NIST SP 800-66 Rev 2
Physical

NIST SP 800-66 Rev 2 164.310(d)(1): Device and Media Controls (Standard)

Implement policies governing receipt and removal of hardware and electronic media containing ePHI into, out of, and within the facility.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 64 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 7 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-10.3 Disable Autorun and Autoplay for Removable Media
  • CIS-11.3 Protect Recovery Data
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.9 Encrypt Data on Removable Media
  • CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices

FedRAMP High · 7 controls

  • AC-20(2) Portable Storage Devices Restricted Use
  • MP-1 Policy and Procedures
  • MP-2 Media Access
  • MP-4 Media Storage
  • MP-5 Media Transport
  • MP-7 Media Use
  • PE-16 Delivery and Removal

FedRAMP Moderate · 7 controls

  • AC-20(2) Portable Storage Devices Restricted Use
  • MP-1 Policy and Procedures
  • MP-2 Media Access
  • MP-4 Media Storage
  • MP-5 Media Transport
  • MP-7 Media Use
  • PE-16 Delivery and Removal

CMMC 2.0 · 6 controls

NIST SP 800-161 Rev 1 · 5 controls

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

SOC 2 · 4 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment
  • ANSSI-HYG-15 Protect Against Threats Related to Removable Media
  • ANSSI-HYG-30 Apply Physical Protection Measures to Mobile Devices

PCI DSS 4.0 · 3 controls

  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 9.4.3 9.4.3 Securing media sent outside the facility
  • 9.4.5 9.4.5 Inventory logs of electronic media

C5 (Germany) · 2 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets
  • CCM-DCS-02 Off-Site Transfer Authorization Policy and Procedures
  • CCM-DCS-04 Secure Media Transportation Policy and Procedures

ISO 27001:2022 · 2 controls

  • 7.10 Storage media
  • 7.9 Security of assets off-premises

ISO 27002:2022 · 2 controls

  • 7.10 Storage media
  • 7.9 Security of assets off-premises
  • ASD37-13 Control removable storage media (Very Good)
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AM-3 Ensure security of asset lifecycle management

ISO 27701:2019 · 1 control

  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Physical

Query this from an agent

The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.