Quick-reference card
| Field | Value |
|---|---|
| Control ID | MP-06 |
| Control name | Media Sanitization |
| Framework | NIST SP 800-53 Revision 5 |
| Control family | Media Protection |
| Baselines | LOW MODERATE HIGH PRIVACY |
| Implementation level | Organization |
| Relevance | Organization (First Party and Third Party) |
| Risk severity | HIGH |
What this control requires
MP-06 requires organizations to sanitize all system media before disposing of it, releasing it outside organizational control, or reusing it. That means rendering data unrecoverable through clearing, purging, cryptographic erasure, or physical destruction, and matching the sanitization method to the sensitivity of the information stored on the media.
The scope is broader than most teams assume. MP-06 covers every form of media that stores or has stored organizational data, including hard drives, solid-state drives, USB devices, mobile phones, network components, printers, copiers, scanners, and paper documents. If the media ever held protected information, it falls under this control’s sanitization requirements before it leaves your custody.
Specifically, the control also demands that the strength and integrity of the sanitization mechanism match the security category or classification of the data. A quick reformat won’t satisfy MP-06 for media that held highly sensitive records. Organizations must define which techniques apply at each classification level, document those decisions, and verify that sanitization actually occurred before any media moves out the door.
Why it matters
Media sanitization failures create one of the most preventable yet damaging exposure vectors in information security. When media leaves organizational control without proper sanitization, every record on that device or document becomes accessible to anyone who encounters it. Unlike network intrusions that require technical skill, unsanitized media hands data to whoever picks it up.
The consequences extend well beyond the initial exposure. Regulatory penalties, litigation costs, and reputational damage compound quickly when investigators determine that a straightforward sanitization step was skipped. For organizations handling health records, financial data, or personally identifiable information (PII), the legal obligations around media disposal are explicit and carry enforcement teeth.
FileFax and Suburban Lung Associates Records Disposal Breach
In February 2015, a CBS Chicago investigative team filmed an unlocked dumpster outside the FileFax building in Northbrook, Illinois, containing hundreds of pounds of paper medical records. FileFax was a third-party medical records storage company and a HIPAA business associate for Suburban Lung Associates, an Illinois pulmonology practice. A tipster had already made roughly ten trips hauling records to a recycling facility before the news crew arrived. The 2,984 patient records were not shredded, not secured, and not retrieved. They were deposited directly into an accessible, open dumpster.
The breach maps directly to an MP-06 failure. Media sanitization demands that physical media containing protected information be rendered unreadable and unrecoverable before disposal. FileFax instead discarded patient records containing names, addresses, dates of birth, Social Security numbers, medical diagnoses, and treatment details without any sanitization. The Illinois Attorney General sued FileFax, and the company subsequently went out of business. The Department of Health and Human Services Office for Civil Rights (HHS/OCR) levied a $100,000 settlement against FileFax’s successor business, while Suburban Lung Associates paid a $30,000 state settlement. The case became a regulatory reference point for business associate liability under HIPAA.
But the FileFax incident isn’t an outlier; it’s a symptom of how often organizations treat media disposal as an afterthought rather than a security control.
What attackers exploit
- Decommissioned hard drives and SSDs sold or donated without sanitization, allowing forensic recovery of complete file systems
- Unsecured paper records placed in standard trash or recycling bins instead of being shredded or incinerated
- Printer and copier internal storage that retains images of every document processed, often overlooked when equipment is returned at end of lease
- Mobile devices and USB media reassigned internally or returned to vendors without cryptographic erasure
- Backup tapes and removable media stored in unsecured locations past retention periods, creating long-lived exposure windows
How to implement
The most common MP-06 failure isn’t choosing the wrong sanitization technique; it’s having no documented process at all. Teams decommission hardware, recycle paper, return leased equipment, and swap out mobile devices without ever triggering a sanitization workflow. The gap between policy and practice is where data walks out the door.
For your organization
Start by creating a media sanitization policy that maps each media type in your environment to a specific sanitization method. Digital media types include hard disk drives, solid-state drives, USB flash drives, mobile devices, optical media, backup tapes, and the internal storage in printers, copiers, and scanners. Non-digital media types include paper records, microfilm, and microfiche. For each type, define whether clearing, purging, cryptographic erasure, or physical destruction applies, and under what circumstances.
In practice, this means building a media inventory that tracks where sensitive data resides and what category of data each media type holds. You can’t sanitize what you haven’t identified. Tag media with its security classification at provisioning time so that the required sanitization method is known before the media reaches end of life.
Specifically, implement a chain-of-custody process for media awaiting sanitization. Media sitting in a “to be wiped” pile in an IT closet is still live exposure. Designate secure staging areas, assign responsibility to named personnel, and log when media enters and exits the sanitization workflow. Every sanitization event should produce a record that captures the media identifier, the method used, the date, and the person who performed it.
Where destruction is the chosen method, validate that the destruction is complete. Shredding paper to a cross-cut standard, degaussing magnetic media, or physically shredding drives all require verification. Contracted destruction services should provide certificates of destruction for every batch. Spot-check vendor performance periodically by auditing their processes and reviewing destruction certificates against your media disposal logs.
For your vendors
When vendors handle, store, or process your data on their own media, their sanitization practices become your risk. Your vendor risk assessment should include specific questions about how the vendor sanitizes media containing your data before disposal or reuse.
Request documentation of the vendor’s media sanitization policy, including which sanitization techniques they apply to digital and non-digital media. Ask whether they follow National Security Agency (NSA) standards for classified media or National Institute of Standards and Technology (NIST) guidelines for controlled unclassified information (CUI). A vendor who can’t articulate their sanitization standards for different data classifications is a red flag.
But policy documentation alone isn’t sufficient. Ask for sanitization records or certificates of destruction from the vendor’s most recent hardware decommission cycle. These records should show that the vendor logs each sanitization event, identifies the media, names the method, and timestamps the action. If the vendor outsources destruction to a subcontractor, you need visibility into that subcontractor’s practices as well.
Take the FileFax case as a direct warning for vendor oversight. A business associate’s failure to sanitize patient records resulted in regulatory action against both the storage company and the covered entity. Your organization shares liability when a vendor fails to sanitize media containing your data. Include contractual clauses that require vendors to sanitize media according to defined standards, provide destruction certificates on request, and notify you of any sanitization failures.
Periodically verify vendor compliance through evidence requests or on-site audits. Ask for updated media sanitization procedures annually and compare them against what you received during initial onboarding. A vendor whose practices have degraded or whose documentation hasn’t been updated is a vendor whose sanitization controls may no longer be effective.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Media sanitization policy | Documented policy defining approved sanitization techniques (clearing, purging, cryptographic erase, destruction) for each media type and data classification level |
| Media sanitization records | Logs capturing the media identifier, sanitization method applied, date performed, and name of the responsible individual for each disposal or reuse event |
| Certificates of destruction | Third-party destruction vendor certificates confirming physical destruction of hard drives, tapes, or paper records, with batch identifiers and dates |
| Media inventory and tracking | Asset register listing all media types containing organizational data, their security categorization, current custody status, and sanitization disposition |
| Retention and disposition schedule | Records retention policy defining how long each media type is kept and the sanitization method triggered at end of retention |
| System configuration documentation | Settings and procedures for enabling cryptographic erase on encrypted drives, remote wipe on mobile devices, and secure erase on printer and copier internal storage |
| Audit records | System logs and audit trails showing sanitization tool execution, verification outcomes, and any failed sanitization attempts |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.10 Acceptable use of information and other associated assets | Partial |
| ISO 27001:2022 | 7.10 Storage media | Partial |
| ISO 27001:2022 | 7.14 Secure disposal or re-use of equipment | Partial |
| ISO 27001:2022 | 8.10 Information deletion | Partial |
| NIST SP 800-171 Rev 3 | 03.08.03 Media Sanitization | Partial |
Related controls
- AC-03 — Access Enforcement: Restricts who can access media before sanitization; weak access controls let unauthorized users reach media awaiting disposal.
- AC-07 — Unsuccessful Logon Attempts: Protects devices containing sensitive media from brute-force access attempts during the window between decommission and sanitization.
- AU-11 — Audit Record Retention: Governs how long sanitization audit logs must be retained to demonstrate compliance during assessments.
- MA-02 — Controlled Maintenance: Ensures maintenance activities on media-bearing equipment don’t bypass sanitization requirements when components are swapped or repaired.
- MA-03 — Maintenance Tools: Restricts the tools used for maintenance to prevent unauthorized data extraction from media during servicing.
- MA-04 — Nonlocal Maintenance: Addresses sanitization risks when maintenance is performed remotely and media access occurs outside the physical facility.
- MA-05 — Maintenance Personnel: Requires vetting of personnel who handle media during maintenance, reducing the risk of data exfiltration before sanitization occurs.
- PM-22 — Personally Identifiable Information Quality Management: Ensures PII stored on media is accurate and current, directly affecting what must be sanitized and the de-identification methods applied.
- SI-12 — Information Management and Retention: Defines when media reaches end of retention and triggers the sanitization workflow required by MP-06.
- SI-18 — Personally Identifiable Information Quality Operations: Governs operational procedures for PII quality that intersect with sanitization when PII-bearing media is disposed of or reused.
Frequently asked questions
What is NIST SP 800-53 MP-06?
MP-06 is the NIST SP 800-53 control that requires organizations to sanitize all system media, both digital and non-digital, before disposal, release from organizational control, or reuse. Sanitization techniques include clearing, purging, cryptographic erasure, and physical destruction, and the method chosen must match the security category of the information on the media. The control applies across all four baselines (LOW, MODERATE, HIGH, and PRIVACY) and covers everything from hard drives and mobile devices to paper records and printer internal storage.
What happens if MP-06 is not implemented?
Without MP-06, media containing protected information leaves organizational control in a recoverable state, exposing the organization to data breaches, regulatory penalties, and litigation. The FileFax case demonstrated that a single failure to sanitize 2,984 paper patient records resulted in a $100,000 federal settlement and a $30,000 state settlement, plus the closure of the responsible company. Auditors evaluating MP-06 look for documented media sanitization records and certificates of destruction; their absence signals a systemic gap that can trigger findings across multiple control families.
How do you audit MP-06?
Auditing MP-06 starts with verifying that the organization has defined sanitization techniques for each media type and data classification in a documented media protection policy. Assessors then sample media sanitization records to confirm that media was sanitized prior to disposal, prior to release from organizational control, and prior to reuse, checking that each record identifies the method used and that the method is commensurate with the security category of the data. They also review system configuration documentation for technical controls like cryptographic erase settings on encrypted drives and remote wipe capabilities on mobile devices.
What is the difference between clearing and purging media?
Clearing renders data on media unrecoverable through standard user interfaces or software recovery tools, but a laboratory-grade forensic attack might still extract residual data. Purging goes further by making data unrecoverable even against laboratory-level forensic techniques, typically through overwriting, degaussing, or applying specialized firmware-level erase commands. The choice between them depends on the security category of the information; media that held highly sensitive data generally requires purging or physical destruction rather than clearing alone.