Media Protection
Media Protection
Section titled “Media Protection”Authorized By: Chief Information Security Officer (CISO)
Purpose
Section titled “Purpose”This document establishes the Media Protection Policy for Safire, Inc. It defines information security requirements to ensure device and media protection during storage, transport, sanitization, and disposal across their complete lifecycle.
Media protection is essential to prevent unauthorized disclosure of sensitive information, maintain data integrity, and ensure compliance with regulatory requirements, including CMMC, NIST SP 800-171, and other applicable standards.
This Policy applies to all employees, contractors, temporary employees, volunteers, and third parties of Safire who handle, access, transport, store, or dispose of organizational media. It includes appropriate processes to protect data in any medium (e.g., paper, portable devices, cloud storage, etc.) based on the data’s classification.
Policy
Section titled “Policy”- Media Access Safire shall restrict access to digital and non-digital media to authorized individuals.
- Digital media includes, but is not limited to, external hard drives, flash drives, and optical disks.
- Non-digital media includes, but is not limited to, paper and microfilm.
- Media Marking To safeguard information, Safire shall ensure media is marked with appropriate classification labels and handling caveats.
- Media containing Public data requires no marking.
- Media containing Restricted or Confidential data must be labeled in accordance with the Safire Data Protection Policy (e.g., For Official Use Only , Restricted Information ).
- Internal Use: When media remains within a secure, company-controlled enclave, physical marking is recommended but optional, provided digital safeguards are in place.
- Media Storage Safire shall implement physical and logical controls to ensure the secure storage of digital and non-digital media. All users must:
- Classify and label media to identify sensitivity.
- Store sensitive media in locked containers or secured areas when not in use.
- Ensure that access to storage areas is limited to authorized personnel.
- Media Sanitization and Disposal All equipment used to store, process, or transmit Controlled Unclassified Information (CUI) or sensitive company data must be sanitized prior to disposal or release for off-site maintenance.
- Process: The IT Department must identify and verify equipment requiring sanitization.
- Approved Methods: Sanitization must be performed using one of the following methods:
- Clear: Overwriting data (Erasing/Wiping).
- Purge: Degaussing (for magnetic media).
- Destroy: Physical destruction (Shredding, Disintegrating, Incinerating).
- Media Transport When transporting media outside of Safire controlled areas, users must strictly adhere to the following controls:
- Encryption: Sensitive information on digital media must be encrypted during transport.
- Physical Security: Sensitive hard copy information must be enclosed in opaque, sealed envelopes or locked containers.
- Accountability: Transport activities must be restricted to authorized personnel or bonded couriers (e.g., commercial delivery services with tracking).
- Documentation: Safire shall maintain records of transport activities to prevent loss, destruction, or tampering.
- Media Use Safire shall implement physical and logical security controls to protect the confidentiality and integrity of information system storage media throughout its lifecycle. This includes the prohibition of unauthorized portable storage devices on Safire networks.
Compliance
Section titled “Compliance”Compliance Measurement
Section titled “Compliance Measurement”The policy owner will verify compliance through methods such as business tool reports and internal and external audits. Oversight is provided by CISO, IT, and Compliance functions. Enforcement of this policy is coordinated through Human Resources and Executive Management.
Exception
Section titled “Exception”Any exceptions must be approved by the Policy Owner in advance and formally documented.
| Date | Authorized By | Exception Description |
|---|
Non-Compliance
Section titled “Non-Compliance”An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
Related Standards, Policies, Plans, and Procedures
Section titled “Related Standards, Policies, Plans, and Procedures”- Data Classification Policy
- Data Protection Policy
Revision History: Revision History
Section titled “Revision History: Revision History”| Date | Name | Revision Description |
|---|
Referenced Terms
- CUI
- Information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies.
Revision History
- 2026-08-20 — Darren Rush
- Merge pull request #2 from safire-dev/dev (
16cb681)