A diagnostic USB media RACI matrix cmmc implementation should assign IT responsibility for intake and approved use, Security accountability for malware-verification standards and incident decisions, HR responsibility for role-based awareness, Legal consultation on vendor and contractual obligations, and Leadership accountability for resources and risk acceptance. For CMMC 2.0 Level 2 practice MA.L2-3.7.4, every diagnostic or test program must be checked for malicious code before it is used on an organizational system that processes, stores, or transmits CUI.
Why does a diagnostic USB media RACI matrix cmmc approach prevent control gaps?
MA.L2-3.7.4 can look narrow: scan diagnostic and test media before use. After a near-miss, however, an ISSO or FSO usually finds that the failure was not simply “antivirus was off.” The technician believed a vendor-provided USB was urgent, the help desk had no intake ticket, Security had no opportunity to assess the file, and management had never decided who could accept the operational risk of bypassing the process.
A RACI model closes that gap by making four decisions explicit for each step:
- Responsible (R): the person or team that performs the work.
- Accountable (A): the single owner who approves the outcome and is answerable for the control.
- Consulted (C): parties whose input is required before a decision is finalized.
- Informed (I): parties who need notice after the activity or decision occurs.
The distinction between responsible and accountable matters most during urgent troubleshooting. A systems administrator may be responsible for scanning a firmware diagnostic utility, but the Security function should be accountable for the approved scanning method, exception criteria, and disposition of suspicious media. Leadership is not expected to scan a USB drive; it is accountable for ensuring sufficient staffing, tooling, and authority exist to enforce the process.
MA.L2-3.7.4 extends the malicious-code protections required by SI.L2-3.14.2 and SI.L2-3.14.4 to diagnostic and testing tools. Treat a vendor utility, bootable recovery drive, device-driver disc, controller firmware package, and field-service laptop transfer as executable-code risk—not as harmless support material. A documented USB media RACI model prevents the informal “just plug it in once” path that creates both compromise risk and weak assessment evidence.
What is the full RACI matrix for MA.L2-3.7.4?
Use the following matrix as the operating baseline. “IT” includes help desk, endpoint, infrastructure, and system administrators; “Security” includes the ISSO, security analyst, or managed security function. Assign named roles in your policy and ticket workflow rather than leaving responsibility at the department level.
| Control activity | IT | Security | HR | Legal | Leadership | Required evidence |
|---|---|---|---|---|---|---|
| Maintain the written diagnostic-media procedure and approved scanning standard | C | R/A | C | C | I | Approved procedure, revision history, tool configuration baseline |
| Receive media, create intake ticket, label it, and place it in controlled storage | R/A | C | I | I | I | Ticket number, source, custodian, date received, photo or asset record |
| Verify vendor source, download location, checksum, and authenticity documentation | R | A | I | C | I | Vendor advisory, hash comparison, purchase/service record, download URL |
| Scan diagnostic files and media in an approved isolated environment before organizational use | R | A | I | I | I | Microsoft Defender or equivalent scan log, engine/signature version, scan result, timestamp |
| Authorize use after a clean result and document the target system and purpose | R | A | I | I | I | Approval in ticket, target asset ID, technician name, use window |
| Quarantine media or files that are suspicious, unscannable, unsigned, or noncompliant | R | A | I | C | I | Quarantine record, detection details, preservation location, incident linkage |
| Decide whether to notify the vendor, invoke contractual remedies, or preserve evidence | C | R | I | A | I | Vendor notification decision, legal hold direction, correspondence record |
| Train personnel who may request, receive, scan, or use diagnostic media | C | R | A | C | I | Role-based training content, completion report, acknowledgement |
| Approve risk acceptance for an emergency exception when no compliant path exists | C | R | I | C | A | Time-bounded exception, compensating controls, approving executive, closure review |
| Review metrics, exceptions, and evidence quality | R | A | C | C | I | Quarterly review minutes, sample results, corrective-action tracker |
Do not allow a standing exception for “trusted vendors.” Vendor trust can inform source verification, but it does not replace malware scanning. If the media cannot be scanned because it uses an unsupported file system or proprietary boot format, Security should treat that as an exception or investigation—not as automatic authorization.
How should the RACI change for small organizations, MSPs, and federated teams?
What if one person fills several roles?
In a small contractor, the ISSO may also be the IT manager and the person receiving the media. That is workable only if accountability and independent review are still visible. The ISSO can be both R and A for scanning, but the president, operations director, or designated senior official should remain A for emergency risk acceptance. Require a second person to review a monthly sample of completed tickets and exceptions. Separation of duties may be limited; documented oversight should not be.
What if an MSP performs endpoint administration?
An MSP can be Responsible for scan execution and ticket documentation, but the contractor cannot outsource accountability for MA.L2-3.7.4. Retain Security accountability internally, define scan-tool access and log-retention requirements in the MSP agreement, and require escalation within a specified period, such as one hour for a detection or unscannable item. Legal should review whether the agreement addresses incident notification, evidence preservation, subcontractor access, and CUI handling.
What if business units operate independently?
In a federated organization, central Security should own the scanning standard and approval criteria while local IT remains responsible for intake and execution. A local warehouse, engineering site, or program office cannot substitute a different free scanner or maintain an unofficial “known good” USB collection. The diagnostic media RACI matrix should identify one enterprise evidence repository and one exception authority, even when systems are locally administered.
For example, Harbor Ridge Systems, a 145-person contractor supporting fleet sustainment, uses a segmented Windows Server environment for procurement records and CUI-bearing maintenance packages. A field technician received a USB drive containing a controller diagnostic application from an equipment vendor. Under its RACI, the technician opened a ServiceNow intake ticket and delivered the drive to IT; IT scanned it on an isolated workstation; the ISSO reviewed the unsigned executable and required a vendor hash before authorizing use. The delay was measurable, but it was far safer than connecting unknown executable code to the maintenance network.
How do you operationalize this RACI in a ticketing tool?
Your ticket should make the approved path easier than an informal workaround. Configure a ServiceNow catalog item, Jira Service Management request type, or equivalent workflow called Diagnostic/Test Media Intake. Restrict closure so IT cannot mark the request complete without Security approval and attached scan evidence.
Request type: Diagnostic/Test Media Intake Required fields: - Media source: Vendor / Internal / Customer / Other - Vendor name and service ticket number - Media serial number or asset tag - File names, SHA-256 hashes, and digital-signature status - Intended system asset ID and business purpose - Scan workstation: ISOLATED-SCAN-01 - Scan tools: Microsoft Defender Antivirus + CrowdStrike Falcon - Scan result: Clean / Detection / Error / Unscannable - Security approval: Required before "Authorized for Use" - Retention: Attach logs and retain ticket for 3 years Workflow: New -> IT Intake -> Source Verification -> Security Scan Review -> Authorized for Use OR Quarantined/Incident OR Exception Review -> Closed
Configure notification rules to reflect the RACI. IT receives assignment at intake; Security receives automatic notification for every submission and mandatory approval task; Legal receives notice only for vendor dispute, suspected compromise, or preservation needs; Leadership receives exception approvals and quarterly metric reports. HR should receive training completion exceptions, not routine media tickets.
A second worked example illustrates why workflow details matter. Northline Freight Technologies, a 90-person logistics software and hardware integrator, received a bootable USB utility to troubleshoot a failed ruggedized gateway used in a shipping-status workflow. Defender could not scan the boot partition. The ticket automatically routed to Exception Review; Security required the vendor’s signed ISO and SHA-256 value, then IT rebuilt the media from the verified download on controlled media. The original USB was retained in quarantine. That result demonstrates both enforcement and a defensible response to an unscannable item.
How often should leadership review this control and its RACI assignments?
Review the procedure and RACI assignments at least annually, after any malicious-media event or near miss, after a material tool or MSP change, and when a new system boundary begins handling CUI. Perform a quarterly operational review of completed tickets. Sample for source verification, scan logs, timestamps proving scanning occurred before use, Security approvals, exception closure, and the relationship between the ticket and the target asset.
Track a small set of metrics that reveal control health: total media requests, percentage scanned before use, unscannable-media count, detections, emergency exceptions, overdue approvals, and training completion for technicians and administrators. A rising exception count is usually a process-design problem—such as inadequate isolation equipment or unrealistic repair timelines—not merely an employee discipline problem.
Within the next five business days, assign named people to this matrix, test one diagnostic-media intake ticket from receipt through evidence retention, and brief leadership on any gap that would force an unsafe emergency exception.