NIST 800-53 REV 5 • MEDIA PROTECTION

MP-8(2)Equipment Testing

Test downgrading equipment and procedures {{ insert: param, mp-8.2_prm_1 }} to ensure that downgrading actions are being achieved.

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Supplemental Guidance

None.

Practitioner Notes

Just like sanitization equipment, your media downgrading equipment and procedures need to be tested to confirm they work correctly. A flawed downgrade could release sensitive data into an unprotected environment.

Example 1: Test your downgrading procedures annually by performing a downgrade on test media and then attempting data recovery using forensic tools. If any data is recoverable, revise your procedures or replace your equipment.

Example 2: If you use a degausser for downgrading magnetic media, have it calibrated and tested according to the manufacturer's specifications. Document each calibration test with the date, results, and the name of the person who performed the test.