NIST SP 800-88
Inventory, Tracking, Chain of Custody

NIST SP 800-88 NISTSP88-5: Media Inventory, Tracking, Chain of Custody, and Sanitization Records

Maintain media inventory and tracking per NIST SP 800-88 Rev 1 Chapter 3 (Information Sanitization Process) + Chapter 4 (Decision Flow). Inventory must (a) track every piece of storage media from acquisition through sanitization or destruction, (b) record media type + serial number + system assignment + security categorization + data classification + location + ownership, (c) tag media at acquisition to enable lifecycle tracking, (d) interface with property management + IT asset management + records management + procurement systems. Chain of Custody per Section 3.4 must (a) document transfer of media between custodians at every step (system owner to sanitization personnel to disposal vendor to disposition), (b) record handler identity + date + time + purpose + receiving party + verification of integrity, (c) survive across organisational boundaries (when media leaves the organisation) with signed handover documentation, (d) align with legal hold + e-discovery + litigation requirements. Sanitization records per Section 4.7 + Appendix G must capture (a) Certificate of Sanitization (Section 4.8) for every sanitization event covering media identification + sanitization method + date + personnel + verification + witness where applicable, (b) record retention aligned with regulatory + investigative + organisational policy (typically minimum 3 years + longer for high-sensitivity media).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 72 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 4 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal
  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 4 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures
  • ISO21434-23 Backup and recovery procedures

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 1800-32 · 3 controls

  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery

NIST SP 800-53 Rev 5 · 2 controls

  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development

OWASP MASVS · 2 controls

  • OWASPMASVS-1 MASVS-STORAGE: Storage of Sensitive Data
  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • D.3 Backup and Recovery
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability
  • FFIEC-12 Disaster recovery procedures

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO/IEC 27010:2015 · 1 control

  • 27010-8.1 Membership Onboarding

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 1 control

OWASP ASVS · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.