MP.L2-3.8.7: Control the Use of Removable Media to Protect CUI

Mapped to NIST 800-171 Requirement: 3.8.7
CMMC Assessment Objective: MP.L2-3.8.7

What This Control Means
You must establish technical and administrative controls to:
• Restrict the use of removable storage devices
• Authorize only specific media or users for removable media access
• Monitor or block unknown devices
• Prevent the use of removable media entirely on high-risk systems if needed
These measures reduce the risk of malware introduction, data loss, or unauthorized CUI transfer.

Why It Matters
Removable media is one of the most common vectors for:
• Insider threats
• Malware infections
• Data exfiltration
• Accidental leakage of sensitive data
Without strict controls, even a “harmless” USB drive can create a serious security event.

How to Implement It
1. Define a Removable Media Use Policy
• Specify who can use removable media, what types are allowed, and under what conditions
• Prohibit personal USB devices or unknown drives
• Require encryption for any device used with CUI
2. Enforce Controls Technically
• Use endpoint protection or GPOs to:
◦ Block unauthorized removable media
◦ Require encryption
◦ Trigger alerts/logs for usage
3. Require Authorization
• Implement an approval process for removable media requests
• Tag or inventory approved devices
4. Monitor and Log Usage
• Enable logging for insertions/removals
• Track which users accessed which devices and when
5. Train Employees
• Teach users about the risks of removable media
• Include real-world examples and clear guidance

Evidence the Assessor Will Look For
• Written policy on removable media usage
• Technical configurations that restrict media access
• Logs of approved or blocked removable media events
• Encryption settings on allowed devices
• User training documentation on safe media practices

Common Gaps
• No restrictions in place—users can plug in any device
• Devices used without encryption or tracking
• No process for requesting or approving media use
• Staff unaware of risks or policies related to removable media

How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Enforcing removable media policies via endpoint and enclave controls
• Blocking unapproved devices automatically
• Logging all media access events with user and system context
• Providing approval workflows for requesting media use
• Requiring encryption and tagging for authorized media
With Cuick Trac, your removable media environment is monitored, controlled, and secure by default.

Final CTA
The smallest device can cause the biggest breach.
Schedule a Cuick Trac demo to take full control of removable media access—and protect your CUI from the ground up.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.