MP-2: Media Access

MP-02 requires organizations to restrict access to digital and non-digital media to only authorized personnel.

Quick-reference card

FieldValue
Control IDMP-02
Control NameMedia Access
FrameworkNIST SP 800-53 Revision 5
Control FamilyMedia Protection
BaselinesLOW MODERATE HIGH
RelevanceOrganization (First Party and Third Party)
Risk SeverityMedium

What this control requires

MP-02 requires organizations to restrict access to digital and non-digital media to only authorized personnel. That means every flash drive, backup tape, printed report, and removable hard disk in your environment needs a defined access policy tied to specific roles.

Most teams treat media access as a subset of physical security and stop there. In practice, MP-02 demands more than locked cabinets. You need formal access lists that specify who can handle which media types, classification-based rules that match the sensitivity of the data stored on that media, and enforcement mechanisms that work for both digital formats like USB drives and compact discs and non-digital formats like paper records and microfilm. Access control isn’t just a network-layer concept; it extends to every medium that carries organizational data.

The distinction between digital and non-digital media is central to this control. Digital media includes portable storage devices, optical discs, and magnetic tapes. Non-digital media includes printed documents, microfiche, and hardcopy reports. Your access restrictions must address both categories explicitly, because the failure modes differ. A missing USB drive triggers a different investigation than a misfiled medical record, yet both represent an MP-02 gap.

Why it matters

Organizations that treat media access as a physical security afterthought expose themselves to compliance findings that cascade across multiple control families. Auditors assess MP-02 alongside MP-04 (Media Storage), PE-02 (Physical Access Authorizations), and PE-03 (Physical Access Control). A gap in one control often surfaces weaknesses in the others, turning a single media access deficiency into a systemic finding.

Regulatory consequences compound that audit risk. Federal agencies operating under FISMA must demonstrate MP-02 compliance across all three baselines. Contractors handling controlled unclassified information (CUI) face similar obligations under NIST SP 800-171. Failing an MP-02 assessment doesn’t just produce a plan of action and milestones (POA&M) item; it signals to assessors that your organization lacks foundational data handling discipline.

The downstream cost is operational, not hypothetical. Without enforced media access restrictions, you can’t prove chain of custody for sensitive data. That gap undermines your ability to satisfy incident response, backup, and contingency planning controls that depend on knowing who had access to what media and when.

Uncontrolled media access creates specific vectors that adversaries and insider threats exploit.

The following vectors represent the most common media access weaknesses that lead to audit findings or data exposure:

  • Unrestricted USB and removable device access allows unauthorized data exfiltration from endpoints that lack device control policies
  • Paper records without checkout logs make it impossible to trace who accessed sensitive non-digital media or when it left a secured area
  • Shared storage areas without role-based restrictions let personnel access backup tapes, archive discs, or printed materials outside their authorization level
  • Absent or outdated media access lists mean your documented controls don’t reflect actual practice, producing audit exceptions during assessments

How to implement

The most common failure mode in MP-02 implementation is maintaining accurate, current access lists. Organizations define media access policies during initial accreditation and then let those lists go stale as roles change, personnel rotate, and media inventories shift.

For your organization

Start by classifying every media type in your environment. Build a media inventory that distinguishes digital media (USB drives, external hard drives, optical discs, magnetic tapes) from non-digital media (printed documents, microfilm, hardcopy reports). Map each media type to the data classification level it carries.

Define role-based access restrictions for each media type and classification pairing. Your media protection policy should specify which roles can access, handle, transport, and dispose of each category. Avoid blanket “IT staff” designations. Instead, tie access to specific job functions such as backup operators, records managers, or system administrators.

Implement enforcement mechanisms that match the media format. For digital media, deploy endpoint device control software that restricts USB port access to authorized users and logs all removable media connections. For non-digital media, establish physical checkout procedures with sign-out logs in secured storage areas.

Build an evidence trail that auditors can verify. The following artifacts demonstrate MP-02 compliance:

  • A media protection policy that defines access restrictions by media type and data classification
  • Access control lists mapping authorized personnel to specific media categories
  • Device control logs showing USB and removable media access events
  • Physical media checkout records with timestamps and personnel identification

Review and update access lists quarterly, or whenever personnel changes occur. Stale access lists are the single most cited MP-02 deficiency in assessment reports. Automate access list updates where possible by integrating media access permissions with your identity management system.

Common mistakes to avoid include treating all digital media identically regardless of data classification, relying on physical locks alone without documenting who holds keys or combinations, and failing to revoke media access when personnel change roles or depart.

For your vendors

When assessing vendor compliance with MP-02, your goal is to verify that the vendor restricts media access with the same rigor you apply internally. Self-attestation alone isn’t sufficient for a control that directly affects data confidentiality.

Start your assessment with targeted questionnaire questions:

  • What types of digital and non-digital media store or process data related to our organization?
  • Who has authorized access to that media, and how are access lists maintained?
  • What endpoint controls restrict removable media usage on systems that handle our data?
  • How often are media access authorizations reviewed and updated?
  • What physical controls protect non-digital media containing our data?

Request specific evidence rather than accepting policy documents at face value. Ask for a copy of their media protection policy, a sample media access authorization list, device control configuration screenshots, and physical media storage access logs from the past 90 days.

Watch for these red flags during vendor assessments:

  • The vendor can produce a media protection policy but cannot show access lists tied to specific media types
  • Device control software is installed but not actively enforced or monitored
  • Non-digital media handling relies entirely on “trust” with no checkout procedures or access records
  • Media access reviews happen annually rather than on a role-change basis

Verification beyond self-attestation should include reviewing device control audit logs, inspecting physical media storage areas during on-site assessments when possible, and validating that the vendor’s access lists reflect current personnel rosters. Cross-reference the vendor’s media access controls with their responses to MP-04 (Media Storage) and MP-06 (Media Sanitization) to confirm a consistent media lifecycle approach.

Evidence examples

Evidence TypeExample Artifact
Media protection policyDocumented policy defining access restrictions for digital and non-digital media by data classification level
Media access authorization listsRole-based lists specifying which personnel or roles may access each media type
Physical access controls and logsSign-out sheets, key/combination registries, and badge logs for media storage facilities
Device control configurationsEndpoint management tool settings restricting USB, removable drive, and optical disc access
Access control recordsAudit logs from device control software showing media access events with timestamps and user IDs
Environmental protection documentationProcedures for securing media storage rooms, including temperature, humidity, and intrusion controls
System security plan excerptsSSP sections describing how MP-02 is implemented, including media types in scope and enforcement mechanisms

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.10 Acceptable use of information and other associated assetsPartial
ISO 27001:20227.10 Storage mediaPartial
ISO 27001:20227.7 Clear desk and clear screenPartial
NIST SP 800-171 Rev 303.08.02 Media AccessPartial

The following controls intersect with MP-02 and should be assessed together to ensure consistent media handling across your security program:

  • AC-19 — Access Control for Mobile Devices: governs access restrictions on mobile devices that function as removable digital media carriers
  • AU-09 — Protection of Audit Information: ensures that audit logs, including media access records, are protected from unauthorized access and tampering
  • CP-02 — Contingency Plan: defines how media containing backup data is accessed during continuity and disaster recovery operations
  • CP-09 — System Backup: specifies access requirements for backup media to ensure only authorized personnel can create, retrieve, or modify backups
  • CP-10 — System Recovery and Reconstitution: addresses who may access recovery media during system restoration following a disruption
  • MA-05 — Maintenance Personnel: restricts media access for external maintenance personnel who may encounter sensitive data on storage devices
  • MP-04 — Media Storage: complements MP-02 by defining where media is stored, while MP-02 defines who can access it
  • MP-06 — Media Sanitization: governs how media is sanitized before reuse or disposal, dependent on access controls being in place during the sanitization process
  • PE-02 — Physical Access Authorizations: provides the physical access authorization framework that supports media storage area restrictions
  • PE-03 — Physical Access Control: enforces physical entry controls to areas where media is stored or processed

Frequently asked questions

What is NIST SP 800-53 MP-02

MP-02 is the NIST SP 800-53 control that requires organizations to restrict access to digital and non-digital system media to authorized personnel only. It applies across all three security baselines (LOW, MODERATE, HIGH) and covers media types ranging from USB drives and backup tapes to printed documents and microfilm. Organizations must maintain documented access authorization lists that specify which roles may handle each media type based on data classification.

What happens if MP-02 is not implemented

Without MP-02 controls, your organization cannot demonstrate that access to system media is restricted to authorized individuals. Auditors will flag the absence of media access authorization lists and device control enforcement as a plan of action and milestones (POA&M) item. That finding often cascades into related control deficiencies across MP-04 (Media Storage), PE-02 (Physical Access Authorizations), and PE-03 (Physical Access Control), compounding the remediation burden.

How do you audit MP-02

Auditing MP-02 involves verifying that documented media access restrictions match actual practice across both digital and non-digital media types. Assessors review your media protection policy, compare media access authorization lists against current personnel rosters, and inspect device control logs for evidence of enforced USB and removable media restrictions. For non-digital media, auditors check physical storage area access records, including checkout logs and key registries, to confirm that only authorized personnel accessed sensitive printed materials or microfilm.

What types of media does MP-02 cover

MP-02 covers both digital and non-digital system media. Digital media includes flash drives, magnetic tapes, external and removable hard disk drives (solid state and magnetic), compact discs, and digital versatile discs. Non-digital media includes paper documents and microfilm. Your media protection policy must address access restrictions for every media type present in your environment, because each category presents distinct handling, storage, and access control requirements.

Experience superior visibility and a simpler approach to cyber risk management