NIST 800-171 Controls · Media Protection

MP.1.120Sanitize or destroy system media before disposal or reuse

CMMC Level 1SPRS if unmet: -3HIGH priority~4h to implement

Sanitize or destroy information system media before disposal or reuse.

What MP.1.120 means in plain English

Before you throw away, sell, donate, or repurpose a computer, hard drive, USB drive, or printed document that contained CUI, you must make sure the data is unrecoverable. Simply deleting files or formatting a hard drive is NOT enough — the data can be recovered with free tools. You must use a secure wipe tool (like DBAN for hard drives), physically destroy the drive (drilling or degaussing), or use a certified destruction vendor. For paper, use a cross-cut shredder. For your small company, the easiest approach is: wipe drives with DBAN before any device leaves your control, or physically destroy the drive.

The assessment question

Is all media sanitized using NIST 800-88-compliant methods (secure wipe, physical destruction, or certified third-party destruction) before disposal, recycling, or repurposing — and is each disposal event documented?

How to implement MP.1.120

  1. Create a Media Disposal Procedure: before any device is discarded, sold, donated, or returned to a vendor, run the Media Disposal Checklist — determine if it ever stored CUI, and if so, perform appropriate sanitization.
  2. For hard drives and SSDs containing CUI: use DBAN (for HDDs, free) or manufacturer secure erase utilities (for SSDs) to perform a full overwrite or cryptographic erase before disposal.
  3. For BitLocker-encrypted drives: decrypting and wiping, OR destroying the BitLocker key (which makes data unrecoverable) qualifies as cryptographic sanitization per NIST 800-88.
  4. For paper CUI: shred with a P-4 cross-cut shredder or use a certified document destruction service (Iron Mountain, Shred-it) with a Certificate of Destruction.
  5. Maintain a Media Disposal Log: Device/Media Description, Serial Number if applicable, Date, CUI Present (Y/N), Sanitization Method, Performed By, and Certificate of Destruction number if applicable.

Evidence your assessor will ask for

  • Media Disposal Procedure document
  • Media Disposal Log for the past 12 months
  • Certificates of Destruction from any third-party media destruction vendor
  • Screenshots of DBAN or secure erase completion screens (or photos of physically destroyed media)
  • Cross-cut shredder in inventory (receipt or photo)

Does AI prompt monitoring help with this control? Honestly, no.

MP.1.120 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.

Full mapping: which 800-171 controls AI prompt monitoring evidences →

More Media Protection controls

Score yourself against all 110 controls

The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.