Frameworks / NIST SP 800-66 Rev 2 / 164.310(d)(1) NIST SP 800-66 Rev 2
Physical
NIST SP 800-66 Rev 2 164.310(d)(1): Device and Media Controls (Standard) Implement policies governing receipt and removal of hardware and electronic media containing ePHI into, out of, and within the facility.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 64 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-1.2 Address Unauthorized Assets CIS-10.3 Disable Autorun and Autoplay for Removable Media CIS-11.3 Protect Recovery Data CIS-2.1 Establish and Maintain a Software Inventory CIS-3.1 Establish and Maintain a Data Management Process CIS-3.9 Encrypt Data on Removable Media CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices AC-20(2) Portable Storage Devices Restricted Use MP-1 Policy and Procedures MP-2 Media Access MP-4 Media Storage MP-5 Media Transport MP-7 Media Use PE-16 Delivery and Removal AC-20(2) Portable Storage Devices Restricted Use MP-1 Policy and Procedures MP-2 Media Access MP-4 Media Storage MP-5 Media Transport MP-7 Media Use PE-16 Delivery and Removal SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets SOC2-CC6.5 CC6.5 Protecting data on assets until disposal SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ANSSI-HYG-15 Protect Against Threats Related to Removable Media ANSSI-HYG-30 Apply Physical Protection Measures to Mobile Devices 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 9.4.3 9.4.3 Securing media sent outside the facility 9.4.5 9.4.5 Inventory logs of electronic media C5-AM-02 Acceptable Use and Safe Handling of Assets Policy C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets CCM-DCS-02 Off-Site Transfer Authorization Policy and Procedures CCM-DCS-04 Secure Media Transportation Policy and Procedures 7.10 Storage media 7.9 Security of assets off-premises 7.10 Storage media 7.9 Security of assets off-premises ASD37-13 Control removable storage media (Very Good) AUCDR-IS-3 Securely manage information assets over their lifecycle AM-3 Ensure security of asset lifecycle management NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Physical Query this from an agent The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.