MP.L2-3.8.1[a] – Identify media types that contain CUI.
This objective requires your organization to identify all forms of media—both digital and physical—that are used to store, transmit, or process Controlled Unclassified Information (CUI). This includes any medium that could carry sensitive data, whether actively in use or in storage.
MP.L2-3.8.5[a] – Identify controls to protect CUI during transport.
This objective requires your organization to identify how Controlled Unclassified Information (CUI) is protected during physical or digital transport. Whether data is sent via courier, email, VPN, or removable media, you must have clear security controls in place to prevent unauthorized access, loss, or interception.
MP.L2-3.8.4[b] – Examine documentation to confirm individuals authorized to access CUI on media are identified.
This objective ensures that your organization has formally documented who is authorized to access CUI on system or removable media. The goal is to confirm that access is assigned intentionally, recorded clearly, and controlled through policy.
MP.L2-3.8.3[b] – Examine documentation to confirm tools or techniques used to mark media with CUI designation are identified.
This objective ensures your organization has formally documented how media containing Controlled Unclassified Information (CUI) is labeled, including the specific tools, formats, and procedures used. It validates that CUI marking isn’t just practiced—but is also written down for consistency, training, and audit readiness.
MP.L2-3.8.6 – Sanitize or destroy system media containing CUI before disposal or release for reuse.
This control requires your organization to securely erase or physically destroy system media that contains Controlled Unclassified Information (CUI) before it is disposed of, recycled, repurposed, or transferred to another user or organization. The goal is to ensure that no recoverable CUI remains on the media.
3.8.7 – Control the use of removable media on system components
This control requires organizations to limit and monitor the use of removable media—like USB drives, external hard drives, CDs, and SD cards—on systems that store, process, or transmit Controlled Unclassified Information (CUI). Read the full blog breakdown of 3.8.7
3.8.8 – Prohibit the use of portable storage devices when such devices have no identifiable owner
This control requires organizations to block the use of any portable storage device (like USB drives, external hard drives, or SD cards) unless the owner is known and authorized. Devices with unknown origin or unclear ownership must not be allowed on organizational systems. Read the full blog breakdown of 3.8.8
3.8.9 – Protect the confidentiality of backup CUI at storage locations
This control requires organizations to ensure that backups containing Controlled Unclassified Information (CUI) are protected with appropriate security measures—especially when stored off-site or in long-term archival systems. Read the full blog breakdown of 3.8.9