System Use Notification

✓ LOW ✓ MODERATE ✓ HIGH
1 Overlay 3 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

    1. 1.Users are accessing a U.S. Government system;
    2. 2.System usage may be monitored, recorded, and subject to audit;
    3. 3.Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and
    4. 4.Use of the system indicates consent to monitoring and recording;
    1. 1.Display system use information [conditions] , before granting further access to the publicly accessible system;
    2. 2.Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
    3. 3.Include a description of the authorized uses of the system.
Discussion (NIST Supplemental Guidance)

System use notifications can be implemented using messages or warning banners displayed before individuals log in to systems. System use notifications are used only for access via logon interfaces with human users. Notifications are not required when human interfaces do not exist. Based on an assessment of risk, organizations consider whether or not a secondary system use notification is needed to access applications or other system resources after the initial network logon. Organizations consider system use notification messages or banners displayed in multiple languages based on organizational needs and the demographics of system users. Organizations consult with the privacy office for input regarding privacy messaging and the Office of the General Counsel or organizational equivalent for legal review and approval of warning banner content.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AC-8 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. system use notification message or banner to be displayed by the system to users before granting access to the system is defined;
  2. conditions for system use to be displayed by the system before granting further access are defined;
  3. <AC-08_ODP[01] system use notification> is displayed to users before granting access to the system that provides privacy and security notices consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines;
  4. the system use notification states that users are accessing a U.S. Government system;
  5. the system use notification states that system usage may be monitored, recorded, and subject to audit;
  6. the system use notification states that unauthorized use of the system is prohibited and subject to criminal and civil penalties; and
  7. the system use notification states that use of the system indicates consent to monitoring and recording;
  8. the notification message or banner is retained on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system;
  9. for publicly accessible systems, system use information <AC-08_ODP[02] conditions> is displayed before granting further access to the publicly accessible system;
  10. for publicly accessible systems, any references to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities are displayed;
  11. for publicly accessible systems, a description of the authorized uses of the system is included.

Examine

[SELECT FROM: Access control policy; privacy and security policies, procedures addressing system use notification; documented approval of system use notification messages or banners; system audit records; user acknowledgements of notification message or banner; system design documentation; system configuration settings and associated documentation; system use notification messages; system security plan; privacy plan; privacy impact assessment; privacy assessment report; other relevant documents or records].

Interview

[SELECT FROM: System/network administrators; organizational personnel with information security and privacy responsibilities; legal counsel; system developers].

Test

[SELECT FROM: Mechanisms implementing system use notification].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)

HIGH

  • Base control: Included (matches standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AC-8. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Access control policy
  • privacy and security policies, procedures addressing system use notification
  • system security plan
  • privacy plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Mechanisms implementing system use notification

Other Records

  • documented approval of system use notification messages or banners
  • system audit records
  • user acknowledgements of notification message or banner
  • system use notification messages
  • privacy impact assessment
  • privacy assessment report
  • other relevant documents or records