Rules of Behavior

✓ LOW ✓ MODERATE ✓ HIGH
1 Enhancement 1 Overlay 19 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Rules of behavior represent a type of access agreement for organizational users. Other types of access agreements include nondisclosure agreements, conflict-of-interest agreements, and acceptable use agreements (see PS-6 ). Organizations consider rules of behavior based on individual user roles and responsibilities and differentiate between rules that apply to privileged users and rules that apply to general users. Establishing rules of behavior for some types of non-organizational users, including individuals who receive information from federal systems, is often not feasible given the large number of such users and the limited nature of their interactions with the systems. Rules of behavior for organizational and non-organizational users can also be established in AC-8 . The related controls section provides a list of controls that are relevant to organizational rules of behavior. PL-4b , the documented acknowledgment portion of the control, may be satisfied by the literacy training and awareness and role-based training programs conducted by organizations if such training includes rules of behavior. Documented acknowledgements for rules of behavior include electronic or physical signatures and electronic agreement check boxes or radio buttons.

Enhancements NIST SOURCE

PL-4(1) Social Media and External Site/Application Usage Restrictions ✓ LOW ✓ MODERATE ✓ HIGH

Include in the rules of behavior, restrictions on:

  1. (a) Use of social media, social networking sites, and external sites/applications;
  2. (b) Posting organizational information on public websites; and
  3. (c) Use of organization-provided identifiers (e.g., email addresses) and authentication secrets (e.g., passwords) for creating accounts on external sites/applications.
Discussion

Social media, social networking, and external site/application usage restrictions address rules of behavior related to the use of social media, social networking, and external sites when organizational personnel are using such sites for official duties or in the conduct of official business, when organizational information is involved in social media and social networking transactions, and when personnel access social media and networking sites from organizational systems. Organizations also address specific rules that prevent unauthorized entities from obtaining non-public organizational information from social media and networking sites either directly or through inference. Non-public information includes personally identifiable information and system account information.

Open full page for PL-4(1) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for PL-4 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. frequency for reviewing and updating the rules of behavior is defined;
  2. one or more of the following PARAMETER VALUES is/are selected: { <PL-04_ODP[03] frequency>; when the rules are revised or updated};
  3. frequency for individuals to read and re-acknowledge the rules of behavior is defined (if selected);
  4. rules that describe responsibilities and expected behavior for information and system usage, security, and privacy are established for individuals requiring access to the system;
  5. rules that describe responsibilities and expected behavior for information and system usage, security, and privacy are provided to individuals requiring access to the system;
  6. before authorizing access to information and the system, a documented acknowledgement from such individuals indicating that they have read, understand, and agree to abide by the rules of behavior is received;
  7. rules of behavior are reviewed and updated <PL-04_ODP[01] frequency>;
  8. individuals who have acknowledged a previous version of the rules of behavior are required to read and reacknowledge <PL-04_ODP[02] SELECTED PARAMETER VALUES>.

Examine

[SELECT FROM: Security and privacy planning policy; procedures addressing rules of behavior for system users; rules of behavior; signed acknowledgements; records for rules of behavior reviews and updates; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with responsibility for establishing, reviewing, and updating rules of behavior; organizational personnel with responsibility for literacy training and awareness and role-based training; organizational personnel who are authorized users of the system and have signed and resigned rules of behavior; organizational personnel with information security and privacy responsibilities].

Test

[SELECT FROM: Organizational processes for establishing, reviewing, disseminating, and updating rules of behavior; mechanisms supporting and/or implementing the establishment, review, dissemination, and update of rules of behavior].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)
  • Included: (1)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for PL-4. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Security and privacy planning policy

Testing

  • Organizational processes for establishing, reviewing, disseminating, and updating rules of behavior
  • mechanisms supporting and/or implementing the establishment, review, dissemination, and update of rules of behavior

Other Records

  • procedures addressing rules of behavior for system users
  • rules of behavior
  • signed acknowledgements
  • records for rules of behavior reviews and updates
  • other relevant documents or records