yourstate.us
48 CFR 1252.239-84

1252.239-84 Media Transport.

United States · 48 CFR — Federal Acquisition Regulations System · Status: effective

Get this as JSONEmbed this
Cite this
Citation
48 CFR 1252.239-84, 1252.239-84 Media Transport, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/249151
Permanent ID
ys:prov:249151@1
SHA-256
4704aba3b9e6485ad35c477209363e191f43b1acf14f754a1249096ee4867fe2

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

As prescribed in 1239.7204(i), insert a clause substantially as follows: (a) The Contractor shall document activities associated with the transport of DOT information stored on digital and non-digital media and employ cryptographic mechanisms to protect the confidentiality and integrity of this information during transport outside of controlled areas. This applies to— (1) Digital media containing DOT or other Federal agency or other sensitive or third-party provided information that requires protection must be encrypted using FIPS 140-2 [Contracting Officer insert required encryption mode, based on FIPS 199 risk category] when transported outside of controlled areas; and (2) Nondigital media must be secured using the same policies and procedures as paper. (b) Contractors shall ensure accountability for media containing DOT or other Federal agency or other sensitive or third-party provided information that is transported outside of controlled areas. This can be accomplished through appropriate actions such as logging and a documented chain of custody form. (c) DOT or other Federal agency sensitive or third-party provided information that resides on mobile/portable devices (e.g., USB flash drives, external hard drives, and SD cards) must be encrypted using FIPS 140-2 [Contracting Officer insert the required encryption mode based on FIPS 199 risk category]. All Federal agency data residing on laptop computing devices must be protected with NIST-approved encryption software.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.