MP-7: Media Use

MP-07 requires your organization to either restrict or outright prohibit the use of specific types of system media on designated systems

Quick-reference card

FieldValue
Control IDMP-07
Control NameMedia Use
FrameworkNIST SP 800-53, Revision 5
Control FamilyMedia Protection
BaselinesLOW, MODERATE, HIGH
RelevanceOrganization (First Party and Third Party)
Risk SeverityMedium

What this control requires

MP-07 requires your organization to either restrict or outright prohibit the use of specific types of system media on designated systems and components, using defined security controls to enforce that decision. It also mandates that portable storage devices with no identifiable owner are prohibited from connecting to organizational systems. In practical terms, you’re building a policy-plus-enforcement framework that governs every thumb drive, external hard disk, optical disc, and even printed document that touches your environment.

The control sits within the Media Protection family, which addresses how organizations handle information stored on both digital and non-digital media throughout its lifecycle. Where MP-02 focuses on restricting who can access media, MP-07 focuses on restricting what types of media can be used and where they can be used. That distinction matters because even authorized users can introduce risk when they connect unvetted devices to sensitive systems.

Compliance requires more than a written policy. You need technical enforcement mechanisms that prevent unauthorized media from being used, monitoring capabilities that detect policy violations, and an ownership registry that ties every portable storage device to a responsible individual. The NIST SP 800-53 framework treats MP-07 as a baseline control at all three impact levels, which signals that regulators view uncontrolled media use as a foundational risk regardless of system sensitivity.

Why it matters

Portable storage devices remain one of the most reliable ways to exfiltrate data from secured environments. A single USB drive can hold terabytes of information and bypass every network-based security control your organization has deployed. Unlike network exfiltration, which leaves traces in firewall logs, proxy records, and SIEM alerts, physical media removal can evade detection entirely when endpoint controls aren’t enforced at the hardware level.

The risk isn’t theoretical. Organizations that rely on policy documents alone, without corresponding technical controls, create an enforcement gap that insiders and attackers both exploit. Removable media has been the vector in some of the most damaging data breaches in government and enterprise history, precisely because it operates outside the visibility of network security tools.

Harold Thomas Martin III NSA contractor data theft

Harold Thomas Martin III spent more than two decades cycling through seven different government contractor positions at the CIA, NSA, U.S. Cyber Command, the Department of Defense, and the National Reconnaissance Office. Over approximately 20 years, he systematically removed classified materials, including printed documents, CDs, and thumb drives, storing them at his home in Glen Burnie, Maryland, in an unlocked backyard shed, and in his personal vehicle.

When the FBI and Maryland State Police executed a search warrant in August 2016, they discovered approximately 50 terabytes of classified data across those three locations, along with six bankers’ boxes of hard-copy documents marked Secret and Top Secret/SCI. The materials spanned multiple agencies and included hacking tools and cyberweapons from NSA’s elite Tailored Access Operations unit.

The Department of Defense had banned removable media across all defense agencies in 2008 following the Agent.btz worm incident. Martin continued removing media for at least eight more years after that ban took effect. No DLP solution, insider threat monitoring platform, or SIEM generated alerts consistent with the scale of his activity. The prohibition existed on paper, but no technical controls prevented data transfers to removable media, and no exit-point inspection caught physical removal of tens of terabytes over two decades of regular contractor postings. Martin pleaded guilty in 2019 and received a nine-year federal prison sentence, the longest ever imposed for stealing government secrets at the time of sentencing.

What attackers exploit

  • Unmanaged USB ports on workstations and servers where no endpoint agent blocks unauthorized device connections
  • Policy-only enforcement that bans removable media in writing but lacks technical controls to prevent actual use
  • Absent device ownership registries that allow unknown or unattributed storage devices to connect without challenge
  • Gaps between DLP and physical security where data on portable media leaves the network perimeter without triggering alerts
  • Contractor and temporary staff access to systems where removable media controls are less mature than those applied to full-time employees

How to implement

MP-07 implementation fails most often when organizations treat it as a documentation exercise. A written ban on removable media means nothing without technical enforcement at the endpoint, monitoring at the network edge, and physical controls at facility exit points. The challenge is building layered controls that work together, so that a failure in one layer doesn’t leave you fully exposed.

For your organization

Start by classifying which types of media your environment actually uses. Digital media includes USB drives, external hard disks, optical discs, magnetic tapes, and SD cards. Non-digital media includes printed documents and microfilm. Your media use policy should explicitly state whether each type is restricted (allowed under specific conditions) or prohibited (blocked entirely) for each system or system component.

Deploy endpoint protection agents that enforce your policy at the device level. Configure group policies or endpoint management tools to disable USB mass storage, optical drives, and other removable media ports on systems where those media types are prohibited. For systems where some media use is allowed, implement device allowlists that permit only organization-issued or pre-approved devices identified by serial number or hardware ID.

Establish a device ownership registry. Every portable storage device authorized for use in your environment must be tied to a named individual who accepts responsibility for it. Unregistered devices should be automatically blocked by your endpoint controls. This registry also supports your incident response process, because you can trace any device back to its assigned owner if a policy violation or data loss event occurs.

Implement monitoring and logging for all media-related activity. Your DLP and endpoint detection tools should generate alerts when users attempt to connect unauthorized devices, copy sensitive data to removable media, or bypass media restrictions. Feed these alerts into your SIEM for correlation with other insider threat indicators. Conduct periodic audits of media use logs to verify that your technical controls are functioning as intended.

Common mistakes include relying solely on group policy without verifying enforcement, failing to update device allowlists when employees leave, and exempting executives or contractors from media restrictions that apply to the rest of the workforce.

For your vendors

When assessing vendor compliance with MP-07, your questionnaire should include targeted questions about both policy and technical enforcement. Ask whether the vendor maintains a written media use policy, what types of media are restricted or prohibited, and what technical controls enforce those restrictions. The gap between “we have a policy” and “our endpoints block unauthorized USB devices” is where most vendor risk lives.

Request specific evidence: endpoint configuration screenshots showing disabled USB ports or device allowlisting, DLP policy configurations that govern removable media, and audit logs demonstrating that media use events are captured and reviewed. A vendor who can only produce a policy document without corresponding technical artifacts is a red flag.

Ask about the vendor’s device ownership registry. How do they track which portable storage devices are authorized? What happens when an employee or contractor with registered devices separates from the organization? Vendors without a deprovisioning process for media devices create residual risk that persists after the individual’s access is revoked.

Verify that the vendor’s media controls extend to contractors and temporary staff, not just full-time employees. The Martin case demonstrates that contractors with prolonged access and weaker controls represent a material insider threat vector. Your SIG questionnaire should probe whether media restrictions apply uniformly across all personnel categories.

Red flags in vendor responses include vague language about “following best practices” without naming specific tools, inability to produce audit logs for media use events, and exemptions for senior leadership or specific business units.

Evidence examples

Evidence TypeExample Artifact
Media use policyDocumented policy specifying restricted and prohibited media types per system classification, with named approver and annual review date
System use policy and rules of behaviorSigned acknowledgment forms covering removable media restrictions, acceptable use terms, and consequences for violations
Endpoint configuration documentationGroup policy objects or endpoint management console exports showing USB mass storage disabled, device allowlisting enabled, and optical drive restrictions applied
Device ownership registrySpreadsheet or asset management database linking each authorized portable storage device (by serial number) to an assigned owner and approval date
DLP and monitoring configurationDLP policy rules governing data transfers to removable media, with alert thresholds and escalation procedures documented
Audit recordsSIEM logs and endpoint detection reports showing media connection attempts, blocked device events, and policy violation alerts over the review period
System security planSSP sections describing the organization’s media use restrictions, selected controls, enforcement mechanisms, and risk acceptance for any exceptions

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.10 Acceptable use of information and other associated assetsPartial
ISO 27001:20227.10 Storage mediaPartial
NIST SP 800-171 Rev 303.08.07 Media UsePartial
  • AC-19 Access Control for Mobile Devices covers access restrictions on mobile devices that may also function as portable storage, complementing MP-07’s broader media use restrictions.
  • AC-20 Use of External Systems addresses risks from connecting to systems outside organizational control, which often involves portable media as a data transfer mechanism.
  • PL-04 Rules of Behavior establishes the user agreements and acceptable use terms that set expectations for media handling before technical controls enforce them.
  • PM-12 Insider Threat Program provides the organizational framework for detecting and responding to insider threats, including those involving unauthorized media use like the Martin case.
  • SC-34 Non-modifiable Executable Programs protects system integrity by ensuring critical executables can’t be altered through removable media containing malicious code.
  • SC-41 Port and I/O Device Access directly supports MP-07 by controlling physical access to the ports and interfaces where removable media connects.

Frequently asked questions

What is NIST SP 800-53 MP-07

MP-07 is a NIST SP 800-53 control that requires organizations to restrict or prohibit the use of specified types of system media on designated systems, and to block portable storage devices that have no identifiable owner. It applies at all three baseline impact levels (LOW, MODERATE, HIGH) and targets both digital media like USB drives, external hard disks, and optical discs, and non-digital media like printed documents. The control demands both a documented policy and technical enforcement mechanisms that prevent unauthorized media use at the endpoint level.

What happens if MP-07 is not implemented

Failure to implement MP-07 leaves organizations exposed to data exfiltration through portable storage devices, malware introduction via infected removable media, and regulatory noncompliance across frameworks that map to this control. Without technical enforcement of media use restrictions, insider threats can operate undetected for extended periods. The Martin case demonstrated that a policy-only approach to removable media bans, without corresponding endpoint controls and monitoring, allowed approximately 50 terabytes of classified data to be removed over 20 years without triggering a single alert.

How do you audit MP-07

Auditing MP-07 starts with verifying that a current media use policy exists, specifies which media types are restricted or prohibited for each system category, and has been reviewed within its defined cycle. Auditors then validate technical enforcement by examining endpoint configurations for USB blocking or device allowlisting, reviewing DLP policies governing removable media transfers, and checking that audit logs capture media connection events. The device ownership registry should be cross-referenced against current personnel rosters to confirm that only active, authorized individuals have registered devices. Evidence of periodic log reviews and incident response for media policy violations completes the audit trail.

What types of media does MP-07 cover

MP-07 covers both digital and non-digital system media. Digital media includes USB flash drives, external hard disk drives, magnetic tapes, compact discs, digital versatile discs, SD cards, and other portable storage devices. Non-digital media includes paper documents and microfilm. The control also extends to mobile devices with information storage capabilities, which means smartphones and tablets that can function as portable storage fall within scope when connected to organizational systems.

Experience superior visibility and a simpler approach to cyber risk management