NIST 800-53 REV 5 • MEDIA PROTECTION
MP-6(6) — Media Destruction
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Practitioner Notes
This enhancement specifically addresses physical destruction of media — shredding, disintegrating, pulverizing, or incinerating media to make data recovery physically impossible.
Example 1: Purchase a hard drive shredder or contract with a certified destruction vendor (Iron Mountain, Shred-it) that provides on-site destruction services with certificates of destruction. Require the vendor to destroy drives at your location while your staff witnesses the process.
Example 2: For paper documents and optical media, use a cross-cut shredder rated to P-4 or higher (DIN 66399 standard). For drives, if a shredder is not available, use a drill press to put multiple holes through the platters. Document every destruction event with serial numbers, date, method, and witness.