unified

UC-ASSET-04 — Control storage media through use, storage, and destruction

Restrict access to and use of removable and other storage media to authorized personnel and approved media types, and physically secure media commensurate with the classification of the data it holds. Sanitize or destroy media and equipment containing storage using approved techniques before disposal, reuse, or release from control, and verify that data can no longer be read or recovered before protections are discontinued. Retain records of media use, movement, sanitization, and destruction.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Asset Management & Inventory
type
preventive
category
physical

Details

unified_id
UC-ASSET-04
title
Control storage media through use, storage, and destruction
statement
Restrict access to and use of removable and other storage media to authorized personnel and approved media types, and physically secure media commensurate with the classification of the data it holds. Sanitize or destroy media and equipment containing storage using approved techniques before disposal, reuse, or release from control, and verify that data can no longer be read or recovered before protections are discontinued. Retain records of media use, movement, sanitization, and destruction.
domain
Asset Management & Inventory
control_type
preventive
control_category
physical
members
  • framework
    nist-800-53
    control_id
    MP-2
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    MP-6
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    MP-7
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.7.10
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.7.14
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC6.5
    coverage
    full
    relationship
    superset_of
  • framework
    pci-dss
    control_id
    PCI-Req9
    coverage
    partial
    delta
    media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections