MP-5: Media Transport

MP-05 requires organizations to protect, track, and restrict system media whenever it moves outside controlled areas.

Quick-reference card

FieldValue
Control IDMP-05
Control titleMedia Transport
FrameworkNIST SP 800-53 Revision 5
FamilyMedia Protection (MP)
BaselinesMODERATE, HIGH
Implementation levelOrganization
RelevanceFirst Party and Third Party
Risk severityMedium

What This Control Requires

MP-05 requires organizations to protect, track, and restrict system media whenever it moves outside controlled areas. That means every flash drive, external hard drive, backup tape, paper record, and laptop disk that leaves a secured facility must be encrypted or physically secured, logged, and handled only by authorized personnel.

In practice, the control breaks down into four obligations. You must apply specific safeguards (typically encryption for digital media and locked containers for physical media) to anything traveling beyond your facility’s physical or procedural boundaries. You must maintain accountability throughout transit, meaning you can trace who had the media, when, and where. You must document transport activities so auditors can reconstruct the chain of custody. And you must limit transport to personnel you’ve explicitly authorized, whether those individuals are employees or external couriers.

The underlying problem MP-05 addresses is straightforward: data security controls that protect information at rest inside a data center become meaningless the moment that same information leaves the building on unprotected media. Without transport controls, sensitive data travels in whatever state it happened to be stored in, often unencrypted and untracked.

Why It Matters

Most organizations treat media transport as a logistics problem rather than a security control, and that gap produces preventable data exposures. When digital media leaves a controlled environment without encryption, every link in the transport chain (vehicles, mailrooms, courier services, hotel rooms) becomes an unmonitored attack surface. The risk isn’t theoretical. Unencrypted laptops, USB drives, and backup tapes account for a recurring category of breaches in which the data was never “hacked” but simply lost or stolen in transit.

Accretive Health laptop theft and FTC settlement

In July 2011, an employee of Accretive Health — a Chicago-based company managing hospital revenue cycle operations — left a laptop in an unattended car in Minneapolis. The laptop was stolen during a routine car break-in. The device contained unprotected records for approximately 23,500 patients collected at Fairview Health Services hospital locations, including names, Social Security numbers, dates of birth, insurance information, and clinical data. The theft wasn’t a targeted cyberattack; the data was exposed entirely because it was transported without adequate protection.

The Federal Trade Commission (FTC) charged Accretive Health with failing to provide reasonable and appropriate security for consumer information. The FTC’s complaint emphasized that Accretive had no policy requiring laptop encryption, no training on safeguarding data during transport, and no mechanism for verifying that sensitive data was protected before being carried offsite. A consent order finalized in January 2014 required the company to implement a comprehensive information security program and submit to third-party security audits every two years for 20 years (FTC Docket No. C-4432).

The case remains a frequent reference in FTC enforcement discussions because the entire failure was logistical. The data never needed to be on that laptop, in that car, unencrypted. Every obligation MP-05 defines (encryption, accountability, documentation, authorization) would have prevented the exposure or at minimum contained the blast radius.

What attackers exploit

  • Unencrypted portable media: Flash drives, external hard drives, and laptops transported without full-disk encryption expose data to anyone who gains physical access.
  • Absent chain-of-custody records: Without transport logs, organizations can’t determine when media was lost or who last handled it, delaying incident response.
  • Unauthorized personnel handling media: Allowing any employee, rather than specifically authorized individuals, to carry media offsite removes the accountability layer MP-05 requires.
  • Unsecured physical transit: Media shipped via standard mail or left in vehicle compartments lacks the locked-container protections that prevent opportunistic theft.
  • No pre-transport verification: Skipping checks on whether data actually needs to travel and whether protections are applied before departure creates avoidable exposure windows.

How to Implement

Most MP-05 failures don’t come from missing encryption software. They come from the absence of a documented, enforced process that governs who can move media, how it must be protected, and what records must follow it.

For your organization

Start by defining which types of media your organization uses and which contain controlled information. Digital media includes USB flash drives, external hard drives, solid-state drives, magnetic tapes, optical discs, and any removable storage. Non-digital media includes printed reports, microfilm, and paper records containing sensitive data. Your media transport policy should list each type and specify the required protection for transit.

Encryption is the primary technical control for digital media in transit. Require full-disk or full-device encryption on any portable storage that leaves controlled areas. For USB flash drives specifically, deploy hardware-encrypted drives or enforce software encryption through endpoint management tools. Establish cryptographic standards aligned with your key management program rather than leaving encryption methods to individual discretion.

Build a chain-of-custody process that tracks every transport event. At minimum, record the media type, content classification, departure time, destination, authorized carrier, and receipt confirmation. Courier services, whether internal or external, should provide tracking and require signature on delivery. For high-sensitivity media, consider tamper-evident packaging or locked containers.

Restrict transport authorization to named individuals. Maintain a current list of personnel approved to carry media offsite, and require management approval before adding anyone to that list. Train authorized personnel on transport procedures, including what to do if media is lost or compromised in transit.

Common mistakes to avoid:

  • Writing a media transport policy that references “encryption” generically without specifying algorithms, key lengths, or approved tools
  • Allowing any employee with physical access to carry media offsite without explicit authorization
  • Tracking shipments of backup tapes but ignoring USB drives and laptops carried by employees
  • Failing to include non-digital media (paper records, printed reports) in the transport policy

For your vendors

When your vendors transport media containing your data, their controls become your risk. Your vendor assessment should verify that transport protections exist, that they’re documented, and that your data specifically falls within scope of those protections.

Request the vendor’s media transport policy and evaluate whether it covers all media types relevant to your engagement. A vendor that encrypts backup tapes but allows employees to carry unencrypted laptops with client data has a gap that directly affects you. Ask for specifics: what encryption standards they apply, whether they use hardware-encrypted devices, and how they handle non-digital media.

Verify that the vendor maintains chain-of-custody documentation for media transport. Ask for a sample transport log or a description of the tracking process. The log should capture who authorized the transport, who carried the media, the departure and arrival points, and receipt confirmation. If the vendor uses third-party courier services, determine whether those couriers meet the same accountability requirements.

Confirm that the vendor restricts media transport to authorized personnel and maintains a current authorization list. Ask how they revoke transport privileges when employees change roles or leave the organization. A vendor that can’t demonstrate role-based transport authorization likely doesn’t have the accountability layer MP-05 demands.

Red flags to watch for:

  • Vendor policy covers “data in transit” over networks but doesn’t address physical media transport
  • No documented chain-of-custody process for media leaving vendor facilities
  • Vendor can’t name who is authorized to transport media containing your data
  • Encryption is described as “available” rather than mandatory for all media in transit
  • No process for reporting lost or compromised media during transport

Evidence Examples

Evidence TypeExample Artifact
Media transport policyPolicy defining media types in scope, required encryption standards, physical security measures, and authorized transport methods
Authorized personnel listCurrent roster of individuals approved to transport media outside controlled areas, with role justification and approval dates
Chain-of-custody logsTransport records capturing media type, content classification, carrier identity, departure time, destination, and receipt confirmation
Encryption standards documentationSpecification of cryptographic algorithms, key lengths, and approved hardware or software tools for media encryption in transit
Personnel training recordsCompletion records for media transport procedure training, including handling of lost or compromised media
Physical security proceduresDocumentation of locked container requirements, tamper-evident packaging standards, and courier security requirements

Cross-Framework Mapping

FrameworkControl(s)Coverage
ISO 27001:20225.10 Acceptable use of information and other associated assetsPartial
ISO 27001:20227.10 Storage mediaPartial
ISO 27001:20227.9 Security of assets off-premisesPartial
NIST SP 800-171 Rev 303.08.05 Media TransportPartial
  • AC-07 — Unsuccessful Logon Attempts: limits brute-force access to encrypted media by locking accounts after failed authentication attempts
  • AC-19 — Access Control for Mobile Devices: extends transport-like protections to mobile devices that carry data outside controlled areas
  • CP-02 — Contingency Plan: defines recovery procedures when media is lost or destroyed during transport
  • CP-09 — System Backup: governs the creation and protection of backup media that may require offsite transport
  • MP-03 — Media Marking: ensures transported media carries visible classification labels so handlers apply the correct protections
  • MP-04 — Media Storage: controls how media is secured at rest before and after transport events
  • PE-16 — Delivery and Removal: manages the physical entry and exit points through which media passes during transport
  • PL-02 — System Security and Privacy Plans: documents the overall media protection strategy, including transport controls
  • SC-12 — Cryptographic Key Establishment and Management: provides the key infrastructure that makes transport encryption operationally viable
  • SC-13 — Cryptographic Protection: specifies the cryptographic mechanisms applied to media during transport

Frequently Asked Questions

What is NIST SP 800-53 MP-05?

MP-05 is the NIST SP 800-53 control that requires organizations to protect, track, and restrict system media, including flash drives, backup tapes, external hard drives, and paper records, during transport outside controlled areas. The control mandates encryption or physical safeguards, chain-of-custody accountability, documented transport activities, and restriction of transport to authorized personnel. MP-05 applies at the MODERATE and HIGH baselines.

What happens if MP-05 is not implemented?

Without MP-05 controls, any media leaving your facility travels unprotected, creating exposure to theft, loss, and tampering that you can’t detect or reconstruct. Unencrypted portable storage devices and paper records become the weakest link in your data protection program. Regulatory consequences can be severe: as the Accretive Health case demonstrated, the FTC imposed a 20-year consent order with biennial audits for failing to encrypt and track transported media containing patient records.

How do you audit MP-05?

Auditors verify MP-05 by examining whether your media transport policy defines the specific media types in scope, the encryption or physical safeguards applied during transit, and the personnel authorized to carry media offsite. They review chain-of-custody logs for completeness, checking that transport records capture carrier identity, departure and arrival times, and receipt confirmation. Auditors also test whether your authorized personnel list is current and whether transport activities are restricted to individuals on that list.

What types of media does MP-05 cover?

MP-05 covers both digital and non-digital system media. Digital media includes USB flash drives, external and removable hard disk drives (both solid-state and magnetic), magnetic tapes, compact discs, and digital versatile discs. Non-digital media includes paper records and microfilm. The control applies to any of these media types when they’re transported outside controlled areas, meaning spaces where your organization provides physical or procedural protections for information and systems.

Experience superior visibility and a simpler approach to cyber risk management