PL-04 Rules Of Behavior

Planning

Low Moderate High Privacy

Description

The organization establishes and makes readily available to all information system users, a set of rules that describes their responsibilities and expected behavior with regard to information and information system usage. The organization receives signed acknowledgment from users indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to the information system and its resident information.\n

Supplemental Guidance

Electronic signatures are acceptable for use in acknowledging rules of behavior unless specifically prohibited by organizational policy. NIST Special Publication 800-18 provides guidance on preparing rules of behavior.\n

Changes from Rev 4

Control text adds privacy and other minor rewording Adds a selection parameter for action to be taken when rules of behavior change Discussion expanded to provide examples Incorporates acceptance of responsibilities elements of withdrawn App J control AR-5

Enhancements

(0) None.\n

Compliance Mappings

ISO 27001:2022

7.37.3(a)7.3(b)7.3(c)

ISO 27002:2022

5.105.145.46.2

CIS Controls v8

9.4

NIST CSF 2.0

ID.AM

SOC 2 TSC

CC1.1

ISO 17799 (legacy)

7.1.38.1.315.1.5

COBIT 4.1 (legacy)

PO6.5DS5.2PC4