36 MAC Pt. 1, R. 11.1

Media Protection

Year: 2026Length: 946 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 11.1

Media Protection A. Each agency must protect (i.e., physically control and securely store) all sensitive stored data, both hard copy and digital media, on all systems (agency-managed and hosted). All sensitive data on digital media must be protected using an encryption protocol. 1. Media is defined as any medium in which data can be stored, recorded, or printed. This includes both digital and non-digital media. i. Digital media is a form of content that is stored in a digital format, which can be easily accessed and manipulated using electronic devices. Examples of electronic devices include but are not limited to computers, smartphones, tablets, flash storage, diskettes, magnetic tapes, external or removable hard disk drives (e.g., solid state, magnetic), compact discs, and digital versatile discs. Digital media encompasses a wide range of multimedia content, including text, images, audio, video, and interactive elements, and it is often distributed through the internet and various digital communication channels. 2. Non-digital media includes all data storage and records which are not stored within an electronic device. This includes but is not limited to paper and microfilm. 3. Securely storing sensitive digital data includes implementing industry approved encryption protocols. All media storage devices that store sensitive data should employ a hardware-level encryption solution, such as Windows BitLocker or Linux dm-crypt. All portable media must employ an encryption methodology that requires a password, token, or other means of authentication to decrypt. 4. All devices which store sensitive information must be included in an automated or manually maintained inventory. Each agency must employ a procedure for documenting access requests and the return of both digital and non-digital storage media. Digital media storage devices should be cataloged with a make, model, and other identifying information, as well as the responsible party. 5. Media storage solutions must be appropriate for the data which it will contain. For example, backups of sensitive data should be stored via encrypted hard drives or tapes as opposed to flash drives. All media storage devices and records should be classified according to the sensitivity of the data stored within. 6. Storage media may not be subject to the above security standards if it only contains data that has been determined to be in the public domain, publicly releasable, or have limited adverse impacts if accessed by other than authorized personnel. Each agency must employ a process classifying sensitive and non-sensitive data that includes approval by key stakeholders. B. Each agency must limit access to sensitive data on digital and non-digital media to only authorized users based on a user’s need to know. 1. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications. C. Each agency must sanitize or destroy digital and non-digital system media containing sensitive data before disposal or release for reuse. 1. Establish a data retention policy that defines when sensitive data must be destroyed. 2. Ensure the disposal process and method are commensurate with the data sensitivity. 3. Examples of the types of digital media include scanners, copiers, printers, notebook computers, workstations, network components, mobile devices. 4. Examples of the types of non-digital media include paper and microfilm. 5. Sanitize or destroy digital and non-digital system media containing sensitive data before disposal or release for reuse. i. The sanitization process removes information from system media such that the information cannot be retrieved or reconstructed. ii. Acceptable sanitization techniques may include clearing, purging, cryptographic erasure of digital media, de-identification of personally identifiable information, and destruction. Non-digital media should be thoroughly scrubbed to remove all sensitive data prior to release or rendered irrecoverable via cross-cut shredding or incineration. Digital media should be destroyed via methods such as low-level wiping, degaussing, or physical destruction. 6. Ensure that all sensitive data stored and/or hosted by third parties is sanitized or destroyed. The agency should require that the third-party provide certificates of destruction or sanitization when the process is complete. 7. Ensure that appropriate confidentiality agreements are in place for all sensitive agency data stored and/or hosted by third parties. D. Each agency must review sensitive data and determine if the media should be marked with necessary confidentiality markings and distribution limitations. 1. Examples of where data may not need to be marked include publicly releasable data or data that remains in secure areas controlled by the agency. E. Each agency must control access to media containing sensitive data when outside of controlled areas via hardware-level encryption or password authentication on all digital media. 1. All media, both digital and non-digital must be assigned to a responsible party prior to its departure from a controlled area via a documented process. This may be satisfied through a log sheet that denotes the responsible party and a timestamp of the media’s departure and return or an automated inventory system. F. Each agency must encrypt sensitive data stored on digital media. G. Each agency must control the use of removable media on system components. 1. Limit the use of portable storage devices to only approved devices, including devices provided by the agency, devices provided by other approved entities, and devices that are not personally owned. 2. Portable storage devices must be restricted to functionality only necessary for their intended purpose. Devices which do not require the ability to be written to should be configured as “Read Only”. 3. Disable autorun and autoplay functionality for removable media. 4. Configure antimalware software to automatically scan removable media. H. Each agency must prohibit the use of portable storage devices when such devices have no identifiable owner. I. Each agency must protect recovery/backup data with equivalent controls to the original data. This includes encryption and data separation, based on requirements.
36 MAC Pt. 1, R. 11.1: Media Protection | Justis AI