Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    [email protected]

Media Protection Policy template for the FIPS 199 High categorization

A one-page media protection policy for commercial organizations that have elected to protect their information storage media at the High confidentiality impact level: healthcare, financial services, law enforcement, and defense suppliers holding CUI. It implements NIST SP 800-88 Rev. 2, including the sanitization decision flow, verification and validation, and the section 4.6 record fields, with tracking, staging, vendor, and legal-hold rules an auditor can test.

Version 1.2, reviewed 2026-09-22. Free under CC BY 4.0. Not legal or assessment advice.

Who it is for

Organizations whose loss of confidentiality would have a severe or catastrophic effect: hospitals and practices under HIPAA, banks and credit unions under GLBA, police departments and courts under CJIS, and defense contractors and suppliers with CUI under NIST 800-171 and CMMC. If that is not you, use the Moderate edition.

What is inside

  • Purpose, scope, and categorization: who the High election is for, and every media type it covers
  • Tracking: serial at deployment and removal, two names on every removal, marking, physical reconciliation on a schedule, 30-day staging in sealed containers
  • The sanitization decision flow at High, adapted from SP 800-88 Rev. 2 Figure 1
  • A technique table by media type: magnetic, solid-state, hybrid and HAMR, internal reuse, and devices found empty
  • Equipment criteria: byproducts appropriate to the data sensitivity, NSA/CSS Evaluated Products List equipment preferred
  • Records and retention: the Rev. 2 section 4.6 fields, the certificate, and a legal-hold authority
  • Vendor requirements and roles

The decision flow, as the policy states it

  1. Categorize. All media under the policy is High.
  2. Will the media be reused? Failed, obsolete, end-of-life, or not needed: Destroy.
  3. If reused, will it leave organizational control? Internal reuse at High requires Purge; Clear is not sufficient. Media leaving control (sale, donation, lease return, warranty exchange, recycler) requires Destroy.
  4. Sanitize with the technique for the media type: degauss then shred or deform for magnetic media; disintegration to 2 mm or smaller for solid-state; boards separated and disintegrated for hybrid drives; disintegrate, melt, or incinerate for HAMR.
  5. Verify and validate. Inspect the outcome and identify the equipment; a named title records a decision that it met the policy; a rejected outcome is re-sanitized by a stronger method.
  6. Document with the section 4.6 fields, then dispose or redeploy.

Two lines from Rev. 2 shape the table: degaussing alone is Purge, not Destroy (section 3.1.2), and shredding alone should be avoided for anything but the lowest security categories (section 3.1.3).

How to adapt it

  1. Fill the header: organization name, policy owner, effective date.

  2. Replace every [Title] with the role that will actually do the work: media custodian, information security, records management, compliance.

  3. Set the retention period (six years is the placeholder) to match your contracts and regulators.

  4. Decide whether your solid-state acceptance size is 2 mm (the default) or something your regulator specifies.

  5. Name your destruction vendor in section 5 and confirm they meet every condition listed, or strike the ones you cannot verify.

What it rests on

  • 32 CFR Part 2002, section 2002.14
    The CUI rule: Moderate is the floor, classified-grade methods are accepted, and destruction must be unreadable, indecipherable, and irrecoverable.
  • NIST SP 800-88 Rev. 2
    Sections 4.1 (policy elements), 4.5 (verification and validation), 4.6 (documentation), and Appendix C (the certificate).
  • DCSA, Guidance for Destroying CUI (2022)
    Custody, timing, access, and documentation for contracted destruction; paper particle sizes.
  • HIPAA 45 CFR 164.310(d), GLBA Safeguards, FACTA, CJIS Media Protection, IRS 1075
    The regulatory anchors listed in the policy footer.

Primary sources are linked on the Standards page.

Questions

  • Is a written media protection policy required for CMMC?

    NIST SP 800-171 requirement 3.8.3 and the 800-171A assessment objectives require that CUI media be sanitized or destroyed and that you can show how. A written policy is the usual evidence that the practice is defined, repeatable, and owned by someone, and Rev. 2 of SP 800-88 says a sanitization program should start with one.

  • Why does the template say shredding alone is not enough?

    NIST SP 800-88 Rev. 2 section 3.1.3 says pulverize and shred techniques should be avoided for anything but the lowest security categories, because data density and material hardness can leave recoverable fragments. At High, the policy requires degaussing first for magnetic media and disintegration to a small particle size for solid-state media.

  • Can we use this with a different destruction vendor?

    Yes. Section 5 lists the conditions a vendor must meet; it does not name one. Any vendor that destroys on-site under your witness, uses equipment whose output meets your acceptance criterion, and provides a serial-level log and certificate qualifies.

More answers on the FAQ.

Other templates

Download the Word file

Need it tailored, or the destruction it describes?

Request a custom quote