Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.08.03OFFICIAL TITLEPENDING NIST SME REVIEW

03.08.03Media Sanitization

03.08 Media Protection · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires sanitizing system media that contain CUI prior to disposal, release out of organizational control, or release for reuse.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Deleted is not gone. Before a drive, device, copier, or paper record leaves your control — sold, recycled, returned off lease, reassigned outside the CUI boundary — the CUI on it must be genuinely unrecoverable, by methods matched to the media type.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Adopt sanitization methods per media type from NIST SP 800-88 — cryptographic erase, purge, or destruction — and write down which applies to what.
  • Catch the forgotten media: multifunction-printer disks, leased-equipment returns, warranty-replaced drives, and OT equipment shipped for vendor repair.
  • If a destruction vendor is used, keep certificates per lot or serial number rather than a generic annual attestation.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Sanitization records or destruction certificates keyed to serial numbers
  • The written sanitization procedure by media type
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated