unified
UC-ASSET-04 — Control storage media through use, storage, and destruction
Restrict access to and use of removable and other storage media to authorized personnel and approved media types, and physically secure media commensurate with the classification of the data it holds. Sanitize or destroy media and equipment containing storage using approved techniques before disposal, reuse, or release from control, and verify that data can no longer be read or recovered before protections are discontinued. Retain records of media use, movement, sanitization, and destruction.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Asset Management & Inventory
- type
- preventive
- category
- physical
Details
- unified_id
- UC-ASSET-04
- title
- Control storage media through use, storage, and destruction
- statement
- Restrict access to and use of removable and other storage media to authorized personnel and approved media types, and physically secure media commensurate with the classification of the data it holds. Sanitize or destroy media and equipment containing storage using approved techniques before disposal, reuse, or release from control, and verify that data can no longer be read or recovered before protections are discontinued. Retain records of media use, movement, sanitization, and destruction.
- domain
- Asset Management & Inventory
- control_type
- preventive
- control_category
- physical
- members
- framework
- nist-800-53
- control_id
- MP-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- MP-6
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- MP-7
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.7.10
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.7.14
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC6.5
- coverage
- full
- relationship
- superset_of
- framework
- pci-dss
- control_id
- PCI-Req9
- coverage
- partial
- delta
- media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-04 — Control storage media through use, storage, and destruction
- UC-ASSET-04 — Control storage media through use, storage, and destruction maps_to A.7.10 — Storage media
- framework
- iso-27001
- control_id
- A.7.10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-04 — Control storage media through use, storage, and destruction maps_to CC6.5 — The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's objectives.
- framework
- soc2
- control_id
- CC6.5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-04 — Control storage media through use, storage, and destruction mitigates Residual data on improperly disposed or re-used media
- strength
- primary
- rationale
- Sanitizing/destroying media before disposal or reuse and verifying unrecoverability directly prevents residual-data exposure.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-04 — Control storage media through use, storage, and destruction
- UC-ASSET-04 — Control storage media through use, storage, and destruction maps_to MP-6 — Media Sanitization
- framework
- nist-800-53
- control_id
- MP-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-ASSET-04 — Control storage media through use, storage, and destruction
- Security Control Assessment & POA&M Remediation tests UC-ASSET-04 — Control storage media through use, storage, and destruction
- UC-ASSET-04 — Control storage media through use, storage, and destruction maps_to MP-7 — Media Use
- framework
- nist-800-53
- control_id
- MP-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-04 — Control storage media through use, storage, and destruction maps_to PCI-Req9 — Restrict physical access to cardholder data
- framework
- pci-dss
- control_id
- PCI-Req9
- coverage
- partial
- delta
- media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-04 — Control storage media through use, storage, and destruction maps_to MP-2 — Media Access
- framework
- nist-800-53
- control_id
- MP-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-04 — Control storage media through use, storage, and destruction maps_to A.7.14 — Secure disposal or re-use of equipment
- framework
- iso-27001
- control_id
- A.7.14
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-04 — Control storage media through use, storage, and destruction mitigates Theft of equipment, media or unattended devices
- strength
- primary
- rationale
- Physically securing media by classification and restricting access to it directly reduces theft of stored media.
- Endpoint, Media & Information Handling Custody operates UC-ASSET-04 — Control storage media through use, storage, and destruction
- UC-ASSET-04 — Control storage media through use, storage, and destruction mitigates Uncontrolled copying to removable media / unmanaged software installs
- strength
- primary
- rationale
- Restricting removable-media use to authorized personnel and approved types directly prevents uncontrolled copying to removable devices.