Quick-reference card
| Field | Value |
|---|---|
| Control ID | MP-03 |
| Control Name | Media Marking |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Media Protection |
| Baselines | MODERATE HIGH |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Low |
What this control requires
MP-03 requires your organization to apply visible markings to all system media that indicate distribution limitations, handling caveats, and applicable security classifications. Every piece of media containing sensitive information, whether it’s a USB drive, a printed report, or an external hard disk, must carry markings that tell anyone who encounters it exactly how that media should be handled and who is authorized to access it.
The control also lets you define exemptions. If certain types of media never leave a designated controlled area, you can formally exempt them from marking requirements. In practice, this means your organization needs a documented policy that specifies which media types get marked, what the markings look like, and which exemptions apply within which boundaries. Without that policy, auditors have no way to verify your marking program meets the requirements under the Media Protection family.
The distinction between digital and non-digital media matters here. Digital media includes removable hard drives, flash drives, optical discs, and magnetic tapes. Non-digital media includes paper documents and microfilm. Your marking approach needs to account for both categories, and the markings themselves must be human-readable, not just embedded metadata or digital watermarks that a person can’t see when handling the physical media.
Why it matters
Most organizations treat media marking as an afterthought, a checkbox buried in a broader media protection program. That gap creates real compliance exposure during federal audits and third-party assessments. When assessors pull a sample of removable media from your environment and find no consistent markings, you’re looking at a finding that cascades into questions about your entire media handling program.
The risk isn’t a headline-grabbing data breach. It’s the slow erosion of accountability that happens when media circulates without clear handling instructions. A flash drive containing controlled unclassified information (CUI) that lacks proper CUI markings under 32 CFR 2002 can be misrouted, stored improperly, or disposed of without appropriate sanitization, and no one along the chain knew the sensitivity level.
For organizations pursuing or maintaining NIST SP 800-53 compliance at Moderate or High baselines, a failed MP-03 assessment objective signals a broader gap in your media protection posture. Assessors will question whether your organization can reliably track what media contains, where it goes, and who should handle it.
What attackers exploit:
- Unmarked removable media left in common areas or shared workspaces, where social engineering campaigns plant malicious devices disguised as legitimate assets
- Absence of sensitivity markings on printed documents, enabling unauthorized personnel to access, copy, or remove sensitive material without detection
- Inconsistent marking practices across departments, creating gaps where media transitions between teams without proper handling awareness
- Lack of CUI markings on digital media, allowing controlled information to be treated as public or low-sensitivity data during transport and disposal
How to implement
Effective media protection programs fail most often at the marking seams: between digital and non-digital media, between departments with different classification habits, and between policy documents and daily practice. Getting this right means building a marking scheme that people actually follow, not just one that looks complete on paper.
For your organization
Step 1 — Define your marking taxonomy. Establish a documented set of marking categories that align with your information classification scheme. At minimum, cover distribution limitations (who can receive the media), handling caveats (storage, transport, and destruction requirements), and security classifications or CUI categories. Map each category to a specific visual marking format, whether that’s printed labels, color-coded stickers, header and footer stamps on paper documents, or engraved identifiers on hardware.
Step 2 — Inventory media types and assign marking requirements. Catalog every type of system media in your environment, both digital (USB drives, external hard drives, flash storage, optical discs, backup tapes) and non-digital (printed reports, microfilm, paper records). For each type, document the marking method and placement. A flash drive might get a printed label on the casing, while a paper document gets a classification header and footer on every page.
Step 3 — Establish controlled-area exemptions. Identify the specific media types you’re exempting from marking and the controlled areas where those exemptions apply. Document this formally in your media protection policy. An exemption only holds if the media genuinely never leaves the boundary. If a server room stores unmarked backup tapes, your policy must enforce physical controls that prevent those tapes from being removed without first being marked.
Step 4 — Produce and maintain evidence. Your marking security attributes list should be a living document that maps each sensitivity level to its visual marking. Pair this with your media protection policy, your procedures for applying and verifying markings, and your list of designated controlled areas. Conduct periodic spot checks to verify that markings in the field match the policy.
Common mistakes: Organizations frequently define markings in policy but never train personnel on application. Another failure point is allowing ad hoc markings, such as handwritten notes, that don’t match the documented taxonomy. Both create audit findings.
For your vendors
Questionnaire questions to ask:
- Does your organization maintain a documented media marking policy that covers both digital and non-digital system media?
- What marking categories do you use, and how do they map to your information classification scheme?
- Which media types, if any, are exempted from marking, and what controlled-area boundaries apply to those exemptions?
- How do you verify that markings are applied consistently across departments and media types?
Evidence to request: Ask for the vendor’s media protection policy, their media marking security attributes list, and their designated controlled areas documentation. A mature vendor will also provide their media marking procedures, which detail how markings are applied, verified, and updated when classification levels change.
Red flags to watch for: A vendor that can produce a media protection policy but not a specific marking attributes list is likely treating marking as a paper exercise. Similarly, if controlled-area exemptions cover broad categories like “all media in the office” rather than specific media types within specific physical boundaries, the exemption lacks the specificity MP-03 requires.
Verification approach: During on-site assessments or virtual walkthroughs, ask to see sample media items and confirm markings match the documented taxonomy. For remote assessments, request photographs of marked media alongside the policy that governs those markings. Cross-reference the vendor’s exemption list against their physical security controls to confirm that exempted media genuinely stays within controlled areas.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Policy documentation | Media protection policy defining marking requirements, exemption criteria, and controlled-area boundaries |
| Marking taxonomy | Media marking security attributes list mapping each sensitivity level to its visual marking format and placement |
| Procedures | Media marking procedures describing how personnel apply, verify, and update markings on digital and non-digital media |
| Controlled-area designations | Designated controlled areas document listing physical locations where exempted media types may remain unmarked |
| Environmental controls | Physical and environmental protection policy and procedures governing access to controlled areas containing exempted media |
| Media inventory | Inventory of system media types with assigned marking categories and exemption status |
| System security plan | System security plan sections addressing MP-03 implementation, including organization-defined parameters for exempted media types and controlled areas |
Cross-framework mapping
Organizations managing compliance across multiple frameworks can map MP-03 to equivalent controls. For organizations also subject to NIST SP 800-171 requirements, the mapping below shows where media marking obligations overlap.
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.13 Labelling of information | Partial |
| NIST SP 800-171 Rev 3 | 03.08.04 Media Marking | Partial |
Both mappings are partial because MP-03 includes organization-defined parameters for exempted media types and controlled areas that aren’t explicitly addressed in the mapped frameworks.
Related controls
- AC-16 — Security and Privacy Attributes: provides the attribute framework that media markings reference, ensuring consistency between system-level security labels and physical media markings
- CP-09 — System Backup: backup media inherits the sensitivity of the data it contains, making media marking critical for ensuring backup tapes and drives carry appropriate handling instructions
- MP-05 — Media Transport: markings applied under MP-03 directly inform the handling and protection requirements enforced during media transport
- PE-22 — Component Marking: extends the marking concept to system components, complementing media-level markings with hardware-level identification
- SI-12 — Information Management and Retention: retention schedules depend on accurate sensitivity markings to determine when media can be sanitized or destroyed
Frequently asked questions
What is NIST SP 800-53 MP-03
MP-03 is the NIST SP 800-53 control that requires organizations to mark system media with distribution limitations, handling caveats, and applicable security markings so that anyone who encounters the media knows its sensitivity level and handling requirements. The control covers both digital media like USB drives, external hard drives, and optical discs, and non-digital media like paper documents and microfilm. It also allows organizations to define formal exemptions for specific media types that remain within designated controlled areas.
What happens if MP-03 is not implemented
Without MP-03, media circulates through your organization without visible indicators of its sensitivity, distribution restrictions, or handling requirements. This creates direct compliance findings during NIST SP 800-53 assessments at Moderate and High baselines, because assessors cannot verify that your organization tracks and enforces media handling obligations. The practical consequence is that sensitive information, including CUI governed by 32 CFR 2002, can be mishandled, misrouted, or improperly disposed of because personnel along the handling chain had no way to identify the media’s classification.
How do you audit MP-03
Auditing MP-03 starts with reviewing the organization’s media marking security attributes list and verifying it aligns with the documented media protection policy. Assessors then sample physical and digital media from the environment to confirm that markings match the defined taxonomy and that media in controlled areas that lack markings appears on the formal exemption list. The audit also verifies that the designated controlled areas have physical or logical access controls sufficient to keep exempted media within their defined boundaries.
What types of media require security marking under NIST 800-53
Any system media that stores or carries sensitive information requires marking under MP-03, spanning both digital formats (removable hard drives, flash drives, compact discs, digital versatile discs, magnetic tapes) and non-digital formats (paper documents, microfilm). The key exception is media determined to contain publicly releasable information, and media that your organization has formally exempted because it remains within a designated controlled area. Your media marking security attributes list should explicitly identify which media types require marking and which qualify for exemption based on their physical location and handling context.