DKDavid Koran& Associates
Home The CMMC Guide Part III · Media Protection MP.L2-3.8.7
The CMMC Guide · Media Protection Family

MP.L2-3.8.7  Control Removable Media

Control the use of removable media on system components.

Family
Media ProtectionMP, 9 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
OnePer NIST SP 800-171A

1Overview

MP.L2-3.8.7 is the family's second five-point requirement and it governs removable media. It requires that the organization control the use of removable media on system components, so that USB drives, memory cards, and similar devices cannot be used freely to move data in or out. It is a five-point requirement that cannot be deferred on a plan of action.

Removable media is both convenient and dangerous. A USB drive can carry CUI out of the environment in a pocket, or bring malware in past the network defenses, and if any device can be plugged into any system, both paths are wide open. This control requires that the use of removable media on system components be controlled, so that which devices may be used, on which systems, and by whom is governed rather than unrestricted. Its five-point weight reflects that uncontrolled removable media is one of the most direct routes for both data loss and malware entry.

The requirement · NIST SP 800-171 Rev 2, 3.8.7

Control the use of removable media on system components.

The requirement is to control removable media use on system components. In practice this ranges from technical controls that restrict or block removable media, to policy that governs what may be used and how, to a combination of both. The point is that removable media is not used freely and without governance; its use is controlled so that the organization decides what is permitted rather than leaving the ports open to anything.

2The Assessment Objective

NIST SP 800-171A frames 3.8.7 as a single objective: control the use of removable media on system components.

The use of removable media on system components is controlled. Removable media use is governed rather than unrestricted.

MeetsRemovable media use is controlled through technical restrictions, policy, or both.
FailsAny removable media can be used on any system without restriction.

The single objective is controlling removable media use. The common failure is open ports where any device can be connected freely. The assessor looks for controls, technical or policy-based, that govern removable media use on system components.

3Failure Patterns

The failures are about unrestricted removable media.

Open USB ports

Where any USB device can be plugged into any system, removable media is uncontrolled, opening paths for both data exfiltration and malware. Restricting or governing removable media use closes this.

Policy without enforcement

A policy against removable media that is not enforced technically or in practice leaves the actual use uncontrolled. Control has to be real, whether through technical restriction or enforced policy.

No governance of what is permitted

Without deciding which removable media may be used, on which systems, and by whom, use is unrestricted by default. Defining and enforcing what is permitted is the control.

The common root
This control fails on convenience. Removable media is easy and useful, so ports are left open, but an open port is a two-way street for data leaving and malware arriving. Controlling removable media use is what governs that traffic instead of leaving it unrestricted.

4Ownership

This is an IT-owned technical control with a policy dimension.

RoleResponsibility for this control
IT and system administratorImplements technical controls on removable media use and enforces the policy. Owns the technical evidence.
Security or compliance leadDefines what removable media use is permitted and confirms the control is real.
Program leadReviews removable media governance and retains the evidence.
See also: This control works with the prohibition on unowned portable storage at MP.L2-3.8.8 and the least-functionality controls of the configuration management family.

5Tooling

The control is delivered by technical restrictions on removable media and enforced policy.

ObjectiveToolingWhat it provides
technicalDevice control, removable media restrictionsTechnical control over what removable media may be used.
policyEnforced removable media policyGovernance of removable media use on system components.

The caveat is that the control has to be real, not just written. Technical restrictions such as device control provide the strongest enforcement, while policy alone works only if it is genuinely followed and enforced. The assessor examines whether removable media use is actually controlled, so the control has to be effective in practice.

6Evidence

The satisfied version of 3.8.7 shows removable media use governed.

EvidenceWhat it demonstrates
Removable media controlsThe objective. Technical control over removable media use.
Removable media policyThe objective. Governance of what is permitted.

The evidence should show removable media use controlled on system components, through technical restrictions, enforced policy, or both. The removable media controls and policy are the clearest demonstration, and because this control cannot sit on a plan of action, the control has to be real at the time of assessment.

An open port is a two-way street

Uncontrolled removable media lets CUI walk out and malware walk in, so this five-point control asks that its use be governed rather than left open. Putting real technical and policy controls on removable media is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.7. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.7. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing MP.L2-3.8.7 among the five-point derived security requirements. ecfr.gov
← Previous in Media Protection
MP.L2-3.8.6 · Encrypt CUI on Media in Transport
Next in Media Protection →
MP.L2-3.8.8 · Prohibit Unowned Portable Storage
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MP.L2-3.8.7 · Edition 2026.1 · Last reviewed July 12, 2026