MP-1: Policy and Procedures

MP-01 requires your organization to create, document, and distribute a formal media protection policy along with the procedures needed to

Quick-reference card

FieldValue
Control IDMP-01
Control NamePolicy and Procedures
FrameworkNIST SP 800-53 Revision 5
Control FamilyMedia Protection
BaselinesLOW MODERATE HIGH PRIVACY
RelevanceOrganization-level, First Party and Third Party
Risk SeverityLow

What This Control Requires

MP-01 requires your organization to create, document, and distribute a formal media protection policy along with the procedures needed to carry it out. Without this foundational governance document, every other control in the NIST SP 800-53 Media Protection family lacks an enforceable anchor.

In practice, this means the policy must spell out its purpose and scope, assign roles and responsibilities, document management commitment, define coordination mechanisms, and establish compliance expectations consistent with applicable laws and regulations. Your organization must also designate a specific official responsible for developing and maintaining both the policy and its procedures.

The control goes further than a one-time drafting exercise. You’re required to define review and update cadences triggered by specific events, such as audit findings, security incidents, or changes in regulatory requirements. An information security policy that sits unchanged on a shared drive doesn’t satisfy MP-01. The policy must be a living document with evidence of periodic reviews and event-driven updates.

Why It Matters

Most organizations treat media protection policy as a checkbox exercise, producing a boilerplate document that restates NIST control language and never gets revisited. That approach introduces real compliance risk. Auditors are trained to distinguish between a policy that reflects organizational context and one that merely paraphrases the standard.

Failure to maintain MP-01 introduces audit risk and may result in certification withdrawal or regulatory findings. When assessors find an outdated or absent media protection policy, it signals broader governance gaps across the entire MP control family. The result is increased scrutiny on every related technical control, lengthening your audit timeline and raising remediation costs.

In practice, this also means your vendor relationships are affected. Customers and partners performing due diligence will ask for your media protection policy. An incomplete or stale document raises concerns about your organization’s security maturity and can stall procurement decisions.

What auditors flag

  • Media protection policy that hasn’t been reviewed or updated within the organization-defined frequency
  • No designated official responsible for managing the policy and procedures
  • Policy language that restates NIST controls verbatim rather than reflecting organizational context, risk posture, and applicable legal requirements
  • Procedures that exist in isolation from the policy, with no traceability between the two documents
  • No evidence of event-driven updates following audits, incidents, or regulatory changes

How to Implement

For your organization

The most common failure mode with MP-01 is treating it as a documentation task disconnected from your actual media handling practices. Start by grounding the policy in your organization’s risk management strategy and the types of media your environment actually uses.

Step 1: Inventory your media landscape. Before writing anything, catalog the types of media in scope, including removable storage devices, mobile devices, printed materials, and backup tapes. Your policy needs to address what actually exists in your environment, not a generic list.

Step 2: Draft the policy with required elements. Your media protection policy must address purpose, scope, roles and responsibilities, management commitment, coordination among organizational entities, and compliance requirements. Reference your organizational risk management strategy and align with applicable laws and regulations. Do not restate NIST control language as your policy. Instead, translate each requirement into directives that reflect your operating environment.

Step 3: Develop implementing procedures. Procedures should map to specific policy directives and describe how staff carry them out. Document these in your system security plan (SSP) or as standalone procedure documents. Each procedure should identify who performs the action, what triggers it, and what evidence it produces.

Step 4: Designate an accountable official. Assign a named role, not just a department, as responsible for managing the policy lifecycle. This official owns the review schedule, coordinates updates, and ensures dissemination.

Step 5: Define review triggers and cadences. Establish both time-based review frequencies and event-driven triggers. Common triggers include audit findings, security incidents, organizational restructuring, and changes in regulatory requirements. Document these triggers in the policy itself.

Step 6: Disseminate and confirm receipt. Distribute the policy and procedures to all relevant personnel. Maintain evidence of dissemination, such as acknowledgment records or training completion logs.

Common mistakes to avoid

  • Writing policy in isolation from the risk management strategy
  • Failing to distinguish between policy (the “what” and “why”) and procedures (the “how”)
  • Using a template without tailoring it to your media environment
  • Assigning policy ownership to a committee rather than a specific individual

For your vendors

When evaluating a vendor’s MP-01 compliance, your goal is to verify that their media protection governance is substantive, not just that a document exists. Generic policy templates are common, and your security questionnaire process should be designed to surface them.

What to ask in questionnaires

  • “Provide your current media protection policy, including version date and designated policy owner.”
  • “Describe the events that trigger a review and update of your media protection policy.”
  • “Who is the designated official responsible for managing media protection policy and procedures?”
  • “How are media protection procedures disseminated to relevant personnel, and how is receipt confirmed?”

Evidence to request

  • The media protection policy document with version history
  • Documented procedures for media handling, sanitization, transport, and disposal
  • Records of the most recent policy review, including the reviewer and date
  • Acknowledgment logs showing personnel received the current policy

Red flags

  • Policy document with no version date or revision history
  • No named individual designated as the policy owner
  • Policy language that mirrors NIST control text without organizational context
  • No documented review or update within the past 12 to 24 months
  • Procedures that don’t reference or trace back to the governing policy

Verification should go beyond self-attestation. Request the actual policy document, not just a statement that one exists. Compare the version date against the vendor’s claimed review schedule. If the vendor has undergone a recent audit or experienced a security incident, ask whether those events triggered a policy update.

Evidence Examples

Evidence TypeExample Artifact
Media protection policyDocumented policy addressing purpose, scope, roles, management commitment, coordination, compliance, and consistency with applicable regulations
Implementing proceduresStep-by-step procedures for media sanitization, transport, storage, and disposal mapped to policy directives
Designated official recordOrganizational chart or memo designating the individual responsible for media protection policy management
Policy review and update logVersion-controlled records showing review dates, reviewers, changes made, and triggering events
Dissemination recordsAcknowledgment forms or training logs confirming personnel received current policy and procedures
Risk management alignmentDocumentation linking media protection policy to the organizational risk management strategy
System security plan excerptsSSP sections describing how media protection procedures are implemented and maintained

Cross-Framework Mapping

Organizations mapping MP-01 to other compliance frameworks will find overlap across several ISO 27001:2022 controls and NIST SP 800-171 requirements.

FrameworkControl(s)Coverage
ISO 27001:20225.1 Policies for information securityPartial
ISO 27001:20225.2 Information security roles and responsibilitiesPartial
ISO 27001:20225.3 Segregation of dutiesPartial
ISO 27001:20225.31 Legal, statutory, regulatory and contractual requirementsPartial
ISO 27001:20225.36 Compliance with policies, rules and standards for information securityPartial
ISO 27001:20225.37 Documented operating proceduresPartial
ISO 27001:20225.4 Management responsibilitiesPartial
NIST SP 800-171 Rev 303.15.01 Policy and ProceduresPartial
  • PM-09 — Risk Management Strategy: defines the organizational risk context that the media protection policy must align with and reference
  • PS-08 — Personnel Sanctions: establishes consequences for personnel who violate media protection policies and procedures
  • SI-12 — Information Management and Retention: governs how long media protection policy documents and related records must be retained

Frequently Asked Questions

What is NIST SP 800-53 MP-01

MP-01 requires organizations to develop, document, and disseminate a media protection policy and associated procedures, assign a designated official to manage them, and define review and update cadences tied to specific triggering events. It serves as the governance foundation for every other control in the Media Protection family.

Specifically, the policy must address purpose, scope, roles and responsibilities, management commitment, coordination among entities, and compliance with applicable laws. Without MP-01 in place, organizations lack the enforceable framework that gives operational controls like media sanitization and transport their authority.

What happens if MP-01 is not implemented

Without a documented media protection policy and designated official, your organization has no enforceable basis for the remaining MP family controls, which exposes you to audit findings across the entire Media Protection domain. Assessors treat a missing or stale MP-01 as evidence of systemic governance weakness.

The consequences extend beyond a single finding. Auditors will increase scrutiny of related technical controls, and regulatory bodies may view the gap as a failure to meet due diligence obligations. For organizations pursuing FedRAMP authorization or similar certifications, an inadequate MP-01 can delay or block the entire authorization process.

How do you audit MP-01

Start by requesting the media protection policy document and verifying it contains the required elements: purpose, scope, roles, management commitment, coordination, compliance alignment, and consistency with applicable laws. Confirm that a specific individual is designated as the policy owner, not just a department or team.

Review the version history and update log to verify the policy has been reviewed at the organization-defined frequency and following triggering events such as audit findings or security incidents. Then examine the implementing procedures to confirm they trace back to policy directives and describe actionable steps for media handling, sanitization, transport, and disposal.

What types of media does NIST MP-01 cover

MP-01 itself doesn’t enumerate specific media types but instead requires organizations to define the scope of media covered within their policy. In practice, this typically includes removable storage devices (USB drives, external hard drives), backup tapes, optical media, mobile devices, printed documents containing sensitive information, and any other media formats present in the operating environment.

Your policy should reflect the media types that actually exist in your environment rather than defaulting to a generic list. The risk management strategy referenced by PM-09 helps inform which media types warrant the most detailed procedural coverage.

Experience superior visibility and a simpler approach to cyber risk management