CMMCpedia Download

Requirements / Media Protection (MP)

MP.L2-3.8.2

Media Access

Official Source Material

Limit access to CUI on system media to authorized users.

Determine if:

  1. [a] access to CUI on system media is limited to authorized users.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Authorization here is about who may see the CUI, not who may touch the container.

A technician can carry a box of backup drives to a storage room without being authorized to read what is on them. The objective asks whether access to the CUI itself, the controlled unclassified information on the media, is limited to authorized users. Your evidence has to name who is authorized and show how everyone else is kept out.

Maintain a named list of who is authorized, and put someone in charge of it.

The assessment guide's example designates a data owner who approves access and keeps the list of authorized users. A one-page list tied to a contract or project, with the owner's name at the top, answers the assessor's first question. Without it you are arguing that access is limited while unable to say to whom.

A written rule with nothing behind it does not limit anything.

A policy that says only authorized users may access CUI media, sitting alongside an unlocked drawer, leaves [a] with no mechanism. Pair the rule with the physical controls: locked storage, a check-out log, and racks or server rooms that lock.

Racks and server rooms are media storage too.

The drives in your servers and the tapes in your backup unit are system media. Locking the server room and limiting who holds the key limits access to the CUI on everything inside it, and the key list doubles as evidence for this objective.

What falls short

  • A policy stating that unauthorized users must not access CUI media, with no authorized-user list and no locked storage. It gives [a] neither a definition of who is authorized nor a mechanism that limits anyone.

Edge cases

  • IT staff who handle media as part of their duties do not automatically belong on the authorized-user list for the CUI itself. Decide deliberately: either authorize them and record it, or store the CUI encrypted so that handling the media never exposes the content.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.