Policy and Procedures MP-1
Media Protection · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds MP-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Media Protection family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
MP-1 (Media Protection Policy and Procedures) is the paper foundation for the whole MP family. It asks you to write down — and keep current — a media protection policy (the rules) and the procedures that carry them out (the how), name a person who owns them, and review them on a set schedule. ‘Media’ here means anything that holds data: USB (Universal Serial Bus) drives, backup disks and tapes, and the server’s own drives. It is a Low-baseline control that every other MP control leans on.
What good looks like
- Write both a policy and procedures. The policy states purpose, scope, roles, and responsibilities; the procedures give the concrete steps that carry the policy out.
- Name an owner. Designate an official responsible for keeping the media protection policy and procedures current.
- Cover the whole media lifecycle — access, marking, storage, transport, use, and sanitization — so the rest of the MP family has a home.
- Align with the laws and standards the lab is subject to, and make the documents easy to find for the people who must follow them.
- Review and update on a schedule (for example, yearly) and after big changes — a new backup process, a move, or an incident.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established and communicated
How to move it toward Implemented
- Draft a one-to-two-page media protection policy covering media access, marking, storage, transport, use, and sanitization, and name the owner at the top.
- Write short procedures beside it — how a USB drive is approved, how a backup disk is stored, how media is wiped — so the policy is actionable, not just aspirational.
- Set a review cadence (for example, annually) and record the last-reviewed date and reviewer on the document itself.
- Attach the signed, dated policy-and-procedures file as hardening evidence on the asset, naming
MP-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.