This is an organizational aid, not a government-prescribed form, assessment result, or certification. Adapt it to your information, scope, contract, approved procedures, and applicable requirements. Do not place actual CUI or unnecessary personal data in a broadly accessible copy.
Scope or workflow:
Responsible owner: Review date:
1. Identify copies and responsibilities
- □ Confirm the information category and handling instructions with its owner. Record unresolved classification questions.
- □ Follow one authorized workflow through laptops, application caches, printers, paper, removable drives, and destination systems.
- □ Separate confirmed storage from possible copies still being investigated.
- □ Identify devices and media, their locations, responsible owners, permitted users, and approved transfer routes.
- □ Reconcile observations with the assessed inventory and applicable provider responsibilities.
2. Check handling and protection
- □ Check applicable access, marking, storage, transport, and removable-media rules against actual practice.
- □ Record effective settings and test results where relevant; do not rely only on a policy template.
- □ Confirm the approved treatment of paper at shift end and removable media after transfer.
- □ Review local storage and remote-access behavior before making a BYOD or scope decision.
- □ Record exceptions and their owners; an exception is not a declaration of compliance.
3. Plan sanitization before reuse or disposal
- □ Identify all relevant storage components and the proposed reuse, return, or disposal.
- □ Have the responsible person approve a method suitable for the medium, information, and operational constraints.
- □ Coordinate retention, backups, service terms, and safe operation before changing or destroying production media.
- □ Record the actual method, device or media identifier, operator, and completion date.
- □ Record verification of the operation and review whether the outcome is acceptable.
- □ Keep control of media with failed or unresolved sanitization until the responsible person decides the next action.
4. Assemble the supporting evidence
- □ Approved procedures and assigned responsibilities.
- □ Inventory reconciled to observed devices, storage, and physical copies.
- □ Effective configuration and operating records, with coverage and collection limitations.
- □ Sanitization or destruction records with meaningful verification information when performed.
- □ Open gaps, resulting changes, and subsequent checks.
A log supports accountability. It does not alone establish encryption, marking, effective restrictions, sanitization, or satisfaction of every applicable assessment objective.
Inventory field guide
| CSV fields | What to record |
|---|---|
| Asset identifier; medium; owner; location | The actual device or medium and the responsible person or role. Use identifiers rather than controlled content. |
| Classification reference; authorized use; handling restrictions | The applicable decision or instruction, permitted route, and required storage or handling. |
| Method and approval reference | The selected sanitization method and who approved it. Approval is not completion. |
| Completion date; performed by | What actually happened and when. Leave blank until performed; include timezone. |
| Verification; verified by and date | The check, observed result, reviewer, and date. Record failure or uncertainty explicitly. |
| Exceptions; evidence reference | Unresolved issues, responsible follow-up, and the protected location of supporting records. |
Sources and companion guide
Requirements: NIST SP 800-171 Rev. 2, media protection requirements. Assessment procedures: SP 800-171A, June 2018. Current sanitization guidance: SP 800-88 Rev. 2. These documents have different purposes; confirm the requirement version applicable to your assessment.
Read the worked guide to CUI on laptops, printers, and USB drives.