Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >SP 800-53
  3. >Media Protection
  4. >SP800-53-MP-7
SP800-53-MP-7Active

Media Use

Statement

restrict; prohibit the use of types of system media on systems or system components using controls ; and Prohibit the use of portable storage devices in organizational systems when such devices have no identifiable owner.

Location

Control Family
Media Protection

Control Details

Identifier
SP800-53-MP-7
Family
MP

Organisation-Defined Parameters

mp-07_odp.01
types of system media
mp-07_odp.02
restrict; prohibit
mp-07_odp.03
systems or system components
mp-07_odp.04
controls

Supplemental Guidance

System media includes both digital and non-digital media. Digital media includes diskettes, magnetic tapes, flash drives, compact discs, digital versatile discs, and removable hard disk drives. Non-digital media includes paper and microfilm. Media use protections also apply to mobile devices with information storage capabilities. In contrast to MP-2 , which restricts user access to media, MP-7 restricts the use of certain types of media on systems, for example, restricting or prohibiting the use of flash drives or external hard disk drives. Organizations use technical and nontechnical controls to restrict the use of system media. Organizations may restrict the use of portable storage devices, for example, by using physical cages on workstations to prohibit access to certain external ports or disabling or removing the ability to insert, read, or write to such devices. Organizations may also limit the use of portable storage devices to only approved devices, including devices provided by the organization, devices provided by other approved organizations, and devices that are not personally owned. Finally, organizations may restrict the use of portable storage devices based on the type of device, such as by prohibiting the use of writeable, portable storage devices and implementing this restriction by disabling or removing the capability to write to such devices. Requiring identifiable owners for storage devices reduces the risk of using such devices by allowing organizations to assign responsibility for addressing known vulnerabilities in the devices.

Assessment Objective

the use of types of system media is restrict; prohibit on systems or system components using controls; the use of portable storage devices in organizational systems is prohibited when such devices have no identifiable owner.

ATTACK
ATTACK-T1025relatedvia ctid-attack-to-sp800-53
ATTACK-T1052relatedvia ctid-attack-to-sp800-53
ATTACK-T1052.001relatedvia ctid-attack-to-sp800-53
ATTACK-T1092relatedvia ctid-attack-to-sp800-53
ATTACK-T1091relatedvia ctid-attack-to-sp800-53
View in graphReport an issue
← Back to Media Protection
Media Protection30 controls
SP800-53-MP-1Policy and ProceduresSP800-53-MP-2Media AccessSP800-53-MP-2(1)Automated Restricted AccessSP800-53-MP-2(2)Cryptographic ProtectionSP800-53-MP-3Media MarkingSP800-53-MP-4Media StorageSP800-53-MP-4(1)Cryptographic ProtectionSP800-53-MP-4(2)Automated Restricted AccessSP800-53-MP-5Media TransportSP800-53-MP-5(1)Protection Outside of Controlled AreasSP800-53-MP-5(2)Documentation of ActivitiesSP800-53-MP-5(3)CustodiansSP800-53-MP-5(4)Cryptographic ProtectionSP800-53-MP-6Media SanitizationSP800-53-MP-6(1)Review, Approve, Track, Document, and VerifySP800-53-MP-6(2)Equipment TestingSP800-53-MP-6(3)Nondestructive TechniquesSP800-53-MP-6(4)Controlled Unclassified InformationSP800-53-MP-6(5)Classified InformationSP800-53-MP-6(6)Media DestructionSP800-53-MP-6(7)Dual AuthorizationSP800-53-MP-6(8)Remote Purging or Wiping of InformationSP800-53-MP-7Media UseSP800-53-MP-7(1)Prohibit Use Without OwnerSP800-53-MP-7(2)Prohibit Use of Sanitization-resistant MediaSP800-53-MP-8Media DowngradingSP800-53-MP-8(1)Documentation of ProcessSP800-53-MP-8(2)Equipment TestingSP800-53-MP-8(3)Controlled Unclassified InformationSP800-53-MP-8(4)Classified Information