1Overview
MP.L2-3.8.9 closes the Media Protection family by protecting backups. It requires that the organization protect the confidentiality of backup CUI at storage locations, so that the copies of CUI kept for recovery are safeguarded as carefully as the originals. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.
Backups are copies of the organization's data, made so that it can be recovered after loss, and backups of CUI are therefore copies of CUI. If those backups are stored without protection, they become an overlooked route to the very data the program protects: a backup drive in an unsecured location, or backup files anyone can read, exposes CUI just as surely as the primary copy would. This control requires that the confidentiality of backup CUI be protected at its storage locations, extending the same care given to primary data to the backups.
Protect the confidentiality of backup CUI at storage locations.
The requirement is to protect the confidentiality of backup CUI wherever it is stored. In practice this means the backups are encrypted, access-controlled, or physically secured at their storage locations, whether those are on-site, off-site, or with a backup service. The single assessment objective is that this confidentiality protection is in place for backup CUI at its storage locations, so the recovery copies are not a weaker link than the originals.
2The Assessment Objective
NIST SP 800-171A frames 3.8.9 as a single objective: protect the confidentiality of backup CUI at storage locations.
The confidentiality of backup CUI is protected at storage locations. Backups of CUI are safeguarded where they are stored.
The single objective is protecting backup CUI confidentiality at storage. The common failure is unprotected backups treated as an afterthought. The assessor looks for confidentiality protection of backup CUI wherever it is stored.
3Failure Patterns
The failures are about unprotected backups.
Unencrypted backups
Backup CUI stored without encryption is readable by anyone who reaches the backup media or files. Encrypting the backups protects their confidentiality at rest.
Backups in unsecured locations
Backup media kept in an unsecured location, on-site or off, is exposed to whoever can reach it. Securing the storage location protects the backups.
Backup service not verified
Relying on a backup service without confirming it protects the CUI leaves the confidentiality unverified. The protection has to hold wherever the backups are stored, including with a provider.
4Ownership
This is an IT-owned control tied to the backup process.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Protects the confidentiality of backup CUI at its storage locations, through encryption and secured storage. Owns the technical evidence. |
| Security or compliance lead | Confirms backups of CUI are protected wherever stored, including with providers. |
| Program lead | Includes backup protection in the backup process and retains the evidence. |
5Tooling
The control is delivered by encryption and secured storage of backup CUI.
| Objective | Tooling | What it provides |
|---|---|---|
| encrypt | Backup encryption | Confidentiality of backup CUI at rest. |
| secure | Secured storage locations, access control | Protection of backups wherever they are kept. |
The caveat is that the protection has to cover all backup storage locations, including off-site and provider-held backups. Backups protected in one location but not another leave the unprotected copies exposed. The assessor examines whether backup CUI confidentiality is protected at its storage locations, so the protection has to be complete.
6Evidence
The satisfied version of 3.8.9 shows backup CUI protected at storage.
| Evidence | What it demonstrates |
|---|---|
| Backup encryption configuration | The objective. Backup CUI protected at rest. |
| Backup storage protection | The objective. Storage locations secured. |
The evidence should show the confidentiality of backup CUI protected at all its storage locations, through encryption and secured storage. The backup encryption configuration and storage protection are the clearest demonstration of the control.
A backup of CUI is still CUI
Backups hold the same controlled data as the primary systems, and if they are stored without protection they become an overlooked route to it, so this control asks that their confidentiality be protected at storage. Protecting backup CUI wherever it is kept is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.9. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.9. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov