NIST 800-53 REV 5 • MEDIA PROTECTION

MP-8(1)Documentation of Process

Document system media downgrading actions.

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Supplemental Guidance

Organizations can document the media downgrading process by providing information, such as the downgrading technique employed, the identification number of the downgraded media, and the identity of the individual that authorized and/or performed the downgrading action.

Practitioner Notes

Every media downgrading action needs to be documented — what was downgraded, from what level to what level, the method used, and who authorized it.

Example 1: Create a Media Downgrading Record form with fields for: original classification, target classification, media type and serial number, sanitization method, technician name, verifier name, authorizing official, and date. File completed records with your security documentation.

Example 2: Log all downgrading actions in your asset management system. Update the media record to reflect the new classification level, the date of downgrade, and who authorized it. This creates an audit trail that can be reviewed during security inspections.