1Overview
MP.L2-3.8.2 limits who can reach CUI on media. It requires that access to CUI on system media be limited to authorized users, so that the data on media is available only to those who are supposed to have it. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.
Protecting media physically is only half the picture; the CUI on it also has to be restricted to authorized users. This control requires that access to CUI on media be limited, whether that media is a shared drive, a removable device, or stored digital media, so that people without authorization cannot read the CUI it holds. It is the media expression of the same least-access principle that runs through the access control family, applied to the data at rest on media.
Limit access to CUI on system media to authorized users.
The requirement is that only authorized users can access the CUI held on media. In practice this is achieved through access controls on digital media and storage and through physical control of media that holds CUI, so that reaching the data requires authorization. It complements the physical protection of 3.8.1 by governing who may access the CUI, not just where the media is kept.
2The Assessment Objective
NIST SP 800-171A frames 3.8.2 as a single objective: limit access to CUI on media to authorized users.
Access to CUI on system media is limited to authorized users. Only authorized users can access CUI on media.
The single objective is limiting access to authorized users. The common failure is broadly accessible storage where CUI on media can be read by people without authorization. The assessor looks for access to CUI on media restricted to authorized users.
3Failure Patterns
The failures are about CUI on media reachable by the unauthorized.
Broadly accessible storage
Where CUI on shared digital media is accessible to everyone rather than only authorized users, access is not limited. Restricting access to the CUI through permissions closes this.
Removable media without access control
CUI on removable media that anyone can read once they have the device fails the control if the device is not physically controlled or the data protected. Access has to be limited to authorized users.
Authorization not defined
Without defining who is authorized for the CUI, access cannot be limited to them. Knowing the authorized users is the basis for restricting access.
4Ownership
This is an IT-owned control tied to access controls on media and storage.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Restricts access to CUI on media to authorized users through access controls. Owns the technical evidence. |
| Security or compliance lead | Defines who is authorized for CUI and confirms access is limited to them. |
| Program lead | Reviews media access and retains the evidence. |
5Tooling
The control is delivered by access controls on digital media and physical control of media holding CUI.
| Objective | Tooling | What it provides |
|---|---|---|
| digital | Access controls on media and storage | Restriction of CUI on digital media to authorized users. |
| physical | Physical control of media holding CUI | Restriction of access to media that holds CUI. |
The caveat is that limiting access depends on knowing who is authorized. Access controls restrict CUI to those users, but only if the authorized set is defined. The assessor examines whether access to CUI on media is limited to authorized users, so the restriction and the definition of authorization both have to hold.
6Evidence
The satisfied version of 3.8.2 shows CUI on media restricted to authorized users.
| Evidence | What it demonstrates |
|---|---|
| Media access controls | The objective. CUI on media limited to authorized users. |
| Authorization definition | The objective. Who is authorized for the CUI. |
The evidence should show access to CUI on media limited to authorized users, backed by a definition of who is authorized. The access controls and authorization definition are the clearest demonstration, and because this control cannot sit on a plan of action, the restriction has to be real at the time of assessment.
Physical protection is not the same as access control
Keeping media in place does not restrict the CUI on it to authorized users, and this three-point control asks for that access limit. Restricting access to CUI on media through access controls is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.2. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing MP.L2-3.8.2 among the three-point basic security requirements. ecfr.gov