NIST 800-53 REV 5 • MEDIA PROTECTION

MP-6(6)Media Destruction

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Practitioner Notes

This enhancement specifically addresses physical destruction of media — shredding, disintegrating, pulverizing, or incinerating media to make data recovery physically impossible.

Example 1: Purchase a hard drive shredder or contract with a certified destruction vendor (Iron Mountain, Shred-it) that provides on-site destruction services with certificates of destruction. Require the vendor to destroy drives at your location while your staff witnesses the process.

Example 2: For paper documents and optical media, use a cross-cut shredder rated to P-4 or higher (DIN 66399 standard). For drives, if a shredder is not available, use a drill press to put multiple holes through the platters. Document every destruction event with serial numbers, date, method, and witness.