800-53|MP-5

Title

MEDIA TRANSPORT

Description

The organization:

Supplemental

Information system media includes both digital and non-digital media. Digital media includes, for example, diskettes, magnetic tapes, external/removable hard disk drives, flash drives, compact disks, and digital video disks. Non-digital media includes, for example, paper and microfilm. This control also applies to mobile devices with information storage capability (e.g., smart phones, tablets, E-readers), that are transported outside of controlled areas. Controlled areas are areas or spaces for which organizations provide sufficient physical and/or procedural safeguards to meet the requirements established for protecting information and/or information systems. Physical and technical safeguards for media are commensurate with the security category or classification of the information residing on the media. Safeguards to protect media during transport include, for example, locked containers and cryptography. Cryptographic mechanisms can provide confidentiality and integrity protections depending upon the mechanisms used. Activities associated with transport include the actual transport as well as those activities such as releasing media for transport and ensuring that media enters the appropriate transport processes. For the actual transport, authorized transport and courier personnel may include individuals from outside the organization (e.g., U.S. Postal Service or a commercial transport or delivery service). Maintaining accountability of media during transport includes, for example, restricting transport activities to authorized personnel, and tracking and/or obtaining explicit records of transport activities as the media moves through the transportation system to prevent and detect loss, destruction, or tampering. Organizations establish documentation requirements for activities associated with the transport of information system media in accordance with organizational assessments of risk to include the flexibility to define different record-keeping methods for the different types of media transport as part of an overall system of transport-related records.

Reference Item Details

Related: AC-19,CP-9,MP-3,MP-4,RA-3,SC-13,SC-28,SC-8

Category: MEDIA PROTECTION

Family: MEDIA PROTECTION

Priority: P1

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L2 + BL + NG
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L2 + BL
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1 + BL
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1 + BL + NG
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 Bitlocker
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L2 + BL
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1 + BL + NG
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L2 + BL + NG
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1 + BL
18.10.9.3.1 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 BitLocker
18.10.9.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1 + BL
18.10.9.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2 + BL
18.10.9.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 BL
18.10.9.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'WindowsCIS Microsoft Windows 10 EMS Gateway v2.0.0 L1
18.10.9.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L2 + BL
18.10.9.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1 + BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2 + BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2 + BL + NG
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL + NG
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L2 + BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'WindowsCIS Microsoft Windows 10 EMS Gateway v2.0.0 L1
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L2 + BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1 + BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L2 + BL
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L2 + BL + NG
18.10.9.3.14 Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL + NG
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1 + BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2 + BL + NG
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L2 + BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L2 + BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL + NG
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'WindowsCIS Microsoft Windows 10 EMS Gateway v2.0.0 L1
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False' - Enabled: FalseWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False' - Enabled: FalseWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL + NG
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False' - Enabled: FalseWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L2 + BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False' - Enabled: FalseWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L2 + BL + NG
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False' - Enabled: FalseWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L2 + BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False' - Enabled: FalseWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False' - Enabled: FalseWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL
18.10.9.3.15 Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False' - Enabled: FalseWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1 + BL