NIST 800-53 REV 5 • MEDIA PROTECTION
MP-8(1) — Documentation of Process
Document system media downgrading actions.
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Supplemental Guidance
Organizations can document the media downgrading process by providing information, such as the downgrading technique employed, the identification number of the downgraded media, and the identity of the individual that authorized and/or performed the downgrading action.
Practitioner Notes
Every media downgrading action needs to be documented — what was downgraded, from what level to what level, the method used, and who authorized it.
Example 1: Create a Media Downgrading Record form with fields for: original classification, target classification, media type and serial number, sanitization method, technician name, verifier name, authorizing official, and date. File completed records with your security documentation.
Example 2: Log all downgrading actions in your asset management system. Update the media record to reflect the new classification level, the date of downgrade, and who authorized it. This creates an audit trail that can be reviewed during security inspections.