{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"physical","domain":"Asset Management & Inventory","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-04","description":"Restrict access to and use of removable and other storage media to authorized personnel and approved media types, and physically secure media commensurate with the classification of the data it holds. Sanitize or destroy media and equipment containing storage using approved techniques before disposal, reuse, or release from control, and verify that data can no longer be read or recovered before protections are discontinued. Retain records of media use, movement, sanitization, and destruction.","details":{"control_category":"physical","control_type":"preventive","domain":"Asset Management & Inventory","guidance":[],"members":[{"control_id":"MP-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"MP-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"MP-7","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.7.10","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.7.14","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CC6.5","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"PCI-Req9","coverage":"partial","delta":"media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control","framework":"pci-dss","relationship":"intersects_with"}],"statement":"Restrict access to and use of removable and other storage media to authorized personnel and approved media types, and physically secure media commensurate with the classification of the data it holds. Sanitize or destroy media and equipment containing storage using approved techniques before disposal, reuse, or release from control, and verify that data can no longer be read or recovered before protections are discontinued. Retain records of media use, movement, sanitization, and destruction.","title":"Control storage media through use, storage, and destruction","unified_id":"UC-ASSET-04"},"id":"uc:UC-ASSET-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-04","sourceIds":["iso-27001","nist-800-53","pci-dss","soc2"],"sourceUrl":null,"title":"UC-ASSET-04 — Control storage media through use, storage, and destruction","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:08b5bef514bc95ee613c97d66e4be83bb4006e2fe0212dd52f74c76b9351ae2a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","targetId":"uc:UC-ASSET-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10f2c8f3da582a25784d9db0b56806fe33641235b08257f7ed6a433ed4973603","properties":{"control_id":"A.7.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-10-2bfc8971.json","targetId":"ctrl:iso-27001:A.7.10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:125a06279b89f21754fb1b340d7c1c8f71f2a576d096754aeed05bf361d07aad","properties":{"control_id":"CC6.5","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-5-449f6335.json","targetId":"ctrl:soc2:CC6.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b2737972642d38c22017c0d989ded07cce70c5b3b2852d363f78b49ce6fb84b","properties":{"rationale":"Sanitizing/destroying media before disposal or reuse and verifying unrecoverability directly prevents residual-data exposure.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/risk-data-residual-media-disposal-92de3d1d.json","targetId":"risk:data-residual-media-disposal","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2613dd72df3a3b402602ed1c26dc16df6e53ae1fff9573aa65edd71e04188a62","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","targetId":"uc:UC-ASSET-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2a80714376a422021d581ac844e6c3bb3893363620b9f35f4ade04fe1a64e1a0","properties":{"control_id":"MP-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-mp-6-e0c4ff6f.json","targetId":"ctrl:nist-800-53:MP-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:515ec9c2294a081b8d75cf42d360bc0ef4d5cbd832c74b20924a44c13830f51e","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","targetId":"uc:UC-ASSET-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:51bfa3a5e211963ad9901e691414d07aba43664f7a9e4e9f5a473eb883fa25b2","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","targetId":"uc:UC-ASSET-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6776d28cecee08a226dbf756d8ee3d27678183dfd4e101efd550410a9c1cca1b","properties":{"control_id":"MP-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-mp-7-e76f3ab7.json","targetId":"ctrl:nist-800-53:MP-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:890bf8da11cb7f136445bc7254e5e059e3be8727c721c89359c4465a8164c786","properties":{"control_id":"PCI-Req9","coverage":"partial","delta":"media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req9-987072c1.json","targetId":"ctrl:pci-dss:PCI-Req9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ac1ab2f75e2004f1ef5dadc51fc0ed0b661b805a163874c235f9d5ebc5fa288","properties":{"control_id":"MP-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-mp-2-30eeed05.json","targetId":"ctrl:nist-800-53:MP-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4899f7912335a7240c0671a7d3f47a9fbe675ab613f66e382e3146270615b93","properties":{"control_id":"A.7.14","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-14-5ada9a8e.json","targetId":"ctrl:iso-27001:A.7.14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d3158996dd1e69959ea6479d7a90da8f3611ca01ebed079ea2d3c5711e71f800","properties":{"rationale":"Physically securing media by classification and restricting access to it directly reduces theft of stored media.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/risk-phys-theft-of-equipment-media-c64433e7.json","targetId":"risk:phys-theft-of-equipment-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d9cd016c8684b67240a4bbd625d435b1234a4ffd1f0bddf198d85c7da736b211","properties":{},"sourceDetailPath":"/data/v1/records/wf-c39-df8b318a.json","sourceId":"wf:C39","targetDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","targetId":"uc:UC-ASSET-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f07963e4887c624ba43be5f12f38e718a2d0613f0c67a2f78dee9e8379a08d9c","properties":{"rationale":"Restricting removable-media use to authorized personnel and approved types directly prevents uncontrolled copying to removable devices.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/risk-asset-uncontrolled-copying-removable-media-4a9604c7.json","targetId":"risk:asset-uncontrolled-copying-removable-media","type":"mitigates"}],"schemaVersion":1}
