1Overview
MP.L2-3.8.7 is the family's second five-point requirement and it governs removable media. It requires that the organization control the use of removable media on system components, so that USB drives, memory cards, and similar devices cannot be used freely to move data in or out. It is a five-point requirement that cannot be deferred on a plan of action.
Removable media is both convenient and dangerous. A USB drive can carry CUI out of the environment in a pocket, or bring malware in past the network defenses, and if any device can be plugged into any system, both paths are wide open. This control requires that the use of removable media on system components be controlled, so that which devices may be used, on which systems, and by whom is governed rather than unrestricted. Its five-point weight reflects that uncontrolled removable media is one of the most direct routes for both data loss and malware entry.
Control the use of removable media on system components.
The requirement is to control removable media use on system components. In practice this ranges from technical controls that restrict or block removable media, to policy that governs what may be used and how, to a combination of both. The point is that removable media is not used freely and without governance; its use is controlled so that the organization decides what is permitted rather than leaving the ports open to anything.
2The Assessment Objective
NIST SP 800-171A frames 3.8.7 as a single objective: control the use of removable media on system components.
The use of removable media on system components is controlled. Removable media use is governed rather than unrestricted.
The single objective is controlling removable media use. The common failure is open ports where any device can be connected freely. The assessor looks for controls, technical or policy-based, that govern removable media use on system components.
3Failure Patterns
The failures are about unrestricted removable media.
Open USB ports
Where any USB device can be plugged into any system, removable media is uncontrolled, opening paths for both data exfiltration and malware. Restricting or governing removable media use closes this.
Policy without enforcement
A policy against removable media that is not enforced technically or in practice leaves the actual use uncontrolled. Control has to be real, whether through technical restriction or enforced policy.
No governance of what is permitted
Without deciding which removable media may be used, on which systems, and by whom, use is unrestricted by default. Defining and enforcing what is permitted is the control.
4Ownership
This is an IT-owned technical control with a policy dimension.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Implements technical controls on removable media use and enforces the policy. Owns the technical evidence. |
| Security or compliance lead | Defines what removable media use is permitted and confirms the control is real. |
| Program lead | Reviews removable media governance and retains the evidence. |
5Tooling
The control is delivered by technical restrictions on removable media and enforced policy.
| Objective | Tooling | What it provides |
|---|---|---|
| technical | Device control, removable media restrictions | Technical control over what removable media may be used. |
| policy | Enforced removable media policy | Governance of removable media use on system components. |
The caveat is that the control has to be real, not just written. Technical restrictions such as device control provide the strongest enforcement, while policy alone works only if it is genuinely followed and enforced. The assessor examines whether removable media use is actually controlled, so the control has to be effective in practice.
6Evidence
The satisfied version of 3.8.7 shows removable media use governed.
| Evidence | What it demonstrates |
|---|---|
| Removable media controls | The objective. Technical control over removable media use. |
| Removable media policy | The objective. Governance of what is permitted. |
The evidence should show removable media use controlled on system components, through technical restrictions, enforced policy, or both. The removable media controls and policy are the clearest demonstration, and because this control cannot sit on a plan of action, the control has to be real at the time of assessment.
An open port is a two-way street
Uncontrolled removable media lets CUI walk out and malware walk in, so this five-point control asks that its use be governed rather than left open. Putting real technical and policy controls on removable media is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.7. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.7. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing MP.L2-3.8.7 among the five-point derived security requirements. ecfr.gov