NIST 800-171 Controls · Media Protection
MP.2.124 — Control use of removable media on system components
Control the use of removable media on system components.
What MP.2.124 means in plain English
USB drives, external hard drives, SD cards, and any other plug-in storage devices are a major data security risk — employees can accidentally (or intentionally) copy CUI onto an unencrypted thumb drive and lose it. You need a policy and technical controls that define who can use removable media, on which computers, and under what conditions. The simplest approach for a small company: block all USB storage by default using Group Policy, and only allow it on specific approved machines for employees who have a documented business need. Require that any approved USB drives are encrypted.
The assessment question
“Is the use of removable media technically restricted on company systems — with approved use limited to authorized personnel, authorized media, and documented business purposes?”
How to implement MP.2.124
- Block all USB storage devices by default using Group Policy: Computer Configuration > Administrative Templates > System > Removable Storage Access > set "All Removable Storage Classes: Deny all access" to Enabled.
- Create an exception process: employees who have a legitimate business need for USB storage must submit a request, receive management approval, and be issued a company-owned encrypted USB drive (IronKey or BitLocker To Go).
- For approved USB use, require BitLocker To Go (built-in, free) on all company USB drives — this forces anyone who finds a lost drive to know the password before accessing files.
- Document each approved exception: employee name, device description, serial number, purpose, and expiration date for the exception.
- Monitor USB device connections via Windows Event Logs or Microsoft Defender for Endpoint (included in M365 Business Premium) — alert on any unapproved USB connection attempts.
Evidence your assessor will ask for
- Group Policy configuration showing removable storage access blocked by default
- Removable Media Exception Register with approved USB users, devices, and purposes
- BitLocker To Go configuration screenshots for company-issued USB drives
- USB device connection audit log showing monitoring is active
- Removable Media Policy document
Does AI prompt monitoring help with this control? Honestly, no.
MP.2.124 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Media Protection controls
Protect system media containing CUI
MP.1.119Limit access to CUI on system media
MP.1.120Sanitize or destroy system media before disposal or reuse
MP.2.121Mark media with necessary CUI markings and distribution limitations
MP.2.122Control access to media containing CUI during transport
MP.2.123Implement cryptographic mechanisms to protect CUI during transport
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.