11 Ensure separate partition exists for /var/tmpUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 Workstation
1.1.11 Ensure separate partition exists for /var/tmpUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 Server
1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictiveUnixCIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master
1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictiveUnixCIS Kubernetes Benchmark v1.9.0 L1 Master
1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictiveOpenShiftCIS RedHat OpenShift Container Platform v1.6.0 L1
1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictiveUnixCIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master
1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictiveUnixCIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master
1.1.12 Ensure /var/tmp partition includes the noexec optionUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Server
1.1.12 Ensure /var/tmp partition includes the noexec optionUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Workstation
1.1.12 Ensure that the etcd data directory ownership is set to etcd:etcdUnixCIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master
1.1.12 Ensure that the etcd data directory ownership is set to etcd:etcdUnixCIS Kubernetes Benchmark v1.9.0 L1 Master
1.1.12 Ensure that the etcd data directory ownership is set to etcd:etcdUnixCIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master
1.1.12 Ensure that the etcd data directory ownership is set to etcd:etcdUnixCIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master
1.1.13 Ensure /var/tmp partition includes the nodev optionUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Server
1.1.13 Ensure /var/tmp partition includes the nodev optionUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Workstation
1.1.13 Ensure that the admin.conf file permissions are set to 600UnixCIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master
1.1.13 Ensure that the admin.conf file permissions are set to 600UnixCIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master
1.1.13 Ensure that the admin.conf file permissions are set to 600 or more restrictiveUnixCIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master
1.1.13 Ensure that the default administrative credential file permissions are set to 600UnixCIS Kubernetes Benchmark v1.9.0 L1 Master
1.1.13 Ensure that the kubeconfig file permissions are set to 600 or more restrictiveOpenShiftCIS RedHat OpenShift Container Platform v1.6.0 L1
1.1.14 Ensure /var/tmp partition includes the nosuid optionUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Server
1.1.14 Ensure /var/tmp partition includes the nosuid optionUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Workstation
1.1.14 Ensure nodev option set on /home partitionUnixCIS SUSE Linux Enterprise Server 11 L1 v2.1.1
1.1.14 Ensure nodev option set on /home partitionUnixCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1
1.1.15 Ensure nodev option set on /dev/shm partitionUnixCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1
1.1.15 Ensure nodev option set on /dev/shm partitionUnixCIS SUSE Linux Enterprise Server 11 L1 v2.1.1
1.1.15 Ensure that the Scheduler kubeconfig file permissions are set to 600 or more restrictiveOpenShiftCIS RedHat OpenShift Container Platform v1.6.0 L1
1.1.15 Ensure that the scheduler.conf file permissions are set to 600 or more restrictiveUnixCIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master
1.1.15 Ensure that the scheduler.conf file permissions are set to 600 or more restrictiveUnixCIS Kubernetes Benchmark v1.9.0 L1 Master
1.1.15 Ensure that the scheduler.conf file permissions are set to 600 or more restrictiveUnixCIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master
1.1.15 Ensure that the scheduler.conf file permissions are set to 600 or more restrictiveUnixCIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master
1.1.16 Ensure nosuid option set on /dev/shm partitionUnixCIS SUSE Linux Enterprise Server 11 L1 v2.1.1
1.1.16 Ensure nosuid option set on /dev/shm partitionUnixCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1