NIST 800-53 r5 · Controls catalogue · Family MP
MP-7Media Use
{{ insert: param, mp-07_odp.02 }} the use of {{ insert: param, mp-07_odp.01 }} on {{ insert: param, mp-07_odp.03 }} using {{ insert: param, mp-07_odp.04 }} ; and Prohibit the use of portable storage devices in organizational systems when such devices have no identifiable owner.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (6)
- T1025 Data from Removable Media Collection
- T1052 Exfiltration Over Physical Medium Exfiltration
- T1052.001 Exfiltration over USB Exfiltration
- T1091 Replication Through Removable Media Lateral Movement, Initial Access
- T1092 Communication Through Removable Media Command And Control
- T1200 Hardware Additions Initial Access
Weaknesses this control addresses (4)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-284 | Improper Access Control | 6,900+ | This control enforces ownership-based restrictions on portable storage device use, directly implementing access control over media insertion into organizational systems. |
CWE-434 | Unrestricted Upload of File with Dangerous Type | 5,100+ | Requiring identifiable owners for portable devices reduces the attack surface for unrestricted uploads of dangerous file types via anonymous media. |
CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | 300+ | Unowned portable devices represent untrusted control spheres; the prohibition prevents inclusion of functionality or data from such sources. |
CWE-1263 | Improper Physical Access Control | 13 | Prohibiting portable storage devices without identifiable owners is a direct physical access control measure limiting untraceable media interaction with systems. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||