NIST800-PL-4 PL-4 Rules of Behavior
NIST800-PL-4 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
PL-4 Rules of Behavior. a. Establish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for information and system usage, security, and privacy; b. Receive a documented acknowledgment from such individuals, indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the system; c. Review and update the rules of behavior [Assignment: organization-defined frequency]; and d. Require individuals who have acknowledged a previous version of the rules of behavior to read and re-acknowledge [Selection (one or more): [Assignment: organization-defined.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1) (closest match)
- SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3) (closest match)
- SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5) (closest match)
- SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14) (closest match)
- SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12) (closest match)
HIPAA Security Rule
- 164.310(b) Workstation Use (Standard) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: PL - Planning), in our words, not a statement of the standard and not binding on an assessor.
- the planning policy
- the system security and privacy plans