3.15.3

  • Requirement

    a. Establish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.
    b. Provide rules to individuals who require access to the system.
    c. Receive a documented acknowledgement from individuals indicating that they have read, understand, and agree to abide by the rules of behavior before authorizing access to CUI and the system.
    d. Review and update the rules of behavior [Assignment: organization-defined frequency].

  • Discussion

    Rules of behavior represent a type of access agreement for system users. Organizations consider rules of behavior for the handling of CUI based on individual user roles and responsibilities and differentiate between rules that apply to privileged users and rules that apply to general users.

More Info

  • Family

    Planning
  • Related NIST 800-53 ID

    PL-04
  • Reference Documents

    • N/A

NIST 800-171A r3 Assessment Guidance

CMMC Training

Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!