Skip to content

PL-4: Rules of Behavior

An OSCAL Control

Statement

    • a.

      Establish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for information and system usage, security, and privacy;

    • b.

      Receive a documented acknowledgment from such individuals, indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the system;

    • c.

      Review and update the rules of behavior ; and

    • d.

      Require individuals who have acknowledged a previous version of the rules of behavior to read and re-acknowledge .