Establish media sanitization policy per NIST SP 800-88 Rev 1 Chapter 4 (Information Sanitization and Disposition Decision Flow). Policy must (a) define the scope of media covered (electronic storage media + paper + microform + cloud-resident data + ephemeral storage), (b) name accountable roles per Chapter 3 (Information Sanitization and Decisionmaking Process): Information Owner + System Owner + Information System Security Officer + Property Custodian + Media Sanitization Personnel + Security Officer + Security Compliance Officer + Records Officer + General Counsel, (c) establish the sanitization decision flow per Section 4.5 considering Security Categorization (Confidential / Moderate / High per FIPS 199) + intended disposition (re-use within control / re-use leaving control / not re-used) + media type characteristics, (d) define sanitization method categories (Clear + Purge + Destroy) per Section 2.5 with mappings to media types, (e) integrate with property disposal + records retention + IT lifecycle + sustainability programs. Policy must specify minimum sanitization method per security category per disposition path with documented justification for any deviation. Review and update policy annually and on regulatory or technological change.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.