Media Protection

Media protection covers the security measures for managing removable and portable storage media — USB drives, external hard drives, CDs, tapes, and printed materials — that contain sensitive information. It includes controlling who can use removable media, encrypting data on portable devices, tracking media throughout its lifecycle, and securely destroying media when it's no longer needed.

For defense contractors, media protection is particularly important because removable media is a common vector for both data exfiltration (copying CUI to a USB drive) and malware introduction (plugging in infected media). Many organizations restrict or prohibit removable media in CUI environments.

Why It Matters

Media protection is a CMMC domain. Assessors will verify your policies and technical controls for removable media — including how you prevent unauthorized use, how you encrypt portable CUI, and how you destroy media when it's no longer needed.

Related Resources