Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.8.1OFFICIAL STATEMENT BELOWBASIC REQUIREMENTPENDING NIST SME REVIEW

3.8.1Media protection and storage

3.8 Media Protection · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

CUI on anything printed or portable — paper files, external drives, backup tapes — lives in physically controlled, secure storage rather than desk drawers and laptop bags. For media, the safeguard is physical custody, not a login screen.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Find the media first: an honest sweep of where CUI actually rests on paper and portable storage usually surprises, and everything after depends on that answer.
  • The cheapest safeguard is less media — the fewer places CUI exists outside managed systems, the less there is to store, track, and eventually destroy.
  • Locked storage with a short list of people who can open it covers most small-business cases; the discipline is keeping the list and the habit current.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The written media-handling rule naming storage locations and responsible owners
  • A media register — or a documented, defended position that CUI does not leave managed systems
  • Dated periodic checks of the storage areas
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated