NIST 800-53 r5 · Controls catalogue · Family MP
MP-4Media Storage
Physically control and securely store {{ insert: param, mp-4_prm_1 }} within {{ insert: param, mp-4_prm_2 }} ; and Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved equipment, techniques, and procedures.
Last updated: 11 August 2026 23:24 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (2)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 10,900+ | Secure storage and protection of media until destruction or sanitization prevents unauthorized actors from accessing sensitive information on the media. |
CWE-1263 | Improper Physical Access Control | 13 | Physically controlling and securely storing media directly implements proper physical access controls for system media. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2020-36899 | 6.0 | 7.5 | 0.0094 | good |
CVE-2024-12330 UPD | 5.9 | 7.5 | 0.0051 | good |
CVE-2024-56462 UPD | 5.4 | 7.2 | 0.0046 | good |
CVE-2025-3773 UPD | 4.1 | 5.5 | 0.0012 | good |
CVE-2024-3124 UPD | 2.3 | 2.4 | 0.0028 | good |
CVE-2024-3128 UPD | 2.3 | 2.4 | 0.0027 | good |
CVE-2024-3430 UPD | 2.2 | 2.4 | 0.0022 | good |
CVE-2024-2364 UPD | 1.9 | 1.8 | 0.0033 | good |
CVE-2024-2567 UPD | 1.8 | 1.8 | 0.0021 | good |
CVE-2026-2974 UPD | 2.1 | 2.5 | 0.0010 | good |
CVE-2026-13514 | 2.1 | 2.4 | 0.0013 | good |