Quick-reference card
| Field | Value |
|---|---|
| Control ID | MP-01 |
| Control Name | Policy and Procedures |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Media Protection |
| Baselines | LOW MODERATE HIGH PRIVACY |
| Relevance | Organization-level, First Party and Third Party |
| Risk Severity | Low |
What This Control Requires
MP-01 requires your organization to create, document, and distribute a formal media protection policy along with the procedures needed to carry it out. Without this foundational governance document, every other control in the NIST SP 800-53 Media Protection family lacks an enforceable anchor.
In practice, this means the policy must spell out its purpose and scope, assign roles and responsibilities, document management commitment, define coordination mechanisms, and establish compliance expectations consistent with applicable laws and regulations. Your organization must also designate a specific official responsible for developing and maintaining both the policy and its procedures.
The control goes further than a one-time drafting exercise. You’re required to define review and update cadences triggered by specific events, such as audit findings, security incidents, or changes in regulatory requirements. An information security policy that sits unchanged on a shared drive doesn’t satisfy MP-01. The policy must be a living document with evidence of periodic reviews and event-driven updates.
Why It Matters
Most organizations treat media protection policy as a checkbox exercise, producing a boilerplate document that restates NIST control language and never gets revisited. That approach introduces real compliance risk. Auditors are trained to distinguish between a policy that reflects organizational context and one that merely paraphrases the standard.
Failure to maintain MP-01 introduces audit risk and may result in certification withdrawal or regulatory findings. When assessors find an outdated or absent media protection policy, it signals broader governance gaps across the entire MP control family. The result is increased scrutiny on every related technical control, lengthening your audit timeline and raising remediation costs.
In practice, this also means your vendor relationships are affected. Customers and partners performing due diligence will ask for your media protection policy. An incomplete or stale document raises concerns about your organization’s security maturity and can stall procurement decisions.
What auditors flag
- Media protection policy that hasn’t been reviewed or updated within the organization-defined frequency
- No designated official responsible for managing the policy and procedures
- Policy language that restates NIST controls verbatim rather than reflecting organizational context, risk posture, and applicable legal requirements
- Procedures that exist in isolation from the policy, with no traceability between the two documents
- No evidence of event-driven updates following audits, incidents, or regulatory changes
How to Implement
For your organization
The most common failure mode with MP-01 is treating it as a documentation task disconnected from your actual media handling practices. Start by grounding the policy in your organization’s risk management strategy and the types of media your environment actually uses.
Step 1: Inventory your media landscape. Before writing anything, catalog the types of media in scope, including removable storage devices, mobile devices, printed materials, and backup tapes. Your policy needs to address what actually exists in your environment, not a generic list.
Step 2: Draft the policy with required elements. Your media protection policy must address purpose, scope, roles and responsibilities, management commitment, coordination among organizational entities, and compliance requirements. Reference your organizational risk management strategy and align with applicable laws and regulations. Do not restate NIST control language as your policy. Instead, translate each requirement into directives that reflect your operating environment.
Step 3: Develop implementing procedures. Procedures should map to specific policy directives and describe how staff carry them out. Document these in your system security plan (SSP) or as standalone procedure documents. Each procedure should identify who performs the action, what triggers it, and what evidence it produces.
Step 4: Designate an accountable official. Assign a named role, not just a department, as responsible for managing the policy lifecycle. This official owns the review schedule, coordinates updates, and ensures dissemination.
Step 5: Define review triggers and cadences. Establish both time-based review frequencies and event-driven triggers. Common triggers include audit findings, security incidents, organizational restructuring, and changes in regulatory requirements. Document these triggers in the policy itself.
Step 6: Disseminate and confirm receipt. Distribute the policy and procedures to all relevant personnel. Maintain evidence of dissemination, such as acknowledgment records or training completion logs.
Common mistakes to avoid
- Writing policy in isolation from the risk management strategy
- Failing to distinguish between policy (the “what” and “why”) and procedures (the “how”)
- Using a template without tailoring it to your media environment
- Assigning policy ownership to a committee rather than a specific individual
For your vendors
When evaluating a vendor’s MP-01 compliance, your goal is to verify that their media protection governance is substantive, not just that a document exists. Generic policy templates are common, and your security questionnaire process should be designed to surface them.
What to ask in questionnaires
- “Provide your current media protection policy, including version date and designated policy owner.”
- “Describe the events that trigger a review and update of your media protection policy.”
- “Who is the designated official responsible for managing media protection policy and procedures?”
- “How are media protection procedures disseminated to relevant personnel, and how is receipt confirmed?”
Evidence to request
- The media protection policy document with version history
- Documented procedures for media handling, sanitization, transport, and disposal
- Records of the most recent policy review, including the reviewer and date
- Acknowledgment logs showing personnel received the current policy
Red flags
- Policy document with no version date or revision history
- No named individual designated as the policy owner
- Policy language that mirrors NIST control text without organizational context
- No documented review or update within the past 12 to 24 months
- Procedures that don’t reference or trace back to the governing policy
Verification should go beyond self-attestation. Request the actual policy document, not just a statement that one exists. Compare the version date against the vendor’s claimed review schedule. If the vendor has undergone a recent audit or experienced a security incident, ask whether those events triggered a policy update.
Evidence Examples
| Evidence Type | Example Artifact |
|---|---|
| Media protection policy | Documented policy addressing purpose, scope, roles, management commitment, coordination, compliance, and consistency with applicable regulations |
| Implementing procedures | Step-by-step procedures for media sanitization, transport, storage, and disposal mapped to policy directives |
| Designated official record | Organizational chart or memo designating the individual responsible for media protection policy management |
| Policy review and update log | Version-controlled records showing review dates, reviewers, changes made, and triggering events |
| Dissemination records | Acknowledgment forms or training logs confirming personnel received current policy and procedures |
| Risk management alignment | Documentation linking media protection policy to the organizational risk management strategy |
| System security plan excerpts | SSP sections describing how media protection procedures are implemented and maintained |
Cross-Framework Mapping
Organizations mapping MP-01 to other compliance frameworks will find overlap across several ISO 27001:2022 controls and NIST SP 800-171 requirements.
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.1 Policies for information security | Partial |
| ISO 27001:2022 | 5.2 Information security roles and responsibilities | Partial |
| ISO 27001:2022 | 5.3 Segregation of duties | Partial |
| ISO 27001:2022 | 5.31 Legal, statutory, regulatory and contractual requirements | Partial |
| ISO 27001:2022 | 5.36 Compliance with policies, rules and standards for information security | Partial |
| ISO 27001:2022 | 5.37 Documented operating procedures | Partial |
| ISO 27001:2022 | 5.4 Management responsibilities | Partial |
| NIST SP 800-171 Rev 3 | 03.15.01 Policy and Procedures | Partial |
Related Controls
- PM-09 — Risk Management Strategy: defines the organizational risk context that the media protection policy must align with and reference
- PS-08 — Personnel Sanctions: establishes consequences for personnel who violate media protection policies and procedures
- SI-12 — Information Management and Retention: governs how long media protection policy documents and related records must be retained
Frequently Asked Questions
What is NIST SP 800-53 MP-01
MP-01 requires organizations to develop, document, and disseminate a media protection policy and associated procedures, assign a designated official to manage them, and define review and update cadences tied to specific triggering events. It serves as the governance foundation for every other control in the Media Protection family.
Specifically, the policy must address purpose, scope, roles and responsibilities, management commitment, coordination among entities, and compliance with applicable laws. Without MP-01 in place, organizations lack the enforceable framework that gives operational controls like media sanitization and transport their authority.
What happens if MP-01 is not implemented
Without a documented media protection policy and designated official, your organization has no enforceable basis for the remaining MP family controls, which exposes you to audit findings across the entire Media Protection domain. Assessors treat a missing or stale MP-01 as evidence of systemic governance weakness.
The consequences extend beyond a single finding. Auditors will increase scrutiny of related technical controls, and regulatory bodies may view the gap as a failure to meet due diligence obligations. For organizations pursuing FedRAMP authorization or similar certifications, an inadequate MP-01 can delay or block the entire authorization process.
How do you audit MP-01
Start by requesting the media protection policy document and verifying it contains the required elements: purpose, scope, roles, management commitment, coordination, compliance alignment, and consistency with applicable laws. Confirm that a specific individual is designated as the policy owner, not just a department or team.
Review the version history and update log to verify the policy has been reviewed at the organization-defined frequency and following triggering events such as audit findings or security incidents. Then examine the implementing procedures to confirm they trace back to policy directives and describe actionable steps for media handling, sanitization, transport, and disposal.
What types of media does NIST MP-01 cover
MP-01 itself doesn’t enumerate specific media types but instead requires organizations to define the scope of media covered within their policy. In practice, this typically includes removable storage devices (USB drives, external hard drives), backup tapes, optical media, mobile devices, printed documents containing sensitive information, and any other media formats present in the operating environment.
Your policy should reflect the media types that actually exist in your environment rather than defaulting to a generic list. The risk management strategy referenced by PM-09 helps inform which media types warrant the most detailed procedural coverage.