Overview

Security Requirements for 03.08.06 Portable Storage Encryption

This requirement applies to portable storage devices (e.g., USB memory sticks, digital video disks, compact disks, external or removable hard disk drives). See [NIST CRYPTO].[SP 800-111] provides guidance on storage encryption technologies for end user devices.

Assessment GuidanceExamine 0/8

How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).

Discussion

CUI can be stored and transported on a variety of portable media, which increases the chance that the CUI can be lost. When identifying the paths CUI flows through your company, identify devices to include in this requirement.

To mitigate the risk of losing or exposing CUI, implement an encryption scheme to protect the data. Even if the media are lost, proper encryption renders the data inaccessible. When encryption is not an option, apply alternative physical safeguards during transport.

Because the use of cryptography in this requirement is to protect the confidentiality of CUI, the cryptography used must meet the criteria specified in requirement SC.L2-3.13.11.

This requirement, MP.L2-3.8.6, provides additional protections to those provided by MP.L23.8.5. This requirement is intended to protect against situations where control of media access fails, such as through the loss of the media.

Examples

  1. Example 1

    You manage the backups for file servers in your datacenter. You know that in addition to the company’s sensitive information, CUI is stored on the file servers. As part of a broader plan to protect data, you send the backup tapes off site to a vendor. You are aware that your backup software provides the option to encrypt data onto tape. You develop a plan to test and enable backup encryption for the data sent off site. This encryption provides additional protections for the data on the backup tapes during transport and offsite storage [a].

Assessment Methods

Examine
The process of reviewing, inspecting, observing, studying, or analyzing assessment objects (e.g., policies, procedures, plans, system designs, mechanisms) to facilitate understanding, achieve clarification, or obtain evidence.Example: An assessor reads the access control policy and inspects system configuration settings to confirm they match.

Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.

Interview
The process of holding discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or identify the location of evidence.Example: An assessor asks a system administrator to describe how user accounts are approved, reviewed, and disabled.
  • Personnel with system media transport responsibilities
  • Personnel with information security responsibilities
Test
The process of exercising assessment objects (e.g., activities, mechanisms) under specified conditions to compare actual behavior with expected behavior.Example: An assessor attempts to sign in with a disabled account to confirm that access is denied.
  • Cryptographic mechanisms protecting information on digital media during transportation outside controlled areas

Potential Assessment Considerations

  • Are all CUI data on media encrypted or physically protected prior to transport outside of controlled areas [a]?
  • Are cryptographic mechanisms used to protect digital media during transport outside of controlled areas [a]?
  • Do cryptographic mechanisms comply with FIPS 140-2 [a]?

Key References

NIST SP 800-171 Rev. 2 3.8.6

Evidence

  1. 03.08.06.a

    The confidentiality of cui stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards.