Beyond CMMC Level 1
The free web app covers the 17 CMMC Level 1 practices. This requirement is part of the full NIST 800-171 set — get the desktop app to work on all 110 requirements with SPRS scoring. Previously saved data is shown read-only below, and your data always remains exportable in full.
Get the desktop appSecurity Requirements for 03.08.04 Media Markings
The term security marking refers to the application or use of human-readable security attributes. System media includes digital and non-digital media. Marking of system media reflects applicable federal laws, Executive Orders, directives, policies, and regulations. See [NARA MARK].
Assessment GuidanceExamine 0/7
How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).
Discussion
All media, hardcopy and digital, must be properly marked to alert individuals to the presence of CUI stored on the media. The National Archives and Records Administration (NARA) has published guidelines for labeling media of different sizes. 146 MP.L2-3.8.8 requires that media have an identifiable owner, so organizations may find it desirable to include ownership information on the device label as well.
146 NARA, CUI Notice 2019-01: Controlled Unclassified Information (CUI) Coversheets and Labels
Example You were recently contacted by the project team for a new DoD program. The team said they wanted the CUI in use for the program to be properly protected. When speaking with them, you realize that most of the protections will be provided as part of existing enterprise cybersecurity capabilities. They also mentioned that the project team will use several USB drives to share specific data. You explain that the team must ensure the USB drives are externally marked to indicate the presence of CUI [a]. The project team labels the outside of each USB drive with an appropriate CUI label following NARA guidance [a]. Further, the labels indicate that distribution is limited to those employees supporting the DoD program [a].
Assessment Methods
Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.
- Personnel with system media protection and marking responsibilities
- Personnel with information security responsibilities
- Organizational processes for marking information media
- Mechanisms supporting or implementing media marking