Number | Title | Impact | Priority | Subject Area |
---|---|---|---|---|
MP-8 | Media Downgrading | P0 | Media Protection |
Instructions |
---|
The organization: MP-8a. Establishes Assignment: organization-defined information system media downgrading process that includes employing downgrading mechanisms with Assignment: organization-defined strength and integrity; MP-8b. Ensures that the information system media downgrading process is commensurate with the security category and/or classification level of the information to be removed and the access authorizations of the potential recipients of the downgraded information; MP-8c. Identifies Assignment: organization-defined information system media requiring downgrading; and MP-8d. Downgrades the identified information system media using the established process. |
Guidance |
---|
This control applies to all information system media, digital and non-digital, subject to release outside of the organization, whether or not the media is considered removable. The downgrading process, when applied to system media, removes information from the media, typically by security category or classification level, such that the information cannot be retrieved or reconstructed. Downgrading of media includes redacting information to enable wider release and distribution. Downgrading of media also ensures that empty space on the media (e.g., slack space within files) is devoid of information. |
Enhancements | ||||||||
---|---|---|---|---|---|---|---|---|
The organization documents information system media downgrading actions.
The organization employs Assignment: organization-defined tests of downgrading equipment and procedures to verify correct performance Assignment: organization-defined frequency.
The organization downgrades information system media containing Assignment: organization-defined Controlled Unclassified Information (CUI) prior to public release in accordance with applicable federal and organizational standards and policies.
The organization downgrades information system media containing classified information prior to release to individuals without required access authorizations in accordance with NSA standards and policies. |