Quick-reference card
| Field | Value |
|---|---|
| Control ID | MP-04 |
| Control name | Media Storage |
| Framework | NIST SP 800-53 Revision 5 |
| Control family | Media Protection |
| Baselines | MODERATE HIGH |
| Implementation level | Organization — First Party and Third Party |
| Risk severity | Medium |
What this control requires
MP-04 requires your organization to physically control and securely store all designated digital and non-digital media inside defined controlled areas. That means flash drives, removable hard drives, backup tapes, printed reports, and microfilm all need a documented storage location with physical access restrictions proportionate to the sensitivity of the information they contain.
Beyond locking media away, MP-04 also mandates that you protect stored media until it is destroyed or sanitized through approved equipment, techniques, and procedures. In practice, you need an inventory that tracks every piece of media from creation through disposition, procedures that govern check-out and return, and storage environments that match the security category of the data. A locked cabinet may suffice for media holding publicly releasable information, while media containing controlled unclassified information or higher demands a controlled media library with access logs.
This requirement sits within the broader Media Protection family of NIST SP 800-53, which collectively addresses how organizations handle system media across its lifecycle. The storage control specifically closes the gap between access restrictions (who can touch media) and disposal procedures (how media is destroyed), ensuring that media at rest is never left in an uncontrolled state.
Why it matters
Uncontrolled media storage is one of the most overlooked audit findings in federal and regulated environments, yet it is also one of the easiest to prevent. Organizations that lack a formal media inventory and designated storage areas routinely fail assessments because auditors cannot verify chain of custody for sensitive data at rest.
Failure to maintain this control introduces audit risk and may result in certification withdrawal, regulatory findings, or loss of authorization to operate. For organizations pursuing or maintaining a NIST SP 800-53 Moderate or High baseline, an MP-04 gap can stall the entire authorization process until remediation evidence is produced.
The risk extends beyond compliance paperwork. When media leaves a controlled area without documentation, you lose visibility into where sensitive data physically resides. That blind spot compounds over time as personnel change, offices relocate, and legacy devices accumulate in desks, closets, and off-site storage that no one audits.
Even when an organization encrypts data at rest, the absence of physical storage controls means you cannot demonstrate that encryption keys and the media they protect are managed separately. Auditors treat this gap as a compensating control failure, not a mitigating factor.
What attackers exploit
- Untracked removable media left in unlocked desks or open workspaces, enabling opportunistic theft by insiders or visitors
- Legacy backup tapes and hard drives stored in unmarked boxes during office moves, creating unmonitored repositories of sensitive data
- Absence of check-out and return procedures, which allows media to circulate without accountability and delays detection of missing items
- Shared storage areas without access logs, making it impossible to attribute unauthorized access or identify when media was removed
- Non-digital media such as printed reports and microfilm excluded from inventory controls, leaving paper-based sensitive data unprotected
How to implement
Most MP-04 failures stem from the same root cause: organizations define media types in policy but never operationalize the physical controls that policy requires. The gap between documented intent and daily practice is where audit findings concentrate.
For your organization
Step 1 — Define and categorize your media types. List every form of digital media (flash drives, external hard drives, solid-state drives, magnetic tapes, optical discs) and non-digital media (paper records, microfilm) that your systems produce or consume. Map each type to the security category of the information it stores.
Step 2 — Designate controlled storage areas. Assign specific rooms, cabinets, safes, or media libraries for each sensitivity tier. A locked drawer may be sufficient for media holding public information, while media at Moderate or High impact levels requires a controlled library with restricted entry. Document these designations in your system security plan.
Step 3 — Implement check-out and return procedures. Create a log that records who removes media, when, why, and when it is returned. This log is one of the primary artifacts auditors request. Digital tracking systems (barcode or RFID-based asset management) reduce human error compared to paper sign-out sheets.
Step 4 — Conduct periodic inventories. Schedule media inventories at a cadence defined in your media protection policy (quarterly is common for High baseline environments). Reconcile physical counts against your tracking records and investigate discrepancies immediately.
Step 5 — Enforce protection until disposition. Media must remain in its designated storage environment until it is sanitized or destroyed through procedures that meet your organization’s approved methods. Document the destruction or sanitization event for each item, including the method, date, and responsible individual.
Common tooling categories: physical asset management platforms, RFID or barcode inventory systems, secure storage enclosures, media sanitization and destruction equipment.
Common mistakes: defining media types in policy but not maintaining a living inventory, storing backup tapes in server rooms without separate access controls, failing to include non-digital media in the program, and omitting destruction or sanitization records from evidence packages.
You can find a broader implementation walkthrough in this NIST 800-53 compliance checklist.
For your vendors
When your vendors handle media containing your data, you inherit the risk of their storage practices. Assessing MP-04 compliance in your supply chain requires specific evidence, not just attestations. Reviewing third-party risk requirements under NIST 800-53 provides additional context for structuring these assessments.
Questionnaire questions to include:
- Do you maintain a documented inventory of all digital and non-digital media that stores, processes, or transports our data?
- Where are controlled storage areas located, and what physical access controls protect them?
- What check-out and return procedures govern media removal from controlled areas?
- How frequently do you conduct media inventories, and how are discrepancies handled?
- What approved sanitization or destruction methods do you use before media disposition?
Evidence to request: Media protection policy, media inventory logs, physical access records for storage areas, sanitization and destruction certificates, and most recent internal audit findings related to media storage.
Red flags: No documented media inventory, storage areas accessible to personnel without a need-to-know, inability to produce check-out logs, and sanitization procedures that rely solely on software deletion without verification.
Verification approach: Request a recent media inventory report and cross-reference it with the vendor’s system security plan. Ask for photos or descriptions of controlled storage areas. Confirm that sanitization records include the specific method, date, and individual responsible. If the vendor cannot produce these artifacts, treat it as a material gap requiring remediation tracking.
Evidence examples
| Evidence type | Example artifact |
|---|---|
| Policy documentation | Media protection policy defining approved media types, storage requirements, handling procedures, and sanitization methods |
| Media inventory | Current inventory log listing each digital and non-digital media item, its security category, storage location, and custodian |
| Physical access records | Access control logs for designated media storage areas showing entry and exit events |
| Check-out and return logs | Sign-out records documenting media removal, purpose, responsible individual, and return date |
| Storage area documentation | System security plan sections describing controlled areas, cabinet and safe locations, and access restrictions |
| Sanitization and destruction records | Certificates of media sanitization or destruction specifying the method, equipment, date, and responsible individual |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.10 Acceptable use of information and other associated assets | Partial |
| ISO 27001:2022 | 7.10 Storage media | Partial |
| ISO 27001:2022 | 7.7 Clear desk and clear screen | Partial |
| ISO 27001:2022 | 8.10 Information deletion | Partial |
| NIST SP 800-171 Rev 3 | 03.08.01 Media Storage | Partial |
Related controls
- AC-19 — Access Control for Mobile Devices: governs access restrictions on mobile devices that function as removable media, complementing the physical storage requirements of MP-04
- CP-02 — Contingency Plan: defines how backup media is stored and retrieved during disruptions, directly depending on the controlled storage areas MP-04 establishes
- CP-06 — Alternate Storage Site: extends MP-04 storage requirements to off-site locations used for backup and recovery media
- CP-09 — System Backup: produces the backup media that MP-04 requires you to physically control and securely store
- CP-10 — System Recovery and Reconstitution: relies on accessible, integrity-verified backup media that MP-04 storage controls protect
- MP-02 — Media Access: restricts who can access media, while MP-04 governs where that media is physically kept
- MP-07 — Media Use: defines acceptable media usage policies that feed into the inventory and tracking requirements of MP-04
- PE-03 — Physical Access Control: provides the facility-level physical controls that protect the designated media storage areas
- PL-02 — System Security and Privacy Plans: documents the media types, controlled areas, and storage procedures that MP-04 requires
- SC-12 — Cryptographic Key Establishment and Management: governs key management for encrypted media, which must be stored separately from the media it protects
Frequently asked questions
What is NIST SP 800-53 MP-04
MP-04 is the NIST SP 800-53 control that requires organizations to physically control and securely store all designated digital and non-digital media within defined controlled areas. It applies to both digital media (flash drives, backup tapes, removable hard drives, optical discs) and non-digital media (paper records, microfilm). The control also mandates that stored media remains protected until it is destroyed or sanitized using approved equipment and procedures. MP-04 is required for both Moderate and High baselines and includes maintaining inventory logs and check-out and return procedures for accountability.
What happens if MP-04 is not implemented
Without MP-04, your organization cannot demonstrate chain of custody for media containing sensitive data, which typically results in audit findings that stall or block system authorization. Assessors specifically check whether designated controlled areas exist, whether media inventories are current, and whether check-out and return procedures are followed. A gap here affects not just this control but related controls in the Media Protection and Contingency Planning families, compounding the remediation effort required to achieve authorization.
How do you audit MP-04
Auditors verify MP-04 by examining your media protection policy, inspecting the physical controlled areas where media is stored, and reviewing media inventory logs and check-out records. They confirm that every type of digital and non-digital media defined in your policy is accounted for in the inventory and stored in a location with physical access controls proportionate to its security category. Auditors also verify that sanitization and destruction records exist for media that has been dispositioned, confirming approved equipment and techniques were used.
What types of media does MP-04 cover
MP-04 covers both digital and non-digital media types. Digital media includes flash drives, diskettes, magnetic tapes, external or removable hard disk drives (solid state and magnetic), compact discs, and digital versatile discs. Non-digital media includes paper records and microfilm. The storage controls you apply must be commensurate with the security category of the information each media type contains, meaning higher-sensitivity media requires more restrictive physical controls such as a controlled media library rather than a locked desk drawer.