36 MAC Pt. 1, R. 11.1
Media Protection
Cite as 36 Miss. Admin. Code Pt. 1, R. 11.1
Media Protection
A. Each agency must protect (i.e., physically control and securely store) all sensitive
stored data, both hard copy and digital media, on all systems (agency-managed and
hosted). All sensitive data on digital media must be protected using an encryption
protocol.
1. Media is defined as any medium in which data can be stored, recorded, or
printed. This includes both digital and non-digital media.
i.
Digital media is a form of content that is stored in a digital format,
which can be easily accessed and manipulated using electronic
devices. Examples of electronic devices include but are not limited to
computers, smartphones, tablets, flash storage, diskettes, magnetic
tapes, external or removable hard disk drives (e.g., solid state,
magnetic), compact discs, and digital versatile discs. Digital media
encompasses a wide range of multimedia content, including text,
images, audio, video, and interactive elements, and it is often
distributed through the internet and various digital communication
channels.
2. Non-digital media includes all data storage and records which are not stored
within an electronic device. This includes but is not limited to paper and
microfilm.
3. Securely storing sensitive digital data includes implementing industry
approved encryption protocols. All media storage devices that store sensitive
data should employ a hardware-level encryption solution, such as Windows
BitLocker or Linux dm-crypt. All portable media must employ an encryption
methodology that requires a password, token, or other means of authentication
to decrypt.
4. All devices which store sensitive information must be included in an
automated or manually maintained inventory. Each agency must employ a
procedure for documenting access requests and the return of both digital and
non-digital storage media. Digital media storage devices should be cataloged
with a make, model, and other identifying information, as well as the
responsible party.
5. Media storage solutions must be appropriate for the data which it will contain.
For example, backups of sensitive data should be stored via encrypted hard
drives or tapes as opposed to flash drives. All media storage devices and
records should be classified according to the sensitivity of the data stored
within.
6. Storage media may not be subject to the above security standards if it only
contains data that has been determined to be in the public domain, publicly
releasable, or have limited adverse impacts if accessed by other than
authorized personnel. Each agency must employ a process classifying
sensitive and non-sensitive data that includes approval by key stakeholders.
B. Each agency must limit access to sensitive data on digital and non-digital media to
only authorized users based on a user’s need to know.
1. Apply data access control lists, also known as access permissions, to local and
remote file systems, databases, and applications.
C. Each agency must sanitize or destroy digital and non-digital system media containing
sensitive data before disposal or release for reuse.
1. Establish a data retention policy that defines when sensitive data must be
destroyed.
2. Ensure the disposal process and method are commensurate with the data
sensitivity.
3. Examples of the types of digital media include scanners, copiers, printers,
notebook computers, workstations, network components, mobile devices.
4. Examples of the types of non-digital media include paper and microfilm.
5. Sanitize or destroy digital and non-digital system media containing sensitive
data before disposal or release for reuse.
i.
The sanitization process removes information from system media such
that the information cannot be retrieved or reconstructed.
ii.
Acceptable sanitization techniques may include clearing, purging,
cryptographic erasure of digital media, de-identification of personally
identifiable information, and destruction. Non-digital media should be
thoroughly scrubbed to remove all sensitive data prior to release or
rendered irrecoverable via cross-cut shredding or incineration. Digital
media should be destroyed via methods such as low-level wiping,
degaussing, or physical destruction.
6. Ensure that all sensitive data stored and/or hosted by third parties is sanitized
or destroyed. The agency should require that the third-party provide
certificates of destruction or sanitization when the process is complete.
7. Ensure that appropriate confidentiality agreements are in place for all sensitive
agency data stored and/or hosted by third parties.
D. Each agency must review sensitive data and determine if the media should be marked
with necessary confidentiality markings and distribution limitations.
1. Examples of where data may not need to be marked include publicly
releasable data or data that remains in secure areas controlled by the agency.
E. Each agency must control access to media containing sensitive data when outside of
controlled areas via hardware-level encryption or password authentication on all
digital media.
1. All media, both digital and non-digital must be assigned to a responsible party
prior to its departure from a controlled area via a documented process. This
may be satisfied through a log sheet that denotes the responsible party and a
timestamp of the media’s departure and return or an automated inventory
system.
F. Each agency must encrypt sensitive data stored on digital media.
G. Each agency must control the use of removable media on system components.
1. Limit the use of portable storage devices to only approved devices, including
devices provided by the agency, devices provided by other approved entities,
and devices that are not personally owned.
2. Portable storage devices must be restricted to functionality only necessary for
their intended purpose. Devices which do not require the ability to be written
to should be configured as “Read Only”.
3. Disable autorun and autoplay functionality for removable media.
4. Configure antimalware software to automatically scan removable media.
H. Each agency must prohibit the use of portable storage devices when such devices
have no identifiable owner.
I. Each agency must protect recovery/backup data with equivalent controls to the
original data. This includes encryption and data separation, based on requirements.