id: "PS-06" title: "Access Agreements" family: "PS" family_name: "Personnel Security" sort_id: "ps-06" priority: "P2" implementation_level: "organization" enhancements: - ps-6.1 - ps-6.2 - ps-6.3
Develop and document access agreements for organizational systems;
Review and update the access agreements {{ insert: param, ps-06_odp.01 }} ; and
Verify that individuals requiring access to organizational information and systems:
Sign appropriate access agreements prior to being granted access; and
Re-sign access agreements to maintain access to organizational systems when access agreements have been updated or {{ insert: param, ps-06_odp.02 }}.
Guidance
Access agreements include nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements. Signed access agreements include an acknowledgement that individuals have read, understand, and agree to abide by the constraints associated with organizational systems to which access is authorized. Organizations can use electronic signatures to acknowledge access agreements unless specifically prohibited by organizational policy.
Assessment Objective: access agreements are developed and documented for organizational systems;
Assessment Objective: the access agreements are reviewed and updated {{ insert: param, ps-06_odp.01 }};
Assessment Objective: individuals requiring access to organizational information and systems sign appropriate access agreements prior to being granted access;
Assessment Objective: individuals requiring access to organizational information and systems re-sign access agreements to maintain access to organizational systems when access agreements have been updated or {{ insert: param, ps-06_odp.02 }}.
Personnel security policy
personnel security procedures
procedures addressing access agreements for organizational information and systems
access control policy
access control procedures
access agreements (including non-disclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements)
documentation of access agreement reviews, updates, and re-signing
system security plan
privacy plan
other relevant documents or records
Organizational personnel with personnel security responsibilities
organizational personnel who have signed/resigned access agreements
organizational personnel with information security and privacy responsibilities
Organizational processes for reviewing, updating, and re-signing access agreements
mechanisms supporting the reviewing, updating, and re-signing of access agreements