← Controls / MP

MP-03 Media Marking

Media Protection

Moderate High

Description

a. Mark system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information; and b. Exempt [Assignment: organization-defined types of system media] from marking if the media remain within [Assignment: organization-defined controlled areas].

Supplemental Guidance

Security marking refers to the application or use of human-readable security attributes. Digital media includes diskettes, magnetic tapes, external or removable hard disk drives (e.g., solid state, magnetic), flash drives, compact discs, and digital versatile discs. Non-digital media includes paper and microfilm. Controlled unclassified information is defined by the National Archives and Records Administration along with the appropriate safeguarding and dissemination requirements for such information and is codified in [32 CFR 2002]. Security markings are generally not required for media that contains information determined by organizations to be in the public domain or to be publicly releasable. Some organizations may require markings for public information indicating that the information is publicly releasable. System media marking reflects applicable laws, executive orders, directives, policies, regulations, standards, and guidelines.

Patterns that use this control (2)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.13A.7.10

ISO 27002:2022

5.137.10

COBIT 2019

APO14BAI09

CIS Controls v8

CIS 3

PCI DSS v4.0.1

9.4

FINOS CCC

CCC-C16

ISO 42001:2023

A.7.4

MAS TRM

11

ANSSI

Hygiene.8SecNumCloud.9.2

FINMA Circular 2023/1

IV.D(78)IV.D(79)IV.D(80)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.9(1)

EU DORA

Art.8(1)

BIO2

5.137.10

RBI CSF

Annex1.12

FISC Security Guidelines

FISC.F4FISC.O9

LGPD + BCB 4893

LGPD.Art.11

HKMA TM-E-1

TME1.7.2

MLPS 2.0

8.1.10.1

SAMA CSF

3.9

NCA ECC

2-7

UAE IA

T4

CBB TM

TM-9

Qatar NIA

AM

CBUAE

CR-5

CBE CSF

CTO-2

SA JS2

JS2-8.2

CBN CSF

Part3.4

BoG CISD

CISD-V

BCBS 239

Principle 11

FFIEC IS

II.C.13

HIPAA Security Rule

§164.310(d)(1)

ECB CROE

CROE.2.3.3

BOT Cyber Resilience

Ch2.3

CMMC 2.0

MP

Solvency II

DR.266-DataSec

Lloyd's Minimum Standards

MS8.7

HITRUST CSF v11

07.b09.f

ISO 27799

5.38.2

ISO 17799 (legacy)

7.2.210.7.310.8.215.1.3

COBIT 4.1 (legacy)

DS11.6